Agent skill

Review

by notque in notque/vexjoy-agent

Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review.

MITAuto-check: notesDevelopment

Install Review

skills CLI
$ npx skills add notque/vexjoy-agent --skill review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install notque/vexjoy-agent review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review/review .claude/skills/review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review
GitHub stars
438
Token cost
~2k tokens
SKILL.md length
716 words
Files
6 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review.

  • Works in 11 steps: UNDERSTAND → VERIFY → ASSESS → …
  • Development work in your project
  • SKILL.md covers Deep References, Severity Classification, Verdict Rules and Mode 1: Systematic Review…, plus 3 more sections
  • Calls python3, git and gh

What it does

Review is an agent skill from notque/vexjoy-agent. Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/architecture-smell-baseline.md`, `references/audit-playbook.md` and `references/go-review-patterns.md`).

It sits in Development. The repository describes itself as: VexJoy AI Agent with Jev Intelligent Routing - /do routes plain-English requests to the right specialist agent and gates the work with reviews, tests, and a learning loop. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/review”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, Glob, Edit, Task, Agent

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. UNDERSTAND
  2. VERIFY
  3. ASSESS
  4. 5: VERIFY FINDINGS
  5. DOCUMENT
  6. Scope
  7. Dispatch
  8. Aggregate and Verdict
  9. Discover and Pre-check
  10. Run Comprehensive Review
  11. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 5218674. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • Glob
    • Edit
    • Task
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review loads about 2k tokens when it runs, and up to ~8.6k if it reads all its reference files. Until then it costs about 25 tokens; SKILL.md has 716 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, Glob, Edit, Task, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from notque/vexjoy-agent at commit 5218674, republished under its MIT licence (© notque). 716 words, ~1,973 tokens.

Download SKILL.mdSave it as .claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
review
description
Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review.
allowed-tools
Read, Write, Bash, Grep, Glob, Edit, Task, Agent
user-invocable
true
routing.force_route
true
routing.not_for
security scanning (use security), linting (use code-quality), git push/commit/PR (use pr-workflow)
routing.triggers
review code, code review, code review methodology, structured review, code audit, review methodology, comprehensive review, parallel review, 3-reviewer…
routing.category
code-review
routing.pairs_with
security, testing

Review

Three modes. Pick one by request shape, default to systematic.

Request matchesMode
Review a file, diff, or PRSystematic (default)
"parallel review", "multi-reviewer", "3-reviewer"Parallel
"full repo review", "codebase audit", "repo health", review ALL filesFull-repo

Deep References

SignalLoadWhy
Reviewing Go codereferences/go-review-patterns.mdExports, concurrency, resources, metrics, tests
Dispatching Architecture reviewer in parallel modereferences/architecture-smell-baseline.md12 Fowler smells with language counter-examples and severity cap
Writing full-repo reportreferences/report-template.mdReport structure and field definitions
Dispatching full-repo wave agentsreferences/audit-playbook.md8-category checklists with evidence requirements
Receiving review feedbackreferences/receiving-feedback.mdFeedback-handling patterns

Severity Classification

Shared across all modes. When in doubt, classify UP.

LevelScopeExamples
BLOCKINGSecurity, correctness, reliabilityAuth bypass, race condition, resource leak, logic error, test failure
SHOULD FIXMaterial quality, patterns, testsMissing tests, unhelpful errors, pattern violations, N+1 in hot paths
SUGGESTIONOptional, stylisticNaming preferences, comments, micro-optimizations

Decision: security/correctness/reliability risk? -> BLOCKING. Violates patterns or creates maintenance burden? -> SHOULD FIX. Purely stylistic? -> SUGGESTION.

Verdict Rules

ConditionVerdict
Any BLOCKING findingREQUEST-CHANGES (or BLOCK)
SHOULD FIX findings, no BLOCKINGFIX before merge
Only SUGGESTION or cleanAPPROVE

Omit empty severity sections. Include review scope, evidence, and limitations. Validate output:

bash
python3 scripts/validate-review-output.py --type systematic /tmp/review-output.md

Exit 0 = valid; 1 = schema errors; 2 = unparseable; 3 = missing jsonschema.


Mode 1: Systematic Review (default)

Single-reviewer, 4-phase review of a named file, diff, or PR.

Phase 1: UNDERSTAND

Read repository instructions and the complete diff. Read surrounding code to understand each changed path and its consumers. When signatures change, find all callers and interface implementations. Trace parameters to their source: query params may hold any user string; tokens may be server-issued IDs; enums have bounded values. Check validation at each caller.

Gate: Every changed path accounted for, callers traced where needed.

Phase 2: VERIFY

Run relevant tests and required repository checks. Reuse prior results only when they cover current code and environment. Check material claims in comments and PR description against code and tests. Missing tools, skipped checks, and inferred outcomes are not passes.

Gate: Claims have supporting evidence; required checks passed or the gap is recorded.

Phase 3: ASSESS

Assess risks: security (auth, validation, injection, secrets), performance (N+1, unbounded work, allocations on hot paths), architecture (conventions, compatibility, scope, unnecessary abstractions). For extracted helpers, recheck contract and callers.

Gate: Relevant risks and remaining uncertainty are explicit.

Phase 3.5: VERIFY FINDINGS

Before reporting, check each finding's input sequence, existing guards, and proposed fix. Drop unreachable or already-handled claims. Deduplicate when combining reviews; resolve severity from evidence.

