Agent skill

Autoreview

by sozercan in sozercan/kaset

Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship.

MITAuto-check passedDevelopment

Install Autoreview

skills CLI
$ npx skills add sozercan/kaset --skill autoreview -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sozercan/kaset autoreview --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sozercan/kaset.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/autoreview .claude/skills/autoreview && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
autoreview
GitHub stars
2.4k
Token cost
~3k tokens
SKILL.md length
1,470 words
Files
6 (incl. scripts)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship.

  • Development work in your project
  • SKILL.md covers Contract, Pick Target, Parallel Closeout and Review Panels, plus 3 more sections
  • Runs Python and PowerShell scripts from its folder; calls gh, codex and python

What it does

Autoreview is an agent skill from sozercan/kaset. Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/autoreview.test.py` and `scripts/test-review-harness.py`).

It sits in Development. It works with YouTube and macOS. The repository describes itself as: 📼 The missing YouTube and YouTube Music macOS app. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/autoreview”

Requirements

  • Python 3
  • PowerShell

What it can do on your machine

Read from SKILL.md and the folder at commit 4b74e9f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python and PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • codex
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Autoreview loads about 3k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,470 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sozercan/kaset at commit 4b74e9f, republished under its MIT licence (© sozercan). 1,470 words, ~2,964 tokens.

Download SKILL.mdSave it as .claude/skills/autoreview/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
autoreview
description
Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship.

Auto Review

Run the bundled structured review helper as a closeout check. This is code review, not Guardian auto_review approval routing.

Codex review is the default when no engine is set. It usually delivers the best review results and should remain the normal final closeout engine.

Use when:

  • user asks for Codex review / Claude review / autoreview / second-model review
  • after non-trivial code edits, before final/commit/ship
  • reviewing a local branch or PR branch after fixes

Contract

  • Treat review output as advisory. Never blindly apply it.
  • Verify every finding by reading the real code path and adjacent files.
  • Read dependency docs/source/types when the finding depends on external behavior.
  • Reject unrealistic edge cases, speculative risks, broad rewrites, and fixes that over-complicate the codebase.
  • Prefer small fixes at the right ownership boundary; no refactor unless it clearly improves the bug class.
  • When an accepted finding shows a bug class or repeated pattern, inspect the current PR scope for sibling instances before fixing.
  • Fix the scoped bug class at once when practical; stop at touched surfaces, owner boundaries, and clear follow-up territory.
  • Keep going until structured review returns no accepted/actionable findings.
  • If a review-triggered fix changes code, rerun focused tests and rerun the structured review helper.
  • For security-audit suppression changes, verify accepted findings remain auditable: suppressed findings stay in structured output, active output keeps an unsuppressible suppression notice, and aggregate findings cannot hide unrelated active risk.
  • Never switch or override the requested review engine/model. If the review hits model capacity, retry the same command a few times with the same engine/model.
  • Be patient with large bundles. Structured review can take up to 30 minutes while the model call is active, especially with Codex tools or web search.
  • Treat heartbeat lines like review still running: ... elapsed=... pid=... as healthy progress, not a hang. Let the helper continue while heartbeats are advancing. Pass --stream-engine-output when live engine text is useful; Codex and Claude filter tool/file chatter, other engines pass raw output through.
  • Do not kill a review just because it has been quiet for 2-5 minutes, or because it is still running under the 30-minute window. Inspect the process only after missing multiple expected heartbeats, after 30 minutes, or after an obviously failed subprocess; prefer letting the same helper command finish.
  • Tools are useful in review mode. The helper allows read-only inspection tools and web search by default so reviewers can check dependency contracts, upstream docs, and current behavior from a sanitized review workspace, not the real checkout.
  • Security perspective is always included, but it should not cripple legitimate functionality. Report security findings only when the change creates a concrete, actionable risk or removes an important safety check.
  • For regression provenance, keep roles separate: blamed code author, blamed PR author, PR merger/committer, current PR author, and PR/date. If no blamed PR is traceable, use the blamed commit as the provenance: commit SHA, date, and author username. Do not guess a merger or frame missing PR metadata as a separate finding.
  • If the blamed PR was merged by clawsweeper[bot] or another automation, identify the human trigger when practical. Check timeline/comments first; if rate-limited, use gitcrawl/cache or public PR HTML. Look for maintainer commands such as @clawsweeper automerge, /landpr, or labels/status comments that armed automerge. Report automerge triggered by @login; if not found, say trigger unknown.
  • Do not invoke built-in codex review, nested reviewers, or reviewer panels from inside the review. The helper builds one bundle, calls one selected engine, validates one structured result, and stops.
  • Stop as soon as the helper exits 0 with no accepted/actionable findings. Do not run an extra review just to get a nicer "clean" line, a second opinion, or clearer closeout wording.
  • Treat the helper's successful exit plus absence of actionable findings as the clean review result, even if the underlying Codex CLI output is terse.
  • Multi-reviewer panels are opt-in only. Use them when explicitly requested or when risk justifies the extra spend; the main agent still verifies every accepted finding before fixing.
  • If rejecting a finding as intentional/not worth fixing, add a brief inline code comment only when it explains a real invariant or ownership decision that future reviewers should know.
  • If gh/Gitcrawl reports database disk image is malformed, run gitcrawl doctor --json once to let the portable cache repair before retrying review; do not bypass the shim unless repair fails and freshness requires live GitHub.
  • If Gitcrawl reports a portable manifest mismatch, source/runtime DB health error, or stale portable-store checkout, run gitcrawl doctor --json and inspect source_db_health, runtime_db_health, and portable_store_status before falling back to live GitHub.
  • Do not push just to review. Push only when the user requested push/ship/PR update.

