Code Design Rationale Investigator
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
Evidence-based investigative code review using deductive reasoning to determine what actually happened versus what was claimed.
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/assets/skills/sherlock-review .claude/skills/sherlock-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .claude/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .agents/skills && cp -r skills-src/assets/skills/sherlock-review .agents/skills/sherlock-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .agents/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/assets/skills/sherlock-review .cursor/skills/sherlock-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .cursor/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/proffesor-for-testing/agentic-qe.git --path assets/skills/sherlock-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/assets/skills/sherlock-review .gemini/skills/sherlock-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .gemini/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .github/skills && cp -r skills-src/assets/skills/sherlock-review .github/skills/sherlock-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .github/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install proffesor-for-testing/agentic-qe sherlock-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/assets/skills/sherlock-review .opencode/skills/sherlock-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sherlock-review" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/sherlock-review into .opencode/skills/sherlock-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sherlock-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sherlock-reviewEvidence-based investigative code review using deductive reasoning to determine what actually happened versus what was claimed.
Sherlock Review is an agent skill from proffesor-for-testing/agentic-qe. Evidence-based investigative code review using deductive reasoning to determine what actually happened versus what was claimed. Use when verifying implementation claims, investigating bugs, validating fixes, or conducting root cause analysis. Elementary approach to finding truth through systematic observation.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `schemas/output.json` and `scripts/validate-config.json`).
It sits in Development, covering Root cause analysis. It works with Git. The repository describes itself as: Agentic QE Fleet is an open-source AI-powered QA/QE platform designed for use with Coding Agents (works best with Claude Code) featuring specialized agents and skills to support… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1363bc7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
gitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sherlock Review loads about 1.8k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 404 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from proffesor-for-testing/agentic-qe at commit 1363bc7, republished under its MIT licence (© proffesor-for-testing). 404 words, ~1,772 tokens.
.claude/skills/sherlock-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.<default_to_action> When investigating code claims:
The 3-Step Investigation:
# 1. OBSERVE: Gather evidence
git diff <commit>
npm test -- --coverage
# 2. DEDUCE: Compare claim vs reality
# Does code match description?
# Do tests prove the fix/feature?
# 3. CONCLUDE: Verdict with evidence
# SUPPORTED / PARTIALLY SUPPORTED / NOT SUPPORTEDHolmesian Principles:
| Category | What to Check | How |
|---|---|---|
| Claim | PR description, commit messages | Read thoroughly |
| Code | Actual file changes | git diff |
| Tests | Coverage, assertions | Run independently |
| Behavior | Runtime output | Execute locally |
| Timeline | When things happened | git log, git blame |
| Verdict | Meaning |
|---|---|
| ✓ TRUE | Evidence fully supports claim |
| ⚠ PARTIALLY TRUE | Claim accurate but incomplete |
| ✗ FALSE | Evidence contradicts claim |
| ? NONSENSICAL | Claim doesn't apply to context |
## Sherlock Investigation: [Claim]
### The Claim
"[What PR/commit claims to do]"
### Evidence Examined
- Code changes: [files, lines]
- Tests added: [count, coverage]
- Behavior observed: [what actually happens]
### Deductive Analysis
**Claim**: [specific assertion]
**Evidence**: [what you found]
**Deduction**: [logical conclusion]
**Verdict**: ✓/⚠/✗
### Findings
- What works: [with evidence]
- What doesn't: [with evidence]
- What's missing: [gaps in implementation/testing]
### Recommendations
1. [Action based on findings]Every investigation MUST surface at least 3 weighted observations (CRITICAL=3, HIGH=2, MEDIUM=1, LOW=0.5). Elementary observations count at INFORMATIONAL=0.25 weight. A Sherlock investigation that finds nothing is a failed investigation -- Holmes always finds clues.
Steps:
Red Flags:
Steps:
Red Flags:
Steps:
Red Flags:
catch {} swallowing errors## Case: PR #123 "Fix race condition in async handler"
### Claims Examined:
1. "Eliminates race condition"
2. "Adds mutex locking"
3. "100% thread safe"
### Evidence:
- File: src/handlers/async-handler.js
- Changes: Added `async/await`, removed callbacks
- Tests: 2 new tests for async flow
- Coverage: 85% (was 75%)
### Analysis:
**Claim 1: "Eliminates race condition"**
Evidence: Added `await` to sequential operations. No actual mutex.
Deduction: Race avoided by removing concurrency, not synchronization.
Verdict: ⚠ PARTIALLY TRUE (solved differently than claimed)
**Claim 2: "Adds mutex locking"**
Evidence: No mutex library, no lock variables, no sync primitives.
Verdict: ✗ FALSE
**Claim 3: "100% thread safe"**
Evidence: JavaScript is single-threaded. No worker threads used.
Verdict: ? NONSENSICAL (meaningless in this context)
### Conclusion:
Fix works but not for reasons claimed. Race condition avoided by
making operations sequential, not by adding synchronization.
