Official agent skill

Review Loop

by microsoft in microsoft/bocpy

Iterative review loop with subagent reviewer. An agent skill from microsoft/bocpy.

OfficialMITAuto-check passedDevelopment

Install Review Loop

skills CLI
$ npx skills add microsoft/bocpy --skill review-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/bocpy review-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/review-loop .claude/skills/review-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-loop
GitHub stars
201
Token cost
~1.2k tokens
SKILL.md length
639 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Iterative review loop with subagent reviewer. An agent skill from microsoft/bocpy.

  • Works in 5 steps: Identify the Review Target → Spawn Reviewer Subagent → Present Findings → …
  • : reviewing code changes
  • SKILL.md covers When to Use, Severity Levels, Procedure and Guidelines
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review Loop is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Iterative review loop with subagent reviewer. Use when: reviewing code changes, reviewing plans, auditing implementations, validating fixes, running code review, performing quality checks, or when /review is invoked. Spawns a fresh subagent to review a user-specified target, reports severity-tagged findings, applies approved fixes, and repeats until the user is satisfied.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Subagents and Code review. The repository describes itself as: Behavior-Oriented Concurrency in Python. The licence is MIT.

When your agent uses it

  • : reviewing code changes
  • Reviewing plans
  • Auditing implementations
  • Validating fixes

Example prompts

  • “/review-loop”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify the Review Target
  2. Spawn Reviewer Subagent
  3. Present Findings
  4. Apply Fixes
  5. Check Exit Condition

What it can do on your machine

Read from SKILL.md and the folder at commit c8f3ceb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Loop loads about 1.2k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 639 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/bocpy at commit c8f3ceb, republished under its MIT licence (© microsoft). 639 words, ~1,211 tokens.

Download SKILL.mdSave it as .claude/skills/review-loop/SKILL.md (or your agent's skills folder).
name
review-loop
description
Iterative review loop with subagent reviewer. Use when: reviewing code changes, reviewing plans, auditing implementations, validating fixes, running code review, performing quality checks, or when /review is invoked. Spawns a fresh subagent to review a user-specified target, reports severity-tagged findings, applies approved fixes, and repeats until the user is satisfied.
argument-hint
Describe or reference the target to review (file paths, plan, diff, etc.)

Review Loop

Iteratively review a target (code or plan) using a fresh subagent reviewer, present findings, apply fixes, and repeat until the user approves.

When to Use

  • After implementing a non-trivial change
  • Validating a plan before execution
  • Auditing code for correctness, style, or security issues
  • Any time you want an independent second opinion on work in progress

Severity Levels

Findings are tagged with one of four severities:

SeverityMeaning
criticalCorrectness bug, security vulnerability, or data loss risk. Must fix.
highLikely bug, race condition, or significant design flaw. Should fix.
mediumCode smell, unclear logic, missing edge case, or maintainability concern. Recommended fix.
lowStyle nit, naming suggestion, minor improvement. Fix at discretion.

Procedure

1. Identify the Review Target

Ask the user what to review if not already specified. The target can be:

  • One or more source files (by path)
  • A plan (in session memory or conversation)
  • A diff or set of changes
  • A specific function, class, or module

Gather the full content of the target so it can be passed to the reviewer.

2. Spawn Reviewer Subagent

If a specific lens is requested (e.g., correctness-lens, security-lens, adversarial-lens, etc.), use that named lens agent operating in review mode. Otherwise, use a generic reviewer.

Launch a subagent with the following prompt structure:

You are a code reviewer performing a thorough review of the following target. Your job is to find bugs, design flaws, security issues, and quality problems.

Review target: {include the full content of the target here}

Additional context: {include relevant surrounding code, tests, or specifications the reviewer needs to understand the target}

Instructions:

  • Review the target for correctness, security, performance, readability, and adherence to project conventions.

  • For each issue found, report it in this exact format:

    [SEVERITY] Short title

    • Location: file path and line number (or plan step)
    • Problem: what is wrong and why it matters
    • Suggestion: concrete fix or remediation

    where SEVERITY is one of: critical, high, medium, low.

  • If you find no issues, state explicitly that the target looks correct.

  • Do NOT fabricate issues. Only report genuine problems.

  • Order findings by severity (critical first).

Use the Explore subagent for read-only review of code. If the reviewer needs to run tests or execute code to verify a finding, note that as an unverified finding and let the main agent handle verification.

