Agent skill

Code Review

by nstarman in nstarman/quax

A skill your agent uses when reviewing a pull request or diff in the quax repository.

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add nstarman/quax --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nstarman/quax code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nstarman/quax.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
143
Token cost
~3.2k tokens
SKILL.md length
1,705 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when reviewing a pull request or diff in the quax repository.

  • Reviewing a pull request
  • SKILL.md covers Scope of this review, What changed → what to check, Dispatch rules and Value subclasses, plus 7 more sections
  • Calls uv
  • Diff in the quax repository

What it does

Code Review is an agent skill from nstarman/quax. Use when reviewing a pull request or diff in the quax repository. Covers the quax-specific defects that generic review misses — dispatch rules that disagree with the primitive they replace, JAX version gates set at the wrong boundary, Value subclass invariants, trace hot-path regressions, and error paths that were quietly made quieter.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Deep learning, Code review and Pull requests. It works with Python. The repository describes itself as: Multiple dispatch over abstract array types in JAX. The licence is Apache-2.0.

When your agent uses it

  • Reviewing a pull request
  • Diff in the quax repository

Example prompts

  • “/code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 0b6f934. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 3.2k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 1,705 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nstarman/quax at commit 0b6f934, republished under its Apache-2.0 licence (© nstarman). 1,705 words, ~3,161 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Use when reviewing a pull request or diff in the quax repository. Covers the quax-specific defects that generic review misses — dispatch rules that disagree with the primitive they replace, JAX version gates set at the wrong boundary, Value subclass invariants, trace hot-path regressions, and error paths that were quietly made quieter.

Reviewing quax changes

Quax runs a JAX program under a custom interpreter, reinterpreting each primitive according to the types passed in. Two properties follow, and they generate nearly every real defect in this repository:

  • A dispatch rule replaces a JAX primitive. If it disagrees with that primitive about a value, a shape, or a dtype, the disagreement surfaces as a wrong number deep inside somebody else's model.
  • A missing rule is not an error. Dispatch falls back to materialising every operand and calling plain JAX, so the custom type vanishes from the output without a warning. Silence is the default failure mode here.

Scope of this review

Leave these alone — they are already gated or already covered:

  • Formatting, import order, naming, line length. prek runs ruff (E, F, I001, UP), pyright, and taplo on every commit.
  • Generic security checklists. There is no user input, no network, no serialisation of untrusted data, no rendering. Injection and XSS questions do not apply.
  • Value-level correctness of a primitive that already has a test entry. The harness compares against plain JAX for you — see Tests.

Spend the review on the sections below instead.

What changed → what to check

ChangeCheck
A @quax.register rule added or editedDispatch rules
A Value / ArrayValue subclass, or its fieldsValue subclasses
_compat.py, or any JAX_GE_* / jax._src useVersion compatibility
Anything using jax.experimental.hijaxHijax
_trace.py, _dispatch.py, _module.py, _values.pyThe hot path
An except, assert, or fallback branchSilent failure
Anything under tests/Tests

Dispatch rules

The question that finds the most bugs: does this rule agree with the primitive it replaces? Not approximately — in value, in output shape, and in dtype. Read the rule against lax's own semantics for that primitive rather than against what the rule looks like it intends.

Three landed bugs, all of this shape:

  • Unitful.integer_pow raised the units to the power but returned the array unchanged (#180). The array and its metadata must both transform.
  • Zero's strided_slice output shape used floor where lax uses ceil (#181). Shape arithmetic must reproduce lax's rounding exactly.
  • named validated axes positionally where the semantics are pairwise (#192, #194).

Then the mechanical checks:

  • **kw accepted and forwarded. Primitive params come and go across JAX versions (out_dtype on mul_p, out_sharding on reduce_sum_p, sharding on broadcast_in_dim_p). A rigid signature is a future TypeError: got an unexpected keyword argument on somebody's upgrade.
  • Mixed-type rules come in pairs, annotating the operand you do not own as ArrayLike | quax.ArrayValue, with precedence=1 on the specific (MyType, MyType) rule. Without the precedence, both rules match a same-type call and plum raises AmbiguousLookupError.
  • The return annotation is load-bearing. plum runs convert on the return value of any rule with a concrete return annotation, and it is what other rules dispatch against. An annotation that overstates the type (claiming MyType for a comparison that honestly returns bools) is a defect, not a cosmetic issue.
  • Does the custom type survive? If the rule materialises an operand and returns a plain array, that is sometimes the honest answer and sometimes the type silently disappearing. Decide which, explicitly.

A new rule should also make its way into .github/prompts/add-jax-primitive.prompt.md's workflow — that prompt is the authoring counterpart to this section.

