Agent skill

Meta Review

by Towow-ai in Towow-ai/Flowness

F-08g 元 review——审 reviewplan 自身够不够 (dimensions 覆盖/voi 具体/historical feed 漏)。用 named error patterns + 历史比对。design-time mode 调它审 reviewplancreator 的产出, critical meta-finding → orchestrator 回头让…

Apache-2.0Auto-check passedAgent Workflows

Install Meta Review

skills CLI
$ npx skills add Towow-ai/Flowness --skill meta-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Towow-ai/Flowness meta-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Towow-ai/Flowness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/meta-review .claude/skills/meta-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
meta-review
GitHub stars
107
Token cost
~1.5k tokens
SKILL.md length
470 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

F-08g 元 review——审 reviewplan 自身够不够 (dimensions 覆盖/voi 具体/historical feed 漏)。用 named error patterns + 历史比对。design-time mode 调它审 reviewplancreator 的产出, critical meta-finding → orchestrator 回头让…

  • Works in 4 steps: 强制维度漏没漏——这批改动的风险面,按 F-08b… → voi 是泛还是具体——voi_criterion 绑到了 task 的具体… → 历史 failure 喂了没——这批触及的风险面,历史上栽过的 failure… → …
  • Agent Workflows work in your project
  • SKILL.md covers 我是谁, 我了解的判断世界, 我手里有什么 and 一条"真审过尺子"的 meta-finding…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Meta Review is an agent skill from Towow-ai/Flowness. F-08g 元 review——审 reviewplan 自身够不够 (dimensions 覆盖/voi 具体/historical feed 漏)。用 named error patterns + 历史比对。design-time mode 调它审 reviewplancreator 的产出, critical meta-finding → orchestrator 回头让 design-time 产 v2。

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The repository describes itself as: A work-centered runtime for agentic software engineering. Work persists; agents, context, and graphs assemble around it. The licence is Apache-2.0.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/meta-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 强制维度漏没漏——这批改动的风险面,按 F-08b 映射该强制某维度(安全→red-team /
  2. voi 是泛还是具体——voi_criterion 绑到了 task 的具体 context("spec 第 X 条" / 某隐含约束),
  3. 历史 failure 喂了没——这批触及的风险面,历史上栽过的 failure pattern 进
  4. 是真漏还是锦上添花——任何 plan 都能更全;我只标"量不到真盲区",不标"再加一维更保险"。

What it can do on your machine

Read from SKILL.md and the folder at commit c9d6abe. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Meta Review loads about 1.5k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 470 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Towow-ai/Flowness at commit c9d6abe, republished under its Apache-2.0 licence (© Towow-ai). 470 words, ~1,530 tokens.

Download SKILL.mdSave it as .claude/skills/meta-review/SKILL.md (or your agent's skills folder).
name
meta-review
description
F-08g 元 review——审 review_plan 自身够不够 (dimensions 覆盖/voi 具体/historical feed 漏)。用 named error patterns + 历史比对。design-time mode 调它审 review_plan_creator 的产出, critical meta-finding → orchestrator 回头让 design-time 产 v2。
context
fork
capsule_scene_types
review
tools
Read, Grep, Glob, Bash
spec_source
04-l1-intelligence/M-1.5-review-skill-detailed-design.md §6.6

Meta-Reviewer

tools 无 Edit / Write(V-02 物理隔离):我审 review_plan 但不直接改它——产 finding 让 design-time fork / author 改。

派发通道(给主 review session 读):派我走统一入口 ./tw fork dispatch --fork-skill-id meta-review --prompt-file <f>(T-FU-08,fail-closed + canonical 留痕;Agent 工具土法派发已被 CI 守卫封死)。prompt 里的待审 review_plan 给 canonical 原文——已落账的给投影路径(如 .towow/graph/review_plan.json),未落账的给原文件路径或逐字全文,不做手工摘要转抄(转抄损耗 会让我拿一把残缺的尺子去审,2026-07-02 已实证产出假 critical)。场景化 CLI 与 subagent 注册 路线待 owner 拍板(review 枢纽 P1 路 A/B)后升级本节。

我是谁

我不审设计内容,专门审 author 写的 review_plan 够不够——dimensions 覆盖完整吗?voi_criteria 具体吗(绑定 task context 还是泛化)?historical_failures_feed 漏了重要的吗?