Show full SKILL.md (255 more words)Show less
3. Present Findings

After the reviewer returns:

  1. List all findings grouped by severity.
  2. For each finding, include the reviewer's suggested remediation.
  3. If the reviewer found no issues, report that explicitly.
  4. Ask the user which findings to address. The user may:
    • Approve all fixes
    • Select specific findings to fix
    • Dismiss findings they disagree with
    • Ask for clarification on any finding
4. Apply Fixes

For each approved finding:

  1. Implement the suggested fix (or an alternative if the user provides one).
  2. Briefly confirm each fix as it is applied.

If a fix is non-trivial or ambiguous, ask the user for guidance rather than guessing.

5. Check Exit Condition

After fixes are applied, ask the user:

All approved fixes have been applied. Should I run another review pass, or are we done?

  • If the user wants another pass → go to step 2 with the updated target.
  • If the user is satisfied → exit the loop.

Guidelines

  • Fresh context per pass. Each reviewer subagent starts with no memory of previous passes. This prevents anchoring bias and ensures new eyes on the updated code.
  • Do not auto-fix without approval. Always present findings and wait for the user to decide which to address.
  • Verify critical findings. If the reviewer flags a critical or high issue, attempt to verify it (e.g., by running tests or tracing the code) before presenting it to the user. Mark unverified findings as such.
  • Keep the loop bounded. If the reviewer returns only low-severity findings on two consecutive passes, suggest exiting the loop.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/review-loop of microsoft/bocpy.

Open the folder on GitHubat commit c8f3ceb

Compare with similar skills

Review Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Loop this skillmicrosoft/bocpy201—~1.2kAutomated safety check: PassMIT
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT
Local PR Reviewwindmill-labs/windmill18k—~995Automated safety check: PassCustom licence

Similar skills

  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Local PR Review

    windmill-labs/windmill

    Runs the same code review locally that GitHub's auto-review actions run on a PR, delegating to a fresh-context subagent so the review isn't biased by the main session's own reasoning.

    18k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed
  • Auto Devflow

    HuangPuStar/FenixAgent

    A skill your agent uses when starting an issue, bugfix, feature, or refactor that should be driven by multiple coordinated subagents: explore → plan → code → review, with the main agent acting as…

    552 GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed

More from microsoft/bocpy

All 9 skills in this repo
  • Branch Review

    microsoft/bocpy

    Official

    Multi-perspective code review for a branch before merging. An agent skill from microsoft/bocpy.

    201 GitHub stars~3.2k tokensUpdated 9 days ago
    Auto-check passed
  • Official

    Write a C extension whose custom types can live inside a bocpy Cown and travel between worker sub-interpreters.

    201 GitHub stars~5.1k tokensUpdated 9 days ago
    Auto-check passed
  • Official

    Follow bocpy commenting and documentation conventions. An agent skill from microsoft/bocpy.

    201 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Finalize PR

    microsoft/bocpy

    Official

    Finalize a feature branch for merge. An agent skill from microsoft/bocpy.

    201 GitHub stars~3.5k tokensUpdated 9 days ago
    Auto-check passed
  • Multi Perspective Plan

    microsoft/bocpy

    Official

    Multi-perspective planning with rebuttal rounds and adversarial review loop.

    201 GitHub stars~2.8k tokensUpdated 9 days ago
    Auto-check passed
  • Testing Message Queue

    microsoft/bocpy

    Official

    Write tests for the bocpy message queue — the lock-free tag-based MPSC ring buffer.

    201 GitHub stars~2.3k tokensUpdated 9 days ago
    Auto-check passed

Questions about Review Loop

What does Review Loop do?

Iterative review loop with subagent reviewer. An agent skill from microsoft/bocpy. Review Loop is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Iterative review loop with subagent reviewer.

When should I use Review Loop?

Review Loop fits situations like: : reviewing code changes; reviewing plans; auditing implementations; validating fixes.

How do I install Review Loop in Claude Code?

Run `npx skills add microsoft/bocpy --skill review-loop -a claude-code`. Or copy the skill folder (.github/skills/review-loop in microsoft/bocpy) into .claude/skills/review-loop in your project. Claude Code loads it when a task matches its description.

How do I install Review Loop in Codex?

Run `npx skills add microsoft/bocpy --skill review-loop -a codex`. Or copy the skill folder (.github/skills/review-loop in microsoft/bocpy) into .agents/skills/review-loop in your project. Codex loads it when a task matches its description.

Can I use Review Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/bocpy --skill review-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-loop, .gemini/skills/review-loop, .github/skills/review-loop and .opencode/skills/review-loop in your project.

What does Review Loop need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Loop is instructions for the agent only.

Does Review Loop access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Loop use?

Review Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Loop use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Loop?

Skills that share tags, products or a category with Review Loop: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Loop?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/bocpy, which has 201 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.

Source: microsoft/bocpy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.