Agent skill

Review Rfc

by nurettincoban in nurettincoban/ai-prd-workflow

Review an implemented RFC in a fresh context against its acceptance criteria, RULES.md and the test plan, and save the review to reviews/.

MITAuto-check passedProduct & Project Management

Install Review Rfc

skills CLI
$ npx skills add nurettincoban/ai-prd-workflow --skill review-rfc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nurettincoban/ai-prd-workflow review-rfc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nurettincoban/ai-prd-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-rfc .claude/skills/review-rfc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-rfc
GitHub stars
298
Token cost
~1.4k tokens
SKILL.md length
773 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Review an implemented RFC in a fresh context against its acceptance criteria, RULES.md and the test plan, and save the review to reviews/.

  • Tasks that involve Test generation
  • SKILL.md covers Inputs, WHEN ARTIFACTS CONFLICT, STEP 0: RUN IT and PRODUCT TYPE, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve User stories

What it does

Review Rfc is an agent skill from nurettincoban/ai-prd-workflow. Review an implemented RFC in a fresh context against its acceptance criteria, RULES.md and the test plan, and save the review to reviews/.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Product & Project Management, covering Test generation, User stories and PRD writing. The repository describes itself as: RFC-driven development for AI coding agents: idea or existing codebase → verified PRD → features → rules → sequenced RFCs → reviewed code. Agent Skills for Claude Code, Codex… The licence is MIT.

When your agent uses it

  • Tasks that involve Test generation
  • Tasks that involve User stories
  • Tasks that involve PRD writing

Example prompts

  • “/review-rfc”

What it can do on your machine

Read from SKILL.md and the folder at commit b67f4d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Rfc loads about 1.4k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 773 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nurettincoban/ai-prd-workflow at commit b67f4d3, republished under its MIT licence (© nurettincoban). 773 words, ~1,428 tokens.

Download SKILL.mdSave it as .claude/skills/review-rfc/SKILL.md (or your agent's skills folder).
name
review-rfc
description
Review an implemented RFC in a fresh context against its acceptance criteria, RULES.md and the test plan, and save the review to reviews/.
argument-hint
<rfc-id>
context
fork
agent
general-purpose
metadata.source
https://github.com/nurettincoban/ai-prd-workflow
metadata.version
3.0.0
metadata.checksum
sha256:d09031cde2a96a96151860bd2c4f067c7c6b817a2f82e7da193cfd25f5e6a31d

Target RFC ID: "$ARGUMENTS" -- if that still reads as a literal placeholder, use the RFC ID from my message instead. Substitute it for [ID] everywhere below. If no ID was given, ask which RFC to work on before doing anything else.

Fresh eyes first. If this conversation already contains the implementation of this RFC -- you wrote or edited that code here -- stop now. Tell the user to run this review in a new session, ideally on a different model, and do nothing else. A reviewer holding the author's reasoning reads past the same gaps the author did, and the RFC, RULES.md, FEATURES.md and TEST-STRATEGY.md contain everything a reviewer needs -- that is the point of them.

You are an expert code reviewer tasked with reviewing an implementation against its RFC specification and project standards.

Review the implementation of the specified RFC and provide a thorough, actionable assessment. Your review should catch bugs, security issues, and deviations from the specification before the code is merged.

Inputs

  • PRD.md for the Product Type section
  • RFCS.md for the RFC's declared predecessors and current status
  • The RFC being reviewed: RFCs/RFC-[ID]-*.md, including its ## Implementation Notes
  • The implementation code
  • RULES.md for project standards
  • FEATURES.md for requirement traceability
  • TEST-STRATEGY.md for the tests planned for this RFC -- a planned test that does not exist is a finding

WHEN ARTIFACTS CONFLICT

Order of authority: PRD.md > FEATURES.md > RULES.md > RFCs > generated plans. Where this prompt's generic guidance conflicts with RULES.md, RULES.md wins -- it was written for this project and this prompt was not. Never resolve a contradiction between two artifacts silently: state it, say which one you followed and why, and flag the other for correction.

STEP 0: RUN IT

Before assessing anything, run the project's build, typecheck, and test suite. Paste the actual output. Then verify each acceptance criterion has a test that would FAIL if the behavior regressed -- a passing suite is not evidence that the criteria are covered. Reading code cannot distinguish "this test asserts the right thing" from "this test passes."

