Agent skill

Code Review

by pnp in pnp/powershell

Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not…

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add pnp/powershell --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pnp/powershell code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pnp/powershell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
905
Token cost
~2.3k tokens
SKILL.md length
1,200 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not…

  • Reviewing a diff
  • SKILL.md covers Layout, What to look for first, Documentation and changelog and Breaking changes, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Uncommitted changes

What it does

Code Review is an agent skill from pnp/powershell. Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not match the API called, culture and cross-platform bugs, and missing documentation or changelog updates. Use when reviewing a diff, a PR, or uncommitted changes.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes and Code review. It works with PowerShell and Microsoft 365. The licence is MIT.

When your agent uses it

  • Reviewing a diff
  • Uncommitted changes

Example prompts

  • “/code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 04d819a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.3k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pnp/powershell at commit 04d819a, republished under its MIT licence (© pnp). 1,200 words, ~2,293 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not match the API called, culture and cross-platform bugs, and missing documentation or changelog updates. Use when reviewing a diff, a PR, or uncommitted changes.

Playbook: code-review

Review changes to PnP PowerShell for the failure modes this repository actually ships.

Cmdlets here run unattended, against production tenants, often with tenant-wide permissions. A cmdlet that quietly does the wrong thing is worse than one that fails, because nobody finds out until the tenant is already changed. Weight findings accordingly.

Verify before reporting. A claim about behaviour that nobody ran is a guess; say so when it is one.

Language and API rules live in dotnet-standards. This playbook is about what goes wrong here specifically.

Report to the user, in the session. Never post a review, a comment, or an approval to GitHub, and never open an issue for a finding — see Human in the loop.

Layout

  • src/Commands/ — cmdlet implementations, one folder per feature area
  • src/Commands/Base/ — base classes, PipeBinds/ for parameter binding types
  • src/Commands/Attributes/ — permission and behaviour attributes
  • src/ALC/ — assembly load context that isolates private dependencies
  • documentation/<Verb-PnPNoun>.md — the reference page for every cmdlet, one file each
  • pages/articles/ — conceptual articles, listed in pages/articles/toc.yml
  • pages/_site/ — generated site output, never edited by hand
  • build/ — build and generator scripts
  • CHANGELOG.md — release notes

Much of the provisioning behaviour lives in PnP Framework, a separate repository. When a root cause sits there, say so rather than accepting a workaround layered on top here, and do not let a PR claim to fix an issue whose cause it never touched.

What to look for first

Silence

The defect this repository has shipped most often is input accepted and then ignored.

  • catch { } or catch { return null; } — swallowing turns a user's mistake into wrong output
  • A parameter parsed into "no value given", after which the cmdlet proceeds with its default behaviour. Ignoring a -Configuration that could not be read once meant extracting an entire site instead of the one list asked for
  • System.Text.Json ignores unknown members by default, so a misspelled property silently has no effect. Custom enum converters here drop values they cannot parse, case sensitively
  • An unrecognised resource prefix in a permission attribute is silently classified as SharePoint, so a typo'd "garph/…" declares a bogus SharePoint scope while the real Graph requirement goes undeclared — see permissions-auditor
  • A dropped value that widens what the cmdlet does deserves an error, not a warning. An empty handler list means "all handlers", so one unrecognised handler name would otherwise turn a scoped operation into a full one
Unpaged collections

GraphRequestHelper.GetResultCollection follows @odata.nextLink. GraphRequestHelper.Get does not — pointed at a collection endpoint it returns the first page only, with no error. The same applies to RequestHelper. This presents to users as "the cmdlet misses items in large tenants", which is invisible in any tenant small enough to develop against. Check every new collection fetch.

The CSOM equivalent: a query returning more than the list view threshold, or a loop that pages manually and drops the last page.

Base class

Check the base class actually matches what the cmdlet does — a tenant-admin operation on PnPWebCmdlet, or a Graph call from a SharePoint cmdlet, gets the wrong context and the wrong permission flavour. It compiles, and it fails in someone's tenant. The table in new-cmdlet is the reference.

