Agent skill

Aif Review

by unxed in unxed/f4

Perform code review on staged changes or a pull request. An agent skill from unxed/f4.

BSD-3-ClauseAuto-check passedDevelopment

Install Aif Review

skills CLI
$ npx skills add unxed/f4 --skill aif-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install unxed/f4 aif-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/aif-review .claude/skills/aif-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aif-review
GitHub stars
243
Token cost
~3.3k tokens
SKILL.md length
1,362 words
Files
4 (incl. references)
Skills in repo
36
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Perform code review on staged changes or a pull request. An agent skill from unxed/f4.

  • Works in 3 steps: Run git diff --cached to get staged… → If nothing staged, run git diff for… → Analyze each file's changes
  • User says review code
  • SKILL.md covers Step 0: Load Config, Behavior, Context Gates (Read-Only) and Review Checklist, plus 4 more sections
  • Calls git and gh; reaches github.com

What it does

Aif Review is an agent skill from unxed/f4. Perform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay". Optional +check flag validates findings via a fresh-context subagent.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/CHECK-MODE.md`, `references/SEVERITY.md` and `references/VALIDATOR.md`).

It sits in Development, covering Code review, Pull requests and Subagents. It works with Git. The repository describes itself as: dual pane like a charm. The licence is BSD-3-Clause.

When your agent uses it

  • User says review code
  • Is this code okay

Example prompts

  • “review code”
  • “check my code”
  • “review PR”
  • “/aif-review”

Requirements

  • Pre-approved tools (allowed-tools): Bash(git *), Bash(gh *), Read, Glob, Grep, Task, Agent, AskUserQuestion

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Run git diff --cached to get staged changes
  2. If nothing staged, run git diff for unstaged changes
  3. Analyze each file's changes

What it can do on your machine

Read from SKILL.md and the folder at commit 772edc7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(git *)
    • Bash(gh *)
    • Read
    • Glob
    • Grep
    • Task
    • Agent
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aif Review loads about 3.3k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 1,362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from unxed/f4 at commit 772edc7, republished under its BSD-3-Clause licence (© unxed). 1,362 words, ~3,287 tokens.

Download SKILL.mdSave it as .claude/skills/aif-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
aif-review
description
Perform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay". Optional +check flag validates findings via a fresh-context subagent.
allowed-tools
Bash(git *), Bash(gh *), Read, Glob, Grep, Task, Agent, AskUserQuestion
argument-hint
[PR number | branch/commit/tag | empty] [+check]
disable-model-invocation
false

Code Review Assistant

Perform thorough code reviews focusing on correctness, security, performance, and maintainability.

Step 0: Load Config

FIRST: Read .ai-factory/config.yaml if it exists to resolve:

  • Paths: paths.description, paths.architecture, paths.rules_file, paths.roadmap, and paths.rules
  • Language: language.ui for review summary language
  • Git: git.base_branch for branch comparison guidance

If config.yaml doesn't exist, use defaults:

  • Paths: .ai-factory/ for all artifacts
  • Language: en (English)
  • Git: base_branch: main

Behavior

Argument flags

Before routing the argument string into one of the modes below, extract any standalone tokens that flag optional behavior. Strip them from the argument string and route the remainder normally.

  • +check — runs the optional findings validator after the review is produced. The full procedure (when to run, failure modes, output additions, gate-result recomputation) lives in references/CHECK-MODE.md. Default is OFF; the validator runs only when this token is present. The token may appear before or after the main argument (e.g. /aif-review +check, /aif-review 123 +check, /aif-review main +check).

If the leftover argument string is empty, fall back to the empty-argument mode (staged review). Unknown +-prefixed tokens are passed through as part of the main argument so they are not silently consumed.

Edge case: a git ref literally named +check will be consumed by the flag stripper — acceptable compromise.

Without Arguments (Review Staged Changes)
  1. Run git diff --cached to get staged changes
  2. If nothing staged, run git diff for unstaged changes
  3. Analyze each file's changes
With PR Number/URL
  1. Use gh pr view <number> --json to get PR details
  2. Use gh pr diff <number> to get the diff
  3. Review all changes in the PR
With Git Ref (Commits Mode)

Argument routing chain:

  1. Empty → staged review (see above)
  2. Digits or #N → PR mode (see above)
  3. Everything else → validate via git rev-parse --verify → commits mode or ask user

Validation:

bash
git rev-parse --verify <argument> 2>/dev/null
  • Valid ref → enter commits mode (steps below)

  • Invalid ref → do NOT fall back to staged review silently. Ask the user to clarify:

    AskUserQuestion: `<argument>` is not a valid git ref. What did you mean?
    
