Code Review with Beads Tasks
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.
$ npx skills add softspark/ai-toolkit --skill review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install softspark/ai-toolkit review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/review .claude/skills/review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .claude/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/softspark/ai-toolkit/tree/main/app/skills/reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add softspark/ai-toolkit --skill review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install softspark/ai-toolkit review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/app/skills/review .agents/skills/review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .agents/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install softspark/ai-toolkit review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/app/skills/review .cursor/skills/review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .cursor/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/softspark/ai-toolkit.git --path app/skills/review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add softspark/ai-toolkit --skill review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install softspark/ai-toolkit review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/app/skills/review .gemini/skills/review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .gemini/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install softspark/ai-toolkit reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add softspark/ai-toolkit --skill review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/app/skills/review .github/skills/review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .github/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install softspark/ai-toolkit review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/app/skills/review .opencode/skills/review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/review into .opencode/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewReviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.
Review is an agent skill from softspark/ai-toolkit. Reviews code for quality, security, correctness. Triggers: code review, quality review, security review, review PR, review branch.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/diff-analyzer.py`).
It sits in Development, covering Code review, Pull requests and Security review. It works with Git. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitghpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review loads about 3.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 1,274 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,274 words, ~3,118 tokens.
.claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.$ARGUMENTS
Reviews code changes for quality and issues.
git diff --stat main...HEAD 2>/dev/null || git diff --cached --stat 2>/dev/null || echo "no changes detected"Collect every failing signal up front, then review the diff in full anyway:
| Signal | How to read it |
|---|---|
| Merge conflict with base | gh pr view --json mergeable,mergeStateStatus or git merge-tree |
| Failing CI checks | gh pr checks or the platform equivalent |
| Lint / typecheck failure | the project's own commands |
Each failing signal becomes a blocker finding. None of them ends the run.
A review that aborts on the first red signal spends the whole cycle repeating what the tracker already displayed, while the finding that would have told the author something new never gets written. One invocation produces the most complete picture of the change that it can.
Before starting manual review, run the diff analyzer script to get a structured risk assessment:
python3 ${CLAUDE_SKILL_DIR}/scripts/diff-analyzer.py [base_branch]
# Default base branch: main
# Example: python3 ${CLAUDE_SKILL_DIR}/scripts/diff-analyzer.py developThe script outputs JSON with:
If the script reports parallel_review_recommended: true, use the Parallel Review (Agent Teams) mode below.
For significant PRs or large changesets, create a parallel review team:
Create an agent team to review [target]:
- Teammate 1 (security-auditor): "Review for security vulnerabilities, auth issues,
injection risks, secret leaks. Report with severity ratings." Use Opus.
- Teammate 2 (performance-optimizer): "Check for N+1 queries, memory leaks,
unnecessary allocations, caching opportunities. Report with impact ratings." Use Opus.
- Teammate 3 (test-engineer): "Validate test coverage, edge cases, mock quality,
missing assertions. Report coverage gaps." Use Opus.
Each reviewer should report findings independently. Do NOT modify files.After all reviewers complete:
When to use: PRs with >5 files changed, cross-module changes, security-sensitive code. READ-ONLY: No teammate should modify files during review.
| Target | What's Reviewed |
|---|---|
| (none) | Staged changes |
branch | Branch vs main |
pr | Pull request changes |
file.ts | Specific file |
reference/secrets-at-rest.md in security-patternsreference/commercial-messages.md in security-patternsreference/input-validation.md from the security-patterns skill located through the current client's installed catalogbackground-clip: text) or saturated purple/blue hero washesborder-width across all states (zero layout shift) and reserve 2px transparent outlineoverflow-x: clip on html and body; no buttons/links wrapping to 2 lines; image grid tracks use minmax(0, 1fr)font-style: normal, no italic emphasis in headers); max 3 font families (2+1 rule)| Tier | Meaning | Merge impact |
|---|---|---|
blocker | Causes damage: data loss, security hole, money, corruption | Blocks merge, no exceptions |
major | Real defect that will bite in production | Blocks merge unless waived in writing |
minor | Should be fixed, not worth blocking on | Does not block |
nit | Polish, taste, style | Does not block |
Verdict rule — apply it mechanically, do not negotiate with yourself:
blocker → REQUEST_CHANGESmajor without a documented waiver (who waived it, why, what the follow-up is) → REQUEST_CHANGESminor / nit → APPROVENEEDS_DISCUSSION, and state what would resolve itSeverity describes impact, confidence describes certainty — they are independent
axes. A finding with confidence < 6 is reported at the tier its evidence supports
and is never promoted to blocker on suspicion alone.
