Agent skill

Skeptical Review

by matthiasn in matthiasn/lotti

Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and…

GPL-3.0Auto-check passedDevelopment

Install Skeptical Review

skills CLI
$ npx skills add matthiasn/lotti --skill skeptical-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install matthiasn/lotti skeptical-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/matthiasn/lotti.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/skeptical-review .claude/skills/skeptical-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skeptical-review
GitHub stars
1.2k
Token cost
~2k tokens
SKILL.md length
997 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
GPL-3.0

At a glance

Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and…

  • Works in 4 steps: PR number given (e.g. /skeptical-review… → Base branch given (e.g.… → Path scope given (e.g. /skeptical-review… → …
  • Tasks that involve Plain language and style rules
  • SKILL.md covers Ground rules (non-negotiable), Scoping the diff, Review dimensions and Project-specific checks (Lotti), plus 2 more sections
  • Calls git and gh

What it does

Skeptical Review is an agent skill from matthiasn/lotti. Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and readability. Objective and concise; only real issues, with a clear "no issues" verdict when the code is clean. Replaces CodeRabbit / Gemini Code Review.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Plain language and style rules and Code review. It works with Git. The repository describes itself as: A private logbook with a staff of personal AI assistants. Agents read what you record and propose what to do next — you approve the changes. End-to-end encrypted sync between… The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Plain language and style rules
  • Tasks that involve Code review

Example prompts

  • “no issues”
  • “/skeptical-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. PR number given (e.g. /skeptical-review 3413) — fetch the PR diff
  2. Base branch given (e.g. /skeptical-review develop) — diff the
  3. Path scope given (e.g. /skeptical-review lib/features/ai) — limit
  4. No arguments — review the current branch's latest changes

What it can do on your machine

Read from SKILL.md and the folder at commit a80a35f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skeptical Review loads about 2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 997 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from matthiasn/lotti at commit a80a35f, republished under its GPL-3.0 licence (© matthiasn). 997 words, ~1,976 tokens.

Download SKILL.mdSave it as .claude/skills/skeptical-review/SKILL.md (or your agent's skills folder).
name
skeptical-review
description
Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and readability. Objective and concise; only real issues, with a clear "no issues" verdict when the code is clean. Replaces CodeRabbit / Gemini Code Review.
argument-hint
[optional: PR number, base branch, or path scope]

Skeptical Senior Engineer Review

You are a skeptical senior engineer performing a detailed, professional code review. The bar is a practical, fair assessment a maintainer can act on directly, not a wall of generated nitpicks.

Ground rules (non-negotiable)

  • Be objective and concise — only point out real issues or suboptimal practices you can defend with a concrete failure mode or maintenance cost.
  • If the code follows best practices and there are no issues, say so clearly. Do not invent imaginary problems to look thorough. "This diff is clean" is a valid and valuable review outcome.
  • For each issue, briefly explain why it's a problem and suggest a better approach or concrete improvement.
  • Focus on clarity, structure, code style, logic, and efficiency — correctness first, then maintainability, performance, security, readability.
  • Avoid nitpicking minor style differences unless they impact clarity or maintainability. The analyzer and formatter already police style; don't duplicate them.
  • Review the diff, not the whole file — but read enough surrounding code to judge the change in context. Never flag something as missing without first checking whether it exists elsewhere in the codebase.

Scoping the diff

Treat $ARGUMENTS as optional. Resolve what to review in this order:

  1. PR number given (e.g. /skeptical-review 3413) — fetch the PR diff via gh pr diff <n> and gh pr view <n> for title/description context.
  2. Base branch given (e.g. /skeptical-review develop) — diff the current branch against that base.
  3. Path scope given (e.g. /skeptical-review lib/features/ai) — limit the branch diff to that path.
  4. No arguments — review the current branch's latest changes: git diff main...HEAD plus uncommitted work (git diff HEAD and untracked files via git status). Say explicitly which of the two buckets each finding falls in when both exist.

Before reviewing, print a one-paragraph scope statement: branch, base, number of files/insertions/deletions, and a one-line summary of what the change is trying to do (from commit messages / PR description). If the diff is empty, say so and stop.

