Agent skill

Code Review

by yangyuan-zhen in yangyuan-zhen/PolyWeather

“[OMX] Run a comprehensive code review”

— description from SKILL.md by yangyuan-zhen
AGPL-3.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add yangyuan-zhen/PolyWeather --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yangyuan-zhen/PolyWeather code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yangyuan-zhen/PolyWeather.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
315
Token cost
~3.2k tokens
SKILL.md length
1,163 words
Files
1
Skills in repo
26
Repo updated
First seen
Licence
AGPL-3.0

At a glance

  • Works in 7 steps: Identify Changes → Launch Parallel Review Lanes → Review Categories → …
  • SKILL.md covers When to Use, GPT-5.6 Guidance Alignment, State/HUD Phase Contract and Agent Delegation, plus 8 more sections
  • Calls git and make

About this skill

Code Review is a skill in yangyuan-zhen/PolyWeather (315 stars). Its SKILL.md is about 3.2k tokens. Licence: AGPL-3.0.

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify Changes
  2. Launch Parallel Review Lanes
  3. Review Categories
  4. Severity Rating
  5. Architectural Status Contract
  6. Specific Recommendations
  7. Final Synthesis

What it can do on your machine

Read from SKILL.md and the folder at commit 43e658b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 3.2k tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 1,163 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~12
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yangyuan-zhen/PolyWeather at commit 43e658b, republished under its AGPL-3.0 licence (© yangyuan-zhen). 1,163 words, ~3,194 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
[OMX] Run a comprehensive code review

Code Review Skill

Conduct a thorough code review for quality, security, and maintainability with severity-rated feedback.

When to Use

This skill activates when:

  • User requests "review this code", "code review"
  • Before merging a pull request
  • After implementing a major feature
  • User wants quality assessment

GPT-5.6 Guidance Alignment

  • Default to outcome-first progress and completion reporting: state the target result, evidence, validation status, and stop condition before adding process detail.
  • Treat newer user task updates as local overrides for the active workflow branch while preserving earlier non-conflicting constraints.
  • If correctness depends on additional inspection, retrieval, execution, or verification, keep using the relevant tools until the review is grounded; stop once enough evidence exists.
  • Continue through clear, low-risk, reversible next steps automatically; ask only when the next step is materially branching, destructive, credentialed, external-production, or preference-dependent.

Delegates to the code-reviewer and architect agents in parallel for a two-lane review:

  1. Identify Changes

    • Run git diff to find changed files
    • Determine scope of review (specific files or entire PR)
  2. Launch Parallel Review Lanes

    • code-reviewer lane - owns spec compliance, security, code quality, performance, and maintainability findings
    • architect lane - owns the devil's-advocate / design-tradeoff perspective
    • Both lanes run in parallel on a clean context with explicit scope and artifacts, and produce distinct outputs before final synthesis
    • If either lane cannot be launched or does not return evidence, report independent review unavailable; do not substitute the current/authoring lane, and do not approve or mark the review merge-ready.
  3. Review Categories

    • Security - Hardcoded secrets, injection risks, XSS, CSRF
    • Code Quality - Function size, complexity, nesting depth
    • Performance - Algorithm efficiency, N+1 queries, caching
    • Best Practices - Naming, documentation, error handling
    • Maintainability - Duplication, coupling, testability
  4. Severity Rating

    • CRITICAL - Security vulnerability (must fix before merge)
    • HIGH - Bug or major code smell (should fix before merge)
    • MEDIUM - Minor issue (fix when possible)
    • LOW - Style/suggestion (consider fixing)
  5. Architectural Status Contract

    • CLEAR - No unresolved architectural blocker was found
    • WATCH - Non-blocking design/tradeoff concern that must appear in the final synthesis
    • BLOCK - Unresolved design concern that prevents a merge-ready verdict
  6. Specific Recommendations

    • File:line locations for each issue
    • Concrete fix suggestions
    • Code examples where applicable
  7. Final Synthesis

    • Combine the code-reviewer recommendation and the architect status into one final verdict
    • Approval requires explicit evidence from both independent lanes; missing or failed delegation is a blocking unavailable-review state, not an approval fallback
    • Deterministic merge gating rules:
      • If architect status is BLOCK, final recommendation is REQUEST CHANGES
      • Else if code-reviewer recommendation is REQUEST CHANGES, final recommendation is REQUEST CHANGES
      • Else if architect status is WATCH, final recommendation is COMMENT
      • Else final recommendation follows the code-reviewer lane
    • The final report must make architect blockers impossible to miss

State/HUD Phase Contract

Code-review is a merge-readiness gate and Autopilot child phase, not a standalone tracked mode with a code-review-state.json lifecycle. Keep HUD/current-phase state explicit and minimal:

  • Standalone $code-review activation: rely on the hook-owned skill-active-state.json entry (skill:"code-review", phase:"planning") for HUD visibility; do not create an ad-hoc code-review-state.json.
  • Inside active Autopilot: before review work starts, keep mode:"autopilot" active and set the supervised phase to current_phase:"code-review" / skill-active phase:"code-review"; do not activate a peer workflow over Autopilot.
  • On clean review: persist the review artifact/verdict under Autopilot handoff_artifacts.code_review and transition Autopilot to current_phase:"ultraqa" only after durable independent review evidence exists.
  • On non-clean review: persist the review artifact/verdict, set Autopilot current_phase:"rework" for implementation-only fixes or current_phase:"ralplan" when requirements/planning must change, and keep the findings as the scoped handoff.

