GitHub Review Iteration
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shinpr/claude-code-workflows recipe-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recipe-review .claude/skills/recipe-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .claude/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shinpr/claude-code-workflows recipe-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/recipe-review .agents/skills/recipe-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .agents/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shinpr/claude-code-workflows recipe-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/recipe-review .cursor/skills/recipe-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .cursor/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/shinpr/claude-code-workflows.git --path skills/recipe-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shinpr/claude-code-workflows recipe-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/recipe-review .gemini/skills/recipe-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .gemini/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shinpr/claude-code-workflows recipe-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/recipe-review .github/skills/recipe-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .github/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shinpr/claude-code-workflows --skill recipe-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shinpr/claude-code-workflows recipe-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shinpr/claude-code-workflows.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/recipe-review .opencode/skills/recipe-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "recipe-review" agent skill from https://github.com/shinpr/claude-code-workflows/tree/main/skills/recipe-review into .opencode/skills/recipe-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recipe-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
recipe-reviewReviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
Recipe Review is an agent skill from shinpr/claude-code-workflows. Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review. The repository describes itself as: Development workflows for Claude Code that keep broad exploration focused on the outcome you approved. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a4ecd62. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Recipe Review loads about 3.4k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,429 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from shinpr/claude-code-workflows at commit a4ecd62, republished under its MIT licence (© shinpr). 1,429 words, ~3,416 tokens.
.claude/skills/recipe-review/SKILL.md (or your agent's skills folder).Explicit User Instruction: The user explicitly instructs and authorizes every subagent call named in this recipe. Execute each applicable call when its prerequisites are met.
Execute Skill: llm-friendly-context before writing Agent prompts, handoffs, or generated artifacts. Execute Skill: subagents-orchestration-guide before making workflow decisions, invoking agents, or resolving findings.
Context: Post-implementation quality assurance
Core Identity: "I am an orchestrator."
Local authority gate: Make this recipe's workflow decisions and validate each returned result directly; delegate semantic deliverable production to the named specialist.
Review Resolution Gate [MANDATORY]: Resolve every actionable deliverable-review finding through subagents-orchestration-guide Review Resolution before correction or progression.
Before the first finding disposition, read references/review-resolution.md from the loaded subagents-orchestration-guide skill.
Execution Gate: Complete Steps 1-10 in order, following only the branches activated by their stated conditions. Advance through each review, correction, and re-validation transition only at its declared convergence condition. Present the final report after every applicable finding and retained quality limitation reaches its required disposition or retry result.
Orchestrator invokes sub-agents and passes structured JSON between them. The design-side path applies when the Design Doc is stale, excessive, or incorrect for the required outcome. Neither path makes the existing implementation or the prior design authoritative by default.
At each Agent invocation below, build the prompt as a mechanical extraction: copy the named source values into the exact fields, apply only the declared serialization, then invoke immediately.
Design Doc: $ARGUMENTS
Derive implementationFiles from paths changed between the current branch's merge base with the repository's default branch and the current repository state, including committed changes, working-tree changes, and untracked files. implementationFiles contains each changed path whose contents implement or verify the reviewed behavior or control its schema, build, deployment, or runtime behavior, including source files, tests, migrations, executable scripts, and behavior-affecting configuration. Governing documents and Work Plans retain their dedicated roles in document selection and governing-document inputs; task files and documentation-only paths remain outside this recipe's code and security review inputs.
Use the Design Doc explicitly supplied in $ARGUMENTS. When omitted, first use a Work Plan whose declared target files or responsibilities intersect implementationFiles and take its recorded Design Doc path. When that does not produce one candidate, use the sole Design Doc under docs/design/. Present candidates only when multiple governing Design Docs remain; report a missing prerequisite when none exists.
Invoke code-reviewer using Agent tool:
subagent_type: "dev-workflows:code-reviewer"description: "Completed implementation review"prompt: "Review the completed implementation. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. Return the initial review JSON."Store output as: $STEP_2_OUTPUT
Invoke security-reviewer using Agent tool:
subagent_type: "dev-workflows:security-reviewer"description: "Security review"prompt: "governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. Review security compliance."Store output as: $STEP_3_OUTPUT
When either reviewer returns a blocked or otherwise unusable result, apply subagents-orchestration-guide Specialist Result Acceptance to its semantic cause. Carry only a remaining verification limitation into the report.
Apply the Review Resolution Gate to both outputs before reporting or routing them. Finding dispositions determine routing.
