Agent skill

Graph-Based Change Review

by tirth8205 in tirth8205/code-review-graph

Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.

MITAuto-check passedDevelopment

Install Graph-Based Change Review

skills CLI
$ npx skills add tirth8205/code-review-graph --skill review-changes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tirth8205/code-review-graph review-changes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tirth8205/code-review-graph.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-changes .claude/skills/review-changes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-changes
GitHub stars
32k
Used in
1 other repo
Token cost
~331 tokens
SKILL.md length
176 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.

  • Works in 5 steps: Call detect_changes_tool for risk-scored… → Call get_affected_flows_tool only when… → For each high-risk function, call… → …
  • Reviewing a pull request with risk levels and a test-gap analysis
  • SKILL.md covers Review Changes and Token Efficiency Rules
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The agent calls `detect_changes_tool` to get changed functions with risk scores, test gaps and affected flows, then digs deeper only as needed: `get_affected_flows_tool` for the steps of a flow, `query_graph_tool` with the `tests_for` pattern to check coverage of each high-risk function, and `get_impact_radius_tool` when the blast radius is unclear. It finishes by suggesting specific test cases for untested changes.

Findings are grouped by risk level (high, medium, low) with what changed, why it matters, test coverage and a suggested fix, followed by a merge recommendation. Token rules keep the run cheap: start with `get_minimal_context_tool`, ask for minimal detail, prefer targeted queries, and stay near five tool calls and 800 tokens of graph output. The graph narrows the scope but does not replace reading the implementation and its tests before changing code.

When your agent uses it

  • Reviewing a pull request with risk levels and a test-gap analysis
  • Working out the blast radius of a change before merging
  • Finding untested changed functions and proposing test cases

Example prompts

  • “Review my current changes and tell me which ones are high risk and untested.”
  • “What is the blast radius of the changes on this branch?”
  • “Suggest test cases for the changed functions that have no coverage.”

Requirements

  • The code-review-graph tools available to the agent

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Call detect_changes_tool for risk-scored changed functions, test gaps and affected flows.
  2. Call get_affected_flows_tool only when you need the steps of an affected flow.
  3. For each high-risk function, call query_graph_tool with pattern="tests_for" to check test coverage.
  4. Call get_impact_radius_tool when the blast radius is not clear from step 1.
  5. Suggest specific test cases for untested changes.

What it can do on your machine

Read from SKILL.md and the folder at commit 6b12d11. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Graph-Based Change Review loads about 331 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 176 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~331

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tirth8205/code-review-graph at commit 6b12d11, republished under its MIT licence (© tirth8205). 176 words, ~331 tokens.

Download SKILL.mdSave it as .claude/skills/review-changes/SKILL.md (or your agent's skills folder).
name
review-changes
description
Perform a structured code review using change detection and impact

Review Changes

Review a change set with risk scores and blast radius from the knowledge graph.

Steps
  1. Call detect_changes_tool for risk-scored changed functions, test gaps and affected flows.
  2. Call get_affected_flows_tool only when you need the steps of an affected flow.
  3. For each high-risk function, call query_graph_tool with pattern="tests_for" to check test coverage.
  4. Call get_impact_radius_tool when the blast radius is not clear from step 1.
  5. Suggest specific test cases for untested changes.
Output Format

Group findings by risk level (high, medium, low). For each finding give what changed and why it matters, its test coverage, and the suggested fix. End with a merge recommendation.

Token Efficiency Rules

  • Call get_minimal_context_tool(task="<your task>") before any other graph tool.
  • Pass detail_level="minimal" wherever a tool accepts it. Use "standard" only when minimal is not enough.
  • Prefer a targeted query_graph_tool call over a broad listing call.
  • Budget: about five tool calls and 800 tokens of graph output per task.
  • Read the implementation and its tests before changing code. The graph narrows scope; it does not replace the source.

© tirth8205, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/review-changes of tirth8205/code-review-graph.

Open the folder on GitHubat commit 6b12d11

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in tirth8205/code-review-graph, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Graph-Based Change Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Graph-Based Change Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Graph-Based Change Review this skilltirth8205/code-review-graph32k1 repos~331Automated safety check: PassMIT
Worktrunk Tend CI Guidancemax-sixty/worktrunk9k—~6.4kAutomated safety check: PassCustom licence
YugabyteDB Backport Reviewyugabyte/yugabyte-db11k—~2.5kAutomated safety check: PassCustom licence
Liveagent Code ReviewStack-Cairn/LiveAgent2.2k—~2kAutomated safety check: PassMIT
Code Review Graph Navigatorhandsontable/handsontable22k—~939Automated safety check: PassCustom licence
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Worktrunk Tend CI Guidance

    max-sixty/worktrunk

    Adds Worktrunk-specific rules to the tend CI workflows: Codecov polling, Rust test commands, labels and review criteria for pull requests handled in CI.

