Agent skill

Code Review

by modiqo in modiqo/skillspec

Multi-agent code review with deep analysis. An agent skill from modiqo/skillspec.

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add modiqo/skillspec --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install modiqo/skillspec code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review/source .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
706
Token cost
~3k tokens
SKILL.md length
1,145 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Multi-agent code review with deep analysis. An agent skill from modiqo/skillspec.

  • Works in 4 steps: Research & Domain Mapping → Web Research (conditional) → Parallel Review Agents → …
  • The user asks to review code
  • SKILL.md covers Input Collection, Phase 1: Research & Domain…, Phase 2: Web Research… and Phase 3: Parallel Review Agents, plus 1 more section
  • Calls gh and git

What it does

Code Review is an agent skill from modiqo/skillspec. Multi-agent code review with deep analysis. Orchestrates codebase research, optional web research, parallel Rust engineers, codex second opinion, and general-purpose reviewers into a synthesized report. Use when the user asks to review code, review a PR, review changes, audit code quality, or says "review", "/review", "code review", "check my changes", "review this PR", "review diff". Trigger for ANY code review request, even partial — e.g., "look over this", "anything wrong with these changes", "sanity check".

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Pull requests. It works with Rust. The repository describes itself as: SkillSpec makes agent skills followable, testable, and provable with Doctor risk reports, guided imports, structured contracts, and alignment proof. The licence is Apache-2.0.

When your agent uses it

  • The user asks to review code
  • Audit code quality
  • Check my changes
  • ANY code review request

Example prompts

  • “review”
  • “/review”
  • “code review”
  • “/code-review”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Research & Domain Mapping
  2. Web Research (conditional)
  3. Parallel Review Agents
  4. Synthesis

What it can do on your machine

Read from SKILL.md and the folder at commit f4d9ab5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 3k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,145 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from modiqo/skillspec at commit f4d9ab5, republished under its Apache-2.0 licence (© modiqo). 1,145 words, ~3,030 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Multi-agent code review with deep analysis. Orchestrates codebase research, optional web research, parallel Rust engineers, codex second opinion, and general-purpose reviewers into a synthesized report. Use when the user asks to review code, review a PR, review changes, audit code quality, or says "review", "/review", "code review", "check my changes", "review this PR", "review diff". Trigger for ANY code review request, even partial — e.g., "look over this", "anything wrong with these changes", "sanity check".

Code Review

Orchestrate a multi-agent code review pipeline: research the changes, optionally investigate external alternatives, dispatch parallel domain-specific reviewers, and synthesize everything into a structured report.

Input Collection

Prompt the user to select an input mode. Present these options clearly:

What would you like me to review?

  1. Current PR — review the open PR on this branch (description + diff)
  2. Diff to main — review all uncommitted and committed changes vs main
  3. Specific paths — review specific files, crates, or directories

Pick a number, or describe what you'd like reviewed.

Collecting the diff

Mode 1 — Current PR:

bash
gh pr view --json title,body,number,baseRefName
gh pr diff

If no open PR exists, tell the user and suggest mode 2 instead.

Mode 2 — Diff to main:

bash
git diff main...HEAD

Also include git log main..HEAD --oneline for commit context.

Mode 3 — Specific paths: Ask the user for paths. Read the specified files directly. No diff — review the code as-is.

Store the collected input (diff text, PR description, file contents) for use in subsequent phases.

Handling large diffs

If the diff exceeds ~2000 lines, save it to a temporary file (/tmp/code-review-diff.patch) and have agents read it via the Read tool rather than inlining it in their prompts. This prevents context overflow. Reference the file path in agent prompts instead of pasting the diff.

