Ccmanager Config
kbwo/ccmanager
Set up, review, or repair a CCManager config — .ccmanager.json at a git repository root, or the global ~/.config/ccmanager/config.json.
Pre-commit/ship code review: Codex default; optional Claude, Pi, or Kimi.
$ npx skills add udecode/kitcn --skill autoreview -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install udecode/kitcn autoreview --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/autoreview .claude/skills/autoreview && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .claude/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add udecode/kitcn --skill autoreview -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install udecode/kitcn autoreview --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/autoreview .agents/skills/autoreview && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .agents/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/kitcn --skill autoreview -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install udecode/kitcn autoreview --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/autoreview .cursor/skills/autoreview && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .cursor/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/udecode/kitcn.git --path .agents/skills/autoreview--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add udecode/kitcn --skill autoreview -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install udecode/kitcn autoreview --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/autoreview .gemini/skills/autoreview && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .gemini/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install udecode/kitcn autoreviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add udecode/kitcn --skill autoreview -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/autoreview .github/skills/autoreview && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .github/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/kitcn --skill autoreview -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install udecode/kitcn autoreview --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/autoreview .opencode/skills/autoreview && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/kitcn/tree/main/.agents/skills/autoreview into .opencode/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
autoreviewPre-commit/ship code review: Codex default; optional Claude, Pi, or Kimi.
Autoreview is an agent skill from udecode/kitcn. Pre-commit/ship code review: Codex default; optional Claude, Pi, or Kimi.
Its SKILL.md is about 9.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts (for example `AGENTS.md`, `CLAUDE.md` and `scripts/autoreview_test.py`).
It sits in Development. It works with Kimi. The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (Python, TypeScript and PowerShell), which the agent can run.
Shell commands in SKILL.md call:
ghcodexpythonclaudeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
code.claude.comdevelopers.openai.comcursor.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Autoreview loads about 9.5k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 3,997 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 3,997 words, ~9,479 tokens.
.claude/skills/autoreview/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Run the bundled structured review helper as a closeout check. This is code review, not Guardian auto_review approval routing.
Codex review is the default when no engine is set. It uses gpt-5.6-sol with high reasoning by default, then retries once with gpt-5.6-terra only when the account cannot access Sol. Claude review is optional and uses claude-fable-5 by default. Pi and Kimi use the model configured by their respective CLIs unless --model overrides it.
For user-visible behavior, pair autoreview with behavior-validator. Autoreview is source-aware and judges the change bundle; behavior validation is source-blind and judges the running product or tool against a behavior contract. A clean autoreview is not proof that a UI, CLI, API, or generated artifact works from the user's perspective.
Use when:
Do not require autoreview for a change whose entire diff is prose-only internal notes or SKILL.md documentation. Still inspect the diff directly and run the repository's lightweight documentation validation, if any. This exception does not cover user-facing documentation, executable examples, configuration, scripts, generated files, or behavior changes.
--max-priority P1, P2, or P3 only when the caller explicitly asks
for a wider review.review still running: ... elapsed=... pid=... as healthy progress, not a hang. Let the helper continue while heartbeats are advancing. Pass --stream-engine-output when live engine text is useful; Codex and Claude filter tool/file chatter, other runnable engines pass raw output through.verified,unknown); it does not classify arbitrary password-like strings or rescan unchanged history. After that scan passes, locally recognized secret-like values are redacted in place only when they occur exclusively on deleted lines of an entirely removed file; if one of those deleted values also occurs in added, context, or mixed staged/unstaged content, the review fails closed. Install TruffleHog using its official platform-neutral instructions; autoreview fails with that link when the binary is unavailable and never auto-installs it. Repositories should also run TruffleHog in pull-request CI as a backup outside autoreview; repository-local Git hooks are optional. Review bundles still omit security-sensitive paths or files, and explicit prompt and dataset inputs remain checked before engine invocation. Safe large diffs are sent as one pass while they fit the aggregate prompt limit, then partitioned into complete bounded passes without truncation.clawsweeper[bot] or another automation, identify the human trigger when practical. Check timeline/comments first; if rate-limited, use gitcrawl/cache or public PR HTML. Look for maintainer commands such as @clawsweeper automerge, /landpr, or labels/status comments that armed automerge. Report automerge triggered by @login; if not found, say trigger unknown.codex review, nested reviewers, or reviewer panels from inside the review. The helper builds one validated bundle, calls the selected engine once for normal inputs or once per complete bounded chunk for oversized inputs, validates the structured results, and stops.gh/Gitcrawl reports database disk image is malformed, run gitcrawl doctor --json once to let the portable cache repair before retrying review; do not bypass the shim unless repair fails and freshness requires live GitHub.gitcrawl doctor --json and inspect source_db_health, runtime_db_health, and portable_store_status before falling back to live GitHub.Autoreview is a closeout gate, not permission to change the task's product contract. Define scope by the authorized invariant and its architectural owner, not by the first patch.