Pick Target

Dirty local work:

bash
<autoreview-helper> --mode local

Use this only when the patch is actually unstaged/staged/untracked in the current checkout. --mode uncommitted is accepted as an alias for --mode local. For committed, pushed, or PR work, point the helper at the commit or branch diff instead; do not force dirty modes just because the helper docs mention dirty work first. A clean local review only proves there is no local patch.

Branch/PR work:

bash
<autoreview-helper> --mode branch --base origin/main

Optional review context is first-class:

bash
<autoreview-helper> --mode branch --base origin/main --prompt-file /tmp/review-notes.md --dataset /tmp/evidence.json

If an open PR exists, use its actual base:

bash
base=$(gh pr view --json baseRefName --jq .baseRefName)
<autoreview-helper> --mode branch --base "origin/$base"

Committed single change:

bash
<autoreview-helper> --mode commit --commit HEAD

or with the repo-local helper:

bash
.agents/skills/autoreview/scripts/autoreview --mode commit --commit HEAD

Use commit review for already-landed or already-pushed work on main. Reviewing clean main against origin/main is usually an empty diff after push. For a small stack, review each commit explicitly or review the branch before merging with --base.

Show full SKILL.md (571 more words)Show less

Parallel Closeout

Format first if formatting can change line locations. Then it is OK to run tests and review in parallel:

bash
scripts/autoreview --parallel-tests "<focused test command>"

On Windows, the default --parallel-tests shell preserves the platform cmd.exe semantics used by Python shell=True. Use --parallel-tests-shell powershell or --parallel-tests-shell pwsh when the focused test command is PowerShell-specific.

Tradeoff: tests may force code changes that stale the review. If tests or review lead to code edits, rerun the affected tests and rerun review until no accepted/actionable findings remain. Once that rerun exits cleanly, stop; do not spend another long review cycle on redundant confirmation.

Review Panels

Run multiple reviewers against one frozen bundle:

bash
<autoreview-helper> --reviewers codex,claude

--panel is shorthand for Codex plus Claude unless --engine changes the first reviewer:

bash
<autoreview-helper> --panel

Set reviewer models and thinking/effort explicitly:

bash
<autoreview-helper> --reviewers codex,claude --model codex=gpt-5.1 --thinking codex=high --model claude=sonnet --thinking claude=max

Inline syntax is also supported:

bash
<autoreview-helper> --reviewers codex:gpt-5.1:high,claude:sonnet:max

Codex maps thinking to model_reasoning_effort and accepts low, medium, high, or xhigh. Claude maps thinking to --effort and also accepts max. Engines without a real thinking knob reject --thinking.

