Agent skill

Skill Code Review

by nyldn in nyldn/claude-octopus

Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis

MITAuto-check: warningsDevelopment

Install Skill Code Review

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add nyldn/claude-octopus --skill skill-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nyldn/claude-octopus skill-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-code-review .claude/skills/skill-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-code-review
GitHub stars
4.2k
Used in
1 other repo
Token cost
~2.8k tokens
SKILL.md length
685 words
Files
2
Skills in repo
62
Repo updated
First seen
Licence
MIT

At a glance

Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis

  • Works in 2 steps: Detect Open PR → Post Review Comment
  • Thorough quality and security analysis
  • SKILL.md covers MANDATORY COMPLIANCE — DO NOT…, Quick Mode, Usage and Capabilities, plus 5 more sections
  • Calls git, gh and tsx

What it does

Skill Code Review is an agent skill from nyldn/claude-octopus. Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Code review. The repository describes itself as: Run multiple AI models against the same research, design, or coding task. Surface disagreements before you ship. The licence is MIT.

When your agent uses it

  • Thorough quality and security analysis
  • Tasks that involve Code review

Example prompts

  • “/skill-code-review”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Detect Open PR
  2. Post Review Comment

What it can do on your machine

Read from SKILL.md and the folder at commit 4d152db. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • tsx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Code Review loads about 2.8k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 685 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningTells the agent its actions are pre-authorized / not to stop for confirmationSKILL.md:19
    e scope is "too broad" and narrowing it without asking the user

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nyldn/claude-octopus at commit 4d152db, republished under its MIT licence (© nyldn). 685 words, ~2,760 tokens.

Download SKILL.mdSave it as .claude/skills/skill-code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
skill-code-review
description
Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis
disable-model-invocation
true

Host: Codex CLI — This skill was designed for Claude Code and adapted for Codex. Cross-reference commands use installed skill names in Codex rather than /octo:* slash commands. Use the active Codex shell and subagent tools. Do not claim a provider, model, or host subagent is available until the current session exposes it. For host tool equivalents, see skills/blocks/codex-host-adapter.md.

Code Review Skill

MANDATORY COMPLIANCE — DO NOT SKIP

When this skill is invoked, you MUST execute the multi-LLM review pipeline. You are PROHIBITED from:

  • Doing a direct single-model code review without multi-provider synthesis
  • Deciding the scope is "too broad" and narrowing it without asking the user
  • Skipping the provider check or structured review phases
  • Substituting two background Sonnet agents for the full multi-provider pipeline
  • Rationalizing "a focused audit would be more effective" — the user wants multi-LLM perspectives

Your first output line MUST be: 🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-LLM Code Review

Invokes the code-reviewer persona for thorough code analysis during the ink (deliver) phase.

Quick Mode

For fast sanity checks (staged changes, small PRs), skip the full review pipeline and run just two phases:

bash
# Quick: grasp (consensus on scope) → tangle (parallel review)
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh grasp "[review request]"
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh tangle "[synthesized scope]"

Use quick mode when user says "check this PR", "quick review", "sanity check my changes", or for pre-commit checks. Use the full review for PRs with security/architecture impact.

Usage

bash
# Via orchestrate.sh
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh spawn code-reviewer "Review this pull request for security issues"

# Via auto-routing (detects review intent)
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh auto "review the authentication implementation"

Capabilities

  • AI-powered code quality analysis
  • Security vulnerability detection
  • Performance optimization suggestions
  • Architecture and design pattern review
  • TDD compliance and test-first evidence review
  • Autonomous code generation risk detection
  • Best practices enforcement

Persona Reference

This skill wraps the code-reviewer persona defined in:

  • agents/personas/code-reviewer.md
  • CLI: codex-review
  • Model: gpt-5.2-codex
  • Phases: ink

Example Prompts

"Review this PR for OWASP Top 10 vulnerabilities"
"Analyze the error handling in src/api/"
"Check for memory leaks in the connection pool"
"Review the test coverage for the auth module"

Autonomous Implementation Review

When the review context indicates AI-assisted, Autonomous / Dark Factory, or unclear provenance, raise the rigor bar. Do not treat generated code as trustworthy just because it is polished.

TDD Evidence

Check for concrete signs that the change followed red-green-refactor rather than test-after implementation:

  • Compare the diff and recent history when available to see whether tests were added before or alongside production changes.
  • Prefer behavior-defining tests over snapshot-only or mock-heavy tests that merely restate the implementation.
  • Verify the production code looks like the minimum needed to satisfy the tests, rather than a speculative abstraction with unused options.
  • If evidence is missing, mark TDD compliance as unknown and do not assume TDD happened.
Autonomous Codegen Risk Patterns

Elevate or add findings when you see patterns common in high-autonomy output:

  • Option-heavy APIs or abstractions not justified by tests or current requirements
  • Placeholder logic, TODO/FIXME-driven control flow, or dead branches that appear "future ready"
  • Mock, fake, or dummy behavior leaking into production paths
  • Unwired components, unused helpers, or code that exists without an execution path
  • Silent failure handling, broad catch blocks, missing logs, or weak operational visibility
  • Missing rollback notes, migration guards, or release-safety checks for risky changes
Show full SKILL.md (248 more words)Show less
Review Output Addendum

Add a short section to the review synthesis when autonomy or TDD is in scope:

markdown
## TDD / Autonomy Assessment

- Provenance: Human-authored | AI-assisted | Autonomous / Dark Factory | Unknown
- TDD evidence: Confirmed | Partial | Unknown
- Autonomous risk signals: None | Minor | Significant
- Recommendation: Ship | Fix before merge | Re-run with /octo:tdd or tighter supervision

Implementation Completeness Verification

After the code-reviewer persona completes, run stub detection to verify implementation completeness.