    Options:
    1. Review staged changes instead
    2. Cancel

    Based on choice:

    • "Review staged changes" → run staged review (default mode)
    • "Cancel" → inform the user that review was cancelled → STOP
    • "Other" → user provides corrected ref → re-validate via rev-parse

Edge case: a branch with a purely numeric name (e.g. 123) will be interpreted as a PR number — acceptable compromise.

Steps:

  1. Get commit list between the ref and HEAD:

    bash
    git log --oneline --reverse <ref>..HEAD

    If no commits found (HEAD is at or behind <ref>), inform the user and stop.

  2. Check commit count: If more than 20 commits, ask the user before proceeding:

    AskUserQuestion: Found <N> commits to review. Reviewing all of them will be slow and consume significant context. How to proceed?
    
    Options:
    1. Review all <N> commits
    2. Review only the last 20
    3. Cancel

    Based on choice:

    • "Review all" → continue with the full commit list
    • "Review only the last 20" → truncate the list to the 20 most recent commits (keep chronological order)
    • "Cancel" → inform the user that review was cancelled → STOP
  3. Review each commit:

    bash
    git show <commit-hash> --stat
    git show <commit-hash>

    For each commit check:

    • Does the commit message match the actual changes?
    • Are changes atomic (single logical unit per commit)?
    • Are there any issues introduced in this specific commit?
  4. Provide combined summary with per-commit notes

Context Gates (Read-Only)

Before finalizing review findings, run read-only context gates:

  • Check the resolved architecture artifact (if present) for boundary/dependency alignment issues.
  • Check the resolved RULES.md artifact (if present) for explicit convention violations.
  • Check the resolved roadmap artifact (if present) for milestone alignment and mention missing linkage for likely feat/fix/perf work.

Human gate result severity:

  • WARN for non-blocking inconsistencies or missing optional files.
  • ERROR only for explicit blocking criteria requested by the user/review policy.

If the user wants a standalone rules-only pass, suggest /aif-rules-check. Keep human /aif-review gate labels at WARN / ERROR, then append the standard machine-readable gate result with pass|warn|fail status.

Machine-readable gate result

This section is the single owner of aif-gate-result computation:

  • Append one final fenced aif-gate-result JSON block after the human-readable review.
  • Use "gate": "review".
  • "status": "pass|warn|fail" — the more severe (fail > warn > pass) of two independent inputs:
    • findings input — fail when any "Critical Issues" item remains (critical correctness, security, data-loss, performance, downstream regression — see references/SEVERITY.md for the authoritative critical/suggestion definitions); warn when only "Suggestions", missing optional context, or review uncertainty remain; pass when nothing material remains.
    • context-gate input — fail for a blocking (ERROR) gate finding; warn for a non-blocking (WARN) one; pass when none.
    • A failing context gate keeps "status" at fail even with zero Critical Issues — a clean findings list must never mask a failed gate.
  • "blocking": true|false — true only when "status" is fail.
  • "blockers" — merge-blocking findings only: every "Critical Issues" item and every blocking context-gate finding, nothing else.
  • "affected_files" — reviewed or implicated paths.
  • "suggested_next.command" follows "status": fail → /aif-fix by default, but if every blocker came from a single context gate point at that gate's command instead (rules gate → /aif-rules, architecture gate → /aif-architecture, roadmap gate → /aif-roadmap); warn/pass → /aif-commit; null only when no command fits.

/aif-review is read-only for context artifacts by default. Do not modify context files unless user explicitly asks.

Show full SKILL.md (573 more words)Show less
Project Context

Read .ai-factory/skill-context/aif-review/SKILL.md — MANDATORY if the file exists.

This file contains project-specific rules accumulated by /aif-evolve from patches, codebase conventions, and tech-stack analysis. These rules are tailored to the current project.