Phase 1: Research & Domain Mapping

Spawn an Agent (subagent_type: general-purpose) and include the full text of the research-codebase skill instructions in its prompt (read .claude/skills/research-codebase/SKILL.md first). Direct the agent to research the changes with this focus:

  • Map all changed files to their logical domains and crate boundaries
  • Identify which changes are Rust code vs non-Rust (CI, docs, config, TypeScript SDK, nix, etc.)
  • Understand the architectural context around each change — what traits, types, and modules are involved
  • Group changes into at most 4 logical domain groups, merging smaller related changes together
  • Flag any changes that warrant external web research:
    • New dependencies or crate additions
    • Unfamiliar architectural patterns
    • Potentially deprecated API usage
    • Cases where alternative approaches might exist

The research agent will internally spawn codebase-locator, codebase-analyzer, and codebase-pattern-finder sub-agents. You do not need to manage those agents directly.

Parse the research output for:
  1. Domain groups — a list of 1-4 logical clusters, each with:

    • A descriptive name (e.g., "OAuth token refresh flow", "adapter registry refactor")
    • The files and line ranges involved
    • Key context (traits, types, modules, patterns in play)
    • Whether changes are Rust or non-Rust
  2. Web research questions — specific questions worth investigating, or empty if none

  3. Change characterization — new feature, refactor, bugfix, etc., to help reviewers calibrate

Phase 2: Web Research (conditional)

Skip this phase entirely if Phase 1 flagged no web research questions.

If questions were flagged, spawn web-search-researcher agent(s) with the specific questions. Each agent should:

  • Search for the specific concern (e.g., "ring crate security advisories 2026", "tokio channel vs crossbeam performance comparison")
  • Return findings with source links
  • Focus on actionable information relevant to the review

If web research fails or times out, proceed to Phase 3 without it. Note the failure in the final report.

Phase 3: Parallel Review Agents

Spawn all review agents in a single message so they run concurrently. Every agent receives:

  • The full diff (or file contents for mode 3)
  • The research context from Phase 1 (domain map, architectural context)
  • Web research findings from Phase 2 (if any)
  • The PR description (if mode 1)
Path-triggered guardrails (apply BEFORE building agent prompts)

If the diff touches any of these paths, the command catalog guardrails apply and MUST be propagated into every reviewer's prompt:

  • crates/rote-cli/src/cli/parser/parsers/<family>/{mod,spec,tests}.rs
  • crates/rote-cli/src/cli/parser/spec/*.rs
  • crates/rote-search/src/builder/commands.csv
  • crates/xtask/src/gen_artifacts.rs

When this trigger fires:

  1. Read .claude/skills/command-catalog-guardrails/SKILL.md and extract its checklist + drift-class table.
  2. Append both verbatim to every Phase 3 agent prompt (rust-engineer, general-purpose, codex-second-opinion). Each agent must explicitly evaluate the diff against every checklist item and call out failures in its findings table.
  3. In the synthesis report, add a "Catalog Guardrails" section above "Critical" listing any checklist items the agents flagged. Use it to make catalog drift visible separately from generic Rust review findings — the failure modes (silent value drop, help-before-validate, positional ignored) don't fit cleanly into the standard severity buckets.
Show full SKILL.md (472 more words)Show less
Agent dispatch rules

For Rust domain groups — spawn one rust-engineer agent per domain group (max 4). Each agent's prompt should include:

  • Its specific domain assignment and the files/lines it owns
  • The surrounding architectural context from research
  • Instruction to produce detailed findings covering:
    • Correctness, logic errors, edge cases
    • Performance implications
    • Idiomatic Rust (1.94+), type system usage
    • Error handling, safety, concurrency patterns
    • API design, trait boundaries, public interface quality
    • Testing gaps
  • Instruction to format output as a markdown table with columns: #, Severity, Location, Issue, Suggested Fix. Also include a separate "Testing Gaps" table with columns: Gap, Risk, Priority.

For non-Rust changes — spawn one general-purpose agent with a code-review prompt covering:

  • Correctness and completeness of config/CI/doc changes
  • Consistency with existing patterns
  • Security concerns (exposed secrets, overly permissive permissions)
  • SDK changes: API compatibility, test coverage, documentation
  • Same table output format as rust-engineer agents

Always — spawn one codex-second-opinion agent with the full diff. Codex reviews independently without domain partitioning, providing a fresh perspective across all changes. Instruct it to format findings as a markdown table with the same columns.