Stub Detection Process

Step 1: Get changed files

bash
# Get files changed in the commit/PR
if [ -n "$COMMIT_RANGE" ]; then
    changed_files=$(git diff --name-only "$COMMIT_RANGE")
else
    changed_files=$(git diff --name-only HEAD~1..HEAD)
fi

# Filter for source code files
source_files=$(echo "$changed_files" | grep -E "\.(ts|tsx|js|jsx|py|go)$")

Step 2: Check for stub patterns

For each changed file, check for common stub indicators:

bash
for file in $source_files; do
    echo "Checking $file for stubs..."

    # Check 1: Comment-based stubs
    stub_count=$(grep -E "(TODO|FIXME|PLACEHOLDER|XXX)" "$file" 2>/dev/null | wc -l | tr -d ' ')

    if [ "$stub_count" -gt 0 ]; then
        echo "⚠️  WARNING: Found $stub_count stub indicators in $file"
        grep -n -E "(TODO|FIXME|PLACEHOLDER)" "$file" | head -3
    fi

    # Check 2: Empty function bodies
    empty_functions=$(grep -E "function.*\{\s*\}|const.*=>.*\{\s*\}" "$file" 2>/dev/null | wc -l | tr -d ' ')

    if [ "$empty_functions" -gt 0 ]; then
        echo "❌ ERROR: Found $empty_functions empty functions in $file"
        echo "   Empty functions must be implemented before merge"
    fi

    # Check 3: Return null/undefined
    null_returns=$(grep -E "return (null|undefined);" "$file" 2>/dev/null | wc -l | tr -d ' ')

    if [ "$null_returns" -gt 0 ]; then
        echo "⚠️  WARNING: Found $null_returns null/undefined returns in $file"
        echo "   Verify these are intentional, not stubs"
    fi

    # Check 4: Substantive content check
    substantive_lines=$(grep -vE "^\s*(//|/\*|\*|import|export|$)" "$file" 2>/dev/null | wc -l | tr -d ' ')

    if [[ "$file" == *.tsx ]] && [ "$substantive_lines" -lt 10 ]; then
        echo "⚠️  WARNING: Component $file only has $substantive_lines substantive lines"
        echo "   Components should typically be >10 lines"
    fi

    # Check 5: Mock/test data in production
    mock_data=$(grep -E "const.*(mock|test|dummy|fake).*=" "$file" 2>/dev/null | wc -l | tr -d ' ')

    if [ "$mock_data" -gt 0 ]; then
        echo "⚠️  WARNING: Found $mock_data references to mock/test data in $file"
        echo "   Ensure these are not placeholders for production code"
    fi
done

Step 3: Add findings to review synthesis

Include stub detection results in the review output:

markdown
## Implementation Completeness

**Stub Detection Results:**

✅ **Fully Implemented Files:**
- src/components/UserProfile.tsx (42 substantive lines)
- src/api/users.ts (67 substantive lines)

⚠️  **Files with Warnings:**
- src/components/Dashboard.tsx
  - 3 TODO comments (non-blocking)
  - Consider addressing before release

❌ **Files Requiring Implementation:**
- src/utils/analytics.ts
  - 2 empty functions detected (BLOCKING)
  - Must implement before merge

**Verification Levels:**
- Level 1 (Exists): 5/5 files ✅
- Level 2 (Substantive): 3/5 files ⚠️
- Level 3 (Wired): 4/5 files ✅
- Level 4 (Functional): Tests pending

**Recommendation:**
- Fix empty functions in analytics.ts before merge
- Address TODO comments in Dashboard.tsx in follow-up PR
- All other files meet implementation standards
Stub Detection Reference

See .claude/references/stub-detection.md for comprehensive patterns and detection strategies.

When to Block Merge

BLOCKING Issues (must fix):

  • ❌ Empty function bodies
  • ❌ Mock data in production code paths
  • ❌ Components not imported/wired anywhere
  • ❌ API endpoints returning empty objects

NON-BLOCKING Issues (note in review):

  • ⚠️ TODO/FIXME comments (create follow-up tickets)
  • ⚠️ Null returns (if intentional)
  • ⚠️ Low line count (if appropriate for the component)

Post Review to PR (v8.44.0)

After generating the review synthesis, check if the current branch has an open PR and offer to post findings as a PR comment.