If you cannot execute commands in this environment, say so explicitly and mark every verdict below as unverified rather than assessing by reading alone.

PRODUCT TYPE

Read the Product Type section of PRD.md and apply only the checks that fit that type; state which checks you skipped and why. Skipping must be visible, never silent. If PRD.md has no such section, classify the product yourself (web app · mobile app · library/SDK · CLI · service/API · data pipeline · game), say that you did, and recommend running /verify-prd so the classification is recorded once for every later step.

Review Dimensions

Mark an inapplicable dimension N/A with one line of reasoning. Do not fill it with reassuring findings.

Show full SKILL.md (329 more words)Show less
1. RFC ADHERENCE
  • Read the RFC's ## Implementation Notes first. A recorded, approved deviation is not a defect, but judge whether its reasoning holds. A deviation that is not recorded there is a finding
  • Does the implementation satisfy all acceptance criteria in the RFC?
  • Are there missing features that should have been implemented?
  • Are there extra features implemented that are not in scope?
  • Do API contracts match the RFC specifications?
2. RULES COMPLIANCE
  • Does the code follow all standards defined in RULES.md?
  • Are naming conventions, architecture patterns, and folder structure correct?
  • Are error handling and logging standards met?
3. SECURITY
  • Input validation and sanitization
  • Authentication and authorization correctness
  • Data exposure risks (sensitive data in logs, responses, or errors)
  • Protection against common vulnerabilities (injection, XSS, CSRF)
4. PERFORMANCE
  • Unnecessary computations, database calls, or API requests
  • Missing caching opportunities
  • N+1 query problems or unbounded data fetching
  • Scalability concerns under load
5. MAINTAINABILITY
  • Code readability and organization
  • Appropriate test coverage
  • Proper separation of concerns
  • Dead code or unused imports

Output Format

For each review dimension, provide:

  • Verdict: PASS / NEEDS WORK / FAIL
  • Findings: Specific issues with file and line references
  • Suggestions: Concrete fixes or improvements

Then provide:

  • Overall Risk Level: Low / Medium / High / Critical
  • Summary: 2-3 sentence overall assessment
  • Blocking Issues: Issues that must be fixed before merge (if any)
  • Improvement Suggestions: Non-blocking recommendations for better code quality

Save the complete review to reviews/REVIEW-RFC-[ID].md. If that file already exists, append this review as a new ## Round N -- <date> section instead of overwriting it: the earlier rounds record what was found and fixed, and a re-review is judged against them. Then set the RFC's Status in RFCS.md to Reviewed, or to Changes requested if any blocking issue remains. A review that exists only in chat leaves the next session looking at fixed code with no record of what was checked, what was found, or what was consciously accepted as non-blocking -- and /workflow-status looks for this file when reporting whether an RFC has actually been reviewed.

© nurettincoban, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/review-rfc of nurettincoban/ai-prd-workflow.

Open the folder on GitHubat commit b67f4d3

Compare with similar skills

Review Rfc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Rfc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Rfc this skillnurettincoban/ai-prd-workflow298—~1.4kAutomated safety check: PassMIT
AI Test Generationpetrkindlmann/qa-skills170—~4.8kAutomated safety check: PassMIT
Prd V07 Test Planningmattgierhart/PRD-driven-context-engineering180—~3.5kAutomated safety check: NotesMIT
Vscuse Scenario AuthoringOfficeDev/microsoft-365-agents-toolkit780—~4.3kAutomated safety check: PassCustom licence
Write A Specinkeep/open-knowledge4.5k—~4.9kAutomated safety check: PassGPL-3.0
QA Handoff Packagemohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMIT

Similar skills

  • AI Test Generation

    petrkindlmann/qa-skills

    Use AI to write NEW test code from specs, PRDs, user stories, code diffs, bug reports, or OpenAPI specs.

    170 GitHub stars~4.8k tokensUpdated 4 mo ago
    Testing & QAAuto-check passed
  • Prd V07 Test Planning

    mattgierhart/PRD-driven-context-engineering

    Define test cases BEFORE implementation, ensuring every API, business rule, and user journey has verifiable acceptance criteria during PRD v0.7 Build Execution.