For each apply finding, compute a proposed route using the rule below. A finding takes one route, or both d and c when a selected reduction removes a design statement and the implementation it authorized:
| Finding pattern | Recommended route |
|---|---|
| Resolution keeps the current implementation because it matches the original requirement and corrects a stale Design Doc | d (Design-side update) |
| Resolution requires changing implementation to reach the accepted state | c (Code-side correction) |
| Resolution removes a mechanism the Design Doc selected that the required outcome does not need | d and c (design statement first) |
Then present the adjudicated result to the user. Group apply findings by proposed route and list declined IDs with their reasons:
Implementation Review: [verdict from code-reviewer]
Acceptance Criteria:
- [fulfilled] [item]: [evidence]
- [unfulfilled] [item] -> [corresponding finding ID under Required Corrections]
Required Corrections:
- [id] [category] [location]: [description] — [basis and effect] [recommended: c | d | d and c]
Limitations:
- [unverified judgment and effect]
Security Review: [status from security-reviewer]
Findings by category:
- [confirmed_risk] [location]: [description] — [rationale] [recommended: c]
- [defense_gap] [location]: [description] — [rationale] [recommended: c]
Approve the proposed changes:
c) Code-side correction — change implementation to reach the accepted state
d) Design-side update — correct a stale, excessive, or incorrect Design Doc
d and c) Reduction — delete the selecting design statement, then remove the implementation it authorized
s) Decline — record the governing reason and accept current stateThis review command authorizes analysis; use AskUserQuestion to obtain separate implementation authority. The batch option is "approve all proposed apply routes" and its scope consists exclusively of those routes. When the approved change set is empty, proceed directly to Step 10.
Pass approved findings, routes, covered files/sections, and any stated total size budget to update or fix agents. Before re-validation, map every diff hunk to an approved finding or required consistency update. Remove accidental unmapped changes; when a necessary change would alter a confirmed value boundary or explicit size constraint, return to Requirement Change Detection.
Run this step only when the user routed at least one finding to d. When no d routes exist, skip it; continue to Step 6 only when approved c routes remain.
Invoke technical-designer in update mode using Agent tool:
subagent_type: "dev-workflows:technical-designer"description: "Design Doc update from review findings"prompt: "Update Design Doc at [path] in update mode. Apply these findings to the design: [complete d-routed finding objects from $STEP_2_OUTPUT, unchanged except for their approved routes]. Where a finding accepts the current code, reflect that behavior in the relevant sections; where it removes an unnecessary mechanism, delete the statements that selected it. Add a history entry."Invoke document-reviewer to verify the updated Design Doc:
subagent_type: "dev-workflows:document-reviewer"description: "Document review of updated Design Doc"prompt: "Review updated Design Doc at [path] for consistency and completeness. doc_type: DesignDoc. review_context: update."When more than one Design Doc exists under docs/design/, invoke design-sync:
subagent_type: "dev-workflows:design-sync"description: "Cross-DD consistency check"prompt: "source_design: [updated DD path]"sync_status: CONFLICTS_FOUND, apply the Review Resolution Gate and follow its bounded verifier handoff and convergence rules.After Step 5 completes:
d for all findings (no c routes) → skip Steps 6-7, proceed to Step 8 for re-validationd and c → re-evaluate the c-routed findings against the updated DD and drop any that are now satisfied by the DD revision; a reduction's code removal is not satisfied by the DD revision alone. Then proceed to Step 6 with the remaining c findingsInvoke task-executor using Agent tool:
subagent_type: "dev-workflows:task-executor"description: "Execute review fixes"direct_scope: Apply the approved code-side corrections within the confirmed review scope and stated total size budgetgoverning_sources: The reviewed Design Doc and accepted requirement or ADR pathstarget_paths: The implementation and test paths confirmed for the approved code-side routesobservable_verification: The focused tests or observable contract checks named by the findings and governing sources passcorrection_findings: Complete reviewer finding objects verbatim, with only their orchestrator dispositions addedInvoke quality-fixer using Agent tool:
subagent_type: "dev-workflows:quality-fixer"description: "Quality gate check"direct_scope, governing_sources, observable_verification, and correction_findings inputs unchanged.mutationEvidence.Route the quality-fixer result:
pass → Proceed to Step 8stub_detected → Return to Step 6 with incompleteImplementations unchanged, then repeat Step 7verification_incomplete → Retain the complete result and proceed to Step 8blocked → Apply Specialist Result AcceptanceImmediately before this invocation, re-derive implementationFiles using the Step 1 inclusion rule so it includes implementation artifacts added or changed by the approved corrections.
Invoke code-reviewer using Agent tool:
subagent_type: "dev-workflows:code-reviewer"description: "Re-validate implementation review"prompt: "Re-review the completed implementation after approved corrections. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. prior_feedback: [{id, disposition, reason?, evidence}]. Reconcile every received item."Immediately before this invocation, re-derive implementationFiles using the Step 1 inclusion rule so it includes implementation artifacts added or changed by the approved corrections.