Scaling
Diff sizeRust domainsNon-RustCodexTotal agents
Tiny (<20 lines, single domain)1 rust-engineer—12
Medium (multi-domain)2-3 rust-engineersif applicable13-5
Large (many crates)4 rust-engineers (merged)if applicable15-6
Non-Rust only—1 general-purpose12
Mixed1-4 rust-engineers1 general-purpose13-6

Phase 4: Synthesis

After all review agents complete, produce the final report. Do not start synthesis until every agent has returned.

Report structure

Organize findings by severity, not by agent. Every finding goes in a table with a column showing which agent(s) reported it. Deduplicate: if multiple agents report the same issue, merge into one row and list all reporters. Mark multi-reporter findings ✅.

markdown
# Code Review: [PR title / branch name / paths reviewed]

## Overall Assessment
[One sentence: ready to merge / needs changes / needs discussion]

## Cross-Cutting Themes

| Theme | Occurrences | Files | Impact |
|-------|-------------|-------|--------|
| Silent error swallowing | 20+ | state.rs, db.rs, storage.rs, snapshot.rs | Data corruption goes undetected |
| Missing `#[must_use]` | 15+ | dependency.rs, health.rs, state.rs | Discarded return values hide bugs |

## Critical

| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 1 | `db.rs:969` | `replace_command_log` not in transaction — crash = data loss | Wrap in `BEGIN EXCLUSIVE...COMMIT` | rust-eng-state, codex ✅ |
| 2 | `manager.rs:65` | Path traversal — unsanitized workspace name in `join()` | Validate `[a-zA-Z0-9_-]+` | rust-eng-lifecycle, codex ✅ |
| 3 | `state.rs:557` | `conn()` panics via `.expect()` in library code | Return `Result<&Connection>` | rust-eng-state |

## High

| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 4 | `state.rs:1433` | Counter set to `entries.len()` instead of max response ID | Derive from `response_ids.max()` | rust-eng-state, codex ✅ |
| 5 | `storage.rs:468` | Header obfuscation only covers `Authorization: Bearer` | Case-insensitive denylist for secret headers | rust-eng-storage, codex ✅ |

## Medium

| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 6 | `db.rs:479` | Timestamp parse failures silently replaced with `Utc::now()` | Log warning or propagate error | rust-eng-state |
| 7 | `dependency.rs:271` | Broken dependency chains not detected transitively | Iterative fixed-point propagation | rust-eng-deps |

## Low

| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 8 | `dependency.rs:131` | `$100` accepted as variable reference (all-numeric) | Require first char `[A-Za-z_]` | rust-eng-deps, codex ✅ |
| 9 | `lib.rs:322` | `root_path()` returns `&PathBuf` instead of `&Path` | Change return type to `&Path` | rust-eng-storage, rust-eng-lifecycle |

## Testing Gaps

| # | Gap | Risk | Priority | Reported By |
|---|-----|------|----------|-------------|
| 1 | No round-trip test for log_command → reload | Sequence corruption undetected | High | rust-eng-state |
| 2 | Zero tests for dependency inference pipeline | False positives/negatives in production | High | rust-eng-deps |
| 3 | No test for snapshot `restore` | Corrupt workspace state after restore | Medium | rust-eng-lifecycle |

## Web Research
[Only present if Phase 2 ran]

| Question | Finding | Source | Impact on Review |
|----------|---------|--------|-----------------|
| ... | ... | [link] | ... |
Severity definitions
  • Critical — Bugs that corrupt data, lose work, crash in production, or create security vulnerabilities. Must fix before merge.
  • High — Significant correctness or safety issues that will cause problems under realistic conditions. Should fix before merge.
  • Medium — Code quality, robustness, or minor correctness issues. Fix soon, but not necessarily blocking.
  • Low — Style, idiom, minor improvements. Fix at convenience.
Synthesis rules
  • Organize all findings into severity tables — not per-agent sections
  • Deduplicate: if multiple agents report the same issue, merge into one row listing all reporters
  • Multi-reporter findings get ✅ in the Reported By column (high confidence signal)
  • Within each severity table, sort by number of confirming reporters (most first), then by file path
  • Preserve all file:line references in the Location column
  • The "Reported By" column uses short labels: rust-eng-[domain], codex, general
  • Testing gaps get their own consolidated table, also with a Reported By column
  • Cross-cutting themes go above the severity tables — these are patterns, not individual findings
  • If no findings at a severity level, omit that table entirely
Output

Print the report as markdown in the conversation. Do not write to a file unless the user asks.

