Agent skill

Code Review Workflow

by Resgrid in Resgrid/Core

Structured code review workflow for .NET projects using Roslyn MCP tools.

Apache-2.0Auto-check passedDevelopment

Install Code Review Workflow

skills CLI
$ npx skills add Resgrid/Core --skill code-review-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Resgrid/Core code-review-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.forge/skills/code-review-workflow .claude/skills/code-review-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-workflow
GitHub stars
229
Token cost
~2.1k tokens
SKILL.md length
529 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Structured code review workflow for .NET projects using Roslyn MCP tools.

  • Works in 5 steps: MCP-first analysis — Use Roslyn MCP… → Structured output — Every review follows… → Severity-based findings — Categorize… → …
  • Tasks that involve Code review
  • SKILL.md covers Core Principles, Patterns, Anti-patterns and Decision Guide
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review Workflow is an agent skill from Resgrid/Core. Structured code review workflow for .NET projects using Roslyn MCP tools. Multi-dimensional review covering correctness, security, performance, architecture compliance, and test coverage. Load when: "review PR", "review code", "code review", "PR review", "review changes", "review my code", "check code quality".

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Pull requests and Test coverage. It works with .NET. The repository describes itself as: The Open Source Computer Aided Dispatch (CAD), Personnel, Shift Management, Automatic Vehicle Location (AVL) and Emergency Management Platform that powers Resgrid.com. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Pull requests
  • Tasks that involve Test coverage

Example prompts

  • “review PR”
  • “review code”
  • “code review”
  • “/code-review-workflow”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. MCP-first analysis — Use Roslyn MCP tools before reading source files. detect_antipatterns catches more than manual scanning…
  2. Structured output — Every review follows the same format: Summary → Critical → Warnings → Suggestions → Architecture Compliance → Test…
  3. Severity-based findings — Categorize every finding as Critical (must fix before merge), Warning (should fix, creates tech debt), or…
  4. Actionable suggestions — Every finding includes: what's wrong, why it matters, and how to fix it. "This is bad" is not a review comment…
  5. Acknowledge good work — Always include a "What's Good" section. Positive reinforcement of good patterns is as important as flagging bad…

What it can do on your machine

Read from SKILL.md and the folder at commit a31015f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Workflow loads about 2.1k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 529 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Resgrid/Core at commit a31015f, republished under its Apache-2.0 licence (© Resgrid). 529 words, ~2,144 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-workflow/SKILL.md (or your agent's skills folder).
name
code-review-workflow
description
Structured code review workflow for .NET projects using Roslyn MCP tools. Multi-dimensional review covering correctness, security, performance, architecture compliance, and test coverage. Load when: "review PR", "review code", "code review", "PR review", "review changes", "review my code", "check code quality".

Code Review Workflow

Core Principles

  1. MCP-first analysis — Use Roslyn MCP tools before reading source files. detect_antipatterns catches more than manual scanning, get_diagnostics finds what the compiler knows, and find_references reveals blast radius. Only read files for context that tools can't provide.
  2. Structured output — Every review follows the same format: Summary → Critical → Warnings → Suggestions → Architecture Compliance → Test Coverage → What's Good. Consistent structure makes reviews actionable and scannable.
  3. Severity-based findings — Categorize every finding as Critical (must fix before merge), Warning (should fix, creates tech debt), or Suggestion (nice to have). Never mix severities — a cosmetic issue next to a security bug buries the important finding.
  4. Actionable suggestions — Every finding includes: what's wrong, why it matters, and how to fix it. "This is bad" is not a review comment. "This creates N+1 queries because X. Fix by adding .Include() or using a projection" is.
  5. Acknowledge good work — Always include a "What's Good" section. Positive reinforcement of good patterns is as important as flagging bad ones.

Patterns

Full PR Review Flow

Use for non-trivial PRs (3+ files changed, new features, refactors). Execute steps in order:

Step 1: Understand the change scope Get changed files from git diff or user input. Categorize:

  • New files (features, tests, configs)
  • Modified files (which layers? domain, application, infrastructure, API?)
  • Deleted files (was anything depending on them?)

Step 2: Automated analysis Run MCP tools on changed files:

→ detect_antipatterns (file: each changed .cs file)
  Catch: async void, sync-over-async, DateTime.Now, new HttpClient(), broad catch, etc.

→ get_diagnostics (scope: file, path: each changed file)
  Catch: new compiler warnings, nullability issues, unused variables

→ get_public_api (typeName: each modified type)
  Check: API surface changes — new public members, removed members, signature changes

Step 3: Blast radius assessment For each changed public API:

→ find_references (symbolName: changedMethod)
  Count callers. High count = high risk. Flag breaking changes.