    180 GitHub stars~3.5k tokensUpdated 1 mo ago
    Testing & QAAuto-check: notes
  • Vscuse Scenario Authoring

    OfficeDev/microsoft-365-agents-toolkit

    A skill your agent uses when: reading a docs scenario, PRD, mockup, or user flow and using vscuse-ui/noVNC as the primary authoring surface to record, generate, replace, or update vscuse test plans…

    780 GitHub stars~4.3k tokensUpdated yesterday
    Product & Project ManagementAuto-check passed
  • Write A Spec

    inkeep/open-knowledge

    Scope a feature end to end and write an implementation spec under specs/ from an accepted proposal — current-system mapping, goals/non-goals, a Decision Log for one-way-door choices, a live Open…

    4.5k GitHub stars~4.9k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • QA Handoff Package

    mohitagw15856/pm-claude-skills

    Turn a story and its change into a clean 'ready for QA' package — test scenarios, edge cases, the data and environment setup, and what's explicitly out of scope.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Product & Project ManagementAuto-check passed
  • Ralph Tui Create Beads

    subsy/ralph-tui

    Convert PRDs to beads for ralph-tui execution. An agent skill from subsy/ralph-tui.

    2.5k GitHub starsUsed in 1 repo~2.6k tokens
    Product & Project ManagementAuto-check passed

More from nurettincoban/ai-prd-workflow

All 11 skills in this repo
  • Generate Rfcs

    nurettincoban/ai-prd-workflow

    Break the PRD into sequenced implementation RFCs under RFCs/ with an RFCS.md index, then cold-read each RFC for gaps.

    298 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Workflow Status

    nurettincoban/ai-prd-workflow

    Report which workflow artifacts exist, which RFCs are implemented and reviewed, what has drifted, and the next step.

    298 GitHub stars~994 tokensUpdated 2 days ago
    Auto-check passed
  • Document Existing

    nurettincoban/ai-prd-workflow

    Document an existing codebase as PRD.md, FEATURES.md and RULES.md, so new work is planned against the code as it is.

    298 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Generate Rules

    nurettincoban/ai-prd-workflow

    Write RULES.md, the project standards the AI must follow, with registry-verified dependency versions and permanent rule IDs.

    298 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Test Strategy

    nurettincoban/ai-prd-workflow

    Write TEST-STRATEGY.md, a test plan per RFC, before the tests are written.

    298 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Verify Prd

    nurettincoban/ai-prd-workflow

    Review PRD.md for gaps, contradictions and unverifiable claims, write an improved PRD.md and record the findings in PRD-REVIEW.md.

    298 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed

Questions about Review Rfc

What does Review Rfc do?

Review an implemented RFC in a fresh context against its acceptance criteria, RULES.md and the test plan, and save the review to reviews/. Review Rfc is an agent skill from nurettincoban/ai-prd-workflow.md and the test plan, and save the review to reviews/.

When should I use Review Rfc?

Review Rfc fits situations like: tasks that involve Test generation; tasks that involve User stories; tasks that involve PRD writing.

How do I install Review Rfc in Claude Code?

Run `npx skills add nurettincoban/ai-prd-workflow --skill review-rfc -a claude-code`. Or copy the skill folder (skills/review-rfc in nurettincoban/ai-prd-workflow) into .claude/skills/review-rfc in your project. Claude Code loads it when a task matches its description.

How do I install Review Rfc in Codex?

Run `npx skills add nurettincoban/ai-prd-workflow --skill review-rfc -a codex`. Or copy the skill folder (skills/review-rfc in nurettincoban/ai-prd-workflow) into .agents/skills/review-rfc in your project. Codex loads it when a task matches its description.

Can I use Review Rfc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nurettincoban/ai-prd-workflow --skill review-rfc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-rfc, .gemini/skills/review-rfc, .github/skills/review-rfc and .opencode/skills/review-rfc in your project.

What does Review Rfc need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Rfc is instructions for the agent only.

Does Review Rfc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Rfc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Rfc use?

Review Rfc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Rfc use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Rfc?

Skills that share tags, products or a category with Review Rfc: AI Test Generation (petrkindlmann/qa-skills, 170 stars), Prd V07 Test Planning (mattgierhart/PRD-driven-context-engineering, 180 stars), Vscuse Scenario Authoring (OfficeDev/microsoft-365-agents-toolkit, 780 stars) and Write A Spec (inkeep/open-knowledge, 4.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Rfc?

nurettincoban (a GitHub user) maintains it in nurettincoban/ai-prd-workflow, which has 298 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: nurettincoban/ai-prd-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.