Agent skill

Review Loop

by sangrokjung in sangrokjung/claude-forge

Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE.

MITAuto-check passed

Install Review Loop

skills CLI
$ npx skills add sangrokjung/claude-forge --skill review-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sangrokjung/claude-forge review-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sangrokjung/claude-forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-loop .claude/skills/review-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-loop
GitHub stars
852
Token cost
~1.5k tokens
SKILL.md length
789 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE.

  • Works in 6 steps: Implement. Keep the change inside the… → Produce evidence before dispatch. Run… → Dispatch a fresh checker. Use the… → …
  • SKILL.md covers When this applies, The loop, Running it and Re-verification etiquette, plus 2 more sections
  • Calls git

What it does

Review Loop is an agent skill from sangrokjung/claude-forge. Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE. Use before claiming any behavioural change is done, and on requests like "review loop", "adversarial review", "independent review", "get this verified", "is this actually done", "maker checker", "second pair of eyes on this change". Not for prose, docs or typo edits.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/convergence-detection.md`).

The repository describes itself as: oh-my-zsh for Claude Code — 16 agents, 35 commands, 32 skills, 21 safety hooks in one install. v4.0 adds an adversarial review loop: a second agent that never sees the first… The licence is MIT.

Example prompts

  • “review loop”
  • “adversarial review”
  • “independent review”
  • “/review-loop”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Implement. Keep the change inside the scope you declared. Unrelated cleanup that arrives in
  2. Produce evidence before dispatch. Run the targeted tests and, when the change has a surface a
  3. Dispatch a fresh checker. Use the Task/Agent tool to spawn adversarial-reviewer in its own
  4. Read the verdict, not the tone. A checker that praises the change but lists a HIGH finding
  5. Fix and re-dispatch. Every round gets a checker with a fresh context. Reusing the previous
  6. Stop when a current APPROVE exists for the code as it stands, backed by evidence from that

What it can do on your machine

Read from SKILL.md and the folder at commit 34d881d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Loop loads about 1.5k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 789 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sangrokjung/claude-forge at commit 34d881d, republished under its MIT licence (© sangrokjung). 789 words, ~1,485 tokens.

Download SKILL.mdSave it as .claude/skills/review-loop/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-loop
description
Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE. Use before claiming any behavioural change is done, and on requests like "review loop", "adversarial review", "independent review", "get this verified", "is this actually done", "maker checker", "second pair of eyes on this change". Not for prose, docs or typo edits.

review-loop — the independent adversarial loop

Nobody grades their own exam. The maker implements, a separate fresh checker tries to break the claim, and the two alternate until the checker approves the code as it stands right now.

When this applies

Any change to behaviour: executable code, shell/Python/JS/TS/SQL, CI/CD, hooks, commands, agent and skill definitions, runtime prompts, and configuration that changes what the system does.

Exempt: prose documentation, marketing copy, typos, and formatting that cannot change behaviour. When a documentation-only change also touches something a runtime reads, it is behavioural. If you are unsure which side a change falls on, treat it as behavioural.

File count and diff size are not exemptions. A one-line change to an authorization check is behavioural; a 900-line documentation reflow is not.

RiskLanes required
Ordinary behavioural change1 independent checker
Auth, authorization, payments, access-control rules, secrets, destructive data changes, irreversible deploys2 lanes, run by different checkers: correctness plus the risk-specific angle (runtime security, or rollback)

The loop

text
maker implements → targeted test / real-surface QA → fresh checker
     ↑                                                    │
     └────────── REQUEST_CHANGES ← findings ──────────────┘
                                                          │
                                          APPROVE on current code → done

There are exactly three verdicts: APPROVE, REQUEST_CHANGES, UNVERIFIED.

