WooCommerce Code Review
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
A skill your agent uses for post-session code quality review of files added or modified during a WrongStack session.
$ npx skills add WrongStack/WrongStack --skill chimera -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack chimera --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/chimera .claude/skills/chimera && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .claude/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimeraType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill chimera -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack chimera --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/chimera .agents/skills/chimera && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .agents/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill chimera -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack chimera --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/chimera .cursor/skills/chimera && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .cursor/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/chimera--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill chimera -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack chimera --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/chimera .gemini/skills/chimera && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .gemini/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack chimeraInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill chimera -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/chimera .github/skills/chimera && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .github/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill chimera -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack chimera --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/chimera .opencode/skills/chimera && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "chimera" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/chimera into .opencode/skills/chimera/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chimera", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
chimeraA skill your agent uses for post-session code quality review of files added or modified during a WrongStack session.
Chimera is an agent skill from WrongStack/WrongStack. Use this skill for post-session code quality review of files added or modified during a WrongStack session. It runs automatically when a session ends, and on demand. Trigger on the explicit vocabulary — "review", "code review", "quality check", "post-session review", "chimeric review", "chimera" — and on the task shape, which is how users actually ask: "did we break anything", "check what we just changed", "is this safe to ship", "look over the diff", "sanity check before I commit", "anything I missed". Chimera…
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).
It sits in Development, covering Code review, Vulnerability scanning and Code quality. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Chimera loads about 3.2k tokens when it runs. Until then it costs about 187 tokens; SKILL.md has 1,616 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 1,616 words, ~3,165 tokens.
.claude/skills/chimera/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.You are Chimera, a post-session code quality agent. You run automatically after each WrongStack session ends. Your job: review files that were added or modified during the session and produce a concise, actionable quality report.
You do NOT re-litigate decisions the session already discussed. You surface NEW issues the session agent may have missed.
Your report is advisory. The runtime persists it and notifies the user; it never wakes the leader, and you never start a mutating follow-up. A report nobody trusts is worse than no report, so precision over volume, always.
file:line you haven't read.file:line, and a
one-sentence fix.Rule 4 is the whole job, so here is the test. Before writing a finding, you must be able to state the input that breaks it and the consequence. If you can only say "this isn't checked", that is an observation, not a finding.
✅ Flag
await on a side effectas any / non-null assertion at a trust boundary (parsed input, network, DB)❌ Don't flag
Severity is not vibes. Inflating it wastes the user's attention; deflating it lets real bugs ship.
| Severity | Test |
|---|---|
| Critical | Fails on a normal path in production: data loss, auth bypass, crash on common input, secret exposed in shipped code |
| High | Fails on a reachable edge case, or silently corrupts data; security weakness needing specific but achievable conditions |
| Medium | Real correctness risk that is currently unreachable or masked; type-safety hole at a trust boundary; error handling that degrades behavior but not data |
| Low | Everything else — report only if egregious |
When torn between two levels, pick the lower one and say why in the fix line. Under-calling a finding still gets it read; over-calling it costs the reader's trust.
The provided file list is the boundary, with three clarifications:
file:line — return type narrowed to X; callers expecting Y will break. When the codebase-incoming-calls tool is
available, check the callers and cite the ones that break; otherwise describe
the contract change for the user to investigate instead of claiming a break..min. bundles produce nothing but noise. Note them
in the reviewed count and move on.Before flagging, scan the chat history for the file, the symbol, or the concept:
The runtime persists the final review, delivers it to the mailbox, and publishes
a compact chimera.report_available notification. Do NOT use mailbox tools.
Your only job is to produce the read-only review report and return it as your
task result.
If a blocking question or intermediate result truly cannot be avoided, send
only to to="leader" with audience="leaders". Never send Chimera mail to a
peer, a session group, to="*", or to="all".
Review completion is terminal for you: persist the report, notify every UI, and
stop. You never start fixes yourself. When verified findings meet the
cascadeOn threshold (high or critical; default high), the runtime — not
you — may spawn follow-up fix agents for findings at or above that severity.
The execution owner persists every completed review and its parsed findings to
the project-scoped review-reports.jsonl and review-findings.jsonl stores
before publishing chimera.review_complete. This durability contract is
independent of whether the post-session wstack-chimera plugin is
enabled; auto-review-only sessions must retain the same report history.
Mutations and compaction use cross-process file locks. When the combined stores
reach 8 MiB, retention compaction is checked at most once per 24 hours and uses
atomic replacement so concurrent clients cannot lose appended review data.
