Agent skill

Code Review

by open-octo in open-octo/octo-agent

Review local code changes. An agent skill from open-octo/octo-agent.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add open-octo/octo-agent --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install open-octo/octo-agent code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/open-octo/octo-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/skills/defaults/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
125
Token cost
~942 tokens
SKILL.md length
479 words
Files
2
Skills in repo
40
Repo updated
First seen
Licence
MIT

At a glance

Review local code changes. An agent skill from open-octo/octo-agent.

  • Works in 4 steps: Gather context for the review → Dispatch the sub-agent (only when you… → Act on the review → …
  • The user wants a code review
  • Calls git
  • Says review the diff / review my changes / 代码评审 / review 一下改动

What it does

Code Review is an agent skill from open-octo/octo-agent. Review local code changes. Uses an isolated sub-agent for unbiased analysis when the main agent wrote the code; reviews directly in fresh review-only sessions. Checks correctness, conventions, performance, tests, security, and tech design compliance. Use when the user wants a code review or says "review the diff" / "review my changes" / "代码评审" / "review 一下改动".

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `code-reviewer.md`).

It sits in Development, covering Code review and Subagents. The repository describes itself as: Open-source, single-binary, self-hosted AI agent — your models and data stay on your machine. A coding agent on par with Claude Code and a personal assistant lighter than… The licence is MIT.

When your agent uses it

  • The user wants a code review
  • Says review the diff / review my changes / 代码评审 / review 一下改动

Example prompts

  • “review the diff”
  • “review my changes”
  • “review 一下改动”
  • “/code-review”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather context for the review
  2. Dispatch the sub-agent (only when you wrote the code)
  3. Act on the review
  4. Report to user

What it can do on your machine

Read from SKILL.md and the folder at commit fc1385f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 942 tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 479 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~942

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from open-octo/octo-agent at commit fc1385f, republished under its MIT licence (© open-octo). 479 words, ~942 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review
description
Review local code changes. Uses an isolated sub-agent for unbiased analysis when the main agent wrote the code; reviews directly in fresh review-only sessions. Checks correctness, conventions, performance, tests, security, and tech design compliance. Use when the user wants a code review or says "review the diff" / "review my changes" / "代码评审" / "review 一下改动".

Review local code changes. Choose the reviewer based on where the implementation context lives:

  • You implemented the changes in this session (or took part in the design/implementation conversation): dispatch an isolated sub-agent — a fresh agent with no knowledge of this session's implementation decisions. This eliminates the bias of reviewing your own work.
  • Fresh session, review-only request (the user opened this session just to have you review a diff/PR you had no part in): you already ARE the unbiased fresh pair of eyes — review the code yourself, following the same template in code-reviewer.md. Spawning a sub-agent here only adds latency and a context hand-off with zero isolation benefit. Skip step 2 and produce the review report directly.

Process

1. Gather context for the review

Collect everything the reviewer needs:

bash
# What changed
git log --oneline main..HEAD
git diff main...HEAD
git diff
git diff --cached

Also identify:

  • Tech design doc path (if one exists in conversation context or commit messages)
  • Which services/modules are touched
  • Test files added or modified
2. Dispatch the sub-agent (only when you wrote the code)

Call the sub_agent tool with subagent_type: "code-review" — a read-only reviewer that starts with zero context. Pass it the diff range, file list, and tech design reference in the prompt — but NOT your implementation reasoning or conversation history.

If you need to review multiple independent changes (e.g., several PRs), dispatch one sub-agent per change in the same round — they run in parallel. When a dispatch comes back as a handle rather than a result, end your turn and use the completion notification when it arrives. Do not poll sub_agent_status while waiting; use it only if you suspect an agent is stuck or need to list running agents.

The sub-agent prompt should follow the template in code-reviewer.md.

