Agent skill

Auto Review

by WrongStack in WrongStack/WrongStack

A skill your agent uses to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session.

MITAuto-check passedDevelopment

Install Auto Review

skills CLI
$ npx skills add WrongStack/WrongStack --skill auto-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack auto-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/auto-review .claude/skills/auto-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auto-review
GitHub stars
370
Token cost
~1.8k tokens
SKILL.md length
700 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session.

  • Tasks that involve Subagents
  • SKILL.md covers Overview, Status, Requirements and Configuration, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Code review

What it does

Auto Review is an agent skill from WrongStack/WrongStack. Use this skill to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session. Triggers: user says "auto review", "otomatik review", "auto code review", "her değişiklikte review", "/auto-review".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Subagents and Code review. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Tasks that involve Subagents
  • Tasks that involve Code review

Example prompts

  • “auto review”
  • “otomatik review”
  • “auto code review”
  • “/auto-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 0fb4c17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auto Review loads about 1.8k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 700 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit 0fb4c17, republished under its MIT licence (© WrongStack). 700 words, ~1,786 tokens.

Download SKILL.mdSave it as .claude/skills/auto-review/SKILL.md (or your agent's skills folder).
name
auto-review
description
Use this skill to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session. Triggers: user says "auto review", "otomatik review", "auto code review", "her değişiklikte review", "/auto-review".
version
2.1.0
required-capabilities
version-control.manage
required-tools
git
optional-capabilities
fleet.delegate, verification.run

Auto Review — Built-in Plugin

Overview

The wstack-auto-review plugin (built into @wrongstack/core) detects every git-tracked file change during a session and automatically dispatches a review subagent after a trailing file-quiet window. It extends the Chimera review pipeline with mid-session reviews while leaving any work still waiting at session.ended to the post-session Chimera path.

iteration.completed → git diff → trailing quiet window → chimera.review_needed event
                                                   ↓
                                    Director spawns review subagent
                                    (provider/model from config)
                                                  ↓
                                    Severity-ranked report → store + mailbox
                                                  ↓
                                    chimera.review_complete event
                                                  ↓
                                    chimera.report_available notification
                                                  ↓
                                    stop (with cascadeOn set: follow-up fix agents)

Status

This is a built-in plugin (packages/core/src/plugins/auto-review-plugin.ts), NOT a skill-based watcher. It is loaded automatically and enabled by default. Optional overrides in your config:

json
{
  "extensions": {
    "wstack-auto-review": {
      "provider": "deepseek",
      "model": "deepseek-chat",
      "fallbackProfile": "reliable",
      "modelSelection": "round-robin",
      "debounceMs": 15000,
      "maxFilesPerBatch": 15
    }
  }
}

Requirements

  • --director flag (Director mode) — the subagent spawning pipeline (execution.ts) requires the Director to be active. Without it, review events are silently skipped.
  • git available in the session working directory.

Configuration

KeyTypeDefaultDescription
enabledbooleantrueMaster switch
providerstringsession providerLLM provider for review agents
modelstringsession modelLLM model for review agents
fallbackProfilestringeffective fallback profileNamed profile from fallbackProfiles; its first valid entry supplies the primary provider/model when those are omitted, and its entries form the reviewer selection and retry pool
modelSelectionround-robin | randomround-robinChoose each review's starting model in profile order or randomly; remaining entries stay available as fallbacks
debounceMsnumber15000Required file-quiet period before a mid-session review starts
maxFilesPerBatchnumber15Files per review call
maxConcurrentReviewsnumber2Parallel review subagent cap
cascadeOnoff | high | criticalhighFollow-up agents (bug-hunter / security-scanner) for verified findings at or above this severity
maxCascadeDepthnumber2Max fix → re-review cycles when the cascade triggers

Slash commands

CommandAction
/auto-reviewShow status + current config
/auto-review onEnable (via config update)
/auto-review offDisable

What is reviewed

  • Only git-tracked files with staged or unstaged changes; untracked (??) files are never read or reviewed
  • Content-aware — later edits to an already-modified file trigger again when its content fingerprint changes
  • Debounced without loss — rapid edits restart the quiet window; the latest content is reviewed in the background after the full window elapses
  • Lifecycle-safe — session.ended cancels a pending mid-session timer and hands those files to post-session Chimera
  • Capped at maxFilesPerBatch files per call; overflow stays pending
  • Skipped — .wrongstack/ files
  • Deleted files are silently omitted

Completion and cascade

Every completed review is persisted and announced through chimera.report_available. A report never becomes a normal assistant response or wakes the leader. By default (cascadeOn: "high") verified findings at High or Critical trigger follow-up fix agents (bug-hunter / security-scanner), bounded by maxCascadeDepth fix → re-review cycles; findings below that threshold leave the user to decide later whether to act. Set cascadeOn to "critical" or "off" to narrow or disable the cascade.