How to apply skill-context rules:

  • Treat them as project-level overrides for this skill's general instructions
  • When a skill-context rule conflicts with a general rule written in this SKILL.md, the skill-context rule wins (more specific context takes priority — same principle as nested CLAUDE.md files)
  • When there is no conflict, apply both: general rules from SKILL.md + project rules from skill-context
  • Do NOT ignore skill-context rules even if they seem to contradict this skill's defaults — they exist because the project's experience proved the default insufficient
  • CRITICAL: skill-context rules apply to ALL outputs of this skill — including the review summary format and the checklist criteria. If a skill-context rule says "review MUST check X" or "summary MUST include section Y" — you MUST augment the output accordingly. Producing a review that ignores skill-context rules is a bug.

Enforcement: After generating any output artifact, verify it against all skill-context rules. If any rule is violated — fix the output before presenting it to the user.

Review Checklist

Correctness
  • Logic errors or bugs
  • Edge cases handling
  • Null/undefined checks
  • Error handling completeness
  • Type safety (if applicable)
Security
  • SQL injection vulnerabilities
  • XSS vulnerabilities
  • Command injection
  • Sensitive data exposure
  • Authentication/authorization issues
  • CSRF protection
  • Input validation
Performance
  • N+1 query problems
  • Unnecessary re-renders (React)
  • Memory leaks
  • Inefficient algorithms
  • Missing indexes (database)
  • Large payload sizes
Best Practices
  • Code duplication
  • Dead code
  • Magic numbers/strings
  • Proper naming conventions
  • SOLID principles
  • DRY principle
Testing
  • Test coverage for new code
  • Edge cases tested
  • Mocking appropriateness

Output Format

markdown
## Code Review Summary

**Files Reviewed:** [count]
**Risk Level:** 🟢 Low / 🟡 Medium / 🔴 High

### Context Gates
[Architecture / Rules / Roadmap gate results with WARN/ERROR labels]

### Critical Issues
[Each item is a short paragraph in prose, not a labeled record. Order inside the paragraph:
1. Behavioral impact — what breaks for the user or downstream code.
2. Optional note — a code citation, a consequence, or extra context. Include only if it adds signal; skip otherwise.
3. Path — file:line of the affected location (or the closest anchor).
4. Suggested fix — concrete edit that addresses the behavior above.

Example:
> Two clients buying the last item both get a confirmation and stock goes negative — the order creation and stock reservation run in separate transactions. `src/services/order.ts:42`. Wrap `OrderService.create` and `InventoryService.reserve` in a shared transaction so the second buyer fails fast with "out of stock".]

### Suggestions
[Same item shape as Critical Issues. The behavioral impact describes a non-blocking improvement (clarity, performance budget, missing log), not a bug.]

### Questions
[Free-form clarifications. Path optional, fix optional — these are open questions for the author, not findings.]

### Positive Notes
[Free-form acknowledgements of good patterns. No path/fix required.]

When +check reclassifies an item, a short [+check: …] suffix is appended to the item text; see references/CHECK-MODE.md for the exact wording.

Append the final machine-readable result after the markdown summary:

aif-gate-result
{
  "schema_version": 1,
  "gate": "review",
  "status": "pass",
  "blocking": false,
  "blockers": [],
  "affected_files": [],
  "suggested_next": {
    "command": "/aif-commit",
    "reason": "Review found no blocking issues."
  }
}

When the +check flag is set, the aif-gate-result block is assembled after validator filtering — status, blockers, affected_files, and suggested_next are recomputed accordingly. Exception: the whole-dispatch failure path keeps the unfiltered original list and does NOT recompute these fields. See references/CHECK-MODE.md for the full procedure.

Review Style

  • Be constructive, not critical
  • Explain the "why" behind suggestions
  • Provide code examples when helpful
  • Acknowledge good code
  • Prioritize feedback by importance
  • Ask questions instead of making assumptions

Examples

User: /aif-review Review staged changes in current repository.

User: /aif-review 123 Review PR #123 using GitHub CLI.

User: /aif-review https://github.com/org/repo/pull/123 Review PR from URL.

User: /aif-review 2.x Review all commits on the current branch compared to branch 2.x.

User: /aif-review main Review all commits on the current branch compared to main (or to whatever branch is configured as git.base_branch in this repository).

User: /aif-review v1.0.0 Review all commits on the current branch compared to tag v1.0.0.

User: /aif-review +check Review staged changes, then run the +check validator over Critical Issues and Suggestions before rendering. The validator can drop invented items, rewrite partially-correct ones, and reclassify items between the two severity levels (promote a suggestion to critical or demote a critical to suggestion — see references/SEVERITY.md for the rules). It adds a filtering-summary line and rebuilds the gate result from the surviving findings; see references/CHECK-MODE.md for the exact line format.