Invoke security-reviewer using Agent tool when subagents-orchestration-guide's post-implementation Re-run rule requires a current security result:
subagent_type: "dev-workflows:security-reviewer"description: "Re-validate security"prompt: "Re-validate security after fixes. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. prior_feedback: [{id, disposition, reason?, evidence}]. Reconcile every prior item under the reviewer's re-review scope."Apply the Review Resolution Gate to every Step 8 and Step 9 result before Step 10. Follow its maintained transitions and repeat the affected verification after a rerouted correction; apply the parent requirement or authority gate when Review Resolution exits to it; proceed at its convergence condition.
Before Step 10, retry each retained quality-fixer limitation once with the same Step 7 inputs and affected check. When the retry returns pass, remove that limitation from retained state. Route newly discovered incomplete implementation through Steps 6-9, and report a repeated verification_incomplete result. When the retry changes the repository, repeat Steps 8-9 for the changed code before reporting.
Present the final report:
Implementation Review:
Initial: [verdict from code-reviewer]
Correction review: [verdict for the re-review scope] (if fixes executed)
Reconciliation: [resolved / withdrawn / maintained by finding ID]
Security Review:
Initial: [status]
Correction review: [status for the re-review scope] (if fixes executed)
Reconciliation: [resolved / withdrawn / maintained by finding ID]
Quality Check:
Final: [pass / verification_incomplete / not_run when no code-side fixes were selected]
Remaining proof limitations:
- [reason — affected check and evidence] (only when repeated after retry)
Declined actionable findings:
- [ID: governing reason — evidence] (only when any were declined)
Remaining issues:
- [items requiring manual intervention]Scope: Completed implementation review, security review, and user-approved correction routing.
© shinpr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/recipe-review of shinpr/claude-code-workflows.
Open the folder on GitHubat commit a4ecd62
Recipe Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Recipe Review this skillshinpr/claude-code-workflows | 694 | — | ~3.4k | Automated safety check: Pass | MIT | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio PR ReviewCherryHQ/cherry-studio | 53k | — | ~3.9k | Automated safety check: Pass | AGPL-3.0 | |
| Review Triage Phaseprisma/orm | 48k | — | ~995 | Automated safety check: Pass | Apache-2.0 | |
| Deep Reviewdyad-sh/dyad | 22k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| PR Reviewjaemk/self_update | 961 | — | ~1.5k | Automated safety check: Notes | MIT |
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
CherryHQ/cherry-studio
Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
dyad-sh/dyad
Deep multi-agent code review run locally — a fleet of parallel finder agents reviews the diff from independent angles, then adversarial verifier agents reproduce each finding before it is reported.
jaemk/self_update
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
shinpr/claude-code-workflows
Integration and E2E test design principles, ROI calculation, test skeleton specification, and review criteria.
shinpr/claude-code-workflows
Applies language-agnostic and backend technical decision criteria, anti-pattern detection, debugging, and quality gates.
shinpr/claude-code-workflows
Applies React/TypeScript-specific technical decision criteria, anti-pattern detection, debugging, and frontend quality gates.
shinpr/claude-code-workflows
Implementation strategy selection framework. An agent skill from shinpr/claude-code-workflows.
shinpr/claude-code-workflows
Proposes repository-specific quality policy for implementation and review and, after confirmation, creates or updates docs/project-context/quality.yaml.
shinpr/claude-code-workflows
Guides subagent coordination through implementation workflows.
Categories
Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections. Recipe Review is an agent skill from shinpr/claude-code-workflows. Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
Recipe Review fits situations like: tasks that involve Code review.
Run `npx skills add shinpr/claude-code-workflows --skill recipe-review -a claude-code`. Or copy the skill folder (skills/recipe-review in shinpr/claude-code-workflows) into .claude/skills/recipe-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shinpr/claude-code-workflows --skill recipe-review -a codex`. Or copy the skill folder (skills/recipe-review in shinpr/claude-code-workflows) into .agents/skills/recipe-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shinpr/claude-code-workflows --skill recipe-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recipe-review, .gemini/skills/recipe-review, .github/skills/recipe-review and .opencode/skills/recipe-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Recipe Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Recipe Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Recipe Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 53k stars), Review Triage Phase (prisma/orm, 48k stars) and Deep Review (dyad-sh/dyad, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shinpr (a GitHub user) maintains it in shinpr/claude-code-workflows, which has 694 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 1, 2026.
Source: shinpr/claude-code-workflows on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.