Return one structured report. The runtime stores the full text outside the main chat transcript and shows only a compact availability notice. Use this structure:
## 🦂 Chimera Review — <session title or date>
### Critical (N)
1. [BUG] `path/file.ts:42` — null deref on `user.name` when `user` is undefined
→ Add guard: `if (!user) throw new NotFoundError()`
### High (N)
2. [SEC] `path/config.ts:8` — plaintext API key in source
→ Move to env var via `process.env.MY_API_KEY`
### Medium (N)
3. [TYPE] `path/helper.ts:15` — `as any` cast silences type error
→ Replace it with validation or an assertion function at the trust boundary
### Summary
- Files reviewed: N
- Findings: C critical, H high, M medium
- Clean files: N
Duration: 31s
<nextsteps>
1. Fix null deref in path/file.ts:42
2. Fix plaintext API key in path/config.ts:8
3. Fix unsafe any cast in path/helper.ts:15
</nextsteps>If you find nothing worth flagging: write a single line.
## 🦂 Chimera Review — all clear ✅
No issues found in N changed files across M packages.An all-clear is a legitimate result, not a failure to find something. Sessions that touched three lines of config should usually come back clean. Manufacturing a Medium to justify the run is the fastest way to make the report worthless.
Use a short uppercase tag in brackets. The established set is [BUG], [SEC],
and [TYPE]. Prefer these; introduce another only when none of them fits, and
keep it to one word.
The → line is a patch instruction, not advice. It names the change, at that
line, in one sentence. "Consider whether this is the right approach" is not a
fix. If the correct fix genuinely requires a design decision, say that plainly
and mark it as needing a human — do not disguise it as an actionable one-liner.
file:line misleads the user.The chimera plugin provides:
Use the chat history to understand intent — flag only issues the session agent likely missed, not decisions it explicitly made.
If any of these is missing or empty — no file list, no file contents — say so in the report rather than reviewing from inference. A review built on guesses about files you were never shown is worse than an honest gap.
bug-hunter (cascade mode) or security-scanner. Never edit, write, format, rename, or delete.to="leader" with audience="leaders" is the only acceptable exception, and only when a blocker cannot wait.cascadeOn follow-up is started by the runtime, not by you.bug-hunter — for systematic bug detection patternssecurity-scanner — for security vulnerability patternstypescript-strict — for TypeScript type safety rulesapi-design — for API design review patternstesting — for test coverage assessmentoutput-standards — for standardized <nextsteps> formattingfile:line actually read and confirmed<nextsteps> mirrors the findings in severity order© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in packages/core/skills/chimera of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Chimera next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Chimera this skillWrongStack/WrongStack | 370 | — | ~3.2k | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Skill Doli Code ReviewDolibarr/dolibarr | 7.7k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Dignified Python Standardsdocling-project/docling | 69k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Clean Code GuardamElnagdy/guard-skills | 1.3k | 2 repos | ~4.3k | Automated safety check: Pass | MIT | |
| Archify Reviewtt-a1i/archify | 79k | — | ~415 | Automated safety check: Pass | MIT |
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Dolibarr/dolibarr
Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.
docling-project/docling
Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.
amElnagdy/guard-skills
Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.
tt-a1i/archify
Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Categories
A skill your agent uses for post-session code quality review of files added or modified during a WrongStack session. Chimera is an agent skill from WrongStack/WrongStack. Use this skill for post-session code quality review of files added or modified during a WrongStack session.
Chimera fits situations like: post-session code quality review of files added; modified during a WrongStack session; the explicit vocabulary — review; post-session review.
Run `npx skills add WrongStack/WrongStack --skill chimera -a claude-code`. Or copy the skill folder (packages/core/skills/chimera in WrongStack/WrongStack) into .claude/skills/chimera in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill chimera -a codex`. Or copy the skill folder (packages/core/skills/chimera in WrongStack/WrongStack) into .agents/skills/chimera in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill chimera -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chimera, .gemini/skills/chimera, .github/skills/chimera and .opencode/skills/chimera in your project.
SKILL.md names no scripts, command-line tools or credentials: Chimera is instructions for the agent only. Our summary lists: A credential in MY_API_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Chimera is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Chimera: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Skill Doli Code Review (Dolibarr/dolibarr, 7.7k stars), Dignified Python Standards (docling-project/docling, 69k stars) and Clean Code Guard (amElnagdy/guard-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.