Minimal Autopilot phase declaration when the review stage begins:

sh
omx state write --input '{"mode":"autopilot","active":true,"current_phase":"code-review"}' --json

Agent Delegation

Do not self-review as a fallback. If the code-reviewer or architect agent path is missing, unavailable, skipped, or fails, emit a clear unavailable-review result and block approval until the independent lane evidence exists.

Respect the user's current model and reasoning/effort selection when launching review lanes. Do not pass model or reasoning_effort overrides in the review-lane task calls unless the user explicitly asks for review-specific overrides; omitting them lets native subagents inherit the active session settings.

task(
  agent_type="code-reviewer",
  prompt="CODE REVIEW TASK

Review code changes for quality, security, and maintainability.

This is the code/spec/security lane. Do not absorb architectural ownership.

Scope: [git diff or specific files]

Review Checklist:
- Security vulnerabilities (OWASP Top 10)
- Code quality (complexity, duplication)
- Performance issues (N+1, inefficient algorithms)
- Best practices (naming, documentation, error handling)
- Maintainability (coupling, testability)

Output: Code review report with:
- Files reviewed count
- Issues by severity (CRITICAL, HIGH, MEDIUM, LOW)
- Specific file:line locations
- Fix recommendations
- Approval recommendation (APPROVE / REQUEST CHANGES / COMMENT)"
)

task(
  agent_type="architect",
  prompt="ARCHITECTURE / DEVIL'S-ADVOCATE REVIEW TASK

Review the same code changes from the architecture/tradeoff perspective.

Scope: [git diff or specific files]

Focus:
- System boundaries and interfaces
- Hidden coupling or long-term maintainability risks
- Tradeoff tension the main reviewer might miss
- Strongest counterargument against approving as-is

Output:
- Architectural Status: CLEAR / WATCH / BLOCK
- File:line evidence for each concern
- Concrete tradeoff or design recommendation"
)

Run both lanes in parallel, then synthesize them with the deterministic rules above.

External Model Consultation (Preferred)

The code-reviewer agent SHOULD consult Codex for cross-validation.

Protocol
  1. Form your OWN review FIRST - Complete the review independently
  2. Consult for validation - Cross-check findings with Codex
  3. Critically evaluate - Never blindly adopt external findings
  4. Graceful optional consultation fallback - Never block because optional external consultation tools are unavailable; this does not waive the required independent code-reviewer and architect lanes
Show full SKILL.md (452 more words)Show less
When to Consult
  • Security-sensitive code changes
  • Complex architectural patterns
  • Unfamiliar codebases or languages
  • High-stakes production code
When to Skip
  • Simple refactoring
  • Well-understood patterns
  • Time-critical reviews
  • Small, isolated changes
Tool Usage

Prefer native code-reviewer agent consultation or CLI-backed ask_codex surfaces when available. Optional MCP compatibility ask tools may be used only when already enabled. If optional external consultation tools are unavailable, continue with the required independent code-reviewer and architect lanes; do not replace those lanes with self-review.

Note: Codex calls can take up to 1 hour. Consider the review timeline before consulting.

Output Format

CODE REVIEW REPORT
==================

Files Reviewed: 8
Total Issues: 12
Architectural Status: WATCH

CRITICAL (0)
-----------
(none)

HIGH (0)
--------
(none)

MEDIUM (7)
----------
1. src/api/auth.ts:42
   Issue: Email normalization logic is duplicated instead of reusing the shared helper
   Risk: Validation rules can drift between authentication paths
   Fix: Route both paths through the shared normalization helper

2. src/components/UserProfile.tsx:89
   Issue: Derived permissions are recalculated on every render
   Risk: Avoidable work during profile refreshes
   Fix: Memoize the derived permissions list or compute it upstream

3. src/utils/validation.ts:15
   Issue: Form-layer and server-layer validation messages are defined separately
   Risk: User-facing validation guidance can become inconsistent
   Fix: Share one validation message helper across both call sites

LOW (5)
-------
...

ARCHITECTURE WATCHLIST
----------------------
- src/review/orchestrator.ts:88
  Concern: Review result synthesis relies on implicit ordering rather than an explicit blocker contract
  Status: WATCH
  Recommendation: Define deterministic merge gating before expanding reviewers

SYNTHESIS
---------
- code-reviewer recommendation: COMMENT
- architect status: WATCH
- final recommendation: COMMENT

RECOMMENDATION: COMMENT

Address any WATCH concerns before treating the change as merge-ready.

