Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Review a spec-update branch — classify breaking changes, write [compat] changesets, and fix parameter-order patches.
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SAP/ai-sdk-js review-spec-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review-spec-update .claude/skills/review-spec-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .claude/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SAP/ai-sdk-js review-spec-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/review-spec-update .agents/skills/review-spec-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .agents/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SAP/ai-sdk-js review-spec-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/review-spec-update .cursor/skills/review-spec-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .cursor/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SAP/ai-sdk-js.git --path .claude/skills/review-spec-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SAP/ai-sdk-js review-spec-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/review-spec-update .gemini/skills/review-spec-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .gemini/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SAP/ai-sdk-js review-spec-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/review-spec-update .github/skills/review-spec-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .github/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SAP/ai-sdk-js --skill review-spec-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SAP/ai-sdk-js review-spec-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/ai-sdk-js.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/review-spec-update .opencode/skills/review-spec-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-spec-update" agent skill from https://github.com/SAP/ai-sdk-js/tree/main/.claude/skills/review-spec-update into .opencode/skills/review-spec-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-spec-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-spec-updateReview a spec-update branch — classify breaking changes, write [compat] changesets, and fix parameter-order patches.
Review Spec Update is an agent skill from SAP/ai-sdk-js, published by the product's own GitHub organization. Review a spec-update branch — classify breaking changes, write [compat] changesets, and fix parameter-order patches.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with JavaScript. The repository describes itself as: SAP Cloud SDK for AI is the official Software Development Kit (SDK) for SAP AI Core, SAP Generative AI Hub, and Orchestration Service. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cec10a2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Spec Update loads about 3.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 1,287 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SAP/ai-sdk-js at commit cec10a2, republished under its Apache-2.0 licence (© SAP). 1,287 words, ~3,133 tokens.
.claude/skills/review-spec-update/SKILL.md (or your agent's skills folder).<!-- vale Vale.Spelling = NO -->
<!-- vale Vale.Terms = NO -->
You are reviewing a spec-update branch for a generated OpenAPI client package.
<!-- vale Vale.Terms = YES -->
Your goal: identify every change that breaks existing consumer code, create a [compat] changeset for each one, fix broken patches, and create new patches for parameter-order regressions.
# Identify which package(s) changed
git diff main...HEAD --name-only | grep 'packages/'
# For each affected package, get the full generated-client diff
git diff main...HEAD -- packages/<pkg>/src/client/If the diff is empty, confirm that pnpm <pkg> generate was actually executed and commit.
If confirmed, output a summary stating no generated-client changes were detected and stop; no further steps are required.
Focus on src/client/api/ (generated files).
Hand-written code in src/ outside client/ is NOT in scope unless it directly imports a type that was renamed, removed, or had its shape changed in this diff.
In that case, note the affected file but do not modify it; record it as a follow-up task.
Work through the diff methodically. For each changed type/function, decide:
Perspective: The spec-driven development guidelines distinguish between changes that break end users (their previously-correct code stops working) and changes that cause SDK effort (regeneration, migration work) without breaking existing user code. Only the former require
[compat]changesets.
