SeekDB Code Review
oceanbase/seekdb
Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.
Multi-agent code review with deep analysis. An agent skill from modiqo/skillspec.
$ npx skills add modiqo/skillspec --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install modiqo/skillspec code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review/source .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/sourceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add modiqo/skillspec --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install modiqo/skillspec code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/code-review/source .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add modiqo/skillspec --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install modiqo/skillspec code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/code-review/source .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/modiqo/skillspec.git --path .claude/skills/code-review/source--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add modiqo/skillspec --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install modiqo/skillspec code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/code-review/source .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install modiqo/skillspec code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add modiqo/skillspec --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/code-review/source .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add modiqo/skillspec --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install modiqo/skillspec code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/modiqo/skillspec.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/code-review/source .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/modiqo/skillspec/tree/main/.claude/skills/code-review/source into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewMulti-agent code review with deep analysis. An agent skill from modiqo/skillspec.
Code Review is an agent skill from modiqo/skillspec. Multi-agent code review with deep analysis. Orchestrates codebase research, optional web research, parallel Rust engineers, codex second opinion, and general-purpose reviewers into a synthesized report. Use when the user asks to review code, review a PR, review changes, audit code quality, or says "review", "/review", "code review", "check my changes", "review this PR", "review diff". Trigger for ANY code review request, even partial — e.g., "look over this", "anything wrong with these changes", "sanity check".
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review and Pull requests. It works with Rust. The repository describes itself as: SkillSpec makes agent skills followable, testable, and provable with Doctor risk reports, guided imports, structured contracts, and alignment proof. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f4d9ab5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review loads about 3k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,145 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from modiqo/skillspec at commit f4d9ab5, republished under its Apache-2.0 licence (© modiqo). 1,145 words, ~3,030 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder).Orchestrate a multi-agent code review pipeline: research the changes, optionally investigate external alternatives, dispatch parallel domain-specific reviewers, and synthesize everything into a structured report.
Prompt the user to select an input mode. Present these options clearly:
What would you like me to review?
- Current PR — review the open PR on this branch (description + diff)
- Diff to main — review all uncommitted and committed changes vs main
- Specific paths — review specific files, crates, or directories
Pick a number, or describe what you'd like reviewed.
Mode 1 — Current PR:
gh pr view --json title,body,number,baseRefName
gh pr diffIf no open PR exists, tell the user and suggest mode 2 instead.
Mode 2 — Diff to main:
git diff main...HEADAlso include git log main..HEAD --oneline for commit context.
Mode 3 — Specific paths: Ask the user for paths. Read the specified files directly. No diff — review the code as-is.
Store the collected input (diff text, PR description, file contents) for use in subsequent phases.
If the diff exceeds ~2000 lines, save it to a temporary file (/tmp/code-review-diff.patch) and have agents read it via the Read tool rather than inlining it in their prompts. This prevents context overflow. Reference the file path in agent prompts instead of pasting the diff.
Spawn an Agent (subagent_type: general-purpose) and include the full text of the research-codebase skill instructions in its prompt (read .claude/skills/research-codebase/SKILL.md first). Direct the agent to research the changes with this focus:
The research agent will internally spawn codebase-locator, codebase-analyzer, and codebase-pattern-finder sub-agents. You do not need to manage those agents directly.
Domain groups — a list of 1-4 logical clusters, each with:
Web research questions — specific questions worth investigating, or empty if none
Change characterization — new feature, refactor, bugfix, etc., to help reviewers calibrate
Skip this phase entirely if Phase 1 flagged no web research questions.
If questions were flagged, spawn web-search-researcher agent(s) with the specific questions. Each agent should:
If web research fails or times out, proceed to Phase 3 without it. Note the failure in the final report.
Spawn all review agents in a single message so they run concurrently. Every agent receives:
If the diff touches any of these paths, the command catalog guardrails apply and MUST be propagated into every reviewer's prompt:
crates/rote-cli/src/cli/parser/parsers/<family>/{mod,spec,tests}.rscrates/rote-cli/src/cli/parser/spec/*.rscrates/rote-search/src/builder/commands.csvcrates/xtask/src/gen_artifacts.rsWhen this trigger fires:
.claude/skills/command-catalog-guardrails/SKILL.md and extract its checklist + drift-class table.For Rust domain groups — spawn one rust-engineer agent per domain group (max 4). Each agent's prompt should include:
#, Severity, Location, Issue, Suggested Fix. Also include a separate "Testing Gaps" table with columns: Gap, Risk, Priority.For non-Rust changes — spawn one general-purpose agent with a code-review prompt covering:
Always — spawn one codex-second-opinion agent with the full diff. Codex reviews independently without domain partitioning, providing a fresh perspective across all changes. Instruct it to format findings as a markdown table with the same columns.
| Diff size | Rust domains | Non-Rust | Codex | Total agents |
|---|---|---|---|---|
| Tiny (<20 lines, single domain) | 1 rust-engineer | — | 1 | 2 |
| Medium (multi-domain) | 2-3 rust-engineers | if applicable | 1 | 3-5 |
| Large (many crates) | 4 rust-engineers (merged) | if applicable | 1 | 5-6 |
| Non-Rust only | — | 1 general-purpose | 1 | 2 |
| Mixed | 1-4 rust-engineers | 1 general-purpose | 1 | 3-6 |
After all review agents complete, produce the final report. Do not start synthesis until every agent has returned.
Organize findings by severity, not by agent. Every finding goes in a table with a column showing which agent(s) reported it. Deduplicate: if multiple agents report the same issue, merge into one row and list all reporters. Mark multi-reporter findings ✅.
