Agent skill

Code Review

by sortie-ai in sortie-ai/sortie

Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add sortie-ai/sortie --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sortie-ai/sortie code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sortie-ai/sortie.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
196
Token cost
~2.9k tokens
SKILL.md length
1,673 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

  • Tasks that involve Pull requests
  • SKILL.md covers Start from the pull request…, Documentation is part of the…, Orchestrator state: the… and Adapter contracts, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Unit testing

What it does

Code Review is an agent skill from sortie-ai/sortie. Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a sibling, contract widenings that leave test doubles silently asserting nothing, kind-keyed maps missing a new entry, configuration literals that mean opposite things in adjacent blocks, error-taxonomy routing gaps, and wire assumptions that break on pagination. Use on every pull request review in addition to the coding…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, Unit testing and Code quality. It works with GitHub and Jira. The repository describes itself as: Turn tracker tickets into autonomous agent sessions. The licence is MIT.

When your agent uses it

  • Tasks that involve Pull requests
  • Tasks that involve Unit testing
  • Tasks that involve Code quality

Example prompts

  • “Use the code-review skill to review pull requests in this repository for the defect classes a mechanical checklist misses: documentation that…”
  • “/code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 37e601f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.9k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 1,673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~182
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sortie-ai/sortie at commit 37e601f, republished under its MIT licence (© sortie-ai). 1,673 words, ~2,902 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a sibling, contract widenings that leave test doubles silently asserting nothing, kind-keyed maps missing a new entry, configuration literals that mean opposite things in adjacent blocks, error-taxonomy routing gaps, and wire assumptions that break on pagination. Use on every pull request review in addition to the coding standards in copilot-instructions.md. Covers Go orchestrator code, adapter packages, the architecture specification under docs/architecture/, accepted decision records, and operator-facing strings.
license
MIT

Reviewing sortie pull requests

.github/copilot-instructions.md covers the mechanical checks: layering, concurrency, path containment, SQLite rules, error wrapping, resource lifecycle, adapter boundaries, style. Do not repeat them. This skill covers what those checks cannot see: defects that are locally correct and globally wrong.

Two rules govern every finding.

Verify before flagging. Open the file and read the line. A finding that cites a line that says something else costs the maintainer more than silence. State the evidence inline: file, symbol, and what it actually does.

One grounded finding beats five speculative ones. Uncertain findings are noise. If a check below needs a fact you cannot establish from the diff plus the files it touches, say what you could not verify instead of guessing.

Start from the pull request description

.github/pull_request_template.md makes the author declare Intent, Sensitive Areas, Breaking Changes, and Migrations. Treat each as a claim to audit, not as context to absorb.

  • Intent says opt-in or default-off. Find the branch that makes it inert when unconfigured, and confirm nothing outside it changed behavior. An opt-in feature that alters a default path is the failure this claim hides.
  • Sensitive Areas names a file. Review it first and hardest. An empty Sensitive Areas on a diff that touches orchestrator state, an adapter boundary, or workspace removal is itself a finding.
  • Breaking Changes says none. Check exported signatures, domain struct fields consumed by adapters, config field names and defaults, and log or metric names an operator may depend on.
  • Migrations says none. Check internal/persistence/sql/ and any new column read.

Documentation is part of the change

The specification under docs/architecture/ is the contract implementation follows, so drift is a defect, not a nicety. For any behavior change, find the section that describes that behavior and confirm the PR updates it.

  • A documented guarantee with no enforcing line. When a document claims a safety property ("marked dispatched synchronously, which prevents duplicate dispatch"), locate the code that provides it. If the code does it later, elsewhere, or not at all, the document is wrong and the PR that touched the area should fix it.
  • Absolute claims. "No path releases X", "the only mechanism", "always", "never". One counterexample falsifies these permanently, and they rot silently. Ask whether the diff introduces a second path that makes an existing absolute false.
  • Counts in prose. "has nine parts", "three tables", "two packages implement". A new pass, table, or implementation makes them false and nobody notices. Flag the count, and propose a formulation that states the ordering or the property instead.
  • Enumerations that must grow. Adapter lists, reaction kind lists, supported-forge tables. If the PR adds a member, every enumeration of that set is a review target.
  • Operator-visible surface, separate repository. The docs site lives outside this repository. A PR adding a config field, environment variable, CLI flag, or reaction kind cannot update it here. Flag the gap so it is tracked; do not ask for a file this repository does not hold.
  • A changelog bullet in the wrong version section. A diff hunk header names the category (### Fixed), never the enclosing ## [x.y.z] heading, so a bullet inserted into an already-released section reviews as clean. Resolve each added hunk's line number to the nearest preceding ## [ heading and require [Unreleased], then check the bullet appends to the bottom of its category and wraps to its neighbours' width.
  • Accepted decision records are immutable. docs/decisions/ records what was decided and why. Do not propose adding issue numbers, section numbers, or line numbers to one; do not re-litigate a decision recorded there. If the code contradicts an accepted record, that is the finding.

