Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Structured code review when explicitly requested, preferring OpenAI/Codex before Claude.
$ npx skills add udecode/plate-playground-template --skill autoreview -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install udecode/plate-playground-template autoreview --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/autoreview .claude/skills/autoreview && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .claude/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add udecode/plate-playground-template --skill autoreview -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install udecode/plate-playground-template autoreview --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/autoreview .agents/skills/autoreview && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .agents/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/plate-playground-template --skill autoreview -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install udecode/plate-playground-template autoreview --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/autoreview .cursor/skills/autoreview && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .cursor/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/udecode/plate-playground-template.git --path .agents/skills/autoreview--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add udecode/plate-playground-template --skill autoreview -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install udecode/plate-playground-template autoreview --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/autoreview .gemini/skills/autoreview && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .gemini/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install udecode/plate-playground-template autoreviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add udecode/plate-playground-template --skill autoreview -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/autoreview .github/skills/autoreview && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .github/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add udecode/plate-playground-template --skill autoreview -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install udecode/plate-playground-template autoreview --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/udecode/plate-playground-template.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/autoreview .opencode/skills/autoreview && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "autoreview" agent skill from https://github.com/udecode/plate-playground-template/tree/main/.agents/skills/autoreview into .opencode/skills/autoreview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "autoreview", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
autoreviewStructured code review when explicitly requested, preferring OpenAI/Codex before Claude.
Autoreview is an agent skill from udecode/plate-playground-template. Structured code review when explicitly requested, preferring OpenAI/Codex before Claude.
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 27 other files, including scripts and reference files (for example `AGENTS.md`, `references/diagnostics-and-results.md` and `references/repository-entrypoint.md`).
It sits in Development. The repository describes itself as: Plate AI template with React 19, Next 16, Tailwind 4, MCP. The licence is MIT.
Read from SKILL.md and the folder at commit 324070e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Python, TypeScript, PowerShell and Swift, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
codexpython3ghgitpythonFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.openai.comAlso links to:
developers.openai.comlearn.chatgpt.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AMP_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Autoreview loads about 5.3k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 25 tokens; SKILL.md has 2,641 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from udecode/plate-playground-template at commit 324070e, republished under its MIT licence (© udecode). 2,641 words, ~5,280 tokens.
.claude/skills/autoreview/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.Run an independent review when the user or an owning workflow asks for one. This is code review, not Guardian approval routing. Let the reviewer choose how to analyze the change; provide the target, relevant context, and desired severity. Findings are advice to verify, not instructions to apply blindly.
Before starting a review, read the complete diagnostic and result guidance. It is part of this skill; follow its output-path, status, failure, usage, and diagnostic rules.
Use scripts/autoreview beside this skill. Keep its custom codex exec path:
native codex review cannot combine explicit Git target flags with custom instructions.
The helper combines those with evidence, severity filtering, and validated JSON;
it leaves review judgment to Codex. Install this skill once with the canonical
repository's python3 scripts/install-skills autoreview. The default installation
at ~/.agents/skills/autoreview links to this source checkout.
Run from the repository being reviewed:
AUTOREVIEW="$HOME/.agents/skills/autoreview/scripts/autoreview"
python3 "$AUTOREVIEW" --mode localIn the canonical agent-skills repo, the path is
skills/autoreview/scripts/autoreview. Use the selected installation path when
installed with --target. On Windows, invoke the helper with Python 3.10 or newer,
or use the adjacent autoreview.ps1 launcher.
Use --help for the complete flags and environment overrides.
Repositories keep only the shared-skill entrypoint. Read this full skill and its required references from the shared installation. Keep repository-specific thresholds and review requirements in the consumer's instructions. Upstream changes to shared behavior here.
Update the canonical checkout once to update every symlinked consumer. Finish
active reviews before updating their helper. Copy-mode installations require
re-running scripts/install-skills --mode copy --force autoreview after updating
the source checkout. Review commands never download or update themselves.