# Code Review: [PR title / branch name / paths reviewed]
## Overall Assessment
[One sentence: ready to merge / needs changes / needs discussion]
## Cross-Cutting Themes
| Theme | Occurrences | Files | Impact |
|-------|-------------|-------|--------|
| Silent error swallowing | 20+ | state.rs, db.rs, storage.rs, snapshot.rs | Data corruption goes undetected |
| Missing `#[must_use]` | 15+ | dependency.rs, health.rs, state.rs | Discarded return values hide bugs |
## Critical
| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 1 | `db.rs:969` | `replace_command_log` not in transaction — crash = data loss | Wrap in `BEGIN EXCLUSIVE...COMMIT` | rust-eng-state, codex ✅ |
| 2 | `manager.rs:65` | Path traversal — unsanitized workspace name in `join()` | Validate `[a-zA-Z0-9_-]+` | rust-eng-lifecycle, codex ✅ |
| 3 | `state.rs:557` | `conn()` panics via `.expect()` in library code | Return `Result<&Connection>` | rust-eng-state |
## High
| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 4 | `state.rs:1433` | Counter set to `entries.len()` instead of max response ID | Derive from `response_ids.max()` | rust-eng-state, codex ✅ |
| 5 | `storage.rs:468` | Header obfuscation only covers `Authorization: Bearer` | Case-insensitive denylist for secret headers | rust-eng-storage, codex ✅ |
## Medium
| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 6 | `db.rs:479` | Timestamp parse failures silently replaced with `Utc::now()` | Log warning or propagate error | rust-eng-state |
| 7 | `dependency.rs:271` | Broken dependency chains not detected transitively | Iterative fixed-point propagation | rust-eng-deps |
## Low
| # | Location | Issue | Suggested Fix | Reported By |
|---|----------|-------|---------------|-------------|
| 8 | `dependency.rs:131` | `$100` accepted as variable reference (all-numeric) | Require first char `[A-Za-z_]` | rust-eng-deps, codex ✅ |
| 9 | `lib.rs:322` | `root_path()` returns `&PathBuf` instead of `&Path` | Change return type to `&Path` | rust-eng-storage, rust-eng-lifecycle |
## Testing Gaps
| # | Gap | Risk | Priority | Reported By |
|---|-----|------|----------|-------------|
| 1 | No round-trip test for log_command → reload | Sequence corruption undetected | High | rust-eng-state |
| 2 | Zero tests for dependency inference pipeline | False positives/negatives in production | High | rust-eng-deps |
| 3 | No test for snapshot `restore` | Corrupt workspace state after restore | Medium | rust-eng-lifecycle |
## Web Research
[Only present if Phase 2 ran]
| Question | Finding | Source | Impact on Review |
|----------|---------|--------|-----------------|
| ... | ... | [link] | ... |rust-eng-[domain], codex, generalPrint the report as markdown in the conversation. Do not write to a file unless the user asks.
© modiqo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/code-review/source of modiqo/skillspec.
Open the folder on GitHubat commit f4d9ab5
Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review this skillmodiqo/skillspec | 706 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| SeekDB Code Reviewoceanbase/seekdb | 3.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| PR Reviewjaemk/self_update | 961 | — | ~1.5k | Automated safety check: Notes | MIT | |
| PR Reviewjaemk/cached | 2.1k | — | ~2.5k | Automated safety check: Notes | MIT | |
| Resolve PR Reviewshencangsheng/easydb_app | 590 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Coding Agentmastra-ai/mastra | 29k | — | ~2.3k | Automated safety check: Pass | Custom licence |
oceanbase/seekdb
Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.
jaemk/self_update
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.
jaemk/cached
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.
shencangsheng/easydb_app
Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.
mastra-ai/mastra
Authoring playbook for building agents that write, edit, review, or refactor code.
nlfiedler/fastcdc-rs
Reviews a pull request or the current diff against the fastcdc-rs maintainers' standards, runs the cargo checks and ends with a merge recommendation.
modiqo/skillspec
Document and explain the codebase as-is using parallel sub-agents.
modiqo/skillspec
A skill your agent uses when the task needs to browse a website with rote, browse Gmail or an email web app with rote, attach to an active browser, inspect logged-in web app state, snapshot or slice…
modiqo/skillspec
A skill your agent uses when the task needs to run a local command and remember the result, inspect CLI output with provenance, follow a log or process stream, start or observe a background job…
modiqo/skillspec
A skill your agent uses when writing commit messages, creating PR titles, pushing commits, or creating PRs — ensures conventional commit format and that formatting/linting pass before any push
modiqo/skillspec
A skill your agent uses for CLI and shell work through rote: running local commands with rote exec, capturing stdout/stderr/files, following logs and background processes, checking dependency…
modiqo/skillspec
Review code changes by collecting the review target, researching context, checking risks, and reporting findings before summary.
Works with
Categories
Multi-agent code review with deep analysis. An agent skill from modiqo/skillspec. Code Review is an agent skill from modiqo/skillspec. Multi-agent code review with deep analysis.
Code Review fits situations like: the user asks to review code; audit code quality; check my changes; ANY code review request.
Run `npx skills add modiqo/skillspec --skill code-review -a claude-code`. Or copy the skill folder (.claude/skills/code-review/source in modiqo/skillspec) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add modiqo/skillspec --skill code-review -a codex`. Or copy the skill folder (.claude/skills/code-review/source in modiqo/skillspec) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add modiqo/skillspec --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (gh and git).
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review: SeekDB Code Review (oceanbase/seekdb, 3.1k stars), PR Review (jaemk/self_update, 961 stars), PR Review (jaemk/cached, 2.1k stars) and Resolve PR Review (shencangsheng/easydb_app, 590 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
modiqo (a GitHub organization) maintains it in modiqo/skillspec, which has 706 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 9, 2026.
Source: modiqo/skillspec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.