Official agent skill

Review Walkthrough

by trailofbits in trailofbits/skills

Generates an interactive HTML walkthrough for reviewing code changes.

OfficialCC-BY-SA-4.0Auto-check passedFrontend & Design

Install Review Walkthrough

skills CLI
$ npx skills add trailofbits/skills --skill review-walkthrough -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills review-walkthrough --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .claude/skills/review-walkthrough && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-walkthrough
GitHub stars
7.4k
Token cost
~1.7k tokens
SKILL.md length
968 words
Files
5 (incl. scripts)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Generates an interactive HTML walkthrough for reviewing code changes.

  • Tasks that involve HTML artifacts
  • SKILL.md covers Capture the branch diff, Shape the review and Render the artifact
  • Runs Python scripts from its folder; calls git, uv and gh

What it does

Review Walkthrough is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `agents/openai.yaml` and `scripts/render_walkthrough.py`).

It sits in Frontend & Design, covering HTML artifacts. It works with Git. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Tasks that involve HTML artifacts

Example prompts

  • “Use the review-walkthrough skill to generate an interactive HTML walkthrough for reviewing code changes”
  • “/review-walkthrough”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • uv
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, uv and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Walkthrough loads about 1.7k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 968 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 968 words, ~1,687 tokens.

Download SKILL.mdSave it as .claude/skills/review-walkthrough/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
review-walkthrough
description
Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.
disable-model-invocation
true

Review Walkthrough

Generate a self-contained HTML walkthrough of the current branch, with the final diff split into logical steps, explanations, and critical review findings. Choose the grouping and reading order for comprehension; commit order need not dictate either. Invoke as /review-walkthrough:review-walkthrough in Claude Code or $review-walkthrough in Codex.

Capture the branch diff

Respect a user-specified base. Otherwise, use the current open PR's base when PR metadata is available. Without a PR, discover the repository's default branch from git symbolic-ref --quiet --short refs/remotes/origin/HEAD or the configured remote's equivalent. Do not assume it is main. If the selected base is missing or ambiguous, ask for it rather than silently choosing another branch.

Resolve the base and HEAD to commit IDs with git rev-parse --verify --end-of-options "${ref}^{commit}", then compute their merge base with git merge-base. Capture the complete patch using git diff --no-ext-diff --no-textconv --no-color --src-prefix=a/ --dst-prefix=b/ "$merge_base" "$head_sha" --. Initialize variables and run the commands that consume them in the same shell invocation; shell variables do not persist between tool calls. Save the patch to a temporary file outside the checkout and retain its actual path. Stop on a Git error or an empty patch and explain the result.

This scope includes committed changes through the captured HEAD. Mention any uncommitted work that is excluded. Do not change branches, reset the checkout, or alter source files to prepare the review. Keep generated data and HTML outside the checkout unless the user requests a particular output location; generated review artifacts never belong in the captured patch.

For a GitHub PR, collect owner, repo, pr_number, and head_sha from its metadata. Include them only when the PR head matches the captured HEAD and the chosen base matches the PR base. Otherwise use null and explain why comment export is unavailable. A failed authentication or network request is not evidence that no PR exists; report the failure and ask for the base if it cannot be determined. GitHub access is optional when the user supplies the base or confirms there is no PR.

Shape the review

Read the changed files and the surrounding source, tests, configuration, and dependency metadata needed to judge them. Keep the review read-only; do not run the project's tests or install its dependencies merely to build the walkthrough.

Group related files into steps covering one concept each. Put definitions before their consumers, wiring after the components it connects, and tests after or beside their subjects. Copy each complete per-file diff from the captured patch verbatim into exactly one step. Reordering files between steps is allowed; splitting, rewriting, omitting, or inventing their patches is not. Preserve rename, binary, and mode-change entries even when they have no text hunks. Binary summaries identify changed files; their payloads are outside this review.

Write one explanation per step, usually 50–150 words, covering the change's purpose, design choices, trade-offs, and connections to other steps. Refer to actual identifiers. Write one review list per step covering bugs, security, validation, API design, or performance issues supported by the code. Report findings with severity rather than suppressing minor issues. Use an empty list for a step with no findings.

Explanations and review bodies are HTML fragments. Use <p>, <strong>, <em>, <code>, <pre>, and <ul>/<li> for structure. Write literal < and > in prose or snippets as &lt; and &gt;. Backticks and Markdown fences are literal text here. Supported inline tags also include <sup>, <sub>, <kbd>, <del>, and <a href="https://…">. The page sanitizes fragments and converts them to Markdown when preparing a PR comment. Only safe link targets survive; arbitrary attributes, scripts, and images do not. Tables export as text rows with cell separators; captions and row order are preserved. Prefer prose, lists, and code blocks when their structure is sufficient.

Anchor findings to a file in the same step and a line in that file's displayed diff. Use side: "RIGHT" for additions or new-file context and side: "LEFT" for deletions or old-file context. For a range, line and end_line use that same side within one hunk. A finding spanning multiple steps belongs with the file it addresses, or remains unanchored. An unanchored finding is still displayed but cannot become an inline PR comment.

Show full SKILL.md (279 more words)Show less

Render the artifact

Use a file-writing tool to create a JSON object with the fields below. Preserve the literal patch as JSON string data, with no shell expansion.