Phase 4: DOCUMENT
text
Review Summary:
  Files Reviewed: N | Lines Changed: +X/-Y
  Test Status: PASS | FAIL | SKIPPED
  Risk Level: LOW | MEDIUM | HIGH | CRITICAL

BLOCKING:
  1. Issue and consequence — path/file.ext:42
SHOULD FIX:
  1. Issue and consequence — path/file.ext:52
SUGGESTIONS:
  1. Optional improvement — path/file.ext:62

Verdict: APPROVE | REQUEST-CHANGES | NEEDS-DISCUSSION
Rationale: Evidence, scope, and limitations.

Mode 2: Parallel Review

Three concurrent reviewers, then aggregate.

Show full SKILL.md (294 more words)Show less
Step 1: Scope

Identify the diff or files. Record the reviewed revision.

bash
git diff --name-only HEAD
gh pr view --json files -q '.files[].path'

Select Architecture reviewer by language: Go -> golang-general-engineer; Python -> python-general-engineer; TypeScript -> typescript-frontend-engineer; mixed -> Explore.

Step 2: Dispatch

Dispatch three reviewers together. Read-only; no code edits.

ReviewerFocus
SecurityAuth, authorization, input validation, secrets, OWASP
Business LogicRequirements, edge cases, state transitions, failure modes
ArchitectureDesign, structure, performance, maintainability, scope

Pass references/architecture-smell-baseline.md verbatim to the Architecture reviewer. Require [Reviewer] file:line format with severity and consequence.

Step 3: Aggregate and Verdict

Deduplicate findings, resolve severity disagreements from evidence. Apply shared verdict rules. Output a single combined report with severity matrix, combined findings, and recommendation.

Gate: Every reviewer returned, or missing coverage is explicitly stated without claiming approval.


Mode 3: Full-Repo Review

All source files through a 4-wave comprehensive review. Produces a prioritized backlog, not auto-fixes. Use for quarterly health checks, post-refactor audits, or new codebase onboarding.

Options: --directory [dir] (scope to one dir), --skip-precheck, --min-severity [level].

Step 1: Discover and Pre-check

Scan all source files (scripts/, hooks/, skills/, agents/, docs/). Never fall back to git diff.

bash
python3 ~/.claude/scripts/score-component.py --all-agents --all-skills --json

Save scores as triage context. A score alone never determines severity.

Step 2: Run Comprehensive Review

Call comprehensive-review with --review-only and the full file list. Run all 4 waves (0-3). Load references/audit-playbook.md as prompt context for wave agents.

Step 3: Report

Merge deterministic scores with LLM findings. Identify systemic patterns (3+ files). Write full-repo-review-report.md using references/report-template.md.

Gate: Report exists with severity sections and deterministic scores.


Error Handling

ErrorSolution
Reviewer times out or returns nothingReport partial findings, note gap, retry on reduced scope
Validator script missingRun review without validation, note gap in verdict
score-component.py failsProceed with LLM review only, note gap in report
Too many files for single sessionSplit by directory: scripts/, hooks/, agents/, skills/

© notque, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/review/review of notque/vexjoy-agent.

  • SKILL.md
  • references/architecture-smell-baseline.md
  • references/audit-playbook.md
  • references/go-review-patterns.md
  • references/receiving-feedback.md
  • references/report-template.md

Open the folder on GitHubat commit 5218674

Compare with similar skills

Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review this skillnotque/vexjoy-agent438—~2kAutomated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from notque/vexjoy-agent

All 61 skills in this repo
  • Game Asset Generator

    notque/vexjoy-agent

    Deterministic palette/matrix pixel art (not AI). An agent skill from notque/vexjoy-agent.

    438 GitHub stars~2.3k tokensUpdated 5 days ago
    Auto-check: notes
  • PR Workflow

    notque/vexjoy-agent

    Pull request lifecycle: commit, codex review, sync, review, fix, status, cleanup, and PR mining.

    438 GitHub stars~2.8k tokensUpdated 5 days ago
    Auto-check: notes
  • Architecture Deepening

    notque/vexjoy-agent

    Improve architecture across modules by deepening interfaces.

    438 GitHub stars~3.3k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Quality

    notque/vexjoy-agent

    Code quality: cleanup, linting, formatting, quality gates. An agent skill from notque/vexjoy-agent.

    438 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Codebase Analyzer

    notque/vexjoy-agent

    Statistical rule discovery from Go codebase patterns. An agent skill from notque/vexjoy-agent.

    438 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check: notes
  • Comment Quality

    notque/vexjoy-agent

    Review and fix temporal references in code comments. An agent skill from notque/vexjoy-agent.

    438 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check: notes

Categories

Questions about Review

What does Review do?

Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review. Review is an agent skill from notque/vexjoy-agent. Code review: systematic single-file, parallel multi-reviewer, full-repo audit, PR diff review.

When should I use Review?

Review fits situations like: development work in your project.

How do I install Review in Claude Code?

Run `npx skills add notque/vexjoy-agent --skill review -a claude-code`. Or copy the skill folder (skills/review/review in notque/vexjoy-agent) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.

How do I install Review in Codex?

Run `npx skills add notque/vexjoy-agent --skill review -a codex`. Or copy the skill folder (skills/review/review in notque/vexjoy-agent) into .agents/skills/review in your project. Codex loads it when a task matches its description.

Can I use Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add notque/vexjoy-agent --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.

What does Review need to run?

Going by SKILL.md and its folder, Review needs the command-line tools its instructions call (python3, git and gh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, Edit, Task, Agent.

Does Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Review use?

Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.6k tokens, read only when the agent opens those files.

What are the alternatives to Review?

Skills that share tags, products or a category with Review: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review?

notque (a GitHub user) maintains it in notque/vexjoy-agent, which has 438 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 3, 2026.

Source: notque/vexjoy-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.