Step 4: Architecture compliance

→ get_project_graph
  Verify: dependency direction is correct (Domain → nothing, Infra → Domain, Api → Application)
  Flag: circular references, wrong-direction dependencies

Step 5: Test coverage check

→ get_test_coverage_map (projectFilter: changed project)
  Check: do test files exist for every changed type?
  Flag: new types without tests, modified logic without test updates

Step 6: Manual review Read changed files for things tools can't catch:

  • Business logic correctness
  • Naming clarity and consistency
  • Error handling completeness
  • Concurrency safety
  • Security: input validation, authorization checks, data exposure

Step 7: Produce review

markdown
## Review Summary
[1-2 sentence overall assessment: scope, risk level, recommendation]

## Critical (must fix)
- **[File:Line] [Title]** — [What's wrong]. [Why it matters]. [How to fix].
- ...

## Warnings (should fix)
- **[File:Line] [Title]** — [What's wrong]. [Impact if not fixed]. [Suggested fix].
- ...

## Suggestions (nice to have)
- **[File:Line] [Title]** — [Current approach]. [Better alternative]. [Why].
- ...

## Architecture Compliance
[Dependency direction check results. Layer violation findings. Module boundary enforcement.]

## Test Coverage
[Which changed types have tests. Which are missing. Specific test scenarios to add.]

## What's Good
- [Positive finding 1 — reinforce good patterns]
- [Positive finding 2]
- ...
Quick Review

Use for small changes (1-2 files, bug fixes, config changes). Lightweight — skip blast radius and architecture checks.

Steps:

  1. Run detect_antipatterns on changed files
  2. Run get_diagnostics on changed files
  3. Read the changed code for correctness
  4. Produce abbreviated review (Summary + Issues + What's Good)
markdown
## Quick Review
[1 sentence assessment]

### Issues
- [Finding with severity tag: 🔴 Critical / 🟡 Warning / 🔵 Suggestion]

### What's Good
- [Positive note]
Show full SKILL.md (196 more words)Show less
Architecture Compliance Check

Standalone check for architecture-level concerns. Use when reviewing project structure changes, new project additions, or module boundary modifications.

Steps:

  1. Run get_project_graph — visualize the full dependency tree
  2. Verify dependency rules per architecture:
ArchitectureRuleViolation Example
VSAFeatures don't reference each otherFeature A imports from Feature B
Clean ArchitectureDomain has zero project referencesDomain references Infrastructure
DDDAggregates don't reference other aggregatesOrder aggregate imports Product aggregate
Modular MonolithModules communicate only via integration eventsModule A directly references Module B's DbContext
  1. Run find_references on module/layer boundary types to verify encapsulation:
→ find_references(symbolName: "OrdersDbContext")
  Should only be referenced within the Orders module.
  External references = module boundary violation.
  1. Run detect_circular_dependencies to find cycles:
→ detect_circular_dependencies(scope: projects)
  Flag any project-level cycles.

→ detect_circular_dependencies(scope: types, projectFilter: "MyApp.Application")
  Flag type-level cycles within the application layer.

Anti-patterns

Reviewing Without MCP Tools
# BAD — Reading every file manually, missing patterns across the codebase
"Let me read OrderService.cs... looks fine to me."
# Missed: 3 DateTime.Now usages, 1 async void, 2 compiler warnings
# GOOD — MCP-first, then targeted file reads
→ detect_antipatterns: Found 3 DateTime.Now (AP004), 1 async void (AP001)
→ get_diagnostics: 2 CS8600 warnings in OrderService.cs
"I found 6 issues via static analysis. Let me read the files for business logic review..."
Vague Feedback
# BAD
"The code could be better."
"This doesn't look right."
"Consider refactoring this."
# GOOD
"OrderService.cs:47 — `DateTime.Now` should be `TimeProvider.GetUtcNow()`.
DateTime.Now is untestable and uses local timezone. Inject TimeProvider
via primary constructor and call GetUtcNow()."
Missing Security Checks
# BAD — Only checking code style and patterns
"Code looks clean, approved!"
# Missed: SQL injection in raw query, missing authorization attribute, exposed PII in logs
# GOOD — Security is a review dimension
"## Critical
- **OrderController.cs:23** Missing `[Authorize]` — endpoint exposes order data without auth
- **SearchService.cs:45** SQL injection — user input concatenated into raw SQL. Use parameterized query.
## Suggestions
- **LoggingMiddleware.cs:12** PII exposure — email logged at Information level. Mask or use Debug level."
Blocking on Style, Ignoring Substance
# BAD — 10 comments about naming, 0 about the race condition
"Rename `svc` to `service`. Use `var` instead of explicit type. Add XML docs."
# GOOD — Prioritize by impact
"## Critical
- Race condition in OrderService.ProcessAsync — concurrent calls can double-charge
## Suggestions
- Consider renaming `svc` to `service` for clarity"