Choose the Git target explicitly when the default is ambiguous:
| Target | Arguments | Scope |
|---|---|---|
| Local work | --mode local | HEAD → index → working tree, plus untracked files |
| Local candidate against a base | --mode local --base <ref> | Pinned base → index → working tree, plus untracked files |
| Committed branch/PR | --mode branch --base <ref> | Merge-base → HEAD; excludes dirty work |
| One commit | --mode commit --commit <ref> | Raw parent → commit; a root compares against the empty tree |
--mode auto selects local work when dirty, otherwise a branch review using the
PR base or origin/main. Clean main has no implicit review target.
--mode uncommitted is an alias for local. The helper does not fetch refs.
Registered nested linked checkouts from the same repository are outside the current review scope. Their presence or edits do not make the parent dirty; ordinary adjacent files remain included in the review. Worktree boundaries are revalidated without changing Git ignore rules.
For a complete PR candidate including dirty rewrites, use local mode with its pinned merge base—not branch mode:
pr_base=$(gh pr view --json baseRefName --jq .baseRefName)
merge_base=$(git merge-base HEAD "origin/$pr_base")
"$AUTOREVIEW" --mode local --base "$merge_base"When a file has both staged and unstaged changes, both states are reviewed.
A defect in the index remains actionable even if the working tree fixes it;
the report labels it INDEX-only.
Git display settings cannot suppress context markers or add patch colors;
repository configuration is not changed. Source paths and text retain literal
whitespace. An empty present
source uses line 1, column 1, and an empty excerpt; empty physical lines also
use an empty excerpt at column 1. Source identity remains mandatory.
Binary deletions remain in scope as Git deletion metadata; their former contents are not included or reviewed. Each local transition is checked independently: deleting a file in the working tree cannot hide a staged binary change.
Finding locations may use native absolute paths that resolve inside the reviewed repository; these become repository-relative paths before scope and attribution checks, preserving a changed symlink's path when its target is also inside. Parent traversal and paths resolving outside the repository remain invalid. An invalid location still fails the report; findings are never silently dropped.
Local selection honors core.autocrlf from external operator Git configuration,
with repository-local values and attributes retaining precedence. Only its
validated scalar value reaches diff/status; other global and system Git
configuration stays disabled. Repository-owned or relative global-config
overrides are not imported, and reviewed source bytes are not rewritten.
Local collection disables effective Git clean/process commands and requires
conversion to succeed. Unused drivers, unchanged filtered neighbors, staged-only
changes, and deletions can still be reviewed without executing converters.
If Git needs executable conversion to assemble the diff, collection fails before
any reviewer starts. This can include an unchanged filtered file whose stat cache
needs refreshing. Use explicit branch or commit mode for committed content in
that case. Built-in line-ending normalization remains enabled; raw bytes never
stand in for a required executable conversion.
PR-base discovery uses trusted external Git and a scoped GitHub CLI environment,
preserving external authentication/configuration and proxy settings while excluding
inherited Git routing, GH_REPO redirection, and checkout-owned executables.
A differently named AUTOREVIEW_GIT override that cannot also be selected as git
by the child requires an explicit --base; rejected GitHub configuration paths
also require one.
Use --prompt for task-specific guidance, or --prompt-file and --dataset for
repository-relative context files. Context does not expand the selected Git
target. The reviewer cannot read unchanged repository files from its empty
sandbox; supply relevant source or dependency evidence when the diff is insufficient.
--prompt-file also accepts an absolute path inside the repository; the same
sensitive-path, symlink, and mutation checks apply. --dataset stays repo-relative.
Repeated paths in the same evidence role share one validated capture. Equal
content at different paths and prompt-file versus dataset roles stay distinct.
For unchanged committed source, use repeatable --source-context <repo-relative-path>
with branch or commit mode. Use --source-context-file <repo-relative-path> when
that source must stay intact in every review pass. Both read the exact regular-file
blob from the frozen reviewed commit (branch HEAD or --commit), including executable source files.
Local mode, including an auto-selected local target, is unsupported. No separate
context revision or working-copy substitution is accepted. The checkout path must
remain a regular file; its bytes and path topology are revalidated throughout review.
Repeated normalized source-context paths share one capture after every argument
is validated; different paths and evidence roles remain distinct.
Both roles use tracked-source filename classification, so source names such as
src/token_count.py are accepted. Credential directories, stores and keyfiles
remain forbidden. Existing prompt-file and dataset restrictions are unchanged.