Context Efficiency

Run the helper directly so target selection, engine choice, structured validation, and exit status all stay in one path. If output is noisy, summarize the completed helper output after it returns; do not ask another agent or reviewer to rerun the review.

Helper

OpenClaw repo-local helper:

bash
.agents/skills/autoreview/scripts/autoreview --help

agent-scripts checkout helper:

bash
~/Projects/agent-scripts/skills/autoreview/scripts/autoreview --help

On native Windows, invoke the extensionless Python helper through Python:

powershell
python skills\autoreview\scripts\autoreview --help

The smoke harness has thin shell wrappers over a shared Python implementation:

bash
.agents/skills/autoreview/scripts/test-review-harness --fixture benign --engine codex
powershell
skills\autoreview\scripts\test-review-harness.ps1 -Fixture benign -Engine codex

Global helper from agent-scripts:

bash
~/.codex/skills/agent-scripts/autoreview/scripts/autoreview --help

The helper:

  • chooses dirty local changes first
  • accepts --mode uncommitted as an alias for --mode local
  • otherwise uses current PR base if gh pr view works
  • otherwise uses origin/main for non-main branches
  • supports --engine codex, claude, droid, and copilot; default is AUTOREVIEW_ENGINE or codex; Codex should remain the default when nothing is set
  • resolves bare git, gh, reviewer, and PowerShell shell commands from absolute PATH entries only, never from the reviewed checkout; explicit relative --*-bin paths are refused
  • use --mode commit --commit <ref> for already-committed work, especially clean main after landing
  • should be left in --mode auto or forced to --mode branch for PR/branch work; do not force --mode local after committing
  • writes only to stdout unless --output, --json-output, or live streamed engine stderr is set
  • supports --dry-run, --parallel-tests, --parallel-tests-shell, --prompt, --prompt-file, --dataset, --no-tools, --no-web-search, and commit refs
  • supports --stream-engine-output or AUTOREVIEW_STREAM_ENGINE_OUTPUT=1 for live engine text while preserving structured validation; Codex and Claude hide tool/file event details, emit compact activity summaries, and report usage at turn completion
  • supports opt-in review panels with --panel / --reviewers, plus per-engine --model and --thinking
  • allows read-only tools and web search by default where the selected CLI supports them; runs reviewers from a sanitized temporary workspace containing the review prompt instead of the real checkout; forbids nested review in the prompt; Codex is run through codex exec with read-only sandbox and structured output
  • prints review still running: <engine> elapsed=<seconds>s pid=<pid> to stderr at long-running intervals while waiting for the selected review engine, unless streamed output or compact Codex activity has been visible recently
  • prints autoreview clean: no accepted/actionable findings reported when the selected review command exits 0
  • exits nonzero when accepted/actionable findings are present

Final Report

Include:

  • review command used
  • tests/proof run
  • findings accepted/rejected, briefly why
  • the clean review result from the final helper/review run, or why a remaining finding was consciously rejected

Do not run another review solely to improve the final report wording. If the final helper run exited 0 and produced no accepted/actionable findings, report that exact run as clean.

© sozercan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in .agents/skills/autoreview of sozercan/kaset.

  • SKILL.md
  • scripts/autoreview
  • scripts/autoreview.test.py
  • scripts/test-review-harness
  • scripts/test-review-harness.ps1
  • scripts/test-review-harness.py

Open the folder on GitHubat commit 4b74e9f

Compare with similar skills

Autoreview next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Autoreview compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Autoreview this skillsozercan/kaset2.4k—~3kAutomated safety check: PassMIT
Build Helpernhiroyasu/wallpaper-play148—~143Automated safety check: PassMIT
Git Worktree Setupk8zdev/k8z155—~930Automated safety check: PassNone
Core Data ExpertAvdLee/Core-Data-Agent-Skill314—~1.2kAutomated safety check: PassMIT
Liney CLIeverettjf/liney150—~1.2kAutomated safety check: NotesApache-2.0
Native App Performanceharperreed/dotfiles3344 repos~538Automated safety check: PassNone

Similar skills

  • Build Helper

    nhiroyasu/wallpaper-play

    Build and test helper for wallpaper-play. An agent skill from nhiroyasu/wallpaper-play.