| Change | Breaking? | Why |
|---|---|---|
| New required parameter on a function | YES | Existing calls now missing argument |
| Parameter removed from a function | YES | Existing calls pass unknown argument |
| Parameter order changed | YES | Positional calls pass wrong value |
Parameter type narrowed (e.g. string → 'a'|'b') | YES | May reject previously-valid values |
| Parameter type widened | no | Consumers unaffected |
| New optional parameter on a function | no | Existing calls still valid |
| Required request body field becomes optional | no | Less strict |
| Optional request body field becomes required | YES | Existing objects now invalid |
additionalProperties: false added to a request object | YES | Rejects previously-valid extra fields |
| Change | Breaking? | Why |
|---|---|---|
| New required field on a response type | no | Destructuring still works; extra field is fine |
| Field removed from a response type | YES | Code reading that field will get undefined |
| Field renamed | YES | Old name no longer exists |
| Type narrowed on a response field | YES | Code relying on broader type breaks |
| Type widened on a response field | no, unless it newly introduces undefined or null | Widening is safe unless consumers must now handle absence that was impossible before |
| New optional field on a response type | no | Safe addition |
Change to an under-specified response object ({} or no constraints) | no | Spec-driven dev guidelines explicitly allow service teams to keep flexibility here; clients must not rely on its structure |
<!-- vale SAP.Sentences = NO -->
| Change | Breaking? |
|---|---|
Open union 'A'|'B'|any → strict 'A'|'B' | YES — previously-passing any values now rejected by TypeScript |
| Strict union → open (` | any`) |
| New enum member added | no |
| Enum member removed | YES |
| Type renamed | YES (if exported) — also check the new type's shape: a rename often comes with property changes (id → resourceId, removed fields, etc.).<br>Document each property-level breaking change in its own [compat] entry; do not just note the rename.<br>If the old type is entirely deleted and replaced by a structurally different new type with no shared name, treat it as a deletion of the old type plus introduction of a new type.<br>Create one [compat] entry for the deletion and list the migration target type by name if identifiable from the diff. |
| Type deleted | YES (if exported) |
| Type or field deprecated | YES — always create a [compat] entry noting the deprecation and the migration target |
Shared schema split into distinct schemas (e.g. FooConfig → FooConfigInput + FooConfigOutput) | SDK-effort only — not a user breaking change unless the old type was directly exported and consumers referenced it by name. If exported, treat as a type rename/deletion and create a [compat] entry. |
<!-- vale SAP.Sentences = YES -->
When a previously shared schema is split into two or more distinct schemas, assess the downstream impact carefully:
src/index.ts or src/internal.ts? If yes → breaking; create a [compat] entry.[compat] entry.Example: SAPDocumentTranslation split into SAPDocumentTranslationInput (adds bar) + SAPDocumentTranslationOutput → if old type was exported, create a [compat] for the deletion of SAPDocumentTranslation and for the new required bar field on the input variant.
pnpm <pkg> generate
pnpm <pkg> run apply-patchesThen for every function where positional parameters reordered:
ls packages/<pkg>/patches/pnpm <pkg> run apply-patches reported that patch file as failing.
If it failed, the context lines around the reorder changed (e.g. new parameters added nearby).
Update the patch context to match the new generated output (see §Updating a patch below).
Do NOT delete a parameter-order patch just because the working tree already looks correct.headerParameters and queryParameters (i.e., one was removed from the spec), making the ordering moot.The generated functions follow this shape:
functionName: (
param1: Type1,
param2: Type2,
...
) => new OpenApiRequestBuilder(...)<!-- vale SAP.Sentences = NO -->
If the spec reordered headerParameters vs queryParameters, the generator will flip their positions.
<!-- vale SAP.Sentences = YES -->
# 1. Manually edit the generated file to restore the old parameter order
# (swap back to the order consumers expect)
# 2. Stage only that file
git add packages/<pkg>/src/client/api/<api-file>.ts
# 3. Generate the patch against HEAD (which has the newly-generated code)
git diff --cached > packages/<pkg>/patches/backward-compat-<function-name>-order.patch
# 4. Unstage (the patch is the artifact, not the edit)
git restore --staged packages/<pkg>/src/client/api/<api-file>.ts
git restore packages/<pkg>/src/client/api/<api-file>.tsPatch file naming: backward-compat-<camelFunctionName>-order.patch
If the patch context no longer matches (function body changed around the reorder):
# Inspect what changed
git diff main...HEAD -- packages/<pkg>/src/client/api/<api-file>.ts
# Open the patch file, update the context lines (the unchanged lines around the @@)
# to match the new generated code, keeping the - / + lines intact
# Then verify:
pnpm <pkg> generate
pnpm <pkg> run apply-patchesIf you deleted a patch in Step 3 because it was truly obsolete, remove the patches directory if now empty and remove the apply-patches script from package.json.
Check whether the package has an apply-patches script:
cat packages/<pkg>/package.json | grep apply-patchesIf missing, add it.
Add this to package.json scripts:
"apply-patches": "tsx ../../scripts/apply-patches.ts ."Also verify the root package.json runs apply-patches across the repository:
grep apply-patches package.json
# Should have: "apply-patches": "pnpm -r run --if-present apply-patches"For each breaking change, run pnpm changeset --empty once, then edit the generated file.
---
'@sap-ai-sdk/<package-name>': minor
---
[compat] <TypeName(s)>: <what changed and what consumers need to do>.Use minor for all [compat] entries (breaking changes in this project always bump minor).
