Agent skill

Vellum Change Review

by vellum-ai in vellum-ai/vellum-assistant

Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation.

MITAuto-check passedDevelopment

Install Vellum Change Review

skills CLI
$ npx skills add vellum-ai/vellum-assistant --skill vellum-change-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vellum-ai/vellum-assistant vellum-change-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vellum-ai/vellum-assistant.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/vellum-change-review .claude/skills/vellum-change-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vellum-change-review
GitHub stars
1.4k
Token cost
~618 tokens
SKILL.md length
248 words
Files
1
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation.

  • Works in 8 steps: Inspect the actual diff before judging… → Identify which packages are affected:… → Check package boundaries → …
  • Reviewing diffs
  • SKILL.md covers Review Stance, Required Checks and Review Output
  • Calls bun and bunx

What it does

Vellum Change Review is an agent skill from vellum-ai/vellum-assistant. Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation. Use when reviewing diffs, preparing a PR, finishing implementation work, or when the user asks for a code review, quality pass, or pre-merge check in this repository.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Quality gates. The repository describes itself as: An AI Assistant that’s easy to setup, does your work 24/7, knows your preferences and gets better over time. The licence is MIT.

When your agent uses it

  • Reviewing diffs
  • Finishing implementation work
  • The user asks for a code review
  • Pre-merge check in this repository

Example prompts

  • “/vellum-change-review”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the actual diff before judging the change.
  2. Identify which packages are affected: assistant, gateway, clients, cli, skills, packages, or meta.
  3. Check package boundaries
  4. Check persistence changes
  5. Check feature flags
  6. Check user-facing text
  7. Check LLM/provider usage
  8. Check tests and verification

What it can do on your machine

Read from SKILL.md and the folder at commit 33cc983. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vellum Change Review loads about 618 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 248 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~618

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vellum-ai/vellum-assistant at commit 33cc983, republished under its MIT licence (© vellum-ai). 248 words, ~618 tokens.

Download SKILL.mdSave it as .claude/skills/vellum-change-review/SKILL.md (or your agent's skills folder).
name
vellum-change-review
description
Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation. Use when reviewing diffs, preparing a PR, finishing implementation work, or when the user asks for a code review, quality pass, or pre-merge check in this repository.

Vellum Change Review

Review Stance

Prioritize bugs, behavioral regressions, security risks, migration gaps, broken package boundaries, and missing tests. Findings come before summaries. Avoid cosmetic feedback unless it affects correctness, maintainability, or user experience.

Required Checks

  1. Inspect the actual diff before judging the change.
  2. Identify which packages are affected: assistant, gateway, clients, cli, skills, packages, or meta.
  3. Check package boundaries:
    • assistant must not import from gateway by relative path.
    • gateway must not import from assistant by relative path.
    • assistant and skills must not import each other directly.
    • Runtime code must not import from meta.
  4. Check persistence changes:
    • DB schema or data changes need append-only DB migrations.
    • Workspace path, format, or file changes need append-only workspace migrations.
    • Migrations must be idempotent and registered.
  5. Check feature flags:
    • New assistant flags must be declared in meta/feature-flags/feature-flag-registry.json.
    • Default-disabled or rollout-only features must not ship user-facing release notes.
    • New flags may require a companion platform PR.
  6. Check user-facing text:
    • User-facing copy should say "assistant", not "daemon".
    • Examples must use generic names, emails, phone numbers, and IDs.
  7. Check LLM/provider usage:
    • LLM calls must go through the provider abstraction.
    • Comments and logs should use provider-agnostic wording.
  8. Check tests and verification:
    • Look for focused tests covering changed behavior.
    • Prefer scoped bun test path/to/test.ts; never suggest broad bun test.
    • Suggest bunx tsc --noEmit when type-level risk is broad.

Review Output

Use this structure:

markdown
## Findings
- [severity] `path`: issue, impact, and concrete fix.

## Open Questions
- Any uncertainty that affects correctness or review confidence.

## Verification Gaps
- Tests or checks that still need to run.

If no issues are found, say that clearly and still mention residual risk or unrun checks.

© vellum-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/vellum-change-review of vellum-ai/vellum-assistant.

