Agent skill

80 20 Review

by Resgrid in Resgrid/Core

Focus code review effort on the 20% of code that causes 80% of issues.

Apache-2.0Auto-check passedDevelopment

Install 80 20 Review

skills CLI
$ npx skills add Resgrid/Core --skill 80-20-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Resgrid/Core 80-20-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.forge/skills/80-20-review .claude/skills/80-20-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
80-20-review
GitHub stars
229
Token cost
~2.8k tokens
SKILL.md length
344 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Focus code review effort on the 20% of code that causes 80% of issues.

  • Works in 4 steps: Review at checkpoints, not continuously… → Focus on data access, security,… → Blast radius determines depth — A… → …
  • Mentions review
  • SKILL.md covers Core Principles, Patterns, Anti-patterns and Decision Guide
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

80 20 Review is an agent skill from Resgrid/Core. Focus code review effort on the 20% of code that causes 80% of issues. Prioritizes data access, security, concurrency, and integration boundaries over formatting and style. Uses blast radius scoring to determine review depth. Includes checkpoint schedules, critical path identification, and a batch review checklist. Load this skill when reviewing code, PRs, or architecture, or when the user mentions "review", "code review", "PR review", "what should I review", "review priorities", "blast radius", or "critical path".

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Pull requests. The repository describes itself as: The Open Source Computer Aided Dispatch (CAD), Personnel, Shift Management, Automatic Vehicle Location (AVL) and Emergency Management Platform that powers Resgrid.com. The licence is Apache-2.0.

When your agent uses it

  • Mentions review
  • What should I review
  • Review priorities

Example prompts

  • “review”
  • “code review”
  • “PR review”
  • “/80-20-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Review at checkpoints, not continuously — Constant review interrupts flow. Schedule reviews at natural breakpoints: post-implementation…
  2. Focus on data access, security, concurrency, integration — These are the 20% of code areas that cause 80% of production incidents. A…
  3. Blast radius determines depth — A utility function used in one place gets a glance. A middleware change that affects every request gets a…
  4. Automate the trivial — Formatting, import ordering, naming conventions, and basic anti-patterns should be caught by tools (formatters…

What it can do on your machine

Read from SKILL.md and the folder at commit cdfc7ec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

80 20 Review loads about 2.8k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 344 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Resgrid/Core at commit cdfc7ec, republished under its Apache-2.0 licence (© Resgrid). 344 words, ~2,786 tokens.

Download SKILL.mdSave it as .claude/skills/80-20-review/SKILL.md (or your agent's skills folder).
name
80-20-review
description
Focus code review effort on the 20% of code that causes 80% of issues. Prioritizes data access, security, concurrency, and integration boundaries over formatting and style. Uses blast radius scoring to determine review depth. Includes checkpoint schedules, critical path identification, and a batch review checklist. Load this skill when reviewing code, PRs, or architecture, or when the user mentions "review", "code review", "PR review", "what should I review", "review priorities", "blast radius", or "critical path".

80/20 Review

Core Principles

  1. Review at checkpoints, not continuously — Constant review interrupts flow. Schedule reviews at natural breakpoints: post-implementation, pre-PR, post-integration, and post-deploy. Each checkpoint has a different focus.

  2. Focus on data access, security, concurrency, integration — These are the 20% of code areas that cause 80% of production incidents. A missing CancellationToken is more dangerous than a misnamed variable. Review depth should match risk.

  3. Blast radius determines depth — A utility function used in one place gets a glance. A middleware change that affects every request gets a thorough review. Score changes by blast radius and invest review time proportionally.

  4. Automate the trivial — Formatting, import ordering, naming conventions, and basic anti-patterns should be caught by tools (formatters, analyzers, hooks), not humans. Save human attention for things tools can't catch: logic errors, design flaws, and missing edge cases.