  • APPROVE is a completion candidate only when it was issued against the revision that is checked out now, with evidence produced from that same revision.
  • REQUEST_CHANGES means the maker fixes the findings surgically, re-runs the tests, and calls a fresh checker again. Fixing more than the findings restarts the argument.
  • UNVERIFIED means no judgement was reached: the checker never ran, returned empty, timed out, errored, was rate-limited, returned a malformed envelope, or reviewed a state that has since moved. It is not a pass. Retry with a different checker, runtime, or strategy.

If a checker modifies the source, it has joined the maker set and its verdict is void. A past maker can never be that change's checker.

Running it

  1. Implement. Keep the change inside the scope you declared. Unrelated cleanup that arrives in the same diff will be reviewed as part of it.

  2. Produce evidence before dispatch. Run the targeted tests and, when the change has a surface a person uses, exercise that surface the way they would. Record the exact commands and their exit status. Evidence from before your last edit is stale.

  3. Dispatch a fresh checker. Use the Task/Agent tool to spawn adversarial-reviewer in its own context, or a general-purpose agent given that agent's contract. Hand it:

    • the goal and acceptance criteria in one paragraph,
    • the scope (paths, or the diff range),
    • the commands you ran and what they returned,
    • the revision under review (git rev-parse HEAD).

    Do not hand it your conclusion. "I verified this works" is the claim under test, not context.

  4. Read the verdict, not the tone. A checker that praises the change but lists a HIGH finding has returned REQUEST_CHANGES. A checker that died mid-run has returned UNVERIFIED, however encouraging its last message was.

  5. Fix and re-dispatch. Every round gets a checker with a fresh context. Reusing the previous checker means asking someone to re-read their own conclusion.

  6. Stop when a current APPROVE exists for the code as it stands, backed by evidence from that same revision.

Show full SKILL.md (278 more words)Show less

Re-verification etiquette

When you come back for round N+1, say so plainly:

  • state what changed since the last round, in one or two lines, and name the finding each edit addresses;
  • ask the checker to re-reproduce the original defect, not to take your word that it is gone;
  • explicitly invite it to attack the fix itself. Fixes introduce their own defects, and a fix written under review pressure is exactly where a second one hides.

Both of the defects worked through in docs/VERIFICATION-LOOP.md were found this way: the first review broke the guard, and the review of the fix broke the fix.

When rounds stop converging

Three rounds on the same strategy is not a reason to stop, and it is not a reason to keep going unchanged. Switch strategy: a different reproduction, a narrower test, a different checker or runtime, or a re-plan of the approach. See references/convergence-detection.md.

Escalate to the human when the same finding comes back REQUEST_CHANGES twice in a row: two failed attempts at one defect means the diagnosis is wrong, and a third attempt usually makes it worse. Report the finding, both attempted fixes, and the reproduction. See rules/adversarial-review.md.

Never report success when

  • the reviewed revision is not the revision that is checked out now;
  • there is no successful evidence from after the last edit;
  • the checker was the maker, or a fork of the maker's context;
  • a required lane is missing;
  • the checker modified code, returned an empty or malformed verdict, or timed out;
  • you are reusing an APPROVE from a different change or a different session.

In every one of those cases the honest report is what is missing, not "done".

© sangrokjung, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/review-loop of sangrokjung/claude-forge.

  • SKILL.md
  • references/convergence-detection.md

Open the folder on GitHubat commit 34d881d

Compare with similar skills

Review Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Loop this skillsangrokjung/claude-forge852—~1.5kAutomated safety check: PassMIT
Implementsickn33/agentic-awesome-skills47k5 repos~306Automated safety check: PassMIT
Implementcodewhale-hq/Codewhale41k—~190Automated safety check: PassMIT
Incremental Implementationaddyosmani/agent-skills103k1 repos~2.3kAutomated safety check: PassMIT
Implementbestofjs/bestofjs3.1k18 repos~109Automated safety check: PassMIT
ImplementAutomattic/simplenote-android1.9k—~1.1kAutomated safety check: PassGPL-2.0

Similar skills

  • Implement

    sickn33/agentic-awesome-skills

    Implement a piece of work based on a PRD or set of issues. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 5 repos~306 tokens
    Product & Project ManagementAuto-check passed
  • Implement

    codewhale-hq/Codewhale

    Carry an authorized, defined request or approved plan through scoped edits and proportionate verification.