    148 GitHub stars~143 tokensUpdated 4 mo ago
    MobileAuto-check passed
  • Automate git worktree creation and copy private files (not tracked in git) to new workdirs.

    155 GitHub stars~930 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Core Data Expert

    AvdLee/Core-Data-Agent-Skill

    Expert Core Data guidance (iOS/macOS): stack setup, fetch requests & NSFetchedResultsController, saving/merge conflicts, threading & Swift Concurrency, batch operations & persistent history…

    314 GitHub stars~1.2k tokensUpdated 24 days ago
    DevelopmentAuto-check passed
  • Liney CLI

    everettjf/liney

    Use the Liney CLI (liney) to inspect or control a running Liney terminal workspace and the agent sessions it hosts.

    150 GitHub stars~1.2k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Native App Performance

    harperreed/dotfiles

    Native macOS/iOS app performance profiling via xctrace/Time Profiler and CLI-only analysis of Instruments traces.

    334 GitHub starsUsed in 4 repos~538 tokens
    DevelopmentAuto-check passed
  • Hopper Debugger

    steipete/agent-scripts

    Hopper debugging: macOS/iOS binaries, ObjC/Swift symbols, dyld, LLDB.

    7.3k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from sozercan/kaset

  • API Exploration

    sozercan/kaset

    A skill your agent uses when a task needs a new or modified YouTube Music API call, response parser validation, authenticated endpoint investigation, or fixture capture; explore endpoints with swift…

    2.4k GitHub stars~454 tokensUpdated 4 days ago
    Auto-check passed
  • Dev Loop Packaging

    sozercan/kaset

    A skill your agent uses when you need a fresh packaged .app bundle, a fast build-package-relaunch loop, or a packaged runtime repro for Kaset instead of a compile-only verification.

    2.4k GitHub stars~388 tokensUpdated 4 days ago
    Auto-check passed
  • A skill your agent uses when playback, auth recovery, queue sync, or hidden WebView state diverges from native Swift state and you need to debug the DRM playback WebView, bridge events, or…

    2.4k GitHub stars~480 tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Autoreview

What does Autoreview do?

Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship. Autoreview is an agent skill from sozercan/kaset. Run a structured code review (Codex default, Claude optional) as a closeout check on a local or PR branch before commit or ship.

When should I use Autoreview?

Autoreview fits situations like: development work in your project.

How do I install Autoreview in Claude Code?

Run `npx skills add sozercan/kaset --skill autoreview -a claude-code`. Or copy the skill folder (.agents/skills/autoreview in sozercan/kaset) into .claude/skills/autoreview in your project. Claude Code loads it when a task matches its description.

How do I install Autoreview in Codex?

Run `npx skills add sozercan/kaset --skill autoreview -a codex`. Or copy the skill folder (.agents/skills/autoreview in sozercan/kaset) into .agents/skills/autoreview in your project. Codex loads it when a task matches its description.

Can I use Autoreview in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sozercan/kaset --skill autoreview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/autoreview, .gemini/skills/autoreview, .github/skills/autoreview and .opencode/skills/autoreview in your project.

What does Autoreview need to run?

Going by SKILL.md and its folder, Autoreview needs Python and PowerShell for the scripts in its folder and the command-line tools its instructions call (gh, codex and python). Our summary lists: Python 3; PowerShell.

Does Autoreview access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Autoreview safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Autoreview use?

Autoreview is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Autoreview use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Autoreview?

Skills that share tags, products or a category with Autoreview: Build Helper (nhiroyasu/wallpaper-play, 148 stars), Git Worktree Setup (k8zdev/k8z, 155 stars), Core Data Expert (AvdLee/Core-Data-Agent-Skill, 314 stars) and Liney CLI (everettjf/liney, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Autoreview?

sozercan (a GitHub user) maintains it in sozercan/kaset, which has 2,362 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 3, 2026.

Source: sozercan/kaset on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.