Before the first review, record a scope baseline: original request or issue, violated invariant, target branch, intended behavior, owner boundary, relevant sibling surfaces, and public/security/product contracts. Record changed files and non-test LOC as measurements, not hard caps. For inherited or already-bloated branches, distinguish the intended architectural fix from unrelated branch drift.
Before patching a finding, classify it:
Stop patching and report the scope break instead of continuing when:
After the two-cycle pause, continue only when every remaining accepted finding is still an in-scope blocker. Otherwise preserve the useful analysis, identify a coherent root-cause-safe landed subset if one exists, and open or request a follow-up for unrelated work. Do not land a symptom patch or keep committing speculative fixes just to satisfy the reviewer.
Do not stack or push review-triggered fix commits while scope classification or focused proof is unresolved. Keep exploratory edits local until the cycle is proven in scope; if scope breaks, remove them from the landing lane instead of preserving them as branch history.
Critical exceptions must be explicit: active data loss, crash, broken install/upgrade, release blocker, or concrete security exposure. If the exception is not one of those, it is not critical enough to blow up scope.
On release, beta, stable, hotfix, signing, notarization, appcast, package-publish, or release-check work, use freeze discipline even when the branch name is not release-like:
main, not reasons to broaden the release branch.main.Set the skill script paths once, then use "$AUTOREVIEW" and "$AUTOREVIEW_HARNESS" in the examples below.
Choose one:
# Project-local skill in the current repo for Codex and other agents:
export AUTOREVIEW=".agents/skills/autoreview/scripts/autoreview"
export AUTOREVIEW_HARNESS=".agents/skills/autoreview/scripts/test-review-harness"# Claude Code project-local skill in the current repo:
export AUTOREVIEW=".claude/skills/autoreview/scripts/autoreview"
export AUTOREVIEW_HARNESS=".claude/skills/autoreview/scripts/test-review-harness"# Source checkout of openclaw/agent-skills:
export AUTOREVIEW="skills/autoreview/scripts/autoreview"
export AUTOREVIEW_HARNESS="skills/autoreview/scripts/test-review-harness"# Global skill:
export AGENTS_HOME="${AGENTS_HOME:-$HOME/.agents}"
export AUTOREVIEW="$AGENTS_HOME/skills/autoreview/scripts/autoreview"
export AUTOREVIEW_HARNESS="$AGENTS_HOME/skills/autoreview/scripts/test-review-harness"When using Claude Code, set AGENTS_HOME="$HOME/.claude" for global skills.
On native Windows, choose the matching pair:
# Project-local skill in the current repo for Codex and other agents:
$AUTOREVIEW = ".agents\skills\autoreview\scripts\autoreview"
$AUTOREVIEW_HARNESS = ".agents\skills\autoreview\scripts\test-review-harness.ps1"# Claude Code project-local skill in the current repo:
$AUTOREVIEW = ".claude\skills\autoreview\scripts\autoreview"
$AUTOREVIEW_HARNESS = ".claude\skills\autoreview\scripts\test-review-harness.ps1"# Source checkout of openclaw/agent-skills:
$AUTOREVIEW = "skills\autoreview\scripts\autoreview"
$AUTOREVIEW_HARNESS = "skills\autoreview\scripts\test-review-harness.ps1"# Global skill:
$AgentsHome = if ($env:AGENTS_HOME) { $env:AGENTS_HOME } else { Join-Path $HOME ".agents" }
$AUTOREVIEW = Join-Path $AgentsHome "skills\autoreview\scripts\autoreview"
$AUTOREVIEW_HARNESS = Join-Path $AgentsHome "skills\autoreview\scripts\test-review-harness.ps1"Dirty local work:
"$AUTOREVIEW" --mode localUse this only when the patch is actually unstaged/staged/untracked in the
current checkout. --mode uncommitted is accepted as an alias for --mode local.
