Agent skill

Agent Native Reviewer

by udecode in udecode/kitcn

Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions.

Apache-2.0Auto-check: warnings

Install Agent Native Reviewer

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add udecode/kitcn --skill agent-native-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install udecode/kitcn agent-native-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/agent-native-reviewer .claude/skills/agent-native-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-native-reviewer
GitHub stars
450
Token cost
~2.3k tokens
SKILL.md length
1,189 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions.

  • Works in 6 steps: Identify the Changed Surface → Build the Parity Map → Check Source Ownership → …
  • SKILL.md covers Use When, Do Not Use When, Core Principles and Codex Capability Ladder, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Agent Native Reviewer is an agent skill from udecode/kitcn. Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.

Example prompts

  • “/agent-native-reviewer”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the Changed Surface
  2. Build the Parity Map
  3. Check Source Ownership
  4. Check Agent Route
  5. Check Proof
  6. Check Context

What it can do on your machine

Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Native Reviewer loads about 2.3k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:64
    existing Chrome state, profile, tabs, extensions, cookies, or a site state

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 1,189 words, ~2,295 tokens.

Download SKILL.mdSave it as .claude/skills/agent-native-reviewer/SKILL.md (or your agent's skills folder).
name
agent-native-reviewer
description
Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions.

Agent-Native Reviewer

Review whether an agent can perform, verify, and discover the same meaningful action a user can.

The standard is simple:

txt
user action -> agent route -> source owner -> proof command/artifact -> handoff

If one link is missing, the workflow is not agent-native.

Use When

  • .agents/**, .claude/**, .codex/**, skills, prompts, hooks, commands, or workflow docs changed.
  • A feature adds or changes a user-facing action and the repo has agent integration.
  • A reviewer asks whether Codex can reproduce, operate, verify, or maintain the same surface a human can.
  • A repo is becoming mostly agent-maintained and needs fewer hidden human-only paths.

Do Not Use When

  • The task is a normal code review with no agent/tooling/workflow surface.
  • The action is intentionally human-only: MFA, OAuth consent, billing payment entry, CAPTCHA, legal acceptance, biometric unlock, or OS permission prompts.
  • The change is cosmetic and has no meaningful operation to reproduce.

Core Principles

  1. Action parity. Every important user action has an agent route.
  2. Context parity. Agents can see the inputs, state, and constraints needed to act well.
  3. Source ownership. Agents edit the durable source, not generated mirrors or copied output.
  4. Proof parity. Agents can verify the outcome with the same authority a maintainer would trust.
  5. Discoverability. The route is visible from the skill, AGENTS file, command docs, tool schema, or public API docs an agent is expected to read.
  6. Shared workspace. Agent-created artifacts live where humans can inspect, edit, and commit them.

Codex Capability Ladder

Assume Codex is the agent runtime unless the repo says otherwise. Prefer the most repeatable proof and interaction layer that can cover the action:

  1. Tests and scripts first. Unit, integration, browser-test, benchmark, typecheck, lint, import smoke, generated-mirror audit, and source audit are the default proof layer. If a behavior can be proved there, do that before driving an app by hand.
  2. Browser next. Use the Browser plugin for app/browser interaction proof when tests cannot fully prove rendered behavior, native selection, focus, navigation, screenshots, console/network state, or real route behavior.
  3. Chrome after Browser. Use Chrome when the task depends on the user's existing Chrome state, profile, tabs, extensions, cookies, or a site state that Browser cannot access.
  4. Computer Use last. Use Computer Use for OS-level or native-app actions that tests, Browser, and Chrome cannot reach. Treat it as powerful but brittle; record exact manual proof and any limits.

Do not jump straight to UI automation when a focused test, command, or source audit gives stronger evidence. Do not claim a behavior is agent-native unless the selected layer can be rerun or described precisely enough for another agent to repeat.

Dotai Integrations

  • Use autogoal for durable or measurable work. The first checkpoint must copy agent-native requirements into the plan before implementation.
  • Use sync-skills when a skill, rule, template, or generated mirror crosses repo boundaries. Shared behavior belongs in dotai; repo policy stays local.
  • Use sync-vision when the missing parity is reusable taste or doctrine, not just one task's mechanics.
  • Use resolve-pr-feedback for PR review feedback. Do not nest mandatory autoreview; only recommend it after a complete end-to-end feature when an optional independent second pass could materially help.
  • Use hard-cut when stale compatibility, fake aliases, dead commands, or duplicate agent routes should be deleted rather than wrapped.
  • Use tdd or diagnosing-bugs when the parity gap is a real behavior bug, flaky proof, or unclear failure path.

