Agent skill

Review

by SethGammon in SethGammon/Citadel

5-pass structured code review — correctness, security, performance, readability, consistency

MITAuto-check passedDevelopment

Install Review

skills CLI
$ npx skills add SethGammon/Citadel --skill review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SethGammon/Citadel review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SethGammon/Citadel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review .claude/skills/review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review
GitHub stars
922
Token cost
~2.1k tokens
SKILL.md length
979 words
Files
3
Skills in repo
48
Repo updated
First seen
Licence
MIT

At a glance

5-pass structured code review — correctness, security, performance, readability, consistency

  • Works in 5 steps: Resolve scope → Load project conventions → Execute 5 passes → …
  • Tasks that involve Plain language and style rules
  • SKILL.md covers Orientation, Protocol, Step 1 — Resolve scope and Step 2 — Load project…, plus 7 more sections
  • Calls git

What it does

Review is an agent skill from SethGammon/Citadel. 5-pass structured code review — correctness, security, performance, readability, consistency

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `__benchmarks__/no-files-changed.md` and `__benchmarks__/specific-file.md`).

It sits in Development, covering Plain language and style rules and Code review. It works with Git. The repository describes itself as: The operating layer for Claude Code + OpenAI Codex: persistent project memory, intent routing, safety hooks, cost telemetry, and parallel agent fleets. The licence is MIT.

When your agent uses it

  • Tasks that involve Plain language and style rules
  • Tasks that involve Code review

Example prompts

  • “/review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Resolve scope
  2. Load project conventions
  3. Execute 5 passes
  4. Format findings
  5. Produce verdict

What it can do on your machine

Read from SKILL.md and the folder at commit e41ff1d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review loads about 2.1k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 979 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SethGammon/Citadel at commit e41ff1d, republished under its MIT licence (© SethGammon). 979 words, ~2,070 tokens.

Download SKILL.mdSave it as .claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
review
description
5-pass structured code review — correctness, security, performance, readability, consistency
license
MIT
user-invocable
true
trigger_keywords
/review, code review, review this, review PR, review

Orientation

Use when: reviewing code for correctness, security, performance, and readability. Don't use when: generating tests (use /test-gen); security audit (use /security-review); skill file review (use /improve skill-md).

Identity

You are a senior code reviewer executing a structured 5-pass review. You find the problems tools miss: logic errors, security holes, performance cliffs, and convention drift. Every finding is specific, located, and actionable — not "consider improving" but what is wrong, where, and what to do.

Orientation

Input: A review target — one of:

  • A file path (/review src/auth/session.ts)
  • A directory (/review src/auth/)
  • A git diff range (/review --diff HEAD~3 or /review --diff main..feature)
  • No argument defaults to staged + unstaged changes (git diff HEAD)

Output: A structured review report with findings grouped by pass and severity, ending with a summary verdict.

Scope rules:

  • For a file: review that file
  • For a directory: review all source files in that directory (recursive), skip generated files, node_modules, lock files, and build artifacts
  • For a diff: review only changed lines and their surrounding context (20 lines above/below each hunk) — but flag issues in unchanged code only if the change introduces a dependency on that code
  • Binary files, images, and lock files are always skipped

Protocol

Step 1 — Resolve scope

Determine the review target. If a diff range, run git diff and also read the full file for each changed file. If a directory, glob for source files. Read all files in scope before starting passes — do not re-read during each pass.

Step 2 — Load project conventions

Read CLAUDE.md, .eslintrc*, tsconfig.json, .prettierrc*, or equivalent config at repo root. These become the baseline for Pass 5. If no conventions exist, still flag internal inconsistency within the reviewed code.

Step 3 — Execute 5 passes

Run each pass across ALL files. Do not skip a pass — confirm explicitly if nothing found.