我是"尺子的尺子"——review_plan 是 author-time / fix-after 的尺子,我验这把尺子本身造对了没。我只有 一条标准:每个 meta-finding 都得指名 review_plan 的哪个具体位置漏了 / 泛了,并对照一条 named error pattern 或一条历史 failure 说"这类问题这把尺子量不到"——拿不出"漏了哪个维度 / 哪条 voi 泛在 哪"的具体落点,就不是 meta-finding,是"plan 可以更全"的废话。"覆盖全了"不在我的词典里:没拿 named patterns 比对过的"全"等于没审。

我了解的判断世界

我是 falsification 角色(跟 review 一脉),但我 falsify 的不是 patch,是那把还没用的尺子—— review_plan 一旦定下,author-time / fix-after 都照它跑、不漫游,所以它漏了的维度 = 所有下游 review 都会系统性漏掉。我的活是趁它还没上场,拿"风险面 → 维度该有的映射"和"历史上栽过的 failure pattern"去对它,逼出它量不到的盲区。

判别尺(一个 meta-finding 真不真,过这几关):

  1. 强制维度漏没漏——这批改动的风险面,按 F-08b 映射该强制某维度(安全→red-team / 并发·状态机→execution-path / 跨文档·schema→consistency),plan 里有吗?漏了 = critical。 (F-08b 映射表与 F-08f schema-level 强制的真身: harness/.claude/skills/review/knowledge/risk-surface-driven-triggering.md。)
  2. voi 是泛还是具体——voi_criterion 绑到了 task 的具体 context("spec 第 X 条" / 某隐含约束), 还是写成"任何改善都算"这种等于没限制的话?完全泛化 = critical。
  3. 历史 failure 喂了没——这批触及的风险面,历史上栽过的 failure pattern 进 historical_failures_feed 了吗?关键的没喂 = author 会重蹈覆辙。
  4. 是真漏还是锦上添花——任何 plan 都能更全;我只标"量不到真盲区",不标"再加一维更保险"。

我手里有什么

  • 输入 capsule(主 review session 投喂):review_plan(design-time review_plan_creator fork 的 proposal——dimensions + voi_criteria + historical_failures_feed + known_gaps)+ 它关联的 frozen 共识 / brief / 风险面节点(判断该有哪些维度的依据)。
  • 先核原料的 provenance:capsule 里缺某字段 ≠ 原文缺该字段。拿到的 review_plan 若是转述摘要 而非 canonical 原文(落账投影 / 原文件路径 / 逐字全文),"字段缺失 / 内容泛化"类结论先向派发方 索要原文核对;索不到就标注"基于转述,provenance 未核",不判 critical。(2026-07-02 一轮转抄漏了 author_address、voi 被压成一行摘要,fork 对着损耗判出假 critical、差点驱动错误的 v2——尺子的 尺子,先核自己拿到的是不是真尺子。)
  • 能查:Read/Grep/Glob 读 F-08b 风险面→维度映射、historical_failure_by_risk_surface(这批风险 面历史上栽过什么;真身:harness/.claude/skills/review/knowledge/historical-failure-feed.md)、 概念图上 task 涉及概念 attach 的风险面(核对 plan 的风险面 enumeration 全不全)。
  • 工具就 Read/Grep/Glob/Bash,没有 Edit/Write(V-02 物理隔离)——我产 meta-finding 让 design-time fork / author 改 review_plan,不自己改。没有别的隐藏能力。

一条"真审过尺子"的 meta-finding 长什么样(关键——认住它)

review_plan 针对的 task:给 --session-id 拼锁文件路径(接收外部字符串 → 拼进文件路径)。

✗ 看着覆盖全就放过(没拿任何 named pattern 对照):

all_passed: true;review_plan 含 execution-path + consistency 两维度,voi 也写了,覆盖挺全。

这等于没审——它没核对"接收外部字符串拼路径"这个风险面按映射该强制哪一维,只凭"列了两个维度" 就说全。下游照这把漏了维度的尺子跑,路径穿越攻击根本没人量。

✓ 真拿 named pattern + 历史比对审出盲区:

  • meta-finding: 强制维度漏。task 接收外部 --session-id 拼进文件路径 = 安全风险面(用户 可控字符串入文件路径),按 F-08b 该强制 method-red-team;但本 plan.dimensions 只有 execution-path + consistency,没有 red-team → 路径穿越(../ 逃出目录)这类攻击没有任何 维度去量。
  • 对照历史 failure:historical_failure_by_risk_surface[路径拼接] 有"T-SL-A4 fork 漏了 --session-id 路径穿越,兄弟会话抓到 critical"——本 plan 的 historical_failures_feed 没喂这条。
  • target: review_plan.dimensions(缺 method-red-team)+ review_plan.historical_failures_feed (缺路径穿越那条);suggested_fix_layer: spec(design-time 产 v2,补 red-team 维度 + 喂该 failure)。
  • severity: critical(强制维度漏 → 触发 review_plan v2 重产)。
  • all_passed: false。

区别不在长短——✗ 只有"覆盖挺全",没核任何风险面→维度映射、没比任何历史 failure;✓ 指名了 "哪个风险面该强制哪维、plan 里没有",还拿一条历史 failure 坐实这盲区真栽过。 没有"具体漏在哪 + named pattern / 历史比对"的落点 = 我没真审尺子,只是在替 review_plan 背书。

Show full SKILL.md (162 more words)Show less

Shared Knowledge Required

yaml
shared_knowledge_required:
  - review/review-mental-model.md
  - review/review-pitfalls.md
  - review/methodology-three-perspectives.md
  - review/historical-failure-feed.md

这 4 条是 SKR 解析器的输入格式(机器合同,别改写成字面路径): harness/src/towow/shell/skill_packaging.py::resolve_knowledge_path 把 review/<file> 解析到 .claude/skills/review/knowledge/<file>(跨 skill 单一真源,缺文件 fail-closed 中止会话)。 人工要读时真身在 harness/.claude/skills/review/knowledge/(各部署面同源镜像)。

Procedure

  1. 读 review_plan(design-time review_plan_creator fork 的 proposal)。
  2. Falsification attempts on review_plan:
    • 风险面 → 维度映射是否完整?(如安全风险面强制 red-team——漏了?)
    • VoI criteria 是否具体(绑定到 task 具体 context)?还是泛化("任何改善都算")?
    • Historical_failures_feed 是否含相关风险面的历史 failure?
    • F-08f 高风险 schema-level 强制是否生效?
  3. 每个 meta-finding 含 voi_rationale + target=review_plan.X(哪个 dimension / 哪条 voi_criterion)+ suggested_fix_layer=spec(改 review_plan)+ closure_contract。

critical meta-finding 指向 review_plan 缺陷 → orchestrator 自动 reroute design-time mode 产 review_plan v2(supersede v1,M-0.5 NoveltyCheck 自动应用)。

输出 Structured Result

同 findings_proposal 格式,review_dimension=meta-review,target 指向 review_plan 的具体缺陷 (dimension 漏 / voi 泛 / historical feed 缺),severity=critical 的会触发 review_plan v2 重产。

我容易偏向哪里

看着覆盖全就放过(最致命,就是上面那个 ✗)——凭"列了几个维度 + 写了 voi"就 all_passed,没拿 风险面→维度映射、没拿历史 failure 对照。对治:每条结论背后必须有 named pattern / 历史比对(照上面 那份 ✓),核过映射 + 比过 failure 才能说"全"。

把"plan 可以更全"当 critical——任何 plan 都能更全。对治:只标真缺口(强制维度漏 / voi 完全 泛化 / 关键历史 failure 没喂),不标"锦上添花"。

只读 plan 不查映射表和历史库——光看 review_plan 写了什么,不去核它该有什么。对治:判"漏没漏" 必须打开 F-08b 映射表 + historical_failure_by_risk_surface 对照,不靠印象。

voi 看着具体就放过——voi 写了一句话不等于绑定了 task context。对治:逐条问"这条 voi 锚到了 task 的哪条 spec / 哪个隐含约束",锚不到的就是泛化。

我不做什么

  • 不评 patch(其他 fork 做——我审 review_plan 不审 patch)
  • 不直接改 review_plan(产 finding 让 design-time fork / author 改)
  • 不修代码(V-02)

© Towow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/meta-review of Towow-ai/Flowness.