Patterns

Checkpoint Schedule

Review at these natural breakpoints, each with a specific focus:

CHECKPOINT 1: Post-Implementation (self-review)
WHEN: After completing a feature or fix, before committing
FOCUS: Does it work? Does it compile? Do tests pass?
DEPTH: Quick — 5 minutes
CHECKLIST:
□ dotnet build passes
□ dotnet test passes (all existing + new tests)
□ get_diagnostics shows no new warnings
□ No obvious anti-patterns (DateTime.Now, new HttpClient, async void)

CHECKPOINT 2: Pre-PR (focused review)
WHEN: Before creating a pull request
FOCUS: Would a staff engineer approve this?
DEPTH: Thorough on critical paths, glance at routine code — 15-30 minutes
CHECKLIST:
□ Data access: N+1 queries, missing Include, no tracking where possible
□ Security: Auth checks, input validation, no secrets in code
□ Concurrency: CancellationToken propagated, no deadlocks, thread-safe state
□ Error handling: Result pattern used, no swallowed exceptions
□ API surface: TypedResults, proper status codes, response DTOs (not entities)
□ Integration: Events published correctly, consumer idempotency
□ Tests: Integration tests cover the happy path + main error case
□ Breaking changes: Public API surface unchanged (or intentionally changed)

CHECKPOINT 3: Post-Integration (system review)
WHEN: After merging to main or integrating with other modules
FOCUS: Does it play well with the rest of the system?
DEPTH: Targeted — check integration points — 10 minutes
CHECKLIST:
□ Cross-module events consumed correctly
□ Database migrations applied cleanly
□ No circular dependencies introduced
□ CI pipeline passes

CHECKPOINT 4: Post-Deploy (production readiness)
WHEN: Before or immediately after deploying
FOCUS: Is it safe in production?
DEPTH: Quick but critical — 5 minutes
CHECKLIST:
□ Health checks pass
□ Logs produce structured output (no PII)
□ Retry/circuit breaker policies configured for external calls
□ Feature flags in place for risky changes (if applicable)
Critical Path Identification

Use MCP tools to identify the code that matters most:

HIGH-RISK CODE (review thoroughly):
1. Data access layer
   → find_references for DbContext usage
   → Check for N+1 (missing Include/AsSplitQuery), missing CancellationToken
   → Check for raw SQL injection risks

2. Authentication & authorization
   → find_implementations of IAuthorizationHandler
   → Check every endpoint has [Authorize] or explicit [AllowAnonymous]
   → Verify token validation configuration

3. External service integration
   → find_references for HttpClient, IHttpClientFactory
   → Check for retry policies (Polly), timeout configuration
   → Verify error handling for external failures

4. Concurrency & shared state
   → find_references for static fields, ConcurrentDictionary
   → Check BackgroundService implementations for scope management
   → Verify CancellationToken propagation in async chains

5. Message consumers
   → find_implementations of IConsumer
   → Check for idempotency (handle duplicate messages)
   → Verify error handling and dead letter configuration

LOW-RISK CODE (glance or skip):
- DTOs and record definitions
- Extension method registration (AddXxx pattern)
- Configuration binding (Options pattern)
- Simple CRUD with no business logic
- Test helper/fixture code
Blast Radius Scoring

Score each change to determine review investment:

CRITICAL (30+ min review):
- Middleware changes (affects every request)
- Authentication/authorization changes
- Database schema changes (migrations)
- Shared kernel / cross-cutting concern changes
- CI/CD pipeline changes
Signal: Many dependents, hard to roll back, security implications

HIGH (15-30 min review):
- New module or subsystem
- Public API surface changes
- Message consumer changes (affects async workflows)
- EF Core configuration changes (query behavior, indexes)
Signal: Multiple consumers, behavioral changes, data integrity

MEDIUM (5-15 min review):
- New feature within existing module (follows patterns)
- Test additions or modifications
- New endpoint following established conventions
Signal: Localized impact, follows existing patterns

