WooCommerce Code Review
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Runs parallel review agents over a branch, chosen paths or a whole project and merges their findings into one numbered report you can act on by id.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review .claude/skills/review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .claude/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/review .agents/skills/review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .agents/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/review .cursor/skills/review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .cursor/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/VeryGoodOpenSource/vgv-wingspan.git --path skills/review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/review .gemini/skills/review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .gemini/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install VeryGoodOpenSource/vgv-wingspan reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/review .github/skills/review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .github/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/review .opencode/skills/review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/review into .opencode/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewRuns parallel review agents over a branch, chosen paths or a whole project and merges their findings into one numbered report you can act on by id.
Scope comes from file paths you pass, from a detection script that lists the files changed on the current branch, or, on the default branch, from a question asking whether to review chosen paths or the entire project. Each run gets its own folder under docs/code-review named after a scope slug, so one review never overwrites another branch's report.
Default review agents run in parallel against the Very Good Ventures standards for architecture, tests and simplicity, and a project can add its own agents in CLAUDE.md or replace the defaults. Raw per-agent reports are consolidated into a single report with stable numbered findings, and a reference covers filing findings on a pull request. It needs an agent-capable host, with gh or glab for pull request work.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 19e0695. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(*/scripts/detect-review-scope.sh)Bash(gh *)Bash(glab *)From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code (or similar products with agent support)
From compatibility in the SKILL.md frontmatter.
On-Demand Code Review loads about 1.7k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 856 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from VeryGoodOpenSource/vgv-wingspan at commit 19e0695, republished under its MIT licence (© VeryGoodOpenSource). 856 words, ~1,727 tokens.
.claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Run quality review agents. Review manually written code, assess existing codebases, or check a branch before merging. Output is one consolidated report with stable, numbered findings the user can act on by id.
<review_scope>$ARGUMENTS</review_scope>
Parse the review scope above for optional file paths or directories.
If paths are provided:
/ with - (lib/auth/ → lib-auth,
lib/auth/token.dart → lib-auth-token). Same paths always give the same slug.If no paths provided:
Run the scope detection script:
${CLAUDE_SKILL_DIR}/scripts/detect-review-scope.shSCOPE=branch: use the listed files as scope. The scope slug is the current
branch name with / replaced by -. Announce scope summary (changed-file count, areas
affected) and proceed to Step 2.SCOPE=default: tell the user "You're on <CURRENT_BRANCH>. No branch diff
available." Use AskUserQuestion: "What would you like to review?" with options:project.Run pwd and let <PWD> be the result — subagents may change directories, making relative
paths unreliable. Each run gets its own directory <PWD>/docs/code-review/<slug>/, so raw
per-agent reports go in <PWD>/docs/code-review/<slug>/raw/ (absolute) and one run never
clobbers another branch's kept report.
Run the default review agents below in parallel. Projects may add agents in their
CLAUDE.md (include them alongside the defaults) or replace the default set entirely.
Each agent prompt must include:
<RAW_DIR> set to <PWD>/docs/code-review/<slug>/raw and <name> set to the agent's
report name below (a bare stem — the agent writes <RAW_DIR>/<name>.md). Substitute
<PWD> and <slug> with their resolved values — do not pass a relative path.Default agents and their report names (<name>):
| Agent | Report name |
|---|---|
| @vgv-review-agent | vgv-review |
| @architecture-review-agent | architecture-review |
| @test-quality-review-agent | test-quality-review |
| @code-simplicity-review-agent | code-simplicity-review |
If an agent fails: note it, continue with the successful agents, and record the failure in the report header and chat summary so the user knows the review is incomplete. Offer to retry.
Follow the review consolidation procedure:
FINDING-NN ids.<PWD>/docs/code-review/<slug>/review.md using the
report template.If no findings: write the short all-clear report and tell the user the code looks good.