Review Checklist

The code-reviewer lane checks:

Security
  • No hardcoded secrets (API keys, passwords, tokens)
  • All user inputs sanitized
  • SQL/NoSQL injection prevention
  • XSS prevention (escaped outputs)
  • CSRF protection on state-changing operations
  • Authentication/authorization properly enforced
Code Quality
  • Functions < 50 lines (guideline)
  • Cyclomatic complexity < 10
  • No deeply nested code (> 4 levels)
  • No duplicate logic (DRY principle)
  • Clear, descriptive naming
Performance
  • No N+1 query patterns
  • Appropriate caching where applicable
  • Efficient algorithms (avoid O(n²) when O(n) possible)
  • No unnecessary re-renders (React/Vue)
Best Practices
  • Error handling present and appropriate
  • Logging at appropriate levels
  • Documentation for public APIs
  • Tests for critical paths
  • No commented-out code

Architect Lane Checklist

The architect lane checks:

  • Boundary or interface changes are explicit
  • New coupling/tradeoff risks are surfaced
  • Long-horizon maintainability concerns are evidence-backed
  • Architectural status is one of CLEAR, WATCH, or BLOCK
  • Any BLOCK concern cites the reason merge-ready status should be withheld

Approval Criteria

APPROVE - code-reviewer returns APPROVE, architect status is CLEAR, and both independent lanes returned evidence REQUEST CHANGES - code-reviewer returns REQUEST CHANGES, architect status is BLOCK, or required independent review delegation is unavailable/skipped/failed COMMENT - code-reviewer returns COMMENT with architect status CLEAR, architect status is WATCH, or only LOW/MEDIUM improvements remain

Scenario Examples

Good: The user says continue after the workflow already has a clear next step. Continue the current branch of work instead of restarting or re-asking the same question.

Good: The user changes only the output shape or downstream delivery step (for example make a PR). Preserve earlier non-conflicting workflow constraints and apply the update locally.

Bad: The user says continue, and the workflow restarts discovery or stops before the missing verification/evidence is gathered.

Use with Other Skills

With Team:

/team "review recent auth changes and report findings"

Includes coordinated review execution across specialized agents.

With Ralph:

/ralph code-review then fix all issues

On the explicit Ralph path, review findings should flow into automatic fix follow-up without another permission prompt. Plain code-review itself remains read-only and does not promise auto-fix.

With Ultrawork:

/ultrawork review all files in src/

Parallel code review across multiple files.

Best Practices

  • Review early - Catch issues before they compound
  • Review often - Small, frequent reviews better than huge ones
  • Address CRITICAL/HIGH first - Fix security and bugs immediately
  • Consider context - Some "issues" may be intentional trade-offs
  • Learn from reviews - Use feedback to improve coding practices

© yangyuan-zhen, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/code-review of yangyuan-zhen/PolyWeather.

Open the folder on GitHubat commit 43e658b

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillyangyuan-zhen/PolyWeather315—~3.2kAutomated safety check: PassAGPL-3.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from yangyuan-zhen/PolyWeather

All 26 skills in this repo
  • Doctor

    yangyuan-zhen/PolyWeather

    [OMX] Diagnose and fix oh-my-codex installation issues. An agent skill from yangyuan-zhen/PolyWeather.

    315 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Worker

    yangyuan-zhen/PolyWeather

    [OMX] Team worker protocol (ACK, mailbox, task lifecycle) for tmux-based OMX teams

    315 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • AI Slop Cleaner

    yangyuan-zhen/PolyWeather

    [OMX] Run an anti-slop cleanup/refactor/deslop workflow. An agent skill from yangyuan-zhen/PolyWeather.

    315 GitHub stars~2.2k tokensUpdated 18 days ago
    Auto-check passed
  • Analyze

    yangyuan-zhen/PolyWeather

    [OMX] Run read-only deep repository analysis and return a ranked synthesis with explicit confidence, concrete file references, and clear evidence-vs-inference boundaries.

    315 GitHub stars~1.6k tokensUpdated 18 days ago
    Auto-check passed
  • Autoresearch

    yangyuan-zhen/PolyWeather

    [OMX] Stateful validator-gated research loop with native-hook persistence

    315 GitHub stars~786 tokensUpdated 18 days ago
    Auto-check passed
  • Best Practice Research

    yangyuan-zhen/PolyWeather

    [OMX] Bounded best-practice research wrapper using official/upstream evidence first

    315 GitHub stars~1.4k tokensUpdated 18 days ago
    Auto-check passed

Categories

Questions about Code Review

How do I install Code Review in Claude Code?

Run `npx skills add yangyuan-zhen/PolyWeather --skill code-review -a claude-code`. Or copy the skill folder (.codex/skills/code-review in yangyuan-zhen/PolyWeather) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add yangyuan-zhen/PolyWeather --skill code-review -a codex`. Or copy the skill folder (.codex/skills/code-review in yangyuan-zhen/PolyWeather) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yangyuan-zhen/PolyWeather --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git and make).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

yangyuan-zhen (a GitHub user) maintains it in yangyuan-zhen/PolyWeather, which has 315 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 20, 2026.

Source: yangyuan-zhen/PolyWeather on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.