Agent skill

Review Criteria

by romshark in romshark/datapages

Classify Datapages findings by reach and severity and write review-.md reports.

MITAuto-check passedSecurity

Install Review Criteria

skills CLI
$ npx skills add romshark/datapages --skill review-criteria -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install romshark/datapages review-criteria --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review-criteria .claude/skills/review-criteria && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-criteria
GitHub stars
114
Token cost
~1.2k tokens
SKILL.md length
522 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Classify Datapages findings by reach and severity and write review-.md reports.

  • Code reviews and security audits
  • Calls git
  • Tasks that involve Code review
  • Tasks that involve Security review

What it does

Review Criteria is an agent skill from romshark/datapages. Classify Datapages findings by reach and severity and write review-.md reports. Use for code reviews and security audits.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Code review and Security review. The repository describes itself as: A Datastar Go web frontend framework. The licence is MIT.

When your agent uses it

  • Code reviews and security audits
  • Tasks that involve Code review
  • Tasks that involve Security review

Example prompts

  • “/review-criteria”

What it can do on your machine

Read from SKILL.md and the folder at commit 140dbdf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Criteria loads about 1.2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 522 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from romshark/datapages at commit 140dbdf, republished under its MIT licence (© romshark). 522 words, ~1,243 tokens.

Download SKILL.mdSave it as .claude/skills/review-criteria/SKILL.md (or your agent's skills folder).
name
review-criteria
description
Classify Datapages findings by reach and severity and write review-*.md reports. Use for code reviews and security audits.

Reach

Reach describes where the cause runs, not where the symptom appears.

  • Production: users' deployed servers and their visitors' browsers.
    • The root package, runtime/, modules/, and modules/offline/sw.js.
    • Generated datapagesgen, including committed example and acceptance output.
    • Files datapages init writes from internal/generator/skeleton.
    • .github/workflows/release.yml and .goreleaser.yaml.
  • Development: the developer's machine and CI.
    • The CLI, parser, and generator, including crashes, wrong diagnostics, and generated code that does not compile.
    • datapages watch and code gated by datapages.IsDevMode.
    • Agent skills under internal/generator/agentdocs/data.
  • Repository: code no user application runs.
    • Examples and acceptance cases outside datapagesgen, internal/tools/, magefiles/, docs/, and tests.

Apply these exceptions:

  • A defect found in an example has the reach of its cause. An example XSS caused by runtime/htmlattr has production reach.
  • A datapages.IsDevMode branch has development reach unless a request can enable it; then it has production reach.
  • An unsafe example pattern has repository reach. Recommend the documentation or skill that should warn against it.
  • Application responsibilities listed in SECURITY.md are not framework vulnerabilities. Missing guidance is Info.

Severity

Rate impact as if the cause ran in production:

  • Critical: a remote client needs only network access to run server code, run JavaScript in another visitor's browser, or read or change another session's data.
  • High: Critical impact behind an attacker-controlled precondition, such as an account or a documented application pattern; a few requests crash or hang the server; a correct application silently loses a write or misroutes data.
  • Medium: a common path fails with a workaround; sustained load grows memory or goroutines without bound; paths, versions, or timing leak without direct value to an attacker.
  • Low: unusual input or configuration causes a defect; a diagnostic or log is wrong; code is slow outside a hot path.
  • Info: no defect. Use for hardening, test gaps, and unclear documentation.

Lower impact one level for development reach and two for repository reach, but not below Low. Remote code execution through datapages watch from a page the developer visits is High. XSS in an example template is Medium.

Show full SKILL.md (192 more words)Show less

Report

Write review-<topic>.md in the repository root. .gitignore excludes it. For a single-diff review in chat, use the finding fields and omit the report shell.

markdown
# Review: <scope>

Commit `<hash>`. Scope: <paths>. Method: <what was read, run, fuzzed or measured>.

<Bottom line: the most severe findings and what to fix first.>

| ID | Severity | Reach | Title | Status |
| -- | -------- | ----- | ----- | ------ |
| F1 | ...      | ...   | ...   | ...    |

## F1. <The defect as a sentence>

- Severity: <level>, or <level> (impact <level>, <reach> reach) when lowered
- Reach: Production | Development | Repository
- Type: CWE-<n> <name> | Correctness | Concurrency | Resource leak | Performance | API | Documentation | Test
- Location: `<path>:<line>` at the reviewed commit
- Status: Open

Description: <what the code does and why it is wrong>.

Impact: <who can do what to whom, or what a framework user sees>.

Reproduction: <test, command, or input; expected and actual output>.

Recommendation: <fix and the test that fails without it>.

## Areas reviewed, no finding

- <Component>: <what was checked and the evidence that it is correct>.