Review Process

1. Identify the Changed Surface

Classify the action surface:

SurfaceExamples
Skill/workflowSKILL.md, .mdc, plan template, generated mirror, lockfile
Command/toolCLI command, script, MCP tool, GitHub workflow, package script
Public APIexported package API, docs example, release artifact
Product actionbutton, form, keyboard shortcut, browser route, OS/device path
Maintainer actionissue triage, PR feedback, security advisory, release lane

For incremental reviews, start from the changed files and expand only to the source owner, generated mirror, lockfile, command, or docs that prove parity.

2. Build the Parity Map

Use this map for every meaningful action:

User actionAgent routeSource ownerMirror/lock/docProofStatus
actionskill/tool/commandfile/pathgenerated/config/doccommand/artifactpass/gap/N/A

Status rules:

  • pass: source owner, route, proof, and discoverability are present.
  • gap: agent cannot safely perform or verify the action.
  • N/A: intentionally human-only or outside the current repo authority, with a concrete reason.
Show full SKILL.md (494 more words)Show less
3. Check Source Ownership

Flag any workflow that asks agents to edit output instead of source.

Common source boundaries:

OutputSource owner
.agents/skills/**/SKILL.md installed mirrorexternal skill package or .agents/rules/** source
.claude/skills/**/SKILL.md installed mirrorexternal skill package or .agents/rules/** source
root AGENTS.md generated block.agents/AGENTS.md or repo generator input
generated barrel/export filepackage source plus barrel generator command
generated docs/template outputregistry/package/docs source named by repo policy
copied skill in many reposdotai source plus Skills CLI install/update

Finding severity is high when the wrong owner would make future agents lose the fix during sync.

4. Check Agent Route

The route must be usable without hidden human context:

  • skill name or tool is discoverable from the available skill list, AGENTS.md, README, or command docs;
  • arguments are explicit enough for an agent to call correctly;
  • required credentials, browser state, local env, or external access are named;
  • authority boundaries are clear: read-only, patch, commit, push, comment, merge, publish, delete.

Do not demand a wrapper skill for every small action. Prefer patching the owner skill, AGENTS routing, or command docs when an existing route fits.

5. Check Proof

Every important agent action needs a verification path:

  • exact command, cwd, and expected result;
  • generated mirror or lockfile audit;
  • browser route/screenshot/console caveat when UI behavior changed;
  • issue/PR/security fetch when public maintainer state changed;
  • source audit when the claim is structural;
  • N/A reason when no automated proof fits.

Proof must run in the owning workspace. A downstream install is not proved by a source-package validation alone, and a source-package change is not proved by a downstream command alone.

6. Check Context

Agents need the same operational context a human maintainer uses:

  • the relevant vision/doctrine file is linked or routed;
  • project-specific commands live in the project, not in dotai;
  • final handoff tells the user what changed, what needs attention, and what was not verified;
  • recurring misses are written into the durable owner, not left in chat.

If the missing context is reusable taste, route to sync-vision. If it is workflow mechanics, patch the skill/template. If it is one-off, record it in the active plan or final handoff.

Findings

Use severity by consequence:

  • P0: agent can perform a destructive/public action without authority or proof.
  • P1: important user or maintainer action has no safe agent route, or the source/generated boundary is wrong.
  • P2: route exists but is hard to discover, lacks proof, or will rot during sync.
  • P3: wording or docs polish that would improve agent success but is not a blocker.

Suppress low-confidence guesses. If runtime observation is required, ask for or run the proof instead of inventing a finding.

What Not To Flag

  • Human-only security/legal/payment ceremonies.
  • Cosmetic UI actions without operational meaning.
  • Missing automation for rare admin tasks when the repo has no safe authority model for agents.
  • A repo-local fork that intentionally keeps product policy out of dotai.
  • A generated mirror that is stale only because the required sync command has not run yet; request the sync/proof instead.

Output Format

md
## Agent-Native Review

### Verdict
PASS | NEEDS WORK

### Capability Map
| User action | Agent route | Source owner | Mirror/lock/doc | Proof | Status |
|---|---|---|---|---|---|

### Findings
1. [P1] Title -- `file:line`
   Impact: ...
   Fix: ...
   Proof: ...

### Accepted / Rejected
- Accepted: ...
- Rejected: ... because ...

### Verification
- command or source audit -> result

### Needs Attention
- ...

© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/agent-native-reviewer of udecode/kitcn.