Every source block carries path, commit, blob and mode provenance. --source-context
bytes are partitioned with the change when needed. --source-context-file blocks
stay complete in every pass and must fit with the instructions and change framing;
the helper refuses an over-capacity plan without dropping required evidence.
Context never adds finding targets or instruction authority. This is a
source-provenance contract, not secret-content scanning.
"$AUTOREVIEW" --mode branch --base origin/main --source-context src/token_count.py
"$AUTOREVIEW" --mode branch --base origin/main --source-context-file src/token_count.pyThe default threshold is P0 only: material blockers to normal operation or
safety. Use --max-priority P1, P2, or P3 when the caller requests a wider
review. AUTOREVIEW_MAX_PRIORITY accepts the same P0–P3 values; an explicit
flag overrides it. Invalid resolved priorities fail during argument parsing,
before preparation or reviewer startup.
Do not add unrelated redesign goals or prescribe file counts, reading
sequences, or ritual extra passes. Historical blame requires a verified
parent-relative patch; otherwise leave the attribution unknown.
"$AUTOREVIEW" --mode local --prompt-file review-notes.md --dataset evidence.jsonFor automatic reviewer selection, try OpenAI models through Codex before Claude.
Start with --engine codex even when the invoking agent uses Codex or asks for
an independent second opinion. Use Claude only when the user explicitly selects
it or Codex is unavailable for the review; report the concrete availability failure
before switching. Do not switch because a review is slow, rate-limited, or returns
findings, or to bypass a safety refusal or isolation failure.
Codex defaults to gpt-6.1-sol, high reasoning, with a single gpt-6-sol retry
only for an account-access failure. Explicit gpt-6.1-sol selections use the same
retry. Explicit gpt-6-sol selections retain their access-only gpt-6-luna retry;
other explicit models, including Luna and Astra, have no model fallback.
Explicit gpt-5.6-sol selections retain their access-only gpt-5.6-terra retry.
GPT-6.1 Sol rejects none and minimal effort before review preparation;
GPT-6 Sol and Luna reject minimal. An effort-only override keeps the default model.
Honor explicit user engine/model choices.
The helper does not automatically fall back between engines.
Use --engine, --model, and --thinking to override the defaults.
--codex-speed fast selects priority service when supported; --codex-speed ultrafast
selects Ultrafast when the active model catalog lists it (Codex otherwise silently
sends the standard tier). Only Claude accepts
--fallback-model. Per-engine environment overrides use AUTOREVIEW_<ENGINE>_*.
If your account cannot access Sol or Luna, pin an available model. To require GPT-6 Astra without a model fallback, select it explicitly:
"$AUTOREVIEW" --mode local --model gpt-6-astra --thinking highGPT-6.1 Sol and GPT-6 Astra support low, medium, high, xhigh, and max;
neither supports none or minimal. GPT-6 Sol and Luna additionally support none,
but not minimal. AutoReview defaults to
high and does not fall back from an explicit Luna or Astra selection.
Codex's ultra mode uses automatic
delegation and is outside this helper's supported effort levels. Use max
for its deepest supported review. For EU data residency, use
--codex-speed default; GPT-6 fast mode is unavailable there.
See the GPT-6.1 Sol,
GPT-6 Sol, and
GPT-6 Luna model docs
and Codex reasoning modes.
By default, Codex preserves only authentication settings from user configuration; provider, profile, context and catalogue settings remain ignored. To project a named route, select it explicitly through the existing config override:
"$AUTOREVIEW" --mode local --codex-config 'model_provider="review_api"'The selector must match model_provider in the operator's external
CODEX_HOME/config.toml. It accepts one bare or simply quoted identifier;
provider definitions and other capabilities cannot be supplied through overrides.
Projection requires Python 3.11 or tomli; default auth-only operation retains
its existing fallback parser.
The selected route must use https://api.openai.com/v1 and command authentication
with an absolute external executable. Fixed arguments belong in that executable's
wrapper; omitted or empty auth.args are accepted. Omitted wire_api and
requires_openai_auth retain Codex's responses and false defaults. Optional
auth timing and context settings keep native defaults and semantics.
