Agent skill

Code Review Playbook

by yonatangross in yonatangross/orchestkit

Structured review processes, conventional comments, language-specific checklists, and feedback templates.

MITAuto-check passedDevelopment

Install Code Review Playbook

skills CLI
$ npx skills add yonatangross/orchestkit --skill code-review-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yonatangross/orchestkit code-review-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/code-review-playbook .claude/skills/code-review-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-playbook
GitHub stars
290
Token cost
~2.2k tokens
SKILL.md length
900 words
Files
17 (incl. scripts, references, assets)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Structured review processes, conventional comments, language-specific checklists, and feedback templates.

  • Works in 3 steps: Before Reviewing → During Review → After Reviewing
  • Conducting code review
  • SKILL.md covers Overview, Upstream coverage (do not…, Conventional Comments and Review Process, plus 6 more sections
  • Runs Shell and Python scripts from its folder

What it does

Code Review Playbook is an agent skill from yonatangross/orchestkit. Structured review processes, conventional comments, language-specific checklists, and feedback templates. Use when reviewing PRs, conducting code review, or standardizing review practice.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including scripts, reference files and assets (for example `assets/pr-template.md`, `examples/conventional-comments.md` and `references/conventional-comments.md`). Compatibility notes: Claude Code 2.1.277+.

It sits in Development, covering Code review. The repository describes itself as: The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install ork for stable (v9.x), or ork-alpha for the v10 line, which ships daily. The licence is MIT.

When your agent uses it

  • Conducting code review
  • Standardizing review practice

Example prompts

  • “/code-review-playbook”

Requirements

  • Python 3
  • A Bash shell
  • Compatibility (from SKILL.md): Claude Code 2.1.277+.
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, WebFetch, WebSearch

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Before Reviewing
  2. During Review
  3. After Reviewing

What it can do on your machine

Read from SKILL.md and the folder at commit 02bbf9a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • WebFetch
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell and Python, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • google.github.io
    • conventionalcomments.org
    • owasp.org
    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Claude Code 2.1.277+.

    From compatibility in the SKILL.md frontmatter.

Context cost

Code Review Playbook loads about 2.2k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 52 tokens; SKILL.md has 900 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from yonatangross/orchestkit at commit 02bbf9a, republished under its MIT licence (© yonatangross). 900 words, ~2,224 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-playbook/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
code-review-playbook
description
Structured review processes, conventional comments, language-specific checklists, and feedback templates. Use when reviewing PRs, conducting code review, or standardizing review practice.
allowed-tools
Read, Glob, Grep, WebFetch, WebSearch
compatibility
Claude Code 2.1.277+.
license
MIT
context
inherit
user-invocable
false
effort
low
model
haiku
metadata.category
document-asset-creation
metadata.version
2.0.0
metadata.author
OrchestKit
metadata.complexity
low
metadata.tags
code-review, quality, collaboration, best-practices, testing

Code Review Playbook

This skill provides a comprehensive framework for effective code reviews that improve code quality, share knowledge, and foster collaboration. Whether you're a reviewer giving feedback or an author preparing code for review, this playbook ensures reviews are thorough, consistent, and constructive.

Overview

  • Reviewing pull requests or merge requests
  • Preparing code for review (self-review)
  • Establishing code review standards for teams
  • Training new developers on review best practices
  • Resolving disagreements about code quality
  • Improving review processes and efficiency

Upstream coverage (do not restate)

This skill is a thin wrapper. General review craft is documented first-party elsewhere; only OrchestKit's own decisions live here. Load Read("references/ork-delta.md") for the house rules that survived the retired files.

TopicGo here instead
Review philosophy, speed, tone, PR sizinghttps://google.github.io/eng-practices/review/
Conventional comment labels and decorationsreferences/conventional-comments.md, https://conventionalcomments.org/
OWASP Top 10 review checksrules/security-baseline.md, https://owasp.org/Top10/
Generic language and framework review checklistsrules/typescript-quality.md, rules/python-quality.md, rules/linting-biome-rules.md
Review report shape and multi-agent full-PR reviework:review-pr
Applying findings to the working tree/code-review --fix, /simplify (see below)
Security-only pass over the current branch/security-review
GitHub review mechanics (approve, request changes, inline comments)https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/reviewing-changes-in-pull-requests

Conventional Comments

issue [blocking]: Missing error handling for API call
If the API returns a 500 error, this will crash. Add try/catch.

security [blocking]: API endpoint is not authenticated
The /api/admin/users endpoint is missing auth middleware.

Load Read("references/conventional-comments.md") for the full format, labels (praise, nitpick, suggestion, issue, question, security, bug, breaking), decorations ([blocking], [non-blocking], [if-minor]), and examples.