### Recommendations:
1. Update PR description to accurately reflect solution
2. Add test for concurrent request handling
3. Remove incorrect technical claims// Evidence-based code review
await Task("Sherlock Review", {
prNumber: 123,
claims: [
"Fixes memory leak",
"Improves performance 30%"
],
verifyReproduction: true,
testEdgeCases: true
}, "qe-code-reviewer");
// Bug fix verification
await Task("Verify Fix", {
bugCommit: 'abc123',
fixCommit: 'def456',
reproductionSteps: steps,
testBoundaryConditions: true
}, "qe-code-reviewer");aqe/sherlock/
├── investigations/* - Investigation reports
├── evidence/* - Collected evidence
├── verdicts/* - Claim verdicts
└── patterns/* - Common deception patternsconst investigationFleet = await FleetManager.coordinate({
strategy: 'evidence-investigation',
agents: [
'qe-code-reviewer', // Code analysis
'qe-security-auditor', // Security claim verification
'qe-performance-validator' // Performance claim verification
],
topology: 'parallel'
});"It is a capital mistake to theorize before one has data." Trust only reproducible evidence. Don't trust commit messages, documentation, or "works on my machine."
The Sherlock Standard: Every claim must be verified empirically. What does the evidence actually show?
© proffesor-for-testing, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in assets/skills/sherlock-review of proffesor-for-testing/agentic-qe.
Open the folder on GitHubat commit 1363bc7
Sherlock Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sherlock Review this skillproffesor-for-testing/agentic-qe | 495 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Code Design Rationale Investigatorcursor/plugins | 11k | 9 repos | ~2.6k | Automated safety check: Pass | None | |
| Debugging and Error Recoveryaddyosmani/agent-skills | 104k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Root Cause Tracingsandgardenhq/sgai | 137 | 4 repos | ~1.4k | Automated safety check: Pass | Custom licence | |
| Codexqa Rootcause Analyzeropenqa-cn/codexqa | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Investigate Issueanalogjs/analog | 3.2k | — | ~2k | Automated safety check: Pass | MIT |
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
addyosmani/agent-skills
Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.
sandgardenhq/sgai
A skill your agent uses when errors occur deep in execution and you need to trace back to find the original trigger - systematically traces bugs backward through call stack, adding instrumentation…
openqa-cn/codexqa
Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.
analogjs/analog
Investigate a GitHub issue end to end — reproduce the reporter's repo or code snippet in an isolated sandbox outside the monorepo, trace the root cause in the source, and draft a reply back to the…
gnomeria/usbtree
Systematic root-cause debugging — reproduce, isolate, fix at the source, prove the fix.
proffesor-for-testing/agentic-qe
Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.
proffesor-for-testing/agentic-qe
Test quality validation through mutation testing, assessing test suite effectiveness by introducing code mutations and measuring kill rate.
proffesor-for-testing/agentic-qe
Profiles application performance under load using k6, Artillery, or JMeter to measure latency, throughput, and error rates.
proffesor-for-testing/agentic-qe
Conduct context-driven code reviews focusing on quality, testability, and maintainability.
proffesor-for-testing/agentic-qe
Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology.
proffesor-for-testing/agentic-qe
Database schema validation, data integrity testing, migration testing, transaction isolation, and query performance.
Works with
Categories
Evidence-based investigative code review using deductive reasoning to determine what actually happened versus what was claimed. Sherlock Review is an agent skill from proffesor-for-testing/agentic-qe. Evidence-based investigative code review using deductive reasoning to determine what actually happened versus what was claimed.
Sherlock Review fits situations like: verifying implementation claims; investigating bugs; validating fixes; conducting root cause analysis.
Run `npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a claude-code`. Or copy the skill folder (assets/skills/sherlock-review in proffesor-for-testing/agentic-qe) into .claude/skills/sherlock-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a codex`. Or copy the skill folder (assets/skills/sherlock-review in proffesor-for-testing/agentic-qe) into .agents/skills/sherlock-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add proffesor-for-testing/agentic-qe --skill sherlock-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sherlock-review, .gemini/skills/sherlock-review, .github/skills/sherlock-review and .opencode/skills/sherlock-review in your project.
Going by SKILL.md and its folder, Sherlock Review needs the command-line tools its instructions call (git and npm).
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Sherlock Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sherlock Review: Code Design Rationale Investigator (cursor/plugins, 11k stars), Debugging and Error Recovery (addyosmani/agent-skills, 104k stars), Root Cause Tracing (sandgardenhq/sgai, 137 stars) and Codexqa Rootcause Analyzer (openqa-cn/codexqa, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
proffesor-for-testing (a GitHub user) maintains it in proffesor-for-testing/agentic-qe, which has 495 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 9, 2026.
Source: proffesor-for-testing/agentic-qe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.