    41k GitHub stars~190 tokensUpdated today
    Auto-check passed
  • Incremental Implementation

    addyosmani/agent-skills

    Delivers a change in thin vertical slices, each implemented, tested, verified and committed before the next, using vertical, contract-first or risk-first slicing.

    103k GitHub starsUsed in 1 repo~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Implement

    bestofjs/bestofjs

    Implement a piece of work based on a spec or set of tickets.

    3.1k GitHub starsUsed in 18 repos~109 tokens
    Auto-check passed
  • Implement

    Automattic/simplenote-android

    End-to-end implementation workflow: plan, implement, verify, commit, and open a draft PR.

    1.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Sparc Implement

    ruvnet/ruflo

    Run the SPARC Pseudocode and Architecture phases (2 and 3) — write algorithm pseudocode, design module boundaries and API contracts, then implement

    74k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check: notes

More from sangrokjung/claude-forge

All 24 skills in this repo
  • Debugging Strategies

    sangrokjung/claude-forge

    Master systematic debugging techniques, profiling tools, and root cause analysis to efficiently track down bugs across any codebase or technology stack.

    852 GitHub starsUsed in 13 repos~3.1k tokens
    Auto-check passed
  • Dependency Upgrade

    sangrokjung/claude-forge

    Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

    852 GitHub starsUsed in 12 repos~2.3k tokens
    Auto-check passed
  • Skill Factory

    sangrokjung/claude-forge

    Analyze session work and automatically convert reusable patterns into Claude Code skills.

    852 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Dev Agent

    sangrokjung/claude-forge

    A skill your agent uses when starting Claude Code projects, writing CLAUDE.md/spec.md, dispatching subagents, or requesting Agent Teams parallel development.

    852 GitHub stars~771 tokensUpdated 1 mo ago
    Auto-check passed
  • Continuous Learning V2

    sangrokjung/claude-forge

    Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    852 GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • Harness Diet

    sangrokjung/claude-forge

    Measure and shrink the always-loaded context of a Claude Code harness (CLAUDE.md + rules without paths frontmatter) back under budget — migrate narrative to reference files, convert rules to…

    852 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Review Loop

What does Review Loop do?

Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE. Review Loop is an agent skill from sangrokjung/claude-forge. Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE.

How do I install Review Loop in Claude Code?

Run `npx skills add sangrokjung/claude-forge --skill review-loop -a claude-code`. Or copy the skill folder (skills/review-loop in sangrokjung/claude-forge) into .claude/skills/review-loop in your project. Claude Code loads it when a task matches its description.

How do I install Review Loop in Codex?

Run `npx skills add sangrokjung/claude-forge --skill review-loop -a codex`. Or copy the skill folder (skills/review-loop in sangrokjung/claude-forge) into .agents/skills/review-loop in your project. Codex loads it when a task matches its description.

Can I use Review Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sangrokjung/claude-forge --skill review-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-loop, .gemini/skills/review-loop, .github/skills/review-loop and .opencode/skills/review-loop in your project.

What does Review Loop need to run?

Going by SKILL.md and its folder, Review Loop needs the command-line tools its instructions call (git).

Does Review Loop access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Loop use?

Review Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Loop use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 651 tokens, read only when the agent opens those files.

What are the alternatives to Review Loop?

Skills that share tags, products or a category with Review Loop: Implement (sickn33/agentic-awesome-skills, 47k stars), Implement (codewhale-hq/Codewhale, 41k stars), Incremental Implementation (addyosmani/agent-skills, 103k stars) and Implement (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Loop?

sangrokjung (a GitHub user) maintains it in sangrokjung/claude-forge, which has 852 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on September 3, 2026.

Source: sangrokjung/claude-forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.