Fill in:

  • {DESCRIPTION} — brief summary of what these changes do
  • {TECH_DESIGN_PATH} — path to tech design doc (or "none")
  • {BASE_SHA} / {HEAD_SHA} — git range
  • {DIFF_STAT} — output of git diff --stat

If the sub_agent tool is not available in this session, perform the review yourself following the same template — and say explicitly in the report that the review was not isolated. (No such disclaimer is needed when you review directly because the request came in a fresh session — that review IS isolated.)

Show full SKILL.md (123 more words)Show less
3. Act on the review

Whether the findings come from the sub-agent or from your own review:

Receiving feedback — rules:

  • Verify before implementing. Don't blindly agree.
  • If any item is unclear, clarify ALL unclear items before fixing any.
  • Implementation order: Critical → Important → Minor, test each fix individually.
  • Push back with technical reasoning if the reviewer is wrong (missing context, doesn't apply to this codebase, YAGNI).
  • No performative agreement ("Great point!", "You're absolutely right!"). Just fix and show the result.

Priority:

  • Critical: fix immediately, no exceptions
  • Important: fix before proceeding
  • Minor: note for later or fix if quick
4. Report to user

Present the review to the user. For sub-agent findings, add your own assessment of each — agree, disagree with reasoning, or need discussion.

© open-octo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in internal/skills/defaults/code-review of open-octo/octo-agent.

  • SKILL.md
  • code-reviewer.md

Open the folder on GitHubat commit fc1385f

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillopen-octo/octo-agent125—~942Automated safety check: PassMIT
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT

Similar skills

  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes

More from open-octo/octo-agent

All 40 skills in this repo
  • Image Gen

    open-octo/octo-agent

    Acquire images as files — generate them with an AI image model (14 providers: OpenAI/gpt-image, Gemini, Qwen, Zhipu, Volcengine, Stability, FLUX, Ideogram, MiniMax, and more), search openly-licensed…

    125 GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Office XLSX

    open-octo/octo-agent

    Create, read, and edit Excel (.xlsx) spreadsheets programmatically with openpyxl — cell values, formulas, styling (fonts/fills/borders/alignment/number formats), merged cells, multiple sheets…

    125 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • Artifact Design

    open-octo/octo-agent

    Design guidance for any HTML/Markdown file shown in octo's Artifacts panel — reports, dashboards, architecture/system diagrams, generated UIs, slide-style pages, 3D scenes.

    125 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ppt Master

    open-octo/octo-agent

    AI-driven multi-format SVG content generation system. An agent skill from open-octo/octo-agent.

    125 GitHub stars~23k tokensUpdated today
    Auto-check: warnings
  • Config Setup

    open-octo/octo-agent

    Configure octo's global settings through guided conversation — set up AI model endpoints (providers, API keys, models), adjust agent defaults (reasoning effort, permission mode, coauthor, workspace…

    125 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Contract Review

    open-octo/octo-agent

    审阅合同条款、识别风险点、给出修改建议。Use when 用户贴出或上传合同文本要求审查, 或提到"合同审查""帮我看看这份合同""这条款有没有问题""重大不利条款""合同风险" "review this contract"等。覆盖服务协议、劳动合同、保密协议(NDA)、采购合同、 租赁合同等常见合同类型,风险条款库为中英双语。仅做通俗的条款风险提示,…

    125 GitHub stars~666 tokensUpdated today
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

Review local code changes. An agent skill from open-octo/octo-agent. Code Review is an agent skill from open-octo/octo-agent. Review local code changes.

When should I use Code Review?

Code Review fits situations like: the user wants a code review; says review the diff / review my changes / 代码评审 / review 一下改动.

How do I install Code Review in Claude Code?

Run `npx skills add open-octo/octo-agent --skill code-review -a claude-code`. Or copy the skill folder (internal/skills/defaults/code-review in open-octo/octo-agent) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add open-octo/octo-agent --skill code-review -a codex`. Or copy the skill folder (internal/skills/defaults/code-review in open-octo/octo-agent) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add open-octo/octo-agent --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 942 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and PR Review (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

open-octo (a GitHub organization) maintains it in open-octo/octo-agent, which has 125 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 8, 2026.

Source: open-octo/octo-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.