Pass 1: Correctness
  • Logic errors (inverted conditions, wrong operator, incorrect boolean logic)
  • Off-by-one errors in loops, slices, index access
  • Null/undefined dereference without guards; unhandled promise rejections or missing awaits
  • Race conditions (shared mutable state in async code without synchronization)
  • Type coercion bugs (loose equality, implicit conversions)
  • Resource leaks (connections/handles/subscriptions never closed); missing cleanup in effects/lifecycle
  • Edge cases: empty arrays, zero values, negative numbers, very large inputs
  • State mutations bypassing the expected mutation path
Pass 2: Security
  • Injection: SQL/NoSQL/command/template injection — user input reaching a query or command without parameterization
  • XSS: dangerouslySetInnerHTML, innerHTML, unescaped template interpolation
  • Auth issues: missing auth checks, broken access control, privilege escalation, JWT validation gaps
  • Secrets: API keys, tokens, passwords, connection strings hardcoded (not env vars)
  • Unsafe deserialization: eval(), Function(), JSON.parse on untrusted input without schema validation, pickle.loads, yaml.load without SafeLoader
  • SSRF: user-controlled URLs passed to fetch/request without allowlist
  • Path traversal: user input in file paths without sanitization
  • Insecure crypto: MD5/SHA1 for passwords, ECB mode, hardcoded IVs, Math.random() for security-sensitive values
  • Dependency issues: prototype pollution-prone patterns, known vulnerable usage
Pass 3: Performance
  • Algorithmic: O(n²) or worse in data-scaling paths (nested loops, repeated array scans)
  • Allocation waste: objects/arrays created inside hot loops or render functions that could be hoisted
  • Missing memoization: expensive derivations recomputed on every call/render
  • N+1 queries: DB/API calls inside loops instead of batched
  • Bundle size: importing entire libraries when one function is needed
  • Render performance: new object/array references in render, missing React.memo on expensive children, inline function props recreated in hot paths
  • I/O in hot paths: sync file reads, blocking ops, layout-thrashing DOM reads (getBoundingClientRect) in animation loops
  • Missing pagination/limits: unbounded queries or list renders
  • Regex catastrophe: nested quantifiers vulnerable to ReDoS
Show full SKILL.md (403 more words)Show less
Pass 4: Readability
  • Naming: vague names (data, info, result), misleading names, inconsistent casing within a file
  • Function length: functions over 50 lines doing multiple things
  • Cognitive complexity: deeply nested conditionals (3+ levels), complex boolean expressions not extracted to named variables
  • Dead code: unreachable branches, commented-out blocks, unused variables/imports/parameters
  • Misleading comments: comments that no longer match the code; TODO/FIXME/HACK markers
  • Magic values: hardcoded numbers or strings without named constants
  • Inconsistent abstraction levels: high-level orchestration mixed with low-level details in the same function
Pass 5: Consistency

Scan against conventions from Step 2: import style/ordering/aliases, error handling pattern, file organization, API signatures, naming conventions. Also flag internal inconsistency within the reviewed code (e.g., some functions throw, others return null for errors in the same module).

Step 4 — Format findings

Every finding must include: File (absolute path), Line, Severity (CRITICAL / WARNING / INFO), Finding (one sentence), Code (problematic lines only), Fix (specific action).

Severity: CRITICAL = production bugs/security/crashes; WARNING = conditional problems or maintenance burden; INFO = minor clarity/style. Group by pass, sort by severity within each pass. If a pass finds nothing: **Pass N ({name})**: No findings.

Step 5 — Produce verdict

Count findings across all passes:

VerdictCriteria
PASS0 critical, 3 or fewer warnings
CONDITIONAL0 critical, more than 3 warnings
FAILAny critical finding

Output the verdict with a one-line rationale and the finding counts.

Contextual Gates

Disclosure: "Running structured code review. Read-only — no files modified." Reversibility: green — read-only 5-pass review; no files modified Trust gates:

  • Any: run review on any target; findings are advisory

Quality Gates

  1. Every finding is actionable — no "consider" without a concrete fix.
  2. No false positives: verify the "bug" isn't handled elsewhere, the "unused import" isn't in a type annotation, the "missing null check" isn't guarded by the caller.
  3. Severity is calibrated — style nit is never CRITICAL, SQL injection is never INFO.
  4. No linter-catchable findings (missing semicolons, indentation). Focus on semantic issues.
  5. Line numbers are accurate — verify against file content.

Fringe Cases

  • No diff vs. main: output "No diff found. Confirm branch or specify base ref."
  • Binary files: skip; note as "(skipped: binary)".
  • Diff >500 lines: warn; note limitation in verdict.

Exit Protocol

Deliver the review in this structure:

## Code Review: {target}

**Scope**: {N files, M total lines} | **Mode**: {file | directory | diff}

---

### Pass 1: Correctness
{findings or "No findings."}

### Pass 2: Security
{findings or "No findings."}

### Pass 3: Performance
{findings or "No findings."}

### Pass 4: Readability
{findings or "No findings."}

### Pass 5: Consistency
{findings or "No findings."}

---

## Verdict: {PASS | CONDITIONAL | FAIL}
{one-line rationale}

| Severity | Count |
|---|---|
| Critical | N |
| Warning | N |
| Info | N |

If the user provided a diff range, also note which findings are in new/changed code vs. pre-existing code surfaced by context — the user should prioritize new-code findings.