Value subclasses

  • eqx.field(static=True) on every non-array field — stored shapes, dtypes, units, axis names, bool flags. Omitting it makes JAX try to trace through the value.
  • aval() must be pure: the same instance returns the same AbstractValue every time, because quax caches it at tracer-construction time. It may bind primitives -- quax evaluates it under the parent trace so that this works (#216), and tests/unit/test_aval_binds_primitive.py pins it -- but it should not need to: aval runs once per tracer, so a bind there is hot-path cost for a shape and a dtype. A change touching where or when aval() is called needs care here.
  • A materialise() that raises is a design decision, not a bug. Unitful, LoraArray, NamedArray, and the MyArray test fixture all raise on purpose, because materialising would discard the information the type exists to carry. Do not "fix" one.
  • __array__ must not silently strip. Returning a bare array from a type carrying a unit or an axis name turns a loud failure into a wrong number. jax.numpy.asarray began calling it in JAX 0.10 where it previously raised.

Version compatibility

This library supports a JAX range, and the compatibility layer is where version work goes wrong.

  • Gate on the version where the API actually changed, not on the nearest flag that already exists. #166 guarded TypedInt conversions on 0.7.2 when the types landed in 0.8.0. If a PR adds a JAX_GE_* use, confirm the boundary against JAX's own history rather than against the surrounding code.
  • Never reintroduce a removed parameter. #205 re-added scan_p's linear after JAX 0.10.2 dropped it. When rebuilding primitive params, pass through what the caller gave you; construct only what the current version takes.
  • Both branches must be exercised. A new gate means two code paths; CI runs the supported floor and the newest release, so say which branch the new tests hit.
  • jax._src reaches need a gate and a comment explaining what changed and why the private API is the only route. _compat.py is the model for this — match its density of explanation, not its brevity.
Show full SKILL.md (840 more words)Show less

Hijax

jax.experimental.hijax is JAX's own extension API for custom types. It is complementary to quax rather than an alternative — the decision guide is in skills/quax/SKILL.md under "Quax, hijax, or both", and quax.examples.hijax is the worked combination. At review time:

  • Ask whether it is needed at all. A hijax primitive costs a typing rule, an expand, and a rule per transform, for one operation. If the change could be a plain @quax.register rule instead, it should be. Hijax earns its cost only when the type must do something quax cannot: a cotangent type that differs from the primal's, invariants checked in the jaxpr, custom batching, or sharding in the type.
  • ArrayValue.aval() must still return a ShapedArray. Returning a HiType makes every jnp function reject the tracer, because jax.Array's isinstance check reads the aval. Build the ShapedArray from the leaf's hijax type instead. tests/unit/test_hijax_interop.py pins this.
  • A hijax value must not be made a pytree, and must not be constructed or attribute-accessed under a trace. Both are legal only inside expand and the type's own methods. A rule that reads value.array in traced code is a bug even though it works eagerly.
  • Cotangent units/metadata must match to_ct_aval. JAX type-checks a bwd rule's output against it, so a rule that returns the primal's type where the cotangent type differs will fail at trace time rather than silently — but only if a test actually differentiates it.
  • The API renames. Names must be resolved by probing, not pinned: VJPHiPrimitive becomes HiPrim after JAX 0.11.1 and MappingSpec only became public in 0.11.0. src/quax/experimental/hijax.py does this once, in _resolve; a change that spells either name anywhere else has reintroduced the coupling.
  • Expect the JAX_CHECK_TRACER_LEAKS fixture, and check it stays narrow. Consuming a hi value under jit reports a false leak on JAX 0.10.2 and 0.11.0 only — a JAX regression, fixed in 0.11.1. tests/usage/test_hijax.py disables the check for those versions and is a no-op elsewhere. A PR that widens it to every version, weakens the check globally, or drops the version bound is a regression: the bound is what makes a recurrence visible.

The hot path

_trace.py, _dispatch.py, _module.py, and Value construction run once per primitive per call. Cost added here is multiplied by the size of the user's program, and this repo has spent four PRs (#168, #173, #174, #187) recovering it.

  • Per-call object construction, isinstance against an ABC, or equinox per-instance validation in these files is a regression until benchmarked otherwise.
  • Caches must not pin what they watch. #187 was a weakref-keyed cache holding a strong reference to the jaxpr it was tracking, so nothing was ever collected.
  • CodSpeed benchmarks live in tests/benchmark/. A change plausibly affecting dispatch cost should say what happened to them.
  • plum's resolution cache is disabled entirely by a single non-faithful type, which is why _compat.py sets jax.Array.__faithful__. Changes near dispatch registration can switch that cache off without any visible symptom but a slow benchmark.