    9k GitHub stars~6.4k tokensUpdated today
    DevelopmentAuto-check passed
  • YugabyteDB Backport Review

    yugabyte/yugabyte-db

    Checks a YugabyteDB backport revision on Phorge against the original diff it was ported from and flags differences, tracing unexplained code back to master.

    11k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Liveagent Code Review

    Stack-Cairn/LiveAgent

    Review an open GitHub pull request or the current local branch and working tree with parallel, independent reviewers and evidence-based validation.

    2.2k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Graph Navigator

    handsontable/handsontable

    Queries a pre-built, Tree-sitter-based code graph of the whole monorepo instead of grepping call chains, for exploring, debugging, refactoring or reviewing code.

    22k GitHub stars~939 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed

More from tirth8205/code-review-graph

  • Knowledge Graph PR Review

    tirth8205/code-review-graph

    Reviews a pull request or branch diff with a code knowledge graph and produces a structured review that includes blast-radius analysis.

    32k GitHub stars~452 tokensUpdated 2 days ago
    Auto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    Auto-check passed
  • Explore Codebase with Graph

    tirth8205/code-review-graph

    Navigates a codebase through the code-review-graph MCP tools: architecture overview, symbol search, caller and callee tracing, flows and oversized functions.

    32k GitHub starsUsed in 1 repo~335 tokens
    Auto-check passed
  • Graph-Guided Safe Refactoring

    tirth8205/code-review-graph

    Plans a refactor from a code dependency graph, previews renames before applying them and checks that the final impact matches the plan.

    32k GitHub starsUsed in 1 repo~332 tokens
    Auto-check passed
  • Code Review Graph Builder

    tirth8205/code-review-graph

    Builds or incrementally updates the code-review knowledge graph for a repository and reports whether the build succeeded, partly or failed.

    32k GitHub stars~295 tokensUpdated 2 days ago
    Auto-check passed
  • Review Delta

    tirth8205/code-review-graph

    Reviews only the code changed since the last commit, using a code-graph MCP server to find risk-scored changes, test gaps and the blast radius, then writes a short report.

    32k GitHub stars~325 tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Graph-Based Change Review

What does Graph-Based Change Review do?

Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation. The agent calls `detect_changes_tool` to get changed functions with risk scores, test gaps and affected flows, then digs deeper only as needed: `get_affected_flows_tool` for the steps of a flow, `query_graph_tool` with the `tests_for` pattern to check coverage of each high-risk function, and `get_impact_radius_tool` when the blast radius is unclear. It finishes by suggesting specific test cases for untested changes.

When should I use Graph-Based Change Review?

Graph-Based Change Review fits situations like: reviewing a pull request with risk levels and a test-gap analysis; working out the blast radius of a change before merging; finding untested changed functions and proposing test cases.

How do I install Graph-Based Change Review in Claude Code?

Run `npx skills add tirth8205/code-review-graph --skill review-changes -a claude-code`. Or copy the skill folder (skills/review-changes in tirth8205/code-review-graph) into .claude/skills/review-changes in your project. Claude Code loads it when a task matches its description.

How do I install Graph-Based Change Review in Codex?

Run `npx skills add tirth8205/code-review-graph --skill review-changes -a codex`. Or copy the skill folder (skills/review-changes in tirth8205/code-review-graph) into .agents/skills/review-changes in your project. Codex loads it when a task matches its description.

Can I use Graph-Based Change Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tirth8205/code-review-graph --skill review-changes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-changes, .gemini/skills/review-changes, .github/skills/review-changes and .opencode/skills/review-changes in your project.

What does Graph-Based Change Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Graph-Based Change Review is instructions for the agent only. Our summary lists: The code-review-graph tools available to the agent.

Does Graph-Based Change Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Graph-Based Change Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Graph-Based Change Review use?

Graph-Based Change Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Graph-Based Change Review use?

About 331 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Graph-Based Change Review?

Skills that share tags, products or a category with Graph-Based Change Review: Worktrunk Tend CI Guidance (max-sixty/worktrunk, 9k stars), YugabyteDB Backport Review (yugabyte/yugabyte-db, 11k stars), Liveagent Code Review (Stack-Cairn/LiveAgent, 2.2k stars) and Code Review Graph Navigator (handsontable/handsontable, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Graph-Based Change Review?

tirth8205 (a GitHub user) maintains it in tirth8205/code-review-graph, which has 31,962 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.

Source: tirth8205/code-review-graph on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.