Requesting Code Review
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
Mandatory engineering, security, testing, git, performance, quality, and response rules.
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install softspark/ai-toolkit ai-toolkit-rules --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .claude/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .claude/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rulesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install softspark/ai-toolkit ai-toolkit-rules --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .agents/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .agents/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install softspark/ai-toolkit ai-toolkit-rules --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .cursor/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .cursor/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/softspark/ai-toolkit.git --path app/claude-app/skills/ai-toolkit-rules--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install softspark/ai-toolkit ai-toolkit-rules --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .gemini/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .gemini/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install softspark/ai-toolkit ai-toolkit-rulesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .github/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .github/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install softspark/ai-toolkit ai-toolkit-rules --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/app/claude-app/skills/ai-toolkit-rules .opencode/skills/ai-toolkit-rules && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-toolkit-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/claude-app/skills/ai-toolkit-rules into .opencode/skills/ai-toolkit-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-toolkit-rules", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-toolkit-rulesMandatory engineering, security, testing, git, performance, quality, and response rules.
AI Toolkit Rules is an agent skill from softspark/ai-toolkit. Mandatory engineering, security, testing, git, performance, quality, and response rules. Claude MUST load this skill for every technical, coding, debugging, review, architecture, DevOps, data, or file-editing task in Chat or Cowork.
Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with Git. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitruffmypypytestnpmcargoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
protobuf.devlinter.aip.devopensource.zalando.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AI Toolkit Rules loads about 5.7k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 3,003 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Never commit: secrets, `.env` files, build artifacts, large binaries.- Add `.env` to `.gitignore`. Use `.env.example` as a template.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 3,003 words, ~5,727 tokens.
.claude/skills/ai-toolkit-rules/SKILL.md (or your agent's skills folder).Apply every relevant rule below before acting. Treat MUST/NEVER language as mandatory.
app/rules/claude-toolkit-rules.mdShared AI development toolkit — lifecycle hooks, safety constitution, multi-platform support.
/debug, /review, /refactor, /analyze, /docs, /plan, /explain, /tdd, /triage-issue/write-a-prd → /prd-to-plan → /prd-to-issues; design: /design-an-interface, /architecture-audit, /refactor-plan/workflow <type> (feature-development, backend-feature, frontend-feature, api-design, database-evolution, test-coverage, security-audit, debugging, incident-response, spike, codebase-onboarding, performance-optimization, infrastructure-change, application-deploy, proactive-troubleshooting)/orchestrate <desc> (3–6 agents) | /swarm <mode> <desc> (map-reduce | consensus | relay)~ or $HOME instead of a hardcoded /Users or /home prefix followed
by a user name. The literal prefix is deliberately not written out here: the
plugin export scans shipped files for exactly that pattern, so an example of
the mistake would be indistinguishable from the mistake.echo $HOME first to get the correct valueapp/rules/edit-discipline.mdUse the edit and write tools to change a file. Do not rewrite tracked files
through bash with sed, awk, tee, a heredoc, or > redirection.
This is not a style preference. A shell rewrite is opaque to the host: the
session records a command, not a change. An edit call records which file
changed and how, so the interface can render it, a reviewer can read it, and a
later turn can cite it. A sed line records none of that, and the only way to
find out what happened is to read the file again.
The shell remains correct for what it is for: running builds, tests, linters, git, package managers, and generators that own their own output.
Before reporting a file-changing task as finished, show what changed:
git diff -- <paths> # tracked files
git status --short # what is new or removedPaste the diff into the reply, or state precisely why it is too large and summarise it by file with the counts. A task that reports success without showing the change asks the reader to take the result on trust, and the reader is the one who has to decide whether to commit it.
For an untracked file, show the content you wrote, not a description of it.
Editing through the tools makes a change recordable; showing the diff makes it reviewed. Either alone leaves the person deciding whether to ship blind to something they are accountable for.
app/rules/git-conventions.mdCo-Authored-By: Claude or any AI co-authorship to commitsfeat:, fix:, docs:, refactor:, test:, chore:app/rules/output-mode.mdoutput-mode: concise
Default response mode for this project is concise. The brand-voice skill (when present in ai-toolkit) auto-loads its concise rules; assistants without that skill should still apply the directives below.
path:line instead of paragraphs describing where things live./brand-voice default (or /brand-voice strict for even tighter)output-mode: value in the project's CLAUDE.mdai-toolkit install --skip rules or strip the <!-- TOOLKIT:output-mode --> block manuallyapp/rules/quality-gates.mdruff check . (0 errors)mypy --strict src/ (0 errors)pytest --cov=src (>70% coverage)app/rules/common/coding-style.mdconst, final, val, let by default.remainingRetries, not r).is, has, can, should.fetchUser, calculateTotal, validateInput).id, url, http).users, orderItems).// TODO(PROJ-123): migrate to v2.1. [Step] → verify: [check]camelCase. Aligns with JSON:API spec, Google JSON Style Guide, and framework defaults (Symfony Serializer, Spring Jackson, json_serializable for Dart). No public major API uses snake_case keys in modern designs except ecosystem-bound cases (Rails/Django APIs defaulting to ecosystem convention).UPPER_SNAKE_CASE. Community consensus: Protocol Buffers style guide (mandatory), Google AIP-126 / api-linter (enforced), Zalando Rule #240, Java/Kotlin/C++/Python enum convention. lowercase snake_case (Stripe-style) is a legitimate outlier but not consensus.camelCase for enum values — no major public API uses it, loses visual distinction between keys and values.app/rules/common/git-team.mdThese rules assume more than one person merges into main. They ship only with
the strict profile; a solo maintainer who commits straight to main is not
doing anything wrong, and a reviewer that keeps flagging "use a feature branch"
in that setting is noise. The solo-safe core (commit format, no secrets, no
force-push) lives in git-workflow.