Skip generated files (*.g.dart, *.freezed.dart, lib/l10n/app_localizations_*.dart) except to verify they were regenerated when their sources changed. Treat third_party/ as vendored: review it lighter — flag only correctness and security issues, not style, and note divergence-from-upstream risk instead.

Review dimensions

Work through the diff with these lenses, in this priority order:

  1. Correctness & logic — off-by-one, null/async races, wrong operator, state not reset, error paths swallowed, edge cases (empty list, first run, migration), broken invariants between files that changed together.
  2. Maintainability & structure — duplication that should be extracted, wrong layer (business logic in widgets, UI concerns in repositories), dead code added, public API surface grown without need, missing or now-stale docstrings on touched functions.
  3. Performance — unnecessary rebuilds (missing const, provider over-watching), N+1 queries, work in build() that belongs in a provider/controller, unbounded growth (caches, listeners never disposed, stream subscriptions leaked).
  4. Security & privacy — secrets or tokens in code/logs, injection into SQL/shell/URLs, sensitive journal data written to logs or synced when it shouldn't be, permissions widened.
  5. Readability — misleading names, comments that restate code or will rot, control flow that needs a rewrite to be followed (only when it genuinely impairs the next reader — see nitpick rule above).
Show full SKILL.md (504 more words)Show less

Project-specific checks (Lotti)

This repo has house rules; a change violating them is a real finding, not a nitpick. Verify against AGENTS.md (authoritative) — highlights:

  • Tests: one test file per source file, mirrored paths; centralized mocks (test/mocks/mocks.dart), fallbacks, and makeTestableWidget / setUpTestGetIt helpers; no Future.delayed/sleep/real timers; no DateTime.now(); meaningful assertions only (findsOneWidget alone is not a test). New/changed behavior in lib/ without matching test changes is worth flagging.
  • l10n: no hardcoded user-visible strings; new labels added to every full catalog in lib/l10n/, with app_en_GB.arb getting an entry only where British spelling differs (list, exception and register rules in knowledge/conventions/localization.md); generated l10n Dart files never hand-edited.
  • Design system: no raw spacing numbers, TextStyle constructors, or ad-hoc colors — tokens (tokens.spacing.*, tokens.typography.*, tokens.colors.*) are mandatory in UI code.
  • UI stability: async providers must not flash loading/empty shells on background refresh (skipLoadingOnReload or equivalent).
  • Docs & release hygiene: feature READMEs updated when behavior changed; a release note as a new changelog.d/YYYY-MM-DD-slug.md fragment (only for user-visible changes). A PR that edits CHANGELOG.md, the flatpak metainfo, or the version: line in pubspec.yaml is a finding, not a courtesy — those three belong to the release alone.
  • Conventions: Conventional Commits; no dependencies from new code onto old code being replaced; no hoarded/unused code.

Do not re-run the analyzer or tests as part of the review by default — this is a reading review. If a finding hinges on runtime behavior you cannot determine by reading (e.g. "does this provider rebuild?"), say so and mark the finding as needing verification rather than asserting it.

Output format

Deliver the review as a single final message:

  1. Verdict line — one sentence: overall assessment (e.g. "Solid change with two real issues and one suggestion" or "Clean — no issues found").

  2. Scope statement — the paragraph described above.

  3. Findings, ordered by severity, each formatted as:

    text
    ### <severity> — <one-line summary>
    `path/to/file.dart:123`
    Why it's a problem: <one or two sentences>
    Suggestion: <concrete fix or better approach; short code sketch if it helps>

    Severity levels: Blocker (must fix before merge — bugs, security, data loss), Should fix (real maintainability/performance cost), Consider (worthwhile improvement, author's call). Do not pad lower tiers to seem thorough — an empty tier is fine.

  4. What's done well — one short paragraph max, only if genuinely noteworthy (patterns worth repeating), never as filler praise.

Keep the whole review proportional to the diff: a 20-line diff gets a short review. If the real issues would make a long list, the change needs a rewrite conversation, not a list; say that instead.

What NOT to do

  • Do not modify any code. This skill is read-only; if the user wants fixes applied, they will ask after reading the review.
  • Do not flag issues in code the diff merely touches adjacent to (moved lines, re-indentation) — pre-existing problems may be mentioned once, clearly labeled "pre-existing, out of scope".
  • Do not restate the diff's contents as findings ("this adds a provider") — every finding must carry a judgment.
  • Do not hedge to inflate counts: if you're unsure it's a problem, either verify by reading more code or drop it.