Orchestrator state: the defects that survive unit tests

State lives in maps keyed by issue and reaction kind, mutated across passes that run in a fixed order each tick. Locally correct edits break neighbors.

  • The retry slot is one per issue. ScheduleRetry cancels any queued retry for that issue first. Any pass that schedules a retry discards whatever another kind had queued, along with its continuation context. When a diff adds or moves a ScheduleRetry call, ask what it displaces and whether the victim can re-detect its own work.
  • Cleanup must be scoped to the escalating kind. An issue-wide clear takes sibling reactions' entries, counters, and fingerprint rows with it. A kind parked in a handoff state has no worker exit left to reseed it, so the loss is permanent until restart.
  • Every pending entry needs a release path. For a new or modified reaction kind, establish who seeds the entry, what drops it (age, terminal state, or its own completion), and what happens across a restart. A kind with no expiry and no terminal check leaks the entry and polls the forge forever.
  • Claim and counter are not the entry. state.Claimed, state.ReactionAttempts, and state.PendingReactions have independent lifetimes. A change that releases one is not evidence the others are released.
  • Kind-keyed maps must gain the new member. A new reaction kind needs an entry wherever kinds are enumerated: pinning behavior, TTL wiring, recovery seeding, validation, metrics labels. Grep the kind constant across the package; a missing entry usually means a silent default, not a compile error.
  • The fingerprint protocol has an order. Upsert the fingerprint, read it back, act, and mark dispatched only after the action succeeded. Marking before the action loses the retry on a transient failure; deleting the row on success re-arms the same observation on the next tick; retaining it blocks a legitimate second episode. Judge which of the three the diff wants, then check it does that.
Show full SKILL.md (754 more words)Show less

Adapter contracts

  • Widening a domain type reaches every implementation and every double. A new field on a shared struct must be populated by each adapter and by each fake in tests. A double that leaves it at the zero value asserts the negative case forever: a bool stays false, a string stays empty, and the test passes while covering nothing.
  • Fixtures must match the live wire shape. Response fixtures built from a hand-written guess hide real bugs: a dropped cursor field, a team key placed in a UUID field, a status list that arrives paginated. Prefer a fixture derived from a recorded response.
  • Pagination is not optional. A single GET against a route that paginates silently truncates at the page size. Any new list read needs the pagination walk, and the review question is what the route's default page size is.
  • Text-sniffing a message is a wire dependency. Matching on a substring of an error body works until the forge rewrites the sentence. Flag it when introduced; when it already exists, flag only if the diff extends it.
  • Adapters normalize at the boundary. A forge-specific field name, status string, or flag reaching orchestrator code is a leak even when it compiles.

Configuration and validation

  • The same literal can mean opposite things. A zero budget disables count-based escalation in one reaction and escalates on first detection in its sibling. When a diff adds a numeric field, compare its semantics against the adjacent block that shares the name.
  • Two environment mechanisms, never conflated. The override registry maps one SORTIE_* variable to one config field and replaces the YAML value. $VAR indirection is a workflow-authored reference expanded at load. A change to one is not a change to the other, and documentation that credits the wrong one is a finding.
  • Offline validation versus construction. sortie validate performs config-shape checks without network access. Credential, project, and state resolution happen when the adapter is constructed. A check placed in the wrong layer either fails offline or never runs.
  • An earlier error can shadow a later arm. If the config layer rejects a combination before the adapter validator sees it, that validator arm is unreachable end to end. Flag a test that claims to cover it through the full path.
  • Durations end in _ms here. A field measured in another unit needs a stated reason, because the reader will assume milliseconds.