main with required reviews and CI. Never commit broken code to it.feat/user-registration, fix/order-total-calc.main before opening a PR to keep linear history.app/rules/common/git-workflow.mdSolo-safe core: everything here holds whether one person or twenty merge into
main. Branching, pull-request, and review conventions for teams live in
git-team and ship only with the strict profile.
feat:, fix:, docs:, refactor:, test:, chore:.feat: add user registration endpoint).fix: prevent duplicate orders (PROJ-456)..env files, build artifacts, large binaries.main is always deployable: run the project's gates before every commit that lands there.git tag v1.2.3. Automate changelog from commits.git stash for WIP, not unfinished commits.git revert over git reset --hard on shared branches.main or shared branches.app/rules/common/performance.mdapp/rules/common/security.md.env to .gitignore. Use .env.example as a template.security-patterns skill, reference/secrets-at-rest.md.security-patterns skill, reference/commercial-messages.md).HttpOnly and Secure flags on authentication cookies.innerHTML, eval(), and dangerouslySetInnerHTML.* in production.npm audit, pip-audit, cargo audit).app/rules/common/testing.mdassert calls are fine if testing one behavior.test_returns_404_when_user_not_found.src/auth/login.ts -> tests/auth/login.test.ts.conftest.py, test-utils.ts, or equivalent.sleep in tests: use polling, events, or test clocks.{} and [], when testing response filters.© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in app/claude-app/skills/ai-toolkit-rules of softspark/ai-toolkit.
Open the folder on GitHubat commit d64db2b
AI Toolkit Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Toolkit Rules this skillsoftspark/ai-toolkit | 179 | — | ~5.7k | Automated safety check: Notes | Apache-2.0 | |
| Requesting Code ReviewHezaoHezao/poirot | 250 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Adk Setupgoogle/adk-python | 22k | — | ~993 | Automated safety check: Notes | Apache-2.0 | |
| Fixexercism/website | 550 | — | ~1.2k | Automated safety check: Notes | AGPL-3.0 | |
| Code Reviewpolyipseity/obsidian-terminal | 948 | — | ~1.6k | Automated safety check: Pass | AGPL-3.0 | |
| Find Regression Riskdotnet/maui | 23k | — | ~1.1k | Automated safety check: Pass | MIT |
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
google/adk-python
Sets up a local ADK Python development environment in a git clone of the open-source adk-python repository: a uv virtual environment, all dependency extras, pre-commit hooks, and a first unit-test…
exercism/website
Fix a GitHub issue end-to-end — fetches issue, creates worktree, plans and implements fix, runs validation, opens PR, cleans up.
polyipseity/obsidian-terminal
A skill your agent uses when reviewing PRs, code changes, or conducting code audits in obsidian-terminal.
dotnet/maui
Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.
ruby-git/ruby-git
Scaffolds and reviews `Git::Commands::*` classes in the ruby-git library, with unit tests, integration tests and YARD docs, using the Base command architecture.
softspark/ai-toolkit
Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.
softspark/ai-toolkit
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Analyzes code quality, complexity, patterns across codebase.
softspark/ai-toolkit
Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.
softspark/ai-toolkit
Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).
Works with
Categories
Mandatory engineering, security, testing, git, performance, quality, and response rules. AI Toolkit Rules is an agent skill from softspark/ai-toolkit. Mandatory engineering, security, testing, git, performance, quality, and response rules.
AI Toolkit Rules fits situations like: development work in your project.
Run `npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a claude-code`. Or copy the skill folder (app/claude-app/skills/ai-toolkit-rules in softspark/ai-toolkit) into .claude/skills/ai-toolkit-rules in your project. Claude Code loads it when a task matches its description.
Run `npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a codex`. Or copy the skill folder (app/claude-app/skills/ai-toolkit-rules in softspark/ai-toolkit) into .agents/skills/ai-toolkit-rules in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill ai-toolkit-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-toolkit-rules, .gemini/skills/ai-toolkit-rules, .github/skills/ai-toolkit-rules and .opencode/skills/ai-toolkit-rules in your project.
Going by SKILL.md and its folder, AI Toolkit Rules needs the command-line tools its instructions call (git, ruff, mypy, pytest, npm and cargo). Our summary lists: Python 3.
SKILL.md names 3 domains. As links in the text: protobuf.dev, linter.aip.dev and opensource.zalando.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
AI Toolkit Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with AI Toolkit Rules: Requesting Code Review (HezaoHezao/poirot, 250 stars), Adk Setup (google/adk-python, 22k stars), Fix (exercism/website, 550 stars) and Code Review (polyipseity/obsidian-terminal, 948 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.
Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.