For committed, pushed, or PR work, point the helper at the commit
or branch diff instead; do not force dirty modes just
because the helper docs mention dirty work first. A clean local review
only proves there is no local patch.
Branch/PR work:
"$AUTOREVIEW" --mode branch --base origin/mainOptional review context is first-class. Prompt files and datasets must be repo-relative so review bundles cannot pull arbitrary host files:
"$AUTOREVIEW" --mode branch --base origin/main --prompt-file review-notes.md --dataset evidence.jsonIf an open PR exists, use its actual base:
base=$(gh pr view --json baseRefName --jq .baseRefName)
"$AUTOREVIEW" --mode branch --base "origin/$base"Committed single change:
"$AUTOREVIEW" --mode commit --commit HEADUse commit review for already-landed or already-pushed work on main. Reviewing
clean main against origin/main is usually an empty diff after push. For a
small stack, review each commit explicitly or review the branch before merging
with --base.
The helper scans the full patch before partitioning it. A safe bundle that fits the aggregate prompt limit remains one integrated review pass. Larger bundles are split at bundle sections and file boundaries where possible; an oversized single-file block is split at line boundaries with repeated file/hunk context and an absolute new- or old-file line offset. Untracked snapshots use injection-safe source-line records so continuation passes retain reportable locations. A single physical diff line split across passes also retains its original addition, deletion, or context marker. Every original bundle byte appears exactly once across the pass sequence, and all validated reports are merged before required-finding and exit-status checks. The helper caps one run at eight bounded passes so an unexpectedly huge branch cannot create unbounded model calls; split still-larger work into coherent review targets.
Chunking makes large-diff review usable, but it cannot give one model call every cross-file implementation detail. For architecture-heavy changes, still prefer a coherent branch or PR shape whose semantic decision surface fits one pass. Removing verified non-authoritative generated noise remains useful, but never drop lockfiles, generated clients, policies, manifests, schemas, or other independently semantic artifacts merely to shrink the review.
Format first if formatting can change line locations. Then it is OK to run tests and review in parallel:
"$AUTOREVIEW" --parallel-tests "<focused test command>"On Windows, the default --parallel-tests shell preserves the platform cmd.exe
semantics used by Python shell=True. Use --parallel-tests-shell powershell
or --parallel-tests-shell pwsh when the focused test command is PowerShell-specific.
Parallel tests inherit only a small allowlist of ordinary OS, CI, and toolchain
variables. Put additional non-secret project controls directly in the test command.
Home and standard config directories point to a temporary isolated root that is
removed after the command exits. Do not put secrets in the command because it is
printed before execution. Set OPENCLAW_TESTBOX=1 on the autoreview process, not
inside the test command, because the environment snapshot and credential staging
happen before the test shell starts:
OPENCLAW_TESTBOX=1 "$AUTOREVIEW" --parallel-tests "pnpm check:changed"On POSIX, the helper puts this isolated Testbox home under the short, sticky
system /tmp; Blacksmith creates an SSH control socket below that home, and a
long macOS TMPDIR can exceed the Unix-socket path limit. With an older helper,
prefix the outer autoreview process with TMPDIR=/tmp. Setting TMPDIR inside
the quoted test command is too late because the isolated home already exists.
This is the narrow trusted-maintainer-code exception: it stages only the Blacksmith credential file into the temporary home so the command can delegate remotely. Never use this credential-hydrated path for untrusted contributor or fork code. Run other secret-bearing or credentialed tests separately in an appropriately isolated remote runner.
Tradeoff: tests may force code changes that stale the review. If tests or review lead to code edits, rerun the affected tests and rerun review until no accepted/actionable findings remain. Once that rerun exits cleanly, stop; do not spend another long review cycle on redundant confirmation.