User: /aif-review 123 +check Review PR #123 with +check validation enabled.

Integration

If GitHub MCP is configured, can:

  • Post review comments directly to PR
  • Request changes or approve
  • Add labels based on review outcome

Tip: Context is heavy after code review. Consider /clear or /compact before continuing with other tasks.

© unxed, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .agents/skills/aif-review of unxed/f4.

  • SKILL.md
  • references/CHECK-MODE.md
  • references/SEVERITY.md
  • references/VALIDATOR.md

Open the folder on GitHubat commit 772edc7

Compare with similar skills

Aif Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aif Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aif Review this skillunxed/f4243—~3.3kAutomated safety check: PassBSD-3-Clause
Parallel Specialist PR Reviewposhan0126/dotclaude870—~1.7kAutomated safety check: PassMIT
Code Reviewvinvcn/mattpocock-skills-zh-CN4.7k—~1.1kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything86k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Parallel Specialist PR Review

    poshan0126/dotclaude

    Reviews a pull request, staged changes or a file by sending the diff to specialist reviewer agents in parallel, then merges their findings into one compact report.

    870 GitHub stars~1.7k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Code Review

    vinvcn/mattpocock-skills-zh-CN

    从固定点(commit、branch、tag 或 merge-base)开始,按 Standards(代码是否符合本仓库记录的编码标准?)和 Spec(代码是否符合来源 issue/spec 的要求?)两个轴线审查变更。两个审查会在并行子代理中运行,并并排报告。适用于用户想审查 branch、PR、进行中的变更,或要求“review since X”时。

    4.7k GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    180k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from unxed/f4

All 36 skills in this repo
  • Comprehensive documentation guide for Golang projects, covering godoc comments, README, CONTRIBUTING, CHANGELOG, Go Playground, Example tests, API docs, and llms.txt.

    244 GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check passed
  • Golang code style conventions — line length and breaking, variable declarations, control flow clarity, when comments help vs hurt.

    244 GitHub starsUsed in 3 repos~2.5k tokens
    Auto-check passed
  • Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…

    244 GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check passed
  • Security audit checklist based on OWASP Top 10 and best practices.

    244 GitHub stars~5.4k tokensUpdated today
    Auto-check: notes
  • Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and…

    244 GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed
  • Golang concurrency design — goroutine lifecycle and leak prevention, channels and select, channel ownership and direction, sync.Mutex/RWMutex/sync.Map/sync.Once/atomics, errgroup, singleflight…

    244 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed

Works with

Categories

Questions about Aif Review

What does Aif Review do?

Perform code review on staged changes or a pull request. An agent skill from unxed/f4. Aif Review is an agent skill from unxed/f4. Perform code review on staged changes or a pull request.

When should I use Aif Review?

Aif Review fits situations like: user says review code; is this code okay.

How do I install Aif Review in Claude Code?

Run `npx skills add unxed/f4 --skill aif-review -a claude-code`. Or copy the skill folder (.agents/skills/aif-review in unxed/f4) into .claude/skills/aif-review in your project. Claude Code loads it when a task matches its description.

How do I install Aif Review in Codex?

Run `npx skills add unxed/f4 --skill aif-review -a codex`. Or copy the skill folder (.agents/skills/aif-review in unxed/f4) into .agents/skills/aif-review in your project. Codex loads it when a task matches its description.

Can I use Aif Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unxed/f4 --skill aif-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aif-review, .gemini/skills/aif-review, .github/skills/aif-review and .opencode/skills/aif-review in your project.

What does Aif Review need to run?

Going by SKILL.md and its folder, Aif Review needs the command-line tools its instructions call (git and gh). Its frontmatter pre-approves these tools: Bash(git *), Bash(gh *), Read, Glob, Grep, Task, Agent, AskUserQuestion.

Does Aif Review access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Aif Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aif Review use?

Aif Review is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aif Review use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Aif Review?

Skills that share tags, products or a category with Aif Review: Parallel Specialist PR Review (poshan0126/dotclaude, 870 stars), Code Review (vinvcn/mattpocock-skills-zh-CN, 4.7k stars), Open Code Review CLI (alibaba/open-code-review, 46k stars) and GitHub Review Iteration (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aif Review?

unxed (a GitHub user) maintains it in unxed/f4, which has 243 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 10, 2026.

Source: unxed/f4 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.