Review Process

1. Before Reviewing

Check Context:

  • Read the PR/MR description
  • Understand the purpose and scope
  • Review linked tickets or issues
  • Check CI/CD pipeline status

Verify Automated Checks:

  • Tests are passing
  • Linting has no errors
  • Type checking passes
  • Code coverage meets targets
  • No merge conflicts

Set Aside Time:

  • Small PR (< 200 lines): 15-30 minutes
  • Medium PR (200-500 lines): 30-60 minutes
  • Large PR (> 500 lines): 1-2 hours (or ask to split)
2. During Review

Follow a Pattern:

  1. High-Level Review (5-10 minutes)

    • Read PR description and understand intent
    • Skim all changed files to get overview
    • Verify approach makes sense architecturally
    • Check that changes align with stated purpose
  2. Detailed Review (20-45 minutes)

    • Line-by-line code review
    • Check logic, edge cases, error handling
    • Verify tests cover new code
    • Look for security vulnerabilities
    • Ensure code follows team conventions
  3. Testing Considerations (5-10 minutes)

    • Are tests comprehensive?
    • Do tests test the right things?
    • Are edge cases covered?
    • Is test data realistic?
  4. Documentation Check (5 minutes)

    • Are complex sections commented?
    • Is public API documented?
    • Are breaking changes noted?
    • Is README updated if needed?
3. After Reviewing

Provide Clear Decision:

  • ✅ Approve: Code is ready to merge
  • 💬 Comment: Feedback provided, no action required
  • 🔄 Request Changes: Issues must be addressed before merge

Respond to Author:

  • Answer questions promptly
  • Re-review after changes made
  • Approve when issues resolved
  • Thank author for addressing feedback

Review Checklists

General Code Quality
  • Readability: Code is easy to understand
  • Naming: Variables and functions have clear, descriptive names
  • Comments: Complex logic is explained
  • Formatting: Code follows team style guide
  • DRY: No unnecessary duplication
  • SOLID Principles: Code follows SOLID where applicable
  • Function Size: Functions are focused and < 50 lines
  • Cyclomatic Complexity: Functions have complexity < 10
Security
  • Authentication: Protected endpoints require auth
  • Authorization: Users can only access their own data
  • Input Sanitization: SQL injection, XSS prevented
  • Secrets Management: No hardcoded credentials or API keys
  • Encryption: Sensitive data encrypted at rest and in transit
  • Rate Limiting: Endpoints protected from abuse

Show full SKILL.md (373 more words)Show less

Quick Start Guide

For Reviewers:

  1. Read PR description and understand intent
  2. Check that automated checks pass
  3. Do high-level review (architecture, approach)
  4. Do detailed review (logic, edge cases, tests)
  5. Use conventional comments for clear communication
  6. Provide decision: Approve, Comment, or Request Changes

For Authors:

  1. Write clear PR description
  2. Perform self-review before requesting review
  3. Ensure all automated checks pass
  4. Keep PR focused and reasonably sized (< 400 lines)
  5. Respond to feedback promptly and respectfully
  6. Make requested changes or explain reasoning

CC Built-in Review Commands (2.1.152+)

This playbook is the manual framework; Claude Code ships built-in commands that automate parts of it:

  • /code-review — reviews the current diff for correctness bugs and reuse/simplification/efficiency cleanups.
  • /code-review --fix (CC 2.1.152+) — runs the review then applies the findings to your working tree (a bug-hunting review covering correctness plus reuse/simplification/efficiency).
  • /code-review --comment — posts findings as inline PR comments.
  • /simplify — CC 2.1.154 changed this: it now runs a cleanup-only review (reuse, simplification, efficiency, altitude) and applies the fixes — it no longer invokes the full /code-review --fix bug-hunt. Reach for /simplify for tidy-ups, /code-review --fix for bug-finding-plus-fix.

Use the built-ins for fast diff-scoped passes; use ork:review-pr for the multi-agent, full-PR review (security + testing + architecture).


Skill Version: 2.0.0 Last Updated: 2026-01-08 Maintained by: OrchestKit

  • ork:architecture-patterns - Enforce testing and architectural best practices during code review
  • ork:security-patterns - Auth, input validation, and OWASP patterns to complement manual review
  • ork:testing-unit - Unit testing patterns to verify during review

Rules

Each category has individual rule files in rules/ loaded on-demand:

CategoryRuleImpactKey Pattern
TypeScript Qualityrules/typescript-quality.mdHIGHNo any, Zod validation, exhaustive switches, React 19
Python Qualityrules/python-quality.mdHIGHPydantic v2, ruff, mypy strict, async timeouts
Security Baselinerules/security-baseline.mdCRITICALNo secrets, auth on endpoints, input validation
Lintingrules/linting-biome-setup.mdHIGHBiome setup, ESLint migration, gradual adoption
Lintingrules/linting-biome-rules.mdHIGHBiome config, type-aware rules, CI integration