## Test coverage gaps

- <What no test exercises, and the finding it would have caught>.
  • Number findings F1, F2, ... in discovery order. Never renumber; later passes continue the sequence.
  • List findings by severity, then by ID.
  • State the defect in the title: "WithFilterSignals writes patterns into a regex literal unescaped", not "Regex escaping issue".
  • Use a CWE ID as the type of a vulnerability.
  • Reproduce every finding with a failing test, command output, or program output.
  • Use status Open; Fixed in <commit> by <TestName>; Won't fix with the reason; Not a defect with evidence; or Unconfirmed with confirmation steps. Use Unconfirmed for findings from reading alone. Before accepting Fixed, git grep the cited test at HEAD.
  • Close a finding by striking through its title and prefixing it, in the heading and in the table: ✅ ~~<title>~~ when Fixed, ❌ WONTFIX: ~~<title>~~ when Won't fix.
  • A Won't fix finding needs a paragraph under its heading explaining why. Labels such as "out of scope" are insufficient.
  • State correct behavior only under "Areas reviewed, no finding", with the evidence. This prevents later passes from repeating the work.

© romshark, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/review-criteria of romshark/datapages.

Open the folder on GitHubat commit 140dbdf

Compare with similar skills

Review Criteria next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Criteria compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Criteria this skillromshark/datapages114—~1.2kAutomated safety check: PassMIT
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence
Trailmark Graph Evolutiontrailofbits/skills7.5k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Post-Patch Validationtrailofbits/skills7.5k—~3.8kAutomated safety check: NotesCC-BY-SA-4.0
Trailmark Review Gatetrailofbits/skills7.5k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.5k GitHub stars~3.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Post-Patch Validation

    trailofbits/skills

    Official

    Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed.

    7.5k GitHub stars~3.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Trailmark Review Gate

    trailofbits/skills

    Official

    Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

    7.5k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

    7.5k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes

More from romshark/datapages

All 15 skills in this repo
  • Datapages

    romshark/datapages

    Apply the Datapages framework rules, build loop and naming conventions, and select the relevant task skill.

    114 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Datapages Events

    romshark/datapages

    Datapages real-time events: event types and subjects, dispatchers, On handlers, per-user and signal-bound subject fields, and the StreamOpen and StreamClose hooks.

    114 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Datapages Sessions

    romshark/datapages

    Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

    114 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Datapages State

    romshark/datapages

    Add per-tab Datapages State[T], initialize and use it in handlers, dispatch state-scoped events, and configure the live instance limit.

    114 GitHub stars~834 tokensUpdated today
    Auto-check passed
  • Git Commits

    romshark/datapages

    Write Datapages commit messages, including the breaking-change marker and the BREAKING block.

    114 GitHub stars~960 tokensUpdated today
    Auto-check passed
  • Datapages Actions

    romshark/datapages

    Write Datapages action handlers (GET, POST, PUT, PATCH, DELETE, QUERY): file responses, parameters, return values, Datastar signals, SSE patching, HTTP error status codes and the RecoverError hook.

    114 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Questions about Review Criteria

What does Review Criteria do?

Classify Datapages findings by reach and severity and write review-.md reports. Review Criteria is an agent skill from romshark/datapages.md reports.

When should I use Review Criteria?

Review Criteria fits situations like: code reviews and security audits; tasks that involve Code review; tasks that involve Security review.

How do I install Review Criteria in Claude Code?

Run `npx skills add romshark/datapages --skill review-criteria -a claude-code`. Or copy the skill folder (.claude/skills/review-criteria in romshark/datapages) into .claude/skills/review-criteria in your project. Claude Code loads it when a task matches its description.

How do I install Review Criteria in Codex?

Run `npx skills add romshark/datapages --skill review-criteria -a codex`. Or copy the skill folder (.claude/skills/review-criteria in romshark/datapages) into .agents/skills/review-criteria in your project. Codex loads it when a task matches its description.

Can I use Review Criteria in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add romshark/datapages --skill review-criteria -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-criteria, .gemini/skills/review-criteria, .github/skills/review-criteria and .opencode/skills/review-criteria in your project.

What does Review Criteria need to run?

Going by SKILL.md and its folder, Review Criteria needs the command-line tools its instructions call (git).

Does Review Criteria access the network?

SKILL.md names 1 domain. As links in the text: cwe.mitre.org. This is read from the text; nothing was executed.

Is Review Criteria safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Criteria use?

Review Criteria is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Criteria use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Criteria?

Skills that share tags, products or a category with Review Criteria: Skillward Audit (Fangcun-AI/SkillWard, 143 stars), Trailmark Graph Evolution (trailofbits/skills, 7.5k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Post-Patch Validation (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Criteria?

romshark (a GitHub user) maintains it in romshark/datapages, which has 114 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 10, 2026.

Source: romshark/datapages on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.