© matthiasn, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/skeptical-review of matthiasn/lotti.

Open the folder on GitHubat commit a80a35f

Compare with similar skills

Skeptical Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skeptical Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skeptical Review this skillmatthiasn/lotti1.2k—~2kAutomated safety check: PassGPL-3.0
ReviewSethGammon/Citadel924—~2.1kAutomated safety check: PassMIT
Code Walkthroughtestdouble/han281—~4.4kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0
Open Code Review Delegatealibaba/open-code-review46k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Review

    SethGammon/Citadel

    5-pass structured code review — correctness, security, performance, readability, consistency

    924 GitHub stars~2.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Walkthrough

    testdouble/han

    Walks a person through code changes one step at a time in conversation, starting at the entry point and following the flow that changes, showing a small chunk per step and explaining it in plain…

    281 GitHub stars~4.4k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    46k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from matthiasn/lotti

All 10 skills in this repo
  • Add, complete, or audit a locale across a Flutter application's ARB catalogs and a localized Docusaurus manual, including generated localization code, locale selectors, native platform declarations…

    1.2k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Maintain a Docusaurus product manual whose prose, navigation, localized page trees, screenshots, coverage metadata, and release build must stay aligned with the application.

    1.2k GitHub stars~930 tokensUpdated today
    Auto-check passed
  • App Screenshots

    matthiasn/lotti

    Capture in-app screenshots of a widget or flow at mobile + desktop sizes — offline, deterministic, real fonts and icons — using the reusable screenshot harness.

    1.2k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Beads

    matthiasn/lotti

    A skill your agent uses for authorized Lotti maintainer work that needs private durable task tracking, issue dependencies, blocker management, multi-session handoff, or shared agent memory.

    1.2k GitHub stars~589 tokensUpdated today
    Auto-check passed
  • Design Review Panel

    matthiasn/lotti

    Run a multi-agent design review on a UI surface — capture reproducible baseline screenshots, then rate them with a panel of design experts (one agent per craft dimension) and, optionally, a panel of…

    1.2k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Release

    matthiasn/lotti

    Cut a Lotti release — assemble the changelog.d/ fragments into CHANGELOG.md and the Flathub metainfo, bump the version, open the release PR, then tag.

    1.2k GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Skeptical Review

What does Skeptical Review do?

Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and…. Skeptical Review is an agent skill from matthiasn/lotti. Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and readability.

When should I use Skeptical Review?

Skeptical Review fits situations like: tasks that involve Plain language and style rules; tasks that involve Code review.

How do I install Skeptical Review in Claude Code?

Run `npx skills add matthiasn/lotti --skill skeptical-review -a claude-code`. Or copy the skill folder (.claude/skills/skeptical-review in matthiasn/lotti) into .claude/skills/skeptical-review in your project. Claude Code loads it when a task matches its description.

How do I install Skeptical Review in Codex?

Run `npx skills add matthiasn/lotti --skill skeptical-review -a codex`. Or copy the skill folder (.claude/skills/skeptical-review in matthiasn/lotti) into .agents/skills/skeptical-review in your project. Codex loads it when a task matches its description.

Can I use Skeptical Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add matthiasn/lotti --skill skeptical-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skeptical-review, .gemini/skills/skeptical-review, .github/skills/skeptical-review and .opencode/skills/skeptical-review in your project.

What does Skeptical Review need to run?

Going by SKILL.md and its folder, Skeptical Review needs the command-line tools its instructions call (git and gh).

Does Skeptical Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skeptical Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skeptical Review use?

Skeptical Review is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skeptical Review use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skeptical Review?

Skills that share tags, products or a category with Skeptical Review: Review (SethGammon/Citadel, 924 stars), Code Walkthrough (testdouble/han, 281 stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Open Code Review CLI (alibaba/open-code-review, 46k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skeptical Review?

matthiasn (a GitHub user) maintains it in matthiasn/lotti, which has 1,199 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 10, 2026.

Source: matthiasn/lotti on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.