Silent failure

Rule 3 of dispatch already degrades silently by design. Anything that makes an error path quieter compounds it and should be treated as a defect rather than a cleanup:

  • assert False for an unreachable branch — assertions vanish under -O, and this was replaced with a real TypeError in #171.
  • A bare except, or a fallback that swallows the reason it was reached.
  • Broadening a rule's annotations so that a previously-unmatched call now materialises instead of raising.

Tests

The harness in tests/unit/test_lax/ and tests/unit/test_numpy/ runs each entry through both plain JAX and quax.quaxify, then asserts the results are equal. Value correctness for a covered primitive is therefore already checked. What it cannot check, and what review must:

  • expect_myarray is the real assertion. It says whether the custom type survives the operation, per output. A True that should be False (or a tuple with the wrong arity) is a coverage hole the suite will happily pass.
  • mark_todo is pytest.mark.skip. A PR that implements a primitive must remove the mark on its entry, or the new rule ships untested.
  • Both files. test_myarray.py and test_jax_array.py are separate; a rule affecting the plain-array path needs an entry in each.
  • Metadata semantics are invisible to MyArray, which carries no units or axis names. Bugs like #180 live in tests/usage/test_<name>.py — a rule on an example type needs coverage there, not only in the unit tests.
  • The suite runs with JAX_CHECK_TRACER_LEAKS=1 and jaxtyping/beartype enabled.

Repo conventions

  • uv run for everything — uv run pytest, uv run prek run --all-files. Never bare python or pytest.
  • Commits use gitmoji plus conventional commits: 🐛 fix(trace): ..., ✅ test: ..., ⚡️ perf: ..., build(deps): ....
  • Pre-commit runs pyright on src/ only, so type errors in tests/ reach CI unreviewed.
  • Doctests are not collected. Examples in README.md, docs/, and src/ docstrings never run — a PR changing one has not tested it, and the diff needs reading on that basis. The exceptions are README.md and skills/quax/SKILL.md, whose python blocks are executed as individual tests by Sybil, wired up in conftest.py.

Further reading

© nstarman, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/code-review of nstarman/quax.

Open the folder on GitHubat commit 0b6f934

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillnstarman/quax143—~3.2kAutomated safety check: PassApache-2.0
AI ReviewPaddlePaddle/Paddle24k—~303Automated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Docling Pull Request Reviewdocling-project/docling69k—~1kAutomated safety check: PassMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Code Graph RAG Pull Request Reviewvitali87/code-graph-rag5.2k—~685Automated safety check: PassMIT

Similar skills

  • AI Review

    PaddlePaddle/Paddle

    使用 PaddlePaddle 仓库规则评审 Pull Request 和全仓库代码变更,覆盖正确性、兼容性、算子、分布式、数值、性能、安全、测试、构建和 PR 信息。当需要审查 Paddle 的代码、测试、算子 YAML、C++/CUDA/XPU kernel、Python API、分布式逻辑或 CI 配置时使用。

    24k GitHub stars~303 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Docling Pull Request Review

    docling-project/docling

    Reviews or re-reviews a Docling pull request in fixed stages, with findings that can be reproduced and an explicit record of every check that was run.

    69k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Code Graph RAG Pull Request Review

    vitali87/code-graph-rag

    Reviews pull requests to code-graph-rag, watching for wrong or missing graph edges in language parsers, cross-language consistency and tests that really exercise a fix.

    5.2k GitHub stars~685 tokensUpdated today
    DevelopmentAuto-check passed
  • Coding Agent

    mastra-ai/mastra

    Authoring playbook for building agents that write, edit, review, or refactor code.

    29k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed

More from nstarman/quax

  • Quax

    nstarman/quax

    A skill your agent uses when writing, reviewing, or debugging JAX code that involves quax — custom array-ish objects (physical units, LoRA, sparse, symbolic zero, named axes), quax.quaxify…

    143 GitHub stars~5.5k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Code Review

What does Code Review do?

A skill your agent uses when reviewing a pull request or diff in the quax repository. Code Review is an agent skill from nstarman/quax. Use when reviewing a pull request or diff in the quax repository.

When should I use Code Review?

Code Review fits situations like: reviewing a pull request; diff in the quax repository.

How do I install Code Review in Claude Code?

Run `npx skills add nstarman/quax --skill code-review -a claude-code`. Or copy the skill folder (.github/skills/code-review in nstarman/quax) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add nstarman/quax --skill code-review -a codex`. Or copy the skill folder (.github/skills/code-review in nstarman/quax) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nstarman/quax --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (uv).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: AI Review (PaddlePaddle/Paddle, 24k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Docling Pull Request Review (docling-project/docling, 69k stars) and Code Reviewer (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

nstarman (a GitHub user) maintains it in nstarman/quax, which has 143 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 4, 2026.

Source: nstarman/quax on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.