Run multiple reviewers against one frozen bundle:
"$AUTOREVIEW" --reviewers codex,claude,pi,kimi--panel is shorthand for Codex plus Claude unless --engine changes the first reviewer:
"$AUTOREVIEW" --panelSet reviewer models and thinking/effort explicitly:
"$AUTOREVIEW" --reviewers codex,claude --model codex=gpt-5.6-sol --thinking codex=high --model claude=claude-fable-5 --thinking claude=maxInline syntax is also supported for simple model IDs:
"$AUTOREVIEW" --reviewers codex:gpt-5.6-sol:high,claude:claude-fable-5:maxFor models with slashes or extra colons, prefer keyed form:
"$AUTOREVIEW" --engine pi --model anthropic/claude-sonnet-4 --thinking high
"$AUTOREVIEW" --reviewers codex,pi --model codex=gpt-5.6-sol --model pi=anthropic/claude-sonnet-4--reviewers all covers Codex, Claude, Pi, and Kimi. Droid, Copilot, Cursor, and OpenCode selections fail closed because their current CLI contracts cannot confine project instructions, filesystem reads, or network fetches to the review boundary.
The helper accepts --model globally or per engine (engine=model) and --thinking globally or per engine (engine=level). Repeat either flag for multiple reviewers.
Recommended model defaults:
| Engine | Default model | Source note |
|---|---|---|
| codex (default) | gpt-5.6-sol -> gpt-5.6-terra on access failure | OpenClaw org review default |
| claude | claude-fable-5 | Anthropic's most capable widely released Claude model |
CLI flags and environment variables override these defaults. Pi and Kimi do not get built-in model defaults because their configured model catalogs may vary by installation. Droid, Copilot, Cursor, and OpenCode are currently refused.
| Engine | Model flag | Example model IDs | Thinking flag | Accepted levels |
|---|---|---|---|---|
| codex (default) | codex --model X exec ... | gpt-5.6-sol, then gpt-5.6-terra on Sol access failure | -c model_reasoning_effort=Y | none, minimal, low, medium, high, xhigh, max |
| claude | claude --model X | claude-fable-5, claude-opus-4-8, claude-sonnet-4-6, claude-haiku-4-5 | --effort Y | low, medium, high, xhigh, max |
| droid | currently refused | Factory model IDs | -r, --reasoning-effort Y | off, none, low, medium, high, xhigh, max |
| copilot | currently refused | Copilot model aliases | not supported | n/a |
| pi | pi --model X | anthropic/claude-sonnet-4, openai/gpt-4o | --thinking Y | off, minimal, low, medium, high, xhigh |
| kimi | kimi --model X | A model alias from the user's Kimi config | [thinking] enabled in the staged config | on, off |
| cursor | currently refused | Cursor model aliases | not supported | n/a |
| opencode | currently refused | OpenCode provider/model IDs | not supported | n/a |
Claude also supports --fallback-model a,b for availability-based fallback chains (model-config). Current Claude docs note that auth, billing, rate-limit, request-size, and transport errors do not trigger fallback, and the changelog documents interactive-session support in v2.1.166.
OpenAI's model guidance identifies Sol as the GPT-5.6 frontier-capability route and documents max support. Autoreview keeps high as its default; use max only for the hardest quality-first reviews after comparing its latency and cost with xhigh on representative changes.
Examples matching current main behavior:
# Codex with explicit model and reasoning
"$AUTOREVIEW" --engine codex --model gpt-5.6-sol --thinking high
# Codex fast mode (priority service tier); needs a model whose catalog lists the tier, silently standard otherwise
"$AUTOREVIEW" --engine codex --codex-speed fast
# Safe Codex model/response tuning overrides (--codex-speed wins over a service_tier here)
"$AUTOREVIEW" --engine codex --codex-config 'service_tier="fast"'
# Claude Code aliases or full model names, with optional availability fallback
"$AUTOREVIEW" --engine claude --model claude-fable-5 --thinking max
"$AUTOREVIEW" --engine claude --model claude-fable-5 --fallback-model claude-opus-4-8,claude-sonnet-4-6
# Pi with explicit model and thinking level
"$AUTOREVIEW" --engine pi --model anthropic/claude-sonnet-4 --thinking high --pi-bin pi
# Kimi with its configured default model, or a configured model alias
"$AUTOREVIEW" --engine kimi --thinking on --kimi-bin kimi
"$AUTOREVIEW" --engine kimi --model kimi-model-alias
--cursor-agent-bin and CURSOR_AGENT_BIN remain compatibility aliases for
--cursor-bin and CURSOR_BIN.