## Code Review Report
### Summary
- **Files Changed**: [count]
- **Lines Added**: [+count]
- **Lines Removed**: [-count]
- **Issues Found**: [count]
- **Overall Confidence**: [1-10] — how confident the reviewer is in the assessment
### Findings
#### Blocker
- **[file:line]**: [issue]
- Severity: blocker | Confidence: [1-10]
- Evidence: [specific code reference and reasoning]
- Suggested fix: [code]
#### Major
- **[file:line]**: [issue]
- Severity: major | Confidence: [1-10]
- Evidence: [specific code reference and reasoning]
- Suggested fix: [code]
#### Minor
- **[file:line]**: [issue]
- Severity: minor | Confidence: [1-10]
- Evidence: [line number + reasoning]
#### Nit
- **[file:line]**: [suggestion]
- Severity: nit | Confidence: [1-10]
### Confidence Guide
| Score | Meaning |
|-------|---------|
| 9-10 | Certain — verified via code, tests, or documentation |
| 7-8 | High — strong evidence, minor assumptions |
| 5-6 | Medium — plausible issue, needs author confirmation |
| 3-4 | Low — speculative, based on patterns not proof |
| 1-2 | Guess — flag for discussion, don't block on this |
### Positive Notes
- [What's good about the code]
### Verdict
[APPROVE / REQUEST_CHANGES / NEEDS_DISCUSSION]
State which clause of the verdict rule produced it, e.g.
"REQUEST_CHANGES — 1 blocker (auth.ts:88)" or
"APPROVE — 2 minor, 1 nit, no blocker or major".
Waived majors must name the waiver and the follow-up.| Excuse | Why It's Wrong |
|---|---|
| "Small change, quick scan is enough" | Small changes introduce subtle bugs — apply consistent review regardless of size |
| "Tests pass, so the code is correct" | Tests validate specific scenarios, not all behaviors — verify missing coverage |
| "It's just a refactor, no need for deep review" | Refactors change invariants — verify behavior preservation, not just compilation |
| "The author is senior, they know what they're doing" | Seniority doesn't prevent mistakes — review the code, not the person |
| "We're in a hurry, ship it" | Rushed reviews create tech debt that costs 10x more to fix later |
After completing the review, perform a self-evaluation pass:
This skill only analyzes. It does NOT modify any files.
/debug to trace root causes/tdd to add test-first coverage/cve-scan for dependency vulnerabilities/analyze for deeper code quality metrics© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in app/skills/review of softspark/ai-toolkit.
Open the folder on GitHubat commit d64db2b
Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review this skillsoftspark/ai-toolkit | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | |
| Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~2k | Automated safety check: Pass | Custom licence | |
| Openqodexopenqodex/openqodex | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Trailmark Review Gatetrailofbits/skills | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Differential Security Reviewtrailofbits/skills | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
trailofbits/skills
Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.
trailofbits/skills
Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
codexstar69/bug-hunter
Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.
softspark/ai-toolkit
Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.
softspark/ai-toolkit
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Analyzes code quality, complexity, patterns across codebase.
softspark/ai-toolkit
Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.
softspark/ai-toolkit
Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).
Works with
Categories
Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit. Review is an agent skill from softspark/ai-toolkit. Reviews code for quality, security, correctness.
Review fits situations like: tasks that involve Code review; tasks that involve Pull requests; tasks that involve Security review.
Run `npx skills add softspark/ai-toolkit --skill review -a claude-code`. Or copy the skill folder (app/skills/review in softspark/ai-toolkit) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add softspark/ai-toolkit --skill review -a codex`. Or copy the skill folder (app/skills/review in softspark/ai-toolkit) into .agents/skills/review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.
Going by SKILL.md and its folder, Review needs Python for the scripts in its folder and the command-line tools its instructions call (git, gh and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review: Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Openqodex (openqodex/openqodex, 303 stars), Trailmark Review Gate (trailofbits/skills, 7.4k stars) and Differential Security Review (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.
Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.