Open the folder on GitHubat commit 33cc983

Compare with similar skills

Vellum Change Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vellum Change Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vellum Change Review this skillvellum-ai/vellum-assistant1.4k—~618Automated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills105k2 repos~5.2kAutomated safety check: PassMIT
PlotJuggler Ship CheckPlotJuggler/PlotJuggler6.2k—~1.3kAutomated safety check: PassMPL-2.0
Requesting Code ReviewHezaoHezao/poirot2495 repos~1.6kAutomated safety check: PassMIT
GAIA Agent Eval Scorecardamd/gaia1.6k—~2.6kAutomated safety check: PassMIT
Pull Requestnoh-rs/nohrs156—~4.1kAutomated safety check: PassMIT

Similar skills

  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    105k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • PlotJuggler Ship Check

    PlotJuggler/PlotJuggler

    Runs a gated finish-line checklist before committing a PlotJuggler PJ4 change: build proof, red-test triage, hooks, docs freshness and a diff self-review.

    6.2k GitHub stars~1.3k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    249 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Adds a release eval scorecard to a GAIA hub agent by writing a harness adapter, running a real eval, and wiring the result into the agent's README and release gate.

    1.6k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Pull Request

    noh-rs/nohrs

    Take a change from working tree to a merge-ready pull request, then keep iterating until the CI checks and AI reviewers (CodeRabbit, cubic) all pass.

    156 GitHub stars~4.1k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Compound Engineering Code Review

    EveryInc/compound-engineering-plugin

    Runs a staged pull request or diff review using selected reviewer personas, checking the change against its stated intent and project standards before producing findings.

    25k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed

More from vellum-ai/vellum-assistant

All 108 skills in this repo
  • Vellum GitHub App Setup

    vellum-ai/vellum-assistant

    Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

    1.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Discord App Setup

    vellum-ai/vellum-assistant

    Connect a Discord bot to the assistant via the Discord Gateway with guided application creation and intent configuration

    1.4k GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • Sentry App Setup

    vellum-ai/vellum-assistant

    Create and configure a Sentry internal integration so the assistant can manage issues, alerts, and releases under its own identity

    1.4k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Memory Corpus Ingest

    vellum-ai/vellum-assistant

    Ingest a large dataset into memory as a skimmed map. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~3k tokensUpdated 2 days ago
    Auto-check: notes
  • Plugin Builder

    vellum-ai/vellum-assistant

    A skill your agent uses when the user wants to build, scaffold, ship, or edit a Vellum plugin that bundles multiple surfaces (hooks, tools, skills, and more) into one installable package.

    1.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Slack App Setup

    vellum-ai/vellum-assistant

    Connect a Slack app to the Vellum Assistant via Socket Mode.

    1.4k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check: warnings

Questions about Vellum Change Review

What does Vellum Change Review do?

Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation. Vellum Change Review is an agent skill from vellum-ai/vellum-assistant. Review Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation.

When should I use Vellum Change Review?

Vellum Change Review fits situations like: reviewing diffs; finishing implementation work; the user asks for a code review; pre-merge check in this repository.

How do I install Vellum Change Review in Claude Code?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-change-review -a claude-code`. Or copy the skill folder (.cursor/skills/vellum-change-review in vellum-ai/vellum-assistant) into .claude/skills/vellum-change-review in your project. Claude Code loads it when a task matches its description.

How do I install Vellum Change Review in Codex?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-change-review -a codex`. Or copy the skill folder (.cursor/skills/vellum-change-review in vellum-ai/vellum-assistant) into .agents/skills/vellum-change-review in your project. Codex loads it when a task matches its description.

Can I use Vellum Change Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vellum-ai/vellum-assistant --skill vellum-change-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vellum-change-review, .gemini/skills/vellum-change-review, .github/skills/vellum-change-review and .opencode/skills/vellum-change-review in your project.

What does Vellum Change Review need to run?

Going by SKILL.md and its folder, Vellum Change Review needs the command-line tools its instructions call (bun and bunx).

Does Vellum Change Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vellum Change Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vellum Change Review use?

Vellum Change Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vellum Change Review use?

About 618 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vellum Change Review?

Skills that share tags, products or a category with Vellum Change Review: Constraint-Driven Development (addyosmani/agent-skills, 105k stars), PlotJuggler Ship Check (PlotJuggler/PlotJuggler, 6.2k stars), Requesting Code Review (HezaoHezao/poirot, 249 stars) and GAIA Agent Eval Scorecard (amd/gaia, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vellum Change Review?

vellum-ai (a GitHub organization) maintains it in vellum-ai/vellum-assistant, which has 1,408 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.

Source: vellum-ai/vellum-assistant on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.