CLI flags take precedence over environment variables.
Store persistent personal defaults in your shell startup file or launcher
environment. For repository-local defaults, use an existing local environment
loader such as an untracked .envrc; the helper does not write a config file.
| Variable | Purpose |
|---|---|
AUTOREVIEW_MODEL | Override the built-in default --model for all engines |
AUTOREVIEW_THINKING | Default --thinking for all engines |
AUTOREVIEW_FALLBACK_MODEL | Default Claude --fallback-model chain |
AUTOREVIEW_<ENGINE>_MODEL | Per-engine model override, for example AUTOREVIEW_CODEX_MODEL=gpt-5.6-sol |
AUTOREVIEW_<ENGINE>_THINKING | Per-engine thinking override |
AUTOREVIEW_CODEX_CONFIG | Safe Codex model/response tuning overrides, semicolon-separated, e.g. service_tier="fast"; capability-bearing keys fail closed |
AUTOREVIEW_CODEX_SPEED | Codex service tier override: fast (priority), flex, or default; silently standard when the model does not list the tier |
AUTOREVIEW_CLAUDE_FALLBACK_MODEL | Claude-only fallback chain |
AUTOREVIEW_PROVIDER_ENV_ALLOW | Comma-separated custom Pi/OpenCode credential variable names; names must end in a recognized credential suffix |
Codex maps thinking to model_reasoning_effort. Claude maps thinking to --effort. Pi maps thinking to --thinking. Kimi maps on and off to [thinking] enabled in the staged review config. Only Claude accepts --fallback-model; global CLI/env fallback requires at least one Claude reviewer, and engine-specific fallback overrides require that reviewer to be selected. Non-Claude fallback overrides, including AUTOREVIEW_<NONCLAUDE>_FALLBACK_MODEL, fail closed instead of being silently ignored.
When autoreview runs inside the repository under review, external reviewer CLIs must not load project-local trust or configuration that the branch controls.
| Engine | Isolation flags | Reference |
|---|---|---|
| codex | Auth-only config overrides, isolated workspace, exec --ignore-user-config --ignore-rules --skip-git-repo-check, plus read-only sandbox | Codex CLI exec --help |
| claude | --safe-mode --setting-sources user --strict-mcp-config --disallowedTools mcp__*; auto-memory and filesystem/shell tools disabled; empty external workspace; WebSearch by default (v2.1.169+) | Claude Code CLI reference |
| droid | Fails closed: current CLI cannot disable both project instructions and all tools | Droid CLI exec --help and --list-tools |
| copilot | Fails closed: repository read tools also expose ignored files outside the reviewed bundle | GitHub Copilot CLI command reference |
| pi | --no-approve --no-session --no-context-files --no-extensions --no-skills --no-prompt-templates --no-themes --no-tools | Pi CLI --help; requires Pi v0.79.0+ |
| kimi | Empty external workspace; staged KIMI_CODE_HOME with sanitized config; Markdown custom agent with no tools/subagents; explicit empty --skills-dir; isolated runtime state | Kimi Code CLI --help; requires Kimi v0.30.0+ |
| opencode | Fails closed: project/global config isolation and private-network fetch denial are not both proven | OpenCode CLI contract |
| cursor | Fails closed: documented read permissions can target absolute host paths and no proven repository-only filesystem sandbox is exposed | Cursor CLI permissions |
Codex --ignore-user-config skips config loading for the exec run. Autoreview reconstructs only the documented cli_auth_credentials_store, forced_login_method, and forced_chatgpt_workspace_id settings from CODEX_HOME/config.toml, keeping authentication usable without forwarding unrelated user configuration. Codex runs in an empty temporary workspace: the validated bundle is its sole repository input, ignored files and linked-worktree metadata remain unreadable, and the zero project-doc budget keeps workspace instructions out of the prompt. --ignore-rules skips user/project execpolicy rules. Claude --safe-mode disables project hooks, skills, plugins, MCP servers, and CLAUDE.md; autoreview supplies WebSearch by default, permits only explicitly domain-constrained WebFetch rules, and exposes no filesystem or shell tools. Pi runs from a neutral temporary directory with project resources disabled and --no-tools. Kimi (-p, stream-json) runs from an empty external workspace with a staged KIMI_CODE_HOME: sanitized model/provider config only (no services, hooks, or extra skill/agent dirs), its OAuth credential directory linked in and device identity copied so native token refreshes remain durable without exposing the rest of the user's Kimi state. A Markdown --agent-file with tools: [] and subagents: [] plus an empty --skills-dir keep project instructions, tools, and MCP servers out of the review; the prompt travels as the --prompt argument, so per-pass prompts are capped at a platform-safe argv budget (120 KiB POSIX, 30 KiB Windows) and larger bundles partition into bounded passes. Droid, Copilot, Cursor, and OpenCode fail closed because their current CLI contracts cannot isolate untrusted review input from host, project, or private-network trust surfaces.