Do not offer to fix anything unless asked. The review is the deliverable.

© SethGammon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/review of SethGammon/Citadel.

  • SKILL.md
  • __benchmarks__/no-files-changed.md
  • __benchmarks__/specific-file.md

Open the folder on GitHubat commit e41ff1d

Compare with similar skills

Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review this skillSethGammon/Citadel922—~2.1kAutomated safety check: PassMIT
Skeptical Reviewmatthiasn/lotti1.2k—~2kAutomated safety check: PassGPL-3.0
Code Walkthroughtestdouble/han279—~4.4kAutomated safety check: PassMIT
Parallel Code Reviewspencerpauly/awesome-cursor-skills842—~781Automated safety check: PassCC0-1.0
Review Triage Phaseprisma/orm48k—~995Automated safety check: PassApache-2.0
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT

Similar skills

  • Skeptical Review

    matthiasn/lotti

    Act as a skeptical senior engineer performing a detailed code review of the latest changes on the current branch (or a given PR) — best practices, maintainability, performance, security, and…

    1.2k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Walkthrough

    testdouble/han

    Walks a person through code changes one step at a time in conversation, starting at the entry point and following the flow that changes, showing a small chunk per step and explaining it in plain…

    279 GitHub stars~4.4k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Parallel Code Review

    spencerpauly/awesome-cursor-skills

    Run four parallel read-only subagents that each review the same diff from a different lens — security, performance, correctness, and readability — then merge findings into one report.

    842 GitHub stars~781 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Adopt PR Branch Context

    pydantic/pydantic-ai-harness

    Official

    Fills in issue-brief.md and pr-decisions.md for an existing pull request, so you can pick up a PR mid-flight with its linked issue and past review decisions summarized.

    948 GitHub stars~1.8k tokensUpdated 5 days ago
    DevelopmentAuto-check passed

More from SethGammon/Citadel

All 48 skills in this repo
  • Create Skill

    SethGammon/Citadel

    Creates new skills from the user's repeating patterns. An agent skill from SethGammon/Citadel.

    922 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check passed
  • Houseclean

    SethGammon/Citadel

    Cross-drive storage audit and cleanup. An agent skill from SethGammon/Citadel.

    922 GitHub stars~2.2k tokensUpdated 6 days ago
    Auto-check passed
  • Loop

    SethGammon/Citadel

    Bounded foreground repetition for the current session. An agent skill from SethGammon/Citadel.

    922 GitHub stars~1.4k tokensUpdated 6 days ago
    Auto-check passed
  • Triage

    SethGammon/Citadel

    GitHub issue and PR investigator. An agent skill from SethGammon/Citadel.

    922 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check passed
  • Watch

    SethGammon/Citadel

    File sentinel that monitors the working directory for changes and marker comments, then auto-triggers appropriate skills.

    922 GitHub stars~2.9k tokensUpdated 6 days ago
    Auto-check passed
  • Archon

    SethGammon/Citadel

    Autonomous multi-session campaign agent. An agent skill from SethGammon/Citadel.

    922 GitHub stars~5.4k tokensUpdated 6 days ago
    Auto-check passed

Works with

Questions about Review

What does Review do?

5-pass structured code review — correctness, security, performance, readability, consistency. Review is an agent skill from SethGammon/Citadel.

When should I use Review?

Review fits situations like: tasks that involve Plain language and style rules; tasks that involve Code review.

How do I install Review in Claude Code?

Run `npx skills add SethGammon/Citadel --skill review -a claude-code`. Or copy the skill folder (skills/review in SethGammon/Citadel) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.

How do I install Review in Codex?

Run `npx skills add SethGammon/Citadel --skill review -a codex`. Or copy the skill folder (skills/review in SethGammon/Citadel) into .agents/skills/review in your project. Codex loads it when a task matches its description.

Can I use Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SethGammon/Citadel --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.

What does Review need to run?

Going by SKILL.md and its folder, Review needs the command-line tools its instructions call (git).

Does Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review use?

Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review?

Skills that share tags, products or a category with Review: Skeptical Review (matthiasn/lotti, 1.2k stars), Code Walkthrough (testdouble/han, 279 stars), Parallel Code Review (spencerpauly/awesome-cursor-skills, 842 stars) and Review Triage Phase (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review?

SethGammon (a GitHub user) maintains it in SethGammon/Citadel, which has 922 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 1, 2026.

Source: SethGammon/Citadel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.