Step 1: Detect Open PR
bash
# Check if we're on a branch with an open PR
CURRENT_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo "")
PR_NUM=""

if [[ -n "$CURRENT_BRANCH" && "$CURRENT_BRANCH" != "main" && "$CURRENT_BRANCH" != "master" ]]; then
    if command -v gh &>/dev/null; then
        PR_NUM=$(gh pr list --head "$CURRENT_BRANCH" --json number --jq '.[0].number' 2>/dev/null || echo "")
    fi
fi
Step 2: Post Review Comment

If an open PR exists, post the review findings as a PR comment:

bash
if [[ -n "$PR_NUM" ]]; then
    echo "Found open PR #${PR_NUM} on branch ${CURRENT_BRANCH}"

    # Build the review comment body from synthesis
    REVIEW_BODY="## Code Review — Claude Octopus

${REVIEW_SYNTHESIS}

*Review generated by Claude Octopus (/octo:review)*
*Providers: available external providers + 🔵 Claude*"

    # Post through the outbound credential gate. Never interpolate generated
    # Markdown directly into a gh shell argument.
    REPO_SLUG=$(gh repo view --json nameWithOwner --jq .nameWithOwner)
    if ! "${CLAUDE_PLUGIN_ROOT:-${HOME}/.claude-octopus/plugin}/scripts/safe-gh-comment.sh" \
            --repo "$REPO_SLUG" pr-comment "$PR_NUM" - <<< "$REVIEW_BODY"; then
        echo "GitHub write state is unknown; check for the review comment before retrying:" >&2
        gh pr view "$PR_NUM" --repo "$REPO_SLUG" --comments || true
        return 1 2>/dev/null || exit 1
    fi
    echo "Review posted to PR #${PR_NUM}"

    # Update agent registry if this agent is tracked
    REGISTRY="${HOME}/.claude-octopus/plugin/scripts/agent-registry.sh"
    if [[ -x "$REGISTRY" ]]; then
        AGENT_ID=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo "")
        "$REGISTRY" update "$AGENT_ID" --pr "$PR_NUM" 2>/dev/null || true
    fi
fi

If no PR exists: Skip posting, present review in terminal only. If gh CLI not available: Skip posting, suggest user install GitHub CLI.

When to Auto-Post vs Ask
  • Auto-post: When invoked as part of /octo:deliver, /octo:factory, or /octo:embrace (automated workflows)
  • Ask first: When invoked standalone via /octo:review — use AskUserQuestion:
    "PR #N found. Post review findings as a PR comment?"
    Options: "Yes, post to PR", "No, terminal only"

© nyldn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/skill-code-review of nyldn/claude-octopus.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 4d152db

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in nyldn/claude-octopus, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Code Review this skillnyldn/claude-octopus4.2k1 repos~2.8kAutomated safety check: WarnMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from nyldn/claude-octopus

All 62 skills in this repo
  • Octopus Quick

    nyldn/claude-octopus

    Quick execution for ad-hoc tasks without full workflow overhead — use for small, self-contained requests

    4.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Octopus Research

    nyldn/claude-octopus

    Thorough research across multiple sources — use for complex topics needing broad synthesis

    4.2k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Octopus Security Audit

    nyldn/claude-octopus

    OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

    4.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Skill Audit

    nyldn/claude-octopus

    Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review

    4.2k GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Skill Content Pipeline

    nyldn/claude-octopus

    Extract patterns and anatomy from URLs — use to reverse-engineer content strategies from live pages

    4.2k GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Skill Context Detection

    nyldn/claude-octopus

    Auto-detect work context (Dev vs Knowledge) — use to tailor workflows based on current task type

    4.2k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed

Categories

Questions about Skill Code Review

What does Skill Code Review do?

Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis. Skill Code Review is an agent skill from nyldn/claude-octopus.

When should I use Skill Code Review?

Skill Code Review fits situations like: thorough quality and security analysis; tasks that involve Code review.

How do I install Skill Code Review in Claude Code?

Run `npx skills add nyldn/claude-octopus --skill skill-code-review -a claude-code`. Or copy the skill folder (skills/skill-code-review in nyldn/claude-octopus) into .claude/skills/skill-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Skill Code Review in Codex?

Run `npx skills add nyldn/claude-octopus --skill skill-code-review -a codex`. Or copy the skill folder (skills/skill-code-review in nyldn/claude-octopus) into .agents/skills/skill-code-review in your project. Codex loads it when a task matches its description.

Can I use Skill Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nyldn/claude-octopus --skill skill-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-code-review, .gemini/skills/skill-code-review, .github/skills/skill-code-review and .opencode/skills/skill-code-review in your project.

What does Skill Code Review need to run?

Going by SKILL.md and its folder, Skill Code Review needs the command-line tools its instructions call (git, gh and tsx).

Does Skill Code Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skill Code Review safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Skill Code Review use?

Skill Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Code Review use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Code Review?

Skills that share tags, products or a category with Skill Code Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Code Review?

nyldn (a GitHub user) maintains it in nyldn/claude-octopus, which has 4,182 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on October 7, 2026.

Source: nyldn/claude-octopus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.