Total: 5 rules across 4 categories

Available Scripts

  • scripts/review-pr.md - Dynamic PR review with auto-fetched GitHub data

    • Auto-fetches: PR title, author, state, changed files, diff stats, comments count
    • Usage: review-pr [PR-number]
    • Requires: GitHub CLI (gh)
    • Uses $ARGUMENTS and !command for live PR data
  • assets/pr-template.md - PR description template

There is deliberately no review-report template here; ork:review-pr owns that output shape. See references/ork-delta.md.

© yonatangross, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references, assets) in src/skills/code-review-playbook of yonatangross/orchestkit.

  • SKILL.md
  • assets/pr-template.md
  • examples/conventional-comments.md
  • references/conventional-comments.md
  • references/ork-delta.md
  • rules/_sections.md
  • rules/_template.md
  • rules/linting-biome-rules.md
  • rules/linting-biome-setup.md
  • rules/python-quality.md
  • rules/security-baseline.md
  • rules/typescript-quality.md
  • scripts/fetch-pr-data.sh
  • scripts/review-pr.md
  • scripts/run-lint-check.sh
  • scripts/run-pr-checks.py
  • … and 1 more

Open the folder on GitHubat commit 02bbf9a

Compare with similar skills

Code Review Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Playbook this skillyonatangross/orchestkit290—~2.2kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow155k—~3.5kAutomated safety check: NotesMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    155k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from yonatangross/orchestkit

All 108 skills in this repo
  • API Design

    yonatangross/orchestkit

    API contract design for REST and GraphQL, covering resource shape, URL and header versioning with deprecation windows, RFC 9457 Problem Details error handling, and OpenAPI specs.

    290 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Architecture Decision Record

    yonatangross/orchestkit

    ADR templates in the Nygard format with context, decision, consequences, and alternatives.

    290 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Audit Full

    yonatangross/orchestkit

    Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.

    290 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Create PR

    yonatangross/orchestkit

    Creates GitHub pull requests with pre-flight validation, conventional title formatting, and structured summary generation.

    290 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Explore

    yonatangross/orchestkit

    Multi-angle codebase exploration spawning 3-5 parallel agents for code structure, data flow, architecture patterns, and health assessment.

    290 GitHub stars~3.9k tokensUpdated today
    Auto-check: notes
  • Python Backend

    yonatangross/orchestkit

    Production Python async patterns including asyncio TaskGroup, FastAPI dependency injection and middleware, SQLAlchemy 2.0 async sessions, and database connection pool tuning.

    290 GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Categories

Questions about Code Review Playbook

What does Code Review Playbook do?

Structured review processes, conventional comments, language-specific checklists, and feedback templates. Code Review Playbook is an agent skill from yonatangross/orchestkit. Structured review processes, conventional comments, language-specific checklists, and feedback templates.

When should I use Code Review Playbook?

Code Review Playbook fits situations like: conducting code review; standardizing review practice.

How do I install Code Review Playbook in Claude Code?

Run `npx skills add yonatangross/orchestkit --skill code-review-playbook -a claude-code`. Or copy the skill folder (src/skills/code-review-playbook in yonatangross/orchestkit) into .claude/skills/code-review-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Playbook in Codex?

Run `npx skills add yonatangross/orchestkit --skill code-review-playbook -a codex`. Or copy the skill folder (src/skills/code-review-playbook in yonatangross/orchestkit) into .agents/skills/code-review-playbook in your project. Codex loads it when a task matches its description.

Can I use Code Review Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yonatangross/orchestkit --skill code-review-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-playbook, .gemini/skills/code-review-playbook, .github/skills/code-review-playbook and .opencode/skills/code-review-playbook in your project.

What does Code Review Playbook need to run?

Going by SKILL.md and its folder, Code Review Playbook needs a shell and Python for the scripts in its folder. Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Read, Glob, Grep, WebFetch, WebSearch. Compatibility (from SKILL.md): Claude Code 2.1.277+..

Does Code Review Playbook access the network?

SKILL.md names 4 domains. As links in the text: google.github.io, conventionalcomments.org, owasp.org and docs.github.com. This is read from the text; nothing was executed.

Is Code Review Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Review Playbook use?

Code Review Playbook is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Playbook use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Code Review Playbook?

Skills that share tags, products or a category with Code Review Playbook: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 155k stars) and Mole Bug Patterns (tw93/Mole, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Playbook?

yonatangross (a GitHub user) maintains it in yonatangross/orchestkit, which has 290 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.

Source: yonatangross/orchestkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.