Codex uses a named permission profile that grants read access only to an empty temporary workspace. This is narrower than repository-root access, which would expose ignored credentials, and narrower than the legacy read-only sandbox, which permits reads across the host filesystem.
Run the helper directly so target selection, engine choice, structured validation, and exit status all stay in one path. If output is noisy, summarize the completed helper output after it returns; do not ask another agent or reviewer to rerun the review.
After setting AUTOREVIEW and AUTOREVIEW_HARNESS above:
"$AUTOREVIEW" --helpThe smoke harness has thin shell wrappers over a shared Python implementation:
"$AUTOREVIEW_HARNESS" --fixture benign --engine codexOn native Windows, invoke the extensionless Python helper through Python:
python $AUTOREVIEW --helpand the smoke harness:
& $AUTOREVIEW_HARNESS -Fixture benign -Engine codexThe helper:
--mode uncommitted as an alias for --mode localgh pr view worksorigin/main for non-main branches--engine droid, copilot, cursor, and opencode only to fail closed with isolation errors; runnable engines are codex, claude, pi, and kimi; default is AUTOREVIEW_ENGINE or codexgit, gh, reviewer, and PowerShell shell commands from absolute PATH entries only, never from the reviewed checkout; explicit --*-bin paths are interpreted from the reviewed repository root when relative and accepted only when both the supplied path and resolved target stay outside the reviewed repository--mode commit --commit <ref> for already-committed work, especially clean main after landing--mode auto or forced to --mode branch for PR/branch work; do not force --mode local after committing--output, --json-output, or live streamed engine stderr is set--dry-run, --parallel-tests, --parallel-tests-shell, --prompt, repo-relative --prompt-file, repo-relative --dataset, --no-tools, --no-web-search, repeatable Codex-only safe model/response tuning with --codex-config key=value, Codex-only --codex-speed fast|flex|default, and commit refs--stream-engine-output or AUTOREVIEW_STREAM_ENGINE_OUTPUT=1 for live engine text while preserving structured validation; Codex and Claude hide tool/file event details, emit compact activity summaries, and report usage at turn completion--panel / --reviewers, plus per-engine --model, --thinking, and Claude --fallback-modelcodex=gpt-5.6-sol with high reasoning and an access-only gpt-5.6-terra retry, plus claude=claude-fable-5; honors AUTOREVIEW_MODEL, AUTOREVIEW_THINKING, AUTOREVIEW_FALLBACK_MODEL, and per-engine AUTOREVIEW_<ENGINE>_MODEL / AUTOREVIEW_<ENGINE>_THINKING environment overrides when CLI flags are omitted--safe-mode (v2.1.169+), --setting-sources user, MCP and auto-memory disabled, no filesystem/shell tools, an empty external workspace, and --fallback-model when setv0.79.0+ from neutral temporary directories with --no-approve, --no-session, disabled Pi context/resource loading, and --no-tools because its built-in read tools are not repository-confinedv0.30.0+ from an empty temporary workspace with a staged KIMI_CODE_HOME, sanitized config, an empty --skills-dir, and a no-tools/no-subagents Markdown --agent-filereview still running: <engine> elapsed=<seconds>s pid=<pid> to stderr at long-running intervals while waiting for the selected review engine, unless streamed output or compact Codex activity has been visible recentlyautoreview clean: no accepted/actionable findings reported when the selected review command exits 0Include:
Do not run another review solely to improve the final report wording. If the final helper run exited 0 and produced no accepted/actionable findings, report that exact run as clean.
© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (scripts) in .agents/skills/autoreview of udecode/kitcn.
Open the folder on GitHubat commit c6010f5
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in udecode/kitcn, which our catalogue first saw on October 7, 2026.
Autoreview next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Autoreview this skilludecode/kitcn | 450 | 1 repos | ~9.5k | Automated safety check: Pass | Apache-2.0 | |
| Ccmanager Configkbwo/ccmanager | 1.3k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Kimi WebbridgeMoonshotAI/kimi-code | 7.8k | — | ~3.6k | Automated safety check: Pass | MIT | |
| Gen ChangesetsMoonshotAI/kimi-code | 7.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Pulse Releasequnqin24/Pulse | 516 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Luvus ModuleRizRiyz/luvus | 954 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 |
kbwo/ccmanager
Set up, review, or repair a CCManager config — .ccmanager.json at a git repository root, or the global ~/.config/ccmanager/config.json.
MoonshotAI/kimi-code
Kimi Browser Extension(Kimi 浏览器扩展,原 Kimi WebBridge)lets AI control the user's real browser — navigate, click, type, read, screenshot, and interact with any website using the user's actual login…
MoonshotAI/kimi-code
A skill your agent uses when generating changesets in the kimi-code repository — deciding whether to write one, which package to list, the bump level, the wording, and the confirmation workflow.
qunqin24/Pulse
Release a new Pulse version end to end — checks, bilingual CHANGELOG entry, VERSION, tag, the release workflow, syncing main, and the issue replies that go with it.
RizRiyz/luvus
Write a luvus module (an extension for luvus, mission control for your AI coding agents).
MoonshotAI/kimi-code
Update Kimi Code CLI user documentation after meaningful code changes that affect product behavior or user experience.
udecode/kitcn
Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.
udecode/kitcn
Prevent feature creep when building software, apps, and AI-powered products.
udecode/kitcn
Repair an unreleased .changeset/.md file so it matches the real branch delta against main.
udecode/kitcn
Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.
udecode/kitcn
A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage
udecode/kitcn
Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.
Works with
Categories
Pre-commit/ship code review: Codex default; optional Claude, Pi, or Kimi. Autoreview is an agent skill from udecode/kitcn. Pre-commit/ship code review: Codex default; optional Claude, Pi, or Kimi.
Autoreview fits situations like: development work in your project.
Run `npx skills add udecode/kitcn --skill autoreview -a claude-code`. Or copy the skill folder (.agents/skills/autoreview in udecode/kitcn) into .claude/skills/autoreview in your project. Claude Code loads it when a task matches its description.
Run `npx skills add udecode/kitcn --skill autoreview -a codex`. Or copy the skill folder (.agents/skills/autoreview in udecode/kitcn) into .agents/skills/autoreview in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill autoreview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/autoreview, .gemini/skills/autoreview, .github/skills/autoreview and .opencode/skills/autoreview in your project.
Going by SKILL.md and its folder, Autoreview needs Python, TypeScript and PowerShell for the scripts in its folder and the command-line tools its instructions call (gh, codex, python and claude). Our summary lists: Python 3; Node.js; PowerShell.
SKILL.md names 3 domains. As links in the text: code.claude.com, developers.openai.com and cursor.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Autoreview is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 9.5k tokens (SKILL.md is roughly 38k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Autoreview: Ccmanager Config (kbwo/ccmanager, 1.3k stars), Kimi Webbridge (MoonshotAI/kimi-code, 7.8k stars), Gen Changesets (MoonshotAI/kimi-code, 7.8k stars) and Pulse Release (qunqin24/Pulse, 516 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.
Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.