How errors reach the user

PnPConnectedCmdlet.ProcessRecord rethrows PipelineStoppedException untouched (src/Commands/Base/PnPConnectedCmdlet.cs:57-60) and catches everything else. Two paths, and the difference is the finding:

  • WriteError / ThrowTerminatingError — under -ErrorAction Stop these surface as a pipeline stop, rethrown unchanged. The ErrorRecord, its ErrorCategory and its target object all reach the user intact.
  • A raw throw — hits the generic catch. Default error action: rethrown as PSInvalidOperationException with the original as inner. Under -ErrorAction Stop or SilentlyContinue: LogError → LoggingUtility.Error → WriteError(new ErrorRecord(new Exception(message), source, ErrorCategory.NotSpecified, null)). Type, inner exception, category and target object are all discarded, so everything the user needs must be in the message text. Under -ErrorAction Ignore the LogError call is skipped altogether (PnPConnectedCmdlet.cs:112-119), so the failure is swallowed with no record at all — worth remembering when a user reports a cmdlet that "does nothing and says nothing".

So a raw throw carrying a custom exception type the caller is meant to inspect is a finding — the type is not observable on that path. So is a fatal condition signalled with WriteWarning and then continuing, and a throw where ThrowTerminatingError with a real ErrorCategory and target object would have told the user which object failed.

Show full SKILL.md (493 more words)Show less
Cmdlet conventions
  • Verb-PnPNoun, approved verbs, correct base class
  • ParameterSpecified(nameof(X)) distinguishes "not supplied" from "supplied as default"
  • Reference-typed parameters that are dereferenced in ExecuteCmdlet need [ValidateNotNull], otherwise -Param $null is a NullReferenceException
  • Permission attributes must match the APIs the cmdlet actually calls, in both directions — over-declaring forces users to grant access the cmdlet never uses
  • Destructive or overwriting behaviour needs ShouldProcess, with -Force bypassing only a secondary ShouldContinue. Force || ShouldProcess(...) is a defect: -Force short-circuits the ||, ShouldProcess is never called, and -Force -WhatIf performs the operation instead of simulating it. Force || ShouldContinue(...) is the correct, repo-standard form
  • A renamed cmdlet keeps its old name as [Alias]
Cross-platform

.NET 8 and PowerShell 7.4+ on Windows, Linux and macOS.

  • No Windows-only path assumptions, no backslash string surgery
  • Environment.NewLine (what StringBuilder.AppendLine writes) mixed with hardcoded \r\n makes generated files churn purely from changing OS
  • Format dates and numbers with CultureInfo.InvariantCulture. A custom format string like "yyyy-MM-ddTHH:mm:ssZ" takes its separators from the current culture and produces 13.53.41 under some locales, which is not a valid xsd:dateTime
  • New package references have ALC consequences: the module assembly and CSOM live in Core, every other dependency is private and goes to Common

Documentation and changelog

A parameter added, renamed, or changed in behaviour requires its documentation/<Cmdlet>.md updated in the same PR. A new cmdlet requires a new page; a removed cmdlet requires its page deleted.

  • ## PARAMETERS sections carry only the platyPS ```yaml metadata blocks. Other fenced blocks there risk the help build; put examples under ## EXAMPLES with ```powershell fences
  • Parameter subsections are listed alphabetically
  • Conceptual content belongs in pages/articles/ with front matter, registered in toc.yml, not in documentation/, which is cmdlet reference only

CHANGELOG.md entries go under [Current nightly] in Added, Changed, Fixed or Removed, each naming the affected cmdlets in backticks and linking its PR. A change in behaviour belongs under Changed even when it fixes a bug, so it appears in the release notes people read before upgrading. A PR with no changelog entry is an incomplete PR — but the file header says it is owner maintained and maintainers do add entries, so raise it as a gap, not a blocker.

Breaking changes

Ask one question: does any correct usage behave differently?

If only previously-broken usage changes — a configuration that was never honoured, an invocation that already threw — it is a fix, and it belongs in a minor release with a Changed entry. Reserve a major release for changes that break usage which was working as documented. Say which of the two a PR is, and name the invocation that changes, rather than labelling it breaking on the strength of a diff. api-surface-diff has the full classification.

