Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses.
$ npx skills add trailofbits/coop --skill review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/coop review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review .claude/skills/review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .claude/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/coop/tree/main/.agents/skills/reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/coop --skill review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/coop review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/review .agents/skills/review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .agents/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/coop --skill review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/coop review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/review .cursor/skills/review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .cursor/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/coop.git --path .agents/skills/review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/coop --skill review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/coop review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/review .gemini/skills/review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .gemini/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/coop reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/coop --skill review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/review .github/skills/review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .github/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/coop --skill review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/coop review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/review .opencode/skills/review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/trailofbits/coop/tree/main/.agents/skills/review into .opencode/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewReview a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses.
Review is an agent skill from trailofbits/coop, published by the product's own GitHub organization. Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses. Use for PR review, /review follow-up, or when asked to inspect a branch without modifying it.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/review-api-usage.md`, `references/review-comments.md` and `references/review-conventions.md`).
It sits in Development, covering Pull requests and API testing. The repository describes itself as: Isolated VM environment for running Claude Code and Codex. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0f1c4ef. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review loads about 3.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,683 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/coop at commit 0f1c4ef, republished under its Apache-2.0 licence (© trailofbits). 1,683 words, ~3,115 tokens.
.claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Review and report only. Do not modify code, commit, push, merge, resolve review threads, or post GitHub comments unless the user explicitly asks for posting.
Prefer, in order:
.codex-review-context.json.gh pr view.origin/main...HEAD for a committed branch.Fetch only a missing base ref. If the diff is empty, stop. Record the exact base and head SHAs so a later force-push cannot silently change the target.
For CI reviews that provide trusted base/head refs in
.codex-review-context.json, use those refs directly. Keep the trusted base
checked out and inspect contributor files with git diff and
git show <head-ref>:<path>; do not materialize or execute the contributor
tree. For a merge-ref checkout supplied by another trusted harness, review the
parents and do not attribute the synthetic merge commit to the contributor.
Gather once and share with every reviewer:
AGENTS.md and relevant system-of-record docs: ARCHITECTURE.md,
trust-model.md, code-style.md, testing.md, .cargo/mutants.toml,
command/config references, and nearby platform notes.Omit generated files such as Cargo.lock, completions, and snapshots from the
verbatim packet, but record their names and sizes and inspect them where a
cross-file invariant depends on them.
The detailed lens prompts live in references/. Read every
selected lens file in full before starting it; the summaries below select the
lenses but do not replace their project-specific checks.
If parallel subagents are available, delegate the applicable lenses concurrently and pass the same packet to each. Otherwise run them sequentially. Each reviewer starts from fresh eyes, returns only diff-introduced issues (or a latent issue made reachable by the diff), and supplies file, changed line, severity, finding, and concrete evidence.
Always run:
Run when triggered:
docs/trust-model.md; inspect tainted subprocess
input, secret storage/logging, host paths, listeners/egress, SSH, and the
updater trust chain. Changes to project configuration, env composition,
persistence/reload, host launch context, or file-transfer defaults, exclusions,
extraction, and mirroring always trigger this lens, even when subprocess code
is unchanged. Call out every stop-and-confirm trigger.Cargo.lock or the exact
installed binary. Check signatures, flags, error behavior, enabled features,
and deprecations using primary documentation.Docs-only diffs need conventions and docs. Skip comments only when no code comment or adjacent behavior changed. Record every skipped lens and why.
These checks come from maintainer discussion on PRs merged after v0.5.4 and
apply across all lenses:
Arc count, or
exit-zero proxies. Verify the real process, TLS rejection, cleanup, or output.all(...) are vacuously true for an empty collection, so prove the expected
strategy, enum tag, alias, or value is present as well as excluding the wrong
one.None and re-deriving a possibly false
message.docs/trust-model.md#host-subprocess-boundary. Shell escaping and argv APIs
alone do not establish safety. Check every interactive, non-interactive,
stdin, and output-capturing path that uses the data.open descriptor pins an inode; a checked path string or parent descriptor
alone does not pin a later child lookup. Include subprocesses, sudo, and
tools that reopen /proc/self/fd paths or their original path arguments.Group candidate findings by file. Open each post-change file once and reject a finding unless all of these hold:
Deduplicate overlapping findings. Falsify each survivor a second time: actively look for the guard, caller, platform fact, or version behavior that would make it wrong. For external API claims, cite the primary versioned source.
Lead with findings ordered by severity, each with a precise file and line. Include a concise evidence paragraph and avoid speculative wording. Then state:
If no findings survive, say so and name residual test or platform gaps. Only post inline comments when asked; post substantive findings inline and one top-level coverage summary. Never include internal severity labels in GitHub comment bodies.
When posting is explicitly requested, prefer an available inline-comment tool.
Otherwise resolve the PR head SHA once and call
repos/{owner}/{repo}/pulls/{number}/comments with the finding body, commit,
path, changed line, and side. Post one final PR-level comment containing the
finding count, any diff-noise notes, lens coverage, and unverified gates. A
local closeout review never posts.
© trailofbits, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (references) in .agents/skills/review of trailofbits/coop.
Open the folder on GitHubat commit 0f1c4ef
Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review this skilltrailofbits/coop | 762 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Check PRonyx-dot-app/onyx | 32k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 85k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| PR Design DocOpenHands/OpenHands | 90k | — | ~2.4k | Automated safety check: Pass | MIT |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
OpenHands/OpenHands
For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
trailofbits/coop
Run the final scope-controlled review before committing, pushing, or opening a PR.
trailofbits/coop
Shepherd the current user's open PR through base updates, CI failures, and review feedback without rewriting history or merging.
trailofbits/coop
Triage and shepherd all open PRs owned by the current GitHub user, isolating each writable worker in its own worktree.
trailofbits/coop
Run and interpret coop's VM integration suite locally on Lima or remotely on Firecracker.
trailofbits/coop
Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized.
Categories
Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses. Review is an agent skill from trailofbits/coop, published by the product's own GitHub organization. Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses.
Review fits situations like: /review follow-up; asked to inspect a branch without modifying it.
Run `npx skills add trailofbits/coop --skill review -a claude-code`. Or copy the skill folder (.agents/skills/review in trailofbits/coop) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/coop --skill review -a codex`. Or copy the skill folder (.agents/skills/review in trailofbits/coop) into .agents/skills/review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/coop --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.
Going by SKILL.md and its folder, Review needs the command-line tools its instructions call (git and gh).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Review: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/coop, which has 762 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/coop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.