Open the folder on GitHubat commit c6010f5

Compare with similar skills

Agent Native Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Native Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Native Reviewer this skilludecode/kitcn450—~2.3kAutomated safety check: WarnApache-2.0
Review Pending PR Reviewsnrwl/nx29k—~3.9kAutomated safety check: PassMIT
Reviewthedaviddias/Front-End-Checklist74k—~556Automated safety check: PassMIT
ReviewClickHouse/ClickHouse50k—~8kAutomated safety check: NotesApache-2.0
Docling Pull Request Reviewdocling-project/docling69k—~1kAutomated safety check: PassMIT
Pre-Landing PR Reviewgarrytan/gstack136k—~19kAutomated safety check: NotesMIT

Similar skills

  • Review, grill, edit, and post pending PR review drafts saved by /review-pr (or its batch/cron runners).

    29k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Review

    thedaviddias/Front-End-Checklist

    A skill your agent uses when applies to product pages, local business pages, recipes, apps, books, and any page that aggregates user reviews.

    74k GitHub stars~556 tokensUpdated 2 days ago
    Marketing & SEOAuto-check passed
  • Review

    ClickHouse/ClickHouse

    Review a ClickHouse Pull Request for correctness, safety, performance, and compliance.

    50k GitHub stars~8k tokensUpdated today
    DatabasesAuto-check: notes
  • Docling Pull Request Review

    docling-project/docling

    Reviews or re-reviews a Docling pull request in fixed stages, with findings that can be reproduced and an explicit record of every check that was run.

    69k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Pre-Landing PR Review

    garrytan/gstack

    Reviews your diff against the base branch before merge, looking for SQL safety problems, LLM trust boundary violations, conditional side effects and other structural issues.

    136k GitHub stars~19k tokensUpdated today
    DevelopmentAuto-check: notes
  • Docs Parity Reviewer

    pydantic/pydantic-ai

    Official

    Use as the final documentation gate before a pydantic-ai-harness capability PR merges.

    20k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from udecode/kitcn

All 33 skills in this repo
  • Walkthrough

    udecode/kitcn

    Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.

    450 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • Avoid Feature Creep

    udecode/kitcn

    Prevent feature creep when building software, apps, and AI-powered products.

    450 GitHub stars~2.7k tokensUpdated 7 days ago
    Auto-check passed
  • Changeset Resolve

    udecode/kitcn

    Repair an unreleased .changeset/.md file so it matches the real branch delta against main.

    450 GitHub stars~922 tokensUpdated 7 days ago
    Auto-check passed
  • Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.

    450 GitHub stars~1.8k tokensUpdated 7 days ago
    Auto-check passed
  • Jotai X

    udecode/kitcn

    A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage

    450 GitHub stars~3.7k tokensUpdated 7 days ago
    Auto-check passed
  • Linear Backlog

    udecode/kitcn

    Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.

    450 GitHub stars~3.1k tokensUpdated 7 days ago
    Auto-check passed

Questions about Agent Native Reviewer

What does Agent Native Reviewer do?

Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions. Agent Native Reviewer is an agent skill from udecode/kitcn. Review agent-native parity for skills, prompts, tools, commands, generated mirrors, repo workflows, and user-facing actions.

How do I install Agent Native Reviewer in Claude Code?

Run `npx skills add udecode/kitcn --skill agent-native-reviewer -a claude-code`. Or copy the skill folder (.agents/skills/agent-native-reviewer in udecode/kitcn) into .claude/skills/agent-native-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Agent Native Reviewer in Codex?

Run `npx skills add udecode/kitcn --skill agent-native-reviewer -a codex`. Or copy the skill folder (.agents/skills/agent-native-reviewer in udecode/kitcn) into .agents/skills/agent-native-reviewer in your project. Codex loads it when a task matches its description.

Can I use Agent Native Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill agent-native-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-native-reviewer, .gemini/skills/agent-native-reviewer, .github/skills/agent-native-reviewer and .opencode/skills/agent-native-reviewer in your project.

What does Agent Native Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Agent Native Reviewer is instructions for the agent only.

Does Agent Native Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent Native Reviewer safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Agent Native Reviewer use?

Agent Native Reviewer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Native Reviewer use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Native Reviewer?

Skills that share tags, products or a category with Agent Native Reviewer: Review Pending PR Reviews (nrwl/nx, 29k stars), Review (thedaviddias/Front-End-Checklist, 74k stars), Review (ClickHouse/ClickHouse, 50k stars) and Docling Pull Request Review (docling-project/docling, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Native Reviewer?

udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.