Reporting

Lead with the finding, not the file tour. For each one give the location, one sentence on the defect, and a concrete failure scenario: the input, and what the user gets instead of what they expected. Rank by consequence. If a check could not be run, say what would settle it.

© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-review of pnp/powershell.

Open the folder on GitHubat commit 04d819a

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillpnp/powershell905—~2.3kAutomated safety check: PassMIT
Ansible Pull Request Reviewansible/ansible71k—~570Automated safety check: PassGPL-3.0
Code ReviewAzure/Azurite2.3k—~734Automated safety check: PassMIT
Docs GuardamElnagdy/guard-skills1.3k—~2.1kAutomated safety check: PassMIT
Codex Reviewjewbetcha/opentrace1167 repos~243Automated safety check: PassMIT
Code ReviewMichaelGrafnetter/DSInternals2k—~4kAutomated safety check: PassMIT

Similar skills

  • Reviews an Ansible pull request by number, following the steps in the project's CLAUDE.md, with early checks for changelog fragments and tests.

    71k GitHub stars~570 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    Azure/Azurite

    Official

    Review Azurite pull requests with service-aware checks for Blob, Queue, and Table behavior, API compatibility, tests, and release notes.

    2.3k GitHub stars~734 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Docs Guard

    amElnagdy/guard-skills

    Checks generated or edited documentation against the source code, flagging invented symbols, outdated samples and unverifiable claims before publishing.

    1.3k GitHub stars~2.1k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Codex Review

    jewbetcha/opentrace

    Professional code review with auto CHANGELOG generation, integrated with Codex AI

    116 GitHub starsUsed in 7 repos~243 tokens
    DevelopmentAuto-check passed
  • Code Review

    MichaelGrafnetter/DSInternals

    Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

    2k GitHub stars~4k tokensUpdated 26 days ago
    DevelopmentAuto-check passed
  • Review Endstate

    Artexis10/endstate

    A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.

    110 GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from pnp/powershell

All 9 skills in this repo
  • Cmdlet Scaffolder

    pnp/powershell

    Generate a new PnP PowerShell cmdlet modelled on an existing sibling - class with the right base class and permission attributes, the documentation page, and the changelog entry.

    905 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Dotnet Standards

    pnp/powershell

    C 12 / .NET 8 and PowerShell cmdlet design rules for this repository - naming, output and error channels, parameter validation, ShouldProcess, async, culture, cross-platform and ALC constraints.

    905 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Issue Triage

    pnp/powershell

    Take a PnP PowerShell GitHub issue, find the cmdlet that owns it, trace the code path, and decide whether the cause is in this repo or in PnP Framework, PnP Core SDK or the service.

    905 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • New Cmdlet

    pnp/powershell

    The conventions a PnP PowerShell cmdlet must satisfy - base class selection, permission attributes, PipeBinds, parameter validation, Graph and CSOM call patterns, and the documentation plus…

    905 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Permissions Auditor

    pnp/powershell

    Audit PnP PowerShell permission attributes against the APIs a cmdlet actually calls and against its documentation.

    905 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • API Surface Diff

    pnp/powershell

    Compare the public cmdlet surface of the current branch against dev - names, aliases, parameters, types, mandatory flags, parameter sets, output types, permissions - and classify each change as…

    905 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not…. Code Review is an agent skill from pnp/powershell. Review changes to PnP PowerShell for the failure modes this repository actually ships - silently ignored input, unpaged Graph collections, the wrong base class, permission attributes that do not match the API called, culture and cross-platform bugs, and missing documentation or changelog updates.

When should I use Code Review?

Code Review fits situations like: reviewing a diff; uncommitted changes.

How do I install Code Review in Claude Code?

Run `npx skills add pnp/powershell --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in pnp/powershell) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add pnp/powershell --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in pnp/powershell) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/powershell --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Ansible Pull Request Review (ansible/ansible, 71k stars), Code Review (Azure/Azurite, 2.3k stars), Docs Guard (amElnagdy/guard-skills, 1.3k stars) and Codex Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

pnp (a GitHub organization) maintains it in pnp/powershell, which has 905 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.

Source: pnp/powershell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.