On POSIX, a private launcher restores the validated caller HOME only for the
selected authentication executable; the engine and reviewer tools retain their
isolated environment and filesystem access. Caller HOME must be an available
absolute directory with no repository-owned path or symlink provenance. Windows
keeps the native executable route. Command-auth runs suppress raw provider
diagnostics and report fixed failure categories, while retaining compact progress,
usage and assistant report streaming. An empty final report fails without exposing
captured stdout.
Catalogue and authentication working-directory paths resolve relative to the operator config directory and must remain outside the reviewed repository. A supplied catalogue is copied byte-for-byte into the private client runtime; retries use the same route and catalogue snapshot. Dry runs check the same ownership and route shape without executing authentication. Codex owns catalogue validation, model access and context clamping. Other custom provider forms and split context overrides are unsupported when projection is selected.
| Optional engine | Prerequisites |
|---|---|
| Claude | CLI 2.1.169+; safe mode with web-only tools |
| Amp | AMP_API_KEY for a plugin-free account; local POSIX execution, no custom endpoint or cloud/orb agent |
| Pi | CLI 0.79.0+; configured model; no tools or project resources |
--engine kimi remains recognized but is refused for reviews and --dry-run
before any Kimi process, configuration read or authentication setup. The supported
Kimi Code prompt mode accepts review content only as a command-line argument;
the helper has no supported private prompt input channel for it. This intentionally
retires the previous Kimi execution path rather than exposing the bundle in process
arguments. Existing --kimi-bin arguments remain accepted for the same clear refusal;
the helper never silently selects another engine. A custom agent file is not an
equivalent replacement because it changes the input into a templated system prompt.
Branch mode with Codex supports added, single-frame PNG, JPEG and WebP files.
Install Pillow in the Python environment running the helper (python -m pip install Pillow).
Use a vision-capable Codex model and a CLI supporting codex exec --image.
No new bypass flag is required. Full decoding rejects corrupt and animated files.
Images must have at most 16,777,216 pixels and no dimension above 16,384 pixels;
decoder bomb warnings fail closed before pixel loading. Added image paths are
limited to 20 MiB of encoded bytes each and 100 MiB total, checked against Git
object sizes before capture. Exceeding a limit fails the entire review.
The helper captures exact bytes from the pinned HEAD, stages only those images in its isolated workspace, and attaches them through Codex's native image input. Every pass receives the path, media type, byte count and SHA-256 manifest alongside the image attachments and text diff. Image findings use the original path and line 1. Text-only review does not require Pillow.
Binary deletions, including images, are reviewed as deletion metadata in every mode without image attachments or Pillow. Other binaries, modified images, local/commit image additions or modifications, and image review with other engines remain unsupported and fail closed. Missing Pillow or provider image limits fail the review rather than silently dropping assets. Sensitive-path, source-mutation, authentication and sandbox controls remain enabled.
For partial clones, materialize required Git objects before review. The isolated Git reader intentionally disables lazy network fetching; do not weaken that boundary.
The helper owns reviewer isolation, sanitized authentication, process cleanup,
Git scope, and structured result validation. Keep those controls enabled.
Before repository detection or target selection, Git must pass --version
within 10 seconds. Failure exits 2 with an incomplete diagnostic and the
resolved executable (or the unresolved selection); it never means scoped-clean.
Executable discovery skips inaccessible search candidates; an inaccessible
explicit executable override still fails preflight.
Set AUTOREVIEW_GIT to a trusted external Git executable to override every
helper-owned Git invocation. On macOS with a broken selected Xcode, use
DEVELOPER_DIR=/Applications/Xcode.app/Contents/Developer for the invocation.
Only an absolute, external DEVELOPER_DIR is additionally retained in Git's
sanitized environment;
neither override is forwarded to the isolated reviewer environment.
Every reviewer pass must inspect its bundle for real credentials and report suspected credentials as P0 findings without reproducing their values. Harmless placeholders and test fixtures are not credentials. Autoreview does not require or invoke an external secret scanner. Never work around an isolation failure.
Keep approved secret scanning outside autoreview; reviewer findings happen after transmission. Reintroducing a scanner requires an explicit maintainer decision. See #240 for rationale and history.