Type narrowed:
[compat] `DocumentKeyValueListPair`, `RetrievalDocumentKeyValueListPair`, `VectorDocumentKeyValueListPair`: the `matchMode` property type was narrowed from an open union (`'ANY' | 'ALL' | any`) to the strict `FilterMatchModeEnum` (`'ANY' | 'ALL'`).Field removed from response:
[compat] `CollectionPendingResponse`: fields `Location` and `status` were removed.
A new `monitorURL` property was added instead.Required field added to request type:
[compat] `TextOnlyBaseChunk`: new required field `id: string` added and `metadata` is now optional.Field type changed:
[compat] `BaseDocument` / `DocumentInput`: `chunks` type changed from `TextOnlyBaseChunk[]` to `TextOnlyBaseChunkCreate[]`.
The `metadata` property is now optional.Optional became required:
[compat] `PromptTemplateSubstitutionRequest` now requires the `inputParams` property.'a'|'b' → 'a'|'b'|'c')These get rolled into the [feat] changeset that should already exist for the spec update.
If no [feat] changeset exists yet for this spec update, create one with pnpm changeset --empty.
Label it [feat] <package-name>: updated generated client to latest spec before rolling in non-breaking changes.
# Recreate raw generated output, then verify the shared patch runner succeeds
pnpm <pkg> generate
pnpm <pkg> run apply-patches
# TypeScript compiles
pnpm <pkg> compile
# Tests pass
pnpm <pkg> test
# List changesets created
ls .changeset/If pnpm <pkg> run apply-patches fails, return to Step 3 §Updating a patch for each failing patch file.
Do not proceed to compile or test until all patches apply cleanly.
List each failing patch file by name in your output.
If compilation fails, inspect the error output to determine whether the failure is caused by a breaking change not yet covered by a [compat] changeset or patch.
If so, return to Step 2 or Step 3.
If the failure is unrelated to this spec update, note it as a pre-existing issue and do not block the review.
If tests fail, apply the same triage: attribute failures to this spec update or flag them as pre-existing.
src/client/ against main[compat] changeset[compat] changesetadditionalProperties: false added to any request object → [compat] changeset created[compat]; unexported without structural change → no action needed[compat] changeset with migration target{} bodies) confirmed as non-breaking and omitted from [compat]pnpm <pkg> apply-patches from fresh generated output)apply-patches script (added if missing)© SAP, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/review-spec-update of SAP/ai-sdk-js.
Open the folder on GitHubat commit cec10a2
Review Spec Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Spec Update this skillSAP/ai-sdk-js | 126 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| JavaScript Concept Fact Checkerleonardomso/33-js-concepts | 67k | 1 repos | ~5k | Automated safety check: Pass | MIT | |
| GSAP Core Animationgreensock/gsap-skills | 16k | 3 repos | ~3.7k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
leonardomso/33-js-concepts
Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.
greensock/gsap-skills
Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.
oso95/scroll-world
Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.
SAP/ai-sdk-js
Sync model types from SAP Notes 3437766. An agent skill from SAP/ai-sdk-js.
Works with
Review a spec-update branch — classify breaking changes, write [compat] changesets, and fix parameter-order patches. Review Spec Update is an agent skill from SAP/ai-sdk-js, published by the product's own GitHub organization. Review a spec-update branch — classify breaking changes, write [compat] changesets, and fix parameter-order patches.
Run `npx skills add SAP/ai-sdk-js --skill review-spec-update -a claude-code`. Or copy the skill folder (.claude/skills/review-spec-update in SAP/ai-sdk-js) into .claude/skills/review-spec-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SAP/ai-sdk-js --skill review-spec-update -a codex`. Or copy the skill folder (.claude/skills/review-spec-update in SAP/ai-sdk-js) into .agents/skills/review-spec-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SAP/ai-sdk-js --skill review-spec-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-spec-update, .gemini/skills/review-spec-update, .github/skills/review-spec-update and .opencode/skills/review-spec-update in your project.
Going by SKILL.md and its folder, Review Spec Update needs the command-line tools its instructions call (pnpm and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Spec Update is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Spec Update: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and JavaScript Concept Fact Checker (leonardomso/33-js-concepts, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SAP (a GitHub organization, an official publisher) maintains it in SAP/ai-sdk-js, which has 126 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 10, 2026.
Source: SAP/ai-sdk-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.