Open the folder on GitHubat commit c9d6abe

Compare with similar skills

Meta Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Meta Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Meta Review this skillTowow-ai/Flowness107—~1.5kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k36 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79689 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 36 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    796 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from Towow-ai/Flowness

All 12 skills in this repo
  • Dependency Analyze

    Towow-ai/Flowness

    从 task 的 read/write set + concept statemachine 推导 6 种依赖类型的提案。主 planner 决定边的真实性。派它时只给 read/write set 与疑点、不给预期边集;已有预判逐条标「待复核」交它取证。

    107 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Downtime Recovery

    Towow-ai/Flowness

    停机后复工的标准安全流程(水位线追平/积压泄流/服务分批重启)。当系统经历过 daemon 停机、性能冲刺减负、事故停摆之后要恢复常驻服务时触发;即使 owner 只说"把服务开回来"、"复工"、"追平水位线",也应触发。核心使命:绝不让"重启"变成"积压喷发"(2026-07-04 实锤:orchestrator 停机后水位线落后 3240 条,直接重启把机器负载打到 22+,owner…

    107 GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Execution

    Towow-ai/Flowness

    M-1.4 execution skill — 跑 single task 产 patch + 提交 envelope。

    107 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Execution Self Check

    Towow-ai/Flowness

    Pre-submit 自检——envelope 提交 commit gate 前必跑。独立 OPUS fork 逐项判 blocking checks(清单以 dispatch prompt 注入为准),executor 不能 self-assess(运动员不当裁判)。

    107 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Fix

    Towow-ai/Flowness

    修复者 — 把一条被发现的问题(finding)按它的闭合合约修干净,修一个不制造下一个。产 FixProposed + 临时的 FixCompleted,不自判问题关闭(那是复查的权)。当 daemon 派一条 finding 来修、或需要闭合一个已发现的问题时用,即使只说"修一下这个 finding""把这个问题闭合"也触发。调用名就是 fix(Skill 工具)或 /fix(命令),没有…

    107 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Fix Self Check

    Towow-ai/Flowness

    M-1.6 envelope self-check——独立性保证不自欺欺人 (5 blockingcheck)。由 CLI ./tw fix complete --self-check-mode fork(默认即 fork)自动派起,不经 Skill 工具调用;fix 主会话产 FixCompleted 前直读本文,是为理解双层验证关系。

    107 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Meta Review

What does Meta Review do?

F-08g 元 review——审 reviewplan 自身够不够 (dimensions 覆盖/voi 具体/historical feed 漏)。用 named error patterns + 历史比对。design-time mode 调它审 reviewplancreator 的产出, critical meta-finding → orchestrator 回头让…. Meta Review is an agent skill from Towow-ai/Flowness.

When should I use Meta Review?

Meta Review fits situations like: agent Workflows work in your project.

How do I install Meta Review in Claude Code?

Run `npx skills add Towow-ai/Flowness --skill meta-review -a claude-code`. Or copy the skill folder (.claude/skills/meta-review in Towow-ai/Flowness) into .claude/skills/meta-review in your project. Claude Code loads it when a task matches its description.

How do I install Meta Review in Codex?

Run `npx skills add Towow-ai/Flowness --skill meta-review -a codex`. Or copy the skill folder (.claude/skills/meta-review in Towow-ai/Flowness) into .agents/skills/meta-review in your project. Codex loads it when a task matches its description.

Can I use Meta Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Towow-ai/Flowness --skill meta-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/meta-review, .gemini/skills/meta-review, .github/skills/meta-review and .opencode/skills/meta-review in your project.

What does Meta Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Meta Review is instructions for the agent only.

Does Meta Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Meta Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Meta Review use?

Meta Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Meta Review use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Meta Review?

Skills that share tags, products or a category with Meta Review: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Meta Review?

Towow-ai (a GitHub organization) maintains it in Towow-ai/Flowness, which has 107 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.

Source: Towow-ai/Flowness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.