On macOS, reviewer tools cannot access the shared /tmp and /var/tmp trees
(including their /private aliases). Codex preflight rejects those temporary
roots before workspace, runtime, or authentication setup; unset a shared
TMPDIR/TMP/TEMP override to use macOS's private
temporary directory. Other engines and platforms retain their normal isolation.
Tools installed in shared scratch or requiring writes there will be denied too.
Text review files have no size/count cap and are never truncated; image inputs use the explicit safety limits above. Large diffs and datasets are partitioned automatically. Change partitions retain complete datasets when they fit with sufficient change space. This preference may use more passes or prompt bytes than evidence batching; the explicit pass budget still applies. Terminal fallbacks preserve a feasible complete-evidence plan when batch framing cannot fit. Intact instructions, source-context files and required mixed source context must fit the per-pass prompt budget. A failed pass does not produce a partial clean verdict. Otherwise, the planner compares a bounded set of evidence allocations and keeps the existing plan unless total prompt bytes improve without more passes, or equal bytes need fewer passes. Every change is still reviewed against every evidence batch.
Each pass is an independent assignment, not a continuing conversation. Its private completion field must confirm a finished assessment; deferring to another pass leaves the overall review incomplete.
Do not edit inputs during a review: the helper verifies captured sources before
sending and publishing results. Long reviews are normal; advancing heartbeats
mean progress. Use --stream-engine-output for visibility, not extra reviewer
runs. --dry-run checks preparation and startup without contacting a reviewer.
Both dry runs and execution print planned pass count and total prompt bytes.
Use --max-review-passes N (or AUTOREVIEW_MAX_REVIEW_PASSES) to reject the whole
plan before any reviewer starts when it exceeds an explicit campaign budget.
There is no default pass ceiling. --engine-timeout-seconds remains an optional
deadline per process attempt. Pass counts, prompt bytes, and deadlines are not
token hard caps; they do not bound model reasoning or tool use.
Follow the diagnostic and result guidance for local stage observation, output paths, exit codes, status, and usage.
© udecode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 23 other files (scripts, references) in .agents/skills/autoreview of udecode/plate-playground-template.
Open the folder on GitHubat commit 324070e
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in udecode/plate-playground-template, which our catalogue first saw on October 7, 2026.
Autoreview next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Autoreview this skilludecode/plate-playground-template | 240 | 1 repos | ~5.3k | Automated safety check: Pass | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 59 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
udecode/plate-playground-template
One-time setup for a persistent debug browser on 127.0.0.1:9222 for dev-browser --connect.
udecode/plate-playground-template
Transcribe a supplied local or linked video with Gemini Files API when its contents are needed as evidence.
udecode/plate-playground-template
Skill: testing
Categories
Structured code review when explicitly requested, preferring OpenAI/Codex before Claude. Autoreview is an agent skill from udecode/plate-playground-template. Structured code review when explicitly requested, preferring OpenAI/Codex before Claude.
Autoreview fits situations like: development work in your project.
Run `npx skills add udecode/plate-playground-template --skill autoreview -a claude-code`. Or copy the skill folder (.agents/skills/autoreview in udecode/plate-playground-template) into .claude/skills/autoreview in your project. Claude Code loads it when a task matches its description.
Run `npx skills add udecode/plate-playground-template --skill autoreview -a codex`. Or copy the skill folder (.agents/skills/autoreview in udecode/plate-playground-template) into .agents/skills/autoreview in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/plate-playground-template --skill autoreview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/autoreview, .gemini/skills/autoreview, .github/skills/autoreview and .opencode/skills/autoreview in your project.
Going by SKILL.md and its folder, Autoreview needs Python, TypeScript, PowerShell and Swift for the scripts in its folder, the command-line tools its instructions call (codex, python3, gh, git and python) and credentials named AMP_API_KEY. Our summary lists: Python 3; Node.js; PowerShell.
SKILL.md names 4 domains. In commands or code: api.openai.com; the agent is likely to contact it when it follows the instructions. As links in the text: developers.openai.com, learn.chatgpt.com and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Autoreview is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Autoreview: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
udecode (a GitHub organization) maintains it in udecode/plate-playground-template, which has 240 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: udecode/plate-playground-template on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.