LOW (glance or auto-approve):
- Documentation updates
- Formatting / import ordering
- Adding logging statements
- Renaming internal variables
Signal: No behavioral change, cosmetic only
Batch Review Checklist

The 10 highest-value checks for any .NET code review:

THE TOP 10 (in priority order):

1. SQL INJECTION — Any raw SQL or string-interpolated queries?
   → EF parameterizes by default, but check for FromSqlRaw with user input

2. AUTH GAPS — Every endpoint has explicit auth? No open endpoints by accident?
   → Check for missing [Authorize] on new controllers/endpoint groups

3. N+1 QUERIES — Loading collections without Include/join?
   → Check any LINQ that accesses navigation properties after the query

4. CANCELLATION PROPAGATION — CancellationToken passed through the full chain?
   → From endpoint → handler → service → EF query. Breaking the chain = uninterruptible

5. SECRET EXPOSURE — Any connection strings, API keys, or tokens in code?
   → Check for hardcoded strings that look like credentials

6. EXCEPTION SWALLOWING — Catch blocks that silently discard errors?
   → Empty catch, catch with only a log, catch(Exception) without rethrow

7. ASYNC DEADLOCKS — .Result, .Wait(), .GetAwaiter().GetResult()?
   → Any synchronous blocking on async code = potential deadlock

8. ENTITY LEAKS — Domain entities returned directly from API endpoints?
   → Entities should map to response DTOs/records at the API boundary

9. MISSING VALIDATION — User input reaching business logic unchecked?
   → Every command/request DTO should have a corresponding validator

10. RESOURCE LEAKS — Disposable objects not in using/await using blocks?
    → HttpClient, DbContext, FileStream, etc. created without disposal
Review with MCP Tools

Leverage Roslyn MCP tools for efficient, targeted review:

REVIEW WORKFLOW WITH MCP:

1. get_project_graph → Understand what changed in the solution structure
2. get_diagnostics → Catch compiler warnings (CS warnings often signal real issues)
3. detect_antipatterns → Automated anti-pattern scan
4. find_dead_code → Check if the change left any dead code behind
5. detect_circular_dependencies → Verify no new cycles introduced
6. get_test_coverage_map → Verify changed code has test coverage

This MCP-first approach reviews the system-level impact in ~300 tokens
before you even read a single file.

Anti-patterns

Reviewing Every Trivial Change
// BAD — spending 20 minutes reviewing a rename
PR: Rename `OrderSvc` → `OrderService` across 8 files
Reviewer spends 20 minutes verifying each rename is correct.
*This is what Find & Replace + tests are for*

// GOOD — trust the tooling for mechanical changes
PR: Rename `OrderSvc` → `OrderService` across 8 files
Reviewer: "Tests pass? Build passes? Auto-approve."
*Spend that 20 minutes reviewing the authentication change instead*
Skipping Reviews Because "It's Just a Small Change"
// BAD — one-line change to auth middleware, no review
"It's just adding a header, no need to review"
*That header now leaks internal server info to every response*

// GOOD — blast radius determines review, not line count
One-line change to middleware → CRITICAL blast radius → thorough review
"This adds a header to every HTTP response. Is it safe? Does it leak info?
Does it affect caching? Does it break CORS?"
Style Over Substance
// BAD — reviewer focuses on naming while missing the N+1
"Line 15: rename 'x' to 'order' for clarity"
"Line 23: add a blank line between methods"
*Meanwhile, line 28 has an N+1 query that will hammer the database*

// GOOD — substance first, style if time permits
"Line 28: This will produce an N+1 — add .Include(o => o.Items)"
"Line 42: Missing CancellationToken in the EF query"
*Only after critical issues are addressed: "Line 15: consider renaming 'x'"*
Manual Review of Automatable Checks
// BAD — manually checking formatting in every PR
Reviewer spends 5 minutes checking import ordering, bracket placement,
and whitespace consistency.
*Formatters and analyzers do this in milliseconds*