FieldValue
titleFeature or review title
stepsArray of objects with sha (step ID such as step-1), message (step title), files (paths in patch order), and diff (complete per-file patches)
explanationsHTML strings, one per step
reviewsArrays of findings, one per step; each finding has severity (high, medium, or low), title, and HTML body
pr_metaObject with owner, repo, pr_number, and head_sha, or null

An anchored finding also has file, line, and side, plus optional end_line. The three arrays have equal lengths and corresponding entries. File paths match the diff headers without their a/ or b/ prefix; a renamed file uses its new path. Set side explicitly so lines that occur on both sides are unambiguous.

Run the bundled renderer with the actual paths created for this review:

bash
uv run --no-project {baseDir}/scripts/render_walkthrough.py \
  --input /tmp/data.json \
  --diff /tmp/captured.patch \
  --output /tmp/walkthrough.html

The renderer validates the data, compares every step's patches with the complete captured diff, checks anchors, and safely embeds the result in the bundled template. Fix reported input errors rather than bypassing the renderer or generating an alternative page.

Open the output with open on macOS or xdg-open on Linux when a browser is available, and tell the user its path. In a headless run, report the file without opening it. When PR metadata is present, the page lets the user copy a gh api command for their selected comments. It does not execute the command or post anything to GitHub. Comment and Request Changes require a review summary before the command can be copied; the summary is optional for Approve.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in plugins/review-walkthrough/skills/review-walkthrough of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • scripts/pyproject.toml
  • scripts/render_walkthrough.py
  • template.html

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Review Walkthrough next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Walkthrough compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Walkthrough this skilltrailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.0
Explain Testsmeain/dotfiles285—~1.5kAutomated safety check: PassMIT
LobeHub Interactive Prototypelobehub/lobehub83k—~1.6kAutomated safety check: PassCustom licence
Paperclip Pagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT
Openkb Deck NeonVectifyAI/OpenKB4.7k1 repos~4.3kAutomated safety check: PassApache-2.0
Webhome Homepage Builderwebhtv/webhtv1.7k—~3.8kAutomated safety check: PassGPL-3.0

Similar skills

  • Explain Tests

    meain/dotfiles

    Explain test code changes as a side-by-side HTML page — real test code on the left, a short note on the right saying which case that code covers.

    285 GitHub stars~1.5k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed
  • Builds single-file interactive HTML prototypes rendered with the real LobeHub UI components and written as production-style React, so they can later be split into files.

    83k GitHub stars~1.6k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Paperclip Page

    paperclipai/paperclip

    Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.

    99k GitHub stars~1k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Openkb Deck Neon

    VectifyAI/OpenKB

    A skill your agent uses when the user asks the openkb chat to make a deck / slide presentation / PPT / slides / 演示稿 / 幻灯片 from their compiled KB content AND wants a dark, high-tech, neon / glow /…

    4.7k GitHub starsUsed in 1 repo~4.3k tokens
    Frontend & DesignAuto-check passed
  • Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML.

    1.7k GitHub stars~3.8k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Solo Artifacts

    solo-agent/solo

    A skill your agent uses when a Solo task or thread should become an interactive, reviewable, self-contained HTML artifact for progress/status, review/decision, or comparison/leaderboard work inside…

    697 GitHub stars~961 tokensUpdated 25 days ago
    Frontend & DesignAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Review Walkthrough

What does Review Walkthrough do?

Generates an interactive HTML walkthrough for reviewing code changes. Review Walkthrough is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Generates an interactive HTML walkthrough for reviewing code changes.

When should I use Review Walkthrough?

Review Walkthrough fits situations like: tasks that involve HTML artifacts.

How do I install Review Walkthrough in Claude Code?

Run `npx skills add trailofbits/skills --skill review-walkthrough -a claude-code`. Or copy the skill folder (plugins/review-walkthrough/skills/review-walkthrough in trailofbits/skills) into .claude/skills/review-walkthrough in your project. Claude Code loads it when a task matches its description.

How do I install Review Walkthrough in Codex?

Run `npx skills add trailofbits/skills --skill review-walkthrough -a codex`. Or copy the skill folder (plugins/review-walkthrough/skills/review-walkthrough in trailofbits/skills) into .agents/skills/review-walkthrough in your project. Codex loads it when a task matches its description.

Can I use Review Walkthrough in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill review-walkthrough -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-walkthrough, .gemini/skills/review-walkthrough, .github/skills/review-walkthrough and .opencode/skills/review-walkthrough in your project.

What does Review Walkthrough need to run?

Going by SKILL.md and its folder, Review Walkthrough needs Python for the scripts in its folder and the command-line tools its instructions call (git, uv and gh). Our summary lists: Python 3.

Does Review Walkthrough access the network?

SKILL.md contains no URLs. Its commands use git, uv and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Walkthrough safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Review Walkthrough use?

Review Walkthrough is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Walkthrough use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Walkthrough?

Skills that share tags, products or a category with Review Walkthrough: Explain Tests (meain/dotfiles, 285 stars), LobeHub Interactive Prototype (lobehub/lobehub, 83k stars), Paperclip Page (paperclipai/paperclip, 99k stars) and Openkb Deck Neon (VectifyAI/OpenKB, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Walkthrough?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.