Decision Guide

ScenarioReview TypeMCP Tools
Feature PR (3+ files)Full PR ReviewAll tools
Bug fix (1-2 files)Quick Reviewdetect_antipatterns, get_diagnostics
Config/infra changesQuick Review + Manualget_project_graph
New project/module addedArchitecture Complianceget_project_graph, detect_circular_dependencies
Refactor PRFull PR Review + ArchitectureAll tools + find_references (blast radius)
Security-sensitive changeFull PR Review → escalate to security-auditordetect_antipatterns + manual security review
Test-only changesQuick Reviewget_diagnostics only
Performance-critical pathFull PR Review → escalate to performance-analystget_diagnostics + manual review

© Resgrid, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .forge/skills/code-review-workflow of Resgrid/Core.

Open the folder on GitHubat commit a31015f

Compare with similar skills

Code Review Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Workflow this skillResgrid/Core229—~2.1kAutomated safety check: PassApache-2.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Reviewsbroenne/mcp-windows105—~1.6kAutomated safety check: PassMIT
Code Quality ReviewStudentWeis/ropy193—~2.2kAutomated safety check: PassMIT
Health Checkcodewithmukesh/dotnet-claude-kit7511 repos~1.6kAutomated safety check: PassMIT
Reviewing Changesbitwarden/ios694—~1.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review

    sbroenne/mcp-windows

    Review pull requests in mcp-windows for concrete bugs in MCP and CLI contracts, Windows UI automation, element identity, snapshots, bounded searches, and service lifetime.

    105 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Quality Review

    StudentWeis/ropy

    Review a code change, diff, pull request, module, or test suite for code quality, comment and documentation quality, and test quality.

    193 GitHub stars~2.2k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Health Check

    codewithmukesh/dotnet-claude-kit

    Multi-dimensional health assessment for .NET projects with letter grades (A-F) using Roslyn MCP tools.

    751 GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    694 GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Aidd Review

    paralleldrive/aidd

    Conduct a thorough code review focusing on code quality, best practices, security, test coverage, and adherence to project standards and functional requirements.

    384 GitHub stars~945 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from Resgrid/Core

All 23 skills in this repo
  • 80 20 Review

    Resgrid/Core

    Focus code review effort on the 20% of code that causes 80% of issues.

    229 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Autonomous Loops

    Resgrid/Core

    Autonomous iteration loops for .NET development: build-fix, test-fix, refactor, and scaffold loops.

    229 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Learning Log

    Resgrid/Core

    Auto-document insights and discoveries during development sessions.

    229 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Logging

    Resgrid/Core

    Observability for .NET 10 applications. An agent skill from Resgrid/Core.

    229 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Model Selection

    Resgrid/Core

    Strategic Codex model selection for .NET development workflows.

    229 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Model Selection

    Resgrid/Core

    Strategic Claude model selection for .NET development workflows.

    229 GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Code Review Workflow

What does Code Review Workflow do?

Structured code review workflow for .NET projects using Roslyn MCP tools. Code Review Workflow is an agent skill from Resgrid/Core.NET projects using Roslyn MCP tools.

When should I use Code Review Workflow?

Code Review Workflow fits situations like: tasks that involve Code review; tasks that involve Pull requests; tasks that involve Test coverage.

How do I install Code Review Workflow in Claude Code?

Run `npx skills add Resgrid/Core --skill code-review-workflow -a claude-code`. Or copy the skill folder (.forge/skills/code-review-workflow in Resgrid/Core) into .claude/skills/code-review-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Workflow in Codex?

Run `npx skills add Resgrid/Core --skill code-review-workflow -a codex`. Or copy the skill folder (.forge/skills/code-review-workflow in Resgrid/Core) into .agents/skills/code-review-workflow in your project. Codex loads it when a task matches its description.

Can I use Code Review Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Resgrid/Core --skill code-review-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-workflow, .gemini/skills/code-review-workflow, .github/skills/code-review-workflow and .opencode/skills/code-review-workflow in your project.

What does Code Review Workflow need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review Workflow is instructions for the agent only.

Does Code Review Workflow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Workflow use?

Code Review Workflow is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Workflow use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Workflow?

Skills that share tags, products or a category with Code Review Workflow: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review (sbroenne/mcp-windows, 105 stars), Code Quality Review (StudentWeis/ropy, 193 stars) and Health Check (codewithmukesh/dotnet-claude-kit, 751 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Workflow?

Resgrid (a GitHub organization) maintains it in Resgrid/Core, which has 229 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.

Source: Resgrid/Core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.