Show full SKILL.md (288 more words)Show less

Out of scope

  • Don't rely on auto-review without --director. The subagent pipeline requires Director mode; without it, review events silently skip. Verify the director is on before relying on its reviews.
  • Don't start the plugin while a session is mid-flight without a clear contract. Auto-review dispatches reviewers at trailing-quiet windows; the user has to know it's running.
  • Don't read untracked files. ?? files are never reviewed. If a reviewer needs a file, the workflow must have it staged or tracked first.
  • Don't manually trigger a fix from a report. The report goes to the mailbox and notifies UIs. A follow-up fix is a separate user-initiated turn unless the cascadeOn threshold (default high) triggers the correction cascade.
  • Don't re-route the report to mailbox peers or the leader. Runtime handles persistence and notification. Manual mailbox traffic from auto-review is double-handling.
  • Don't tune maxFilesPerBatch above 15 without measuring cost. Larger batches cut parallelism gains and inflate single-review latency.
  • Don't set the debounce below 5s. Too-aggressive debounce starts reviews while the user is still mid-edit; they hit a reviewer they didn't ask for.

Before reporting

  • --director mode is on (auto-review requires it)
  • wstack-auto-review is enabled (the default — check nothing set enabled: false)
  • git is available in the session working directory
  • Only git-tracked files are reviewed; untracked files skipped
  • Reports go to the mailbox + chimera.report_available notification, not to peer mail
  • Follow-up fix agents only when findings meet the cascadeOn threshold (default high)
  • Debounce and maxFilesPerBatch tuned for the workload, not at default

Skills in scope

  • chimera — for the review output format and severity rules
  • node-modern — for understanding the TypeScript plugin code
  • git-flow — for git diff detection patterns
  • multi-agent — for subagent delegation and fleet management
  • security-scanner — for security vulnerability patterns
  • bug-hunter — for systematic bug detection

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/auto-review of WrongStack/WrongStack.

Open the folder on GitHubat commit 0fb4c17

Compare with similar skills

Auto Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auto Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auto Review this skillWrongStack/WrongStack370—~1.8kAutomated safety check: PassMIT
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT
Local PR Reviewwindmill-labs/windmill18k—~995Automated safety check: PassCustom licence

Similar skills

  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Local PR Review

    windmill-labs/windmill

    Runs the same code review locally that GitHub's auto-review actions run on a PR, delegating to a fresh-context subagent so the review isn't biased by the main session's own reasoning.

    18k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed
  • Auto Devflow

    HuangPuStar/FenixAgent

    A skill your agent uses when starting an issue, bugfix, feature, or refactor that should be driven by multiple coordinated subagents: explore → plan → code → review, with the main agent acting as…

    552 GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    370 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    370 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    370 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    370 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    370 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    370 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed

Questions about Auto Review

What does Auto Review do?

A skill your agent uses to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session. Auto Review is an agent skill from WrongStack/WrongStack. Use this skill to configure and understand the built-in auto-review plugin (wstack-auto-review) that fires automated code review subagents on every code change during a session.

When should I use Auto Review?

Auto Review fits situations like: tasks that involve Subagents; tasks that involve Code review.

How do I install Auto Review in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill auto-review -a claude-code`. Or copy the skill folder (packages/core/skills/auto-review in WrongStack/WrongStack) into .claude/skills/auto-review in your project. Claude Code loads it when a task matches its description.

How do I install Auto Review in Codex?

Run `npx skills add WrongStack/WrongStack --skill auto-review -a codex`. Or copy the skill folder (packages/core/skills/auto-review in WrongStack/WrongStack) into .agents/skills/auto-review in your project. Codex loads it when a task matches its description.

Can I use Auto Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill auto-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auto-review, .gemini/skills/auto-review, .github/skills/auto-review and .opencode/skills/auto-review in your project.

What does Auto Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Auto Review is instructions for the agent only.

Does Auto Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auto Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auto Review use?

Auto Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auto Review use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auto Review?

Skills that share tags, products or a category with Auto Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auto Review?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 8, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.