© modiqo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/code-review/source of modiqo/skillspec.

Open the folder on GitHubat commit f4d9ab5

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillmodiqo/skillspec706—~3kAutomated safety check: PassApache-2.0
SeekDB Code Reviewoceanbase/seekdb3.1k—~2.1kAutomated safety check: PassApache-2.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Resolve PR Reviewshencangsheng/easydb_app590—~2.4kAutomated safety check: PassMIT
Coding Agentmastra-ai/mastra29k—~2.3kAutomated safety check: PassCustom licence

Similar skills

  • SeekDB Code Review

    oceanbase/seekdb

    Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.

    3.1k GitHub stars~2.1k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Resolve PR Review

    shencangsheng/easydb_app

    Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.

    590 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Coding Agent

    mastra-ai/mastra

    Authoring playbook for building agents that write, edit, review, or refactor code.

    29k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • fastcdc-rs PR Review

    nlfiedler/fastcdc-rs

    Reviews a pull request or the current diff against the fastcdc-rs maintainers' standards, runs the cargo checks and ends with a merge recommendation.

    218 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from modiqo/skillspec

All 9 skills in this repo
  • Research Codebase

    modiqo/skillspec

    Document and explain the codebase as-is using parallel sub-agents.

    706 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Rote Browse

    modiqo/skillspec

    A skill your agent uses when the task needs to browse a website with rote, browse Gmail or an email web app with rote, attach to an active browser, inspect logged-in web app state, snapshot or slice…

    706 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Rote Shell

    modiqo/skillspec

    A skill your agent uses when the task needs to run a local command and remember the result, inspect CLI output with provenance, follow a log or process stream, start or observe a background job…

    706 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Commit Convention

    modiqo/skillspec

    A skill your agent uses when writing commit messages, creating PR titles, pushing commits, or creating PRs — ensures conventional commit format and that formatting/linting pass before any push

    706 GitHub stars~398 tokensUpdated 1 mo ago
    Auto-check passed
  • Rote Shell

    modiqo/skillspec

    A skill your agent uses for CLI and shell work through rote: running local commands with rote exec, capturing stdout/stderr/files, following logs and background processes, checking dependency…

    706 GitHub stars~7.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Generic Code Review

    modiqo/skillspec

    Review code changes by collecting the review target, researching context, checking risks, and reporting findings before summary.

    706 GitHub stars~560 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Code Review

What does Code Review do?

Multi-agent code review with deep analysis. An agent skill from modiqo/skillspec. Code Review is an agent skill from modiqo/skillspec. Multi-agent code review with deep analysis.

When should I use Code Review?

Code Review fits situations like: the user asks to review code; audit code quality; check my changes; ANY code review request.

How do I install Code Review in Claude Code?

Run `npx skills add modiqo/skillspec --skill code-review -a claude-code`. Or copy the skill folder (.claude/skills/code-review/source in modiqo/skillspec) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add modiqo/skillspec --skill code-review -a codex`. Or copy the skill folder (.claude/skills/code-review/source in modiqo/skillspec) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add modiqo/skillspec --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (gh and git).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: SeekDB Code Review (oceanbase/seekdb, 3.1k stars), PR Review (jaemk/self_update, 961 stars), PR Review (jaemk/cached, 2.1k stars) and Resolve PR Review (shencangsheng/easydb_app, 590 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

modiqo (a GitHub organization) maintains it in modiqo/skillspec, which has 706 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 9, 2026.

Source: modiqo/skillspec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.