Error handling beyond wrapping

  • Route every class. Transport and API errors back off and retry; auth and payload errors are deterministic and escalate without consuming the retry budget; not-found stops. A new call site that collapses these into one branch spends the budget proving a permission error is permanent.
  • A silent early return blinds the operator. A pass that returns without a log leaves no way to tell "working, nothing to do" from "misconfigured, doing nothing". Periodic passes that remove or dispatch nothing should still report why.
  • Degrade-to-continue needs somewhere to continue to. A failure posture copied from a path that has a retry loop is wrong on a path that has none.

Tests

  • A regression test must fail without the fix. For a bug fix, look for the assertion that the old code would violate. A test that passes both ways documents behavior; it does not lock the fix.
  • Zero-value doubles. See the contract-widening note above: this is the most common way a sortie test passes while asserting nothing.
  • Env-gated integration tests skip cleanly. Without SORTIE_<ADAPTER>_TEST=1 they must skip, never fail.

Operator-facing strings

Help text, warnings, and report output are read by operators who never see the schema. A message naming a table, a column, or a code path is a finding. Configuration keys the operator writes are fine.

Do not raise these

  • Go version idioms. The module targets a modern Go release. Range-over-int, per-iteration loop variables, and the standard library added in recent releases compile. Do not claim otherwise; CI is the arbiter.
  • Deliberate decisions recorded in docs/decisions/. Disagreeing with an accepted record is not a review comment.
  • Established patterns repeated correctly. A new pass that mirrors its five siblings is not a finding because you would have written it differently.
  • Equivalent rewrites. Style preferences with no behavioral difference.

Severity

Use the ladder at the end of .github/copilot-instructions.md. Two additions specific to this skill: documentation that states a guarantee the code does not provide is Major, not Minor, because the next implementer builds on it; a leaked or clobbered state entry is Major even when no test fails, because its symptom is a workflow that never completes.

© sortie-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/code-review of sortie-ai/sortie.

Open the folder on GitHubat commit 37e601f

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillsortie-ai/sortie196—~2.9kAutomated safety check: PassMIT
Mariadb Operator PR Reviewmariadb-operator/mariadb-operator1k—~3.3kAutomated safety check: PassApache-2.0
GitHub Swarm Code Reviewruvnet/agentic-flow8166 repos~6.5kAutomated safety check: PassNone
Reviewing Changesbitwarden/ios694—~1.1kAutomated safety check: PassGPL-3.0
Dotnet Copfmflurry/settings-opencode171—~2kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Mariadb Operator PR Review

    mariadb-operator/mariadb-operator

    Perform a structured maintainer-style PR review for the mariadb-operator repository.

    1k GitHub stars~3.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • GitHub Swarm Code Review

    ruvnet/agentic-flow

    Reviews GitHub pull requests with a swarm of specialized agents covering security, performance, architecture, style and accessibility, driven by the gh CLI and ruv-swarm.

    816 GitHub starsUsed in 6 repos~6.5k tokens
    DevelopmentAuto-check passed
  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    694 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Dotnet Cop

    fmflurry/settings-opencode

    Pre-merge code review for .NET 10 pull requests. An agent skill from fmflurry/settings-opencode.

    171 GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

Works with

Categories

Questions about Code Review

What does Code Review do?

Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…. Code Review is an agent skill from sortie-ai/sortie. Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a sibling, contract widenings that leave test doubles silently asserting nothing, kind-keyed maps missing a new entry, configuration literals that mean opposite things in adjacent blocks, error-taxonomy routing gaps, and wire assumptions that break on pagination.

When should I use Code Review?

Code Review fits situations like: tasks that involve Pull requests; tasks that involve Unit testing; tasks that involve Code quality.

How do I install Code Review in Claude Code?

Run `npx skills add sortie-ai/sortie --skill code-review -a claude-code`. Or copy the skill folder (.github/skills/code-review in sortie-ai/sortie) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add sortie-ai/sortie --skill code-review -a codex`. Or copy the skill folder (.github/skills/code-review in sortie-ai/sortie) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sortie-ai/sortie --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Mariadb Operator PR Review (mariadb-operator/mariadb-operator, 1k stars), GitHub Swarm Code Review (ruvnet/agentic-flow, 816 stars), Reviewing Changes (bitwarden/ios, 694 stars) and Dotnet Cop (fmflurry/settings-opencode, 171 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

sortie-ai (a GitHub organization) maintains it in sortie-ai/sortie, which has 196 GitHub stars. The repository was last updated on October 6, 2026.

Source: sortie-ai/sortie on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.