// GOOD — automate the trivial, review the meaningful
Pre-commit hook: dotnet format --verify-no-changes
CI step: dotnet format --verify-no-changes (catches anything the hook missed)
Reviewer: focuses on logic, security, performance, and design

Decision Guide

ScenarioReview DepthFocus Area
New endpoint following existing patternMedium (5-15 min)Auth, validation, response mapping
Authentication/authorization changeCritical (30+ min)Every code path, edge cases, token handling
Database migrationCritical (30+ min)Data loss risk, rollback strategy, index impact
New module or subsystemHigh (15-30 min)Architecture, boundaries, integration points
Bug fix with clear root causeMedium (5-15 min)Root cause correctness, regression test
Rename/formatting/docs PRLow (glance)Tests pass, build passes, auto-approve
EF Core query changesHigh (15-30 min)N+1, tracking, cancellation, SQL generated
Middleware or filter changesCritical (30+ min)Blast radius — affects every request
Test additionsLow-MediumTest quality, are they testing behavior not implementation
CI/CD pipeline changesHigh (15-30 min)Security (secrets), deployment safety, rollback

© Resgrid, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .forge/skills/80-20-review of Resgrid/Core.

Open the folder on GitHubat commit cdfc7ec

Compare with similar skills

80 20 Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

80 20 Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
80 20 Review this skillResgrid/Core229—~2.8kAutomated safety check: PassApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything86k—~1.4kAutomated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from Resgrid/Core

All 13 skills in this repo
  • Autonomous Loops

    Resgrid/Core

    Autonomous iteration loops for .NET development: build-fix, test-fix, refactor, and scaffold loops.

    229 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Learning Log

    Resgrid/Core

    Auto-document insights and discoveries during development sessions.

    229 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Logging

    Resgrid/Core

    Observability for .NET 10 applications. An agent skill from Resgrid/Core.

    229 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Model Selection

    Resgrid/Core

    Strategic Codex model selection for .NET development workflows.

    229 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Model Selection

    Resgrid/Core

    Strategic Claude model selection for .NET development workflows.

    229 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Session Management

    Resgrid/Core

    End-to-end session lifecycle management for .NET projects. An agent skill from Resgrid/Core.

    229 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Categories

Questions about 80 20 Review

What does 80 20 Review do?

Focus code review effort on the 20% of code that causes 80% of issues. 80 20 Review is an agent skill from Resgrid/Core. Focus code review effort on the 20% of code that causes 80% of issues.

When should I use 80 20 Review?

80 20 Review fits situations like: mentions review; what should I review; review priorities.

How do I install 80 20 Review in Claude Code?

Run `npx skills add Resgrid/Core --skill 80-20-review -a claude-code`. Or copy the skill folder (.forge/skills/80-20-review in Resgrid/Core) into .claude/skills/80-20-review in your project. Claude Code loads it when a task matches its description.

How do I install 80 20 Review in Codex?

Run `npx skills add Resgrid/Core --skill 80-20-review -a codex`. Or copy the skill folder (.forge/skills/80-20-review in Resgrid/Core) into .agents/skills/80-20-review in your project. Codex loads it when a task matches its description.

Can I use 80 20 Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Resgrid/Core --skill 80-20-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/80-20-review, .gemini/skills/80-20-review, .github/skills/80-20-review and .opencode/skills/80-20-review in your project.

What does 80 20 Review need to run?

SKILL.md names no scripts, command-line tools or credentials: 80 20 Review is instructions for the agent only.

Does 80 20 Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 80 20 Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 80 20 Review use?

80 20 Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 80 20 Review use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to 80 20 Review?

Skills that share tags, products or a category with 80 20 Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Open Code Review CLI (alibaba/open-code-review, 46k stars) and GitHub Review Iteration (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 80 20 Review?

Resgrid (a GitHub organization) maintains it in Resgrid/Core, which has 229 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 10, 2026.

Source: Resgrid/Core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.