This skill is advisory — take no action until the user picks one. Use AskUserQuestion to present post-review options (the ids and rules follow the consolidation procedure's "Acting on findings" section):
tests/missing-test-file").docs/code-review/<slug>/ for manual review.After fixing (if chosen): re-run linter + test runner (no agent re-run), then present a brief summary of which findings (by id) were fixed.
docs/code-review/<slug>/ directory (report + raw/). Re-running
the same scope overwrites only that slug's directory; a different branch or path uses a
different slug, so a report you keep is never clobbered by a later run of another scope.FINDING-03 keeps pointing at the same issue. Each
finding also carries a stable rule id (e.g. vgv/missing-null-check) the user can act on
as a class.docs/code-review/<slug>/raw/
for drill-down and are linked from the consolidated file.© VeryGoodOpenSource, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/review of VeryGoodOpenSource/vgv-wingspan.
Open the folder on GitHubat commit 19e0695
On-Demand Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| On-Demand Code Review this skillVeryGoodOpenSource/vgv-wingspan | 108 | — | ~1.7k | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Skill Doli Code ReviewDolibarr/dolibarr | 7.7k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Dignified Python Standardsdocling-project/docling | 68k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Clean Code GuardamElnagdy/guard-skills | 1.3k | 2 repos | ~4.3k | Automated safety check: Pass | MIT | |
| Archify Reviewtt-a1i/archify | 79k | — | ~415 | Automated safety check: Pass | MIT |
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Dolibarr/dolibarr
Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.
docling-project/docling
Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.
amElnagdy/guard-skills
Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.
tt-a1i/archify
Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
VeryGoodOpenSource/vgv-wingspan
Rebases the current feature branch onto the latest main, master or develop, stashing uncommitted work first and aborting cleanly if conflicts appear.
VeryGoodOpenSource/vgv-wingspan
Clarifies what to build before how, by asking one question at a time about a feature idea and then handing the result on to planning.
VeryGoodOpenSource/vgv-wingspan
Stages, commits, pushes and opens a pull request with a Conventional Commits message, after running the project's checks unless told to skip them.
VeryGoodOpenSource/vgv-wingspan
Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.
VeryGoodOpenSource/vgv-wingspan
Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.
VeryGoodOpenSource/vgv-wingspan
Turns high-level brainstorming and ideas into well-structured, actionable implementation plans.
Categories
Runs parallel review agents over a branch, chosen paths or a whole project and merges their findings into one numbered report you can act on by id. Scope comes from file paths you pass, from a detection script that lists the files changed on the current branch, or, on the default branch, from a question asking whether to review chosen paths or the entire project. Each run gets its own folder under docs/code-review named after a scope slug, so one review never overwrites another branch's report.
On-Demand Code Review fits situations like: checking a branch before merging it; assessing an existing codebase against quality standards; reviewing hand-written code in one specific directory; turning review findings into numbered items you can pick from.
Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a claude-code`. Or copy the skill folder (skills/review in VeryGoodOpenSource/vgv-wingspan) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a codex`. Or copy the skill folder (skills/review in VeryGoodOpenSource/vgv-wingspan) into .agents/skills/review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.
Going by SKILL.md and its folder, On-Demand Code Review needs a shell for the scripts in its folder. Our summary lists: An agent host that supports parallel subagents; gh or glab for the pull request steps. Its frontmatter pre-approves these tools: Bash(*/scripts/detect-review-scope.sh), Bash(gh *), Bash(glab *). Compatibility (from SKILL.md): Designed for Claude Code (or similar products with agent support).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
On-Demand Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 49 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with On-Demand Code Review: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Skill Doli Code Review (Dolibarr/dolibarr, 7.7k stars), Dignified Python Standards (docling-project/docling, 68k stars) and Clean Code Guard (amElnagdy/guard-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
VeryGoodOpenSource (a GitHub organization) maintains it in VeryGoodOpenSource/vgv-wingspan, which has 108 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 30, 2026.
Source: VeryGoodOpenSource/vgv-wingspan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.