Agent skill

Codebase Review Swarm

by ZaxbyHub in ZaxbyHub/opencode-swarm

Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

MITAuto-check passedDevelopment

Install Codebase Review Swarm

skills CLI
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .claude/skills/codebase-review-swarm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-review-swarm
GitHub stars
496
Token cost
~2.8k tokens
SKILL.md length
1,393 words
Files
11 (incl. scripts, references, assets)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

  • Works in 4 steps: references/review-protocol-v8.2.md -… → assets/jsonl-schemas.md - exact… → assets/review-report-template.md - final… → …
  • Running a full-repository security or QA audit with cited evidence
  • SKILL.md covers Graph-first evidence contract, Load order, Non-negotiable invariants and Current standards to apply, plus 3 more sections
  • Runs Python scripts from its folder; calls git

What it does

This is for full-repository or large-subsystem reviews, not for ordinary implementation or quick PR comments. The agent acts as architect and orchestrator, producing a verified review report and supporting artifacts under .swarm/review-v8, and never edits source, upgrades dependencies or applies fixes. It starts from graph evidence (a repo map health check, a context pack, and route and data traces for security tracks) but treats the graph as advisory and falls back to reading the source when the graph is stale, missing or inconclusive.

Two invariants drive the work. No quote, no claim: every factual claim cites an exact path, line range and verbatim excerpt. Coverage closure: every unit in a chosen track must end reviewed, not applicable, skipped with a reason or blocked before a report is allowed. The process runs a Phase 0 inventory, selected exhaustive tracks, reviewer and critic validation and coverage closure. A protocol, JSONL schemas and a report template are read first, init-review-run.py creates the run folder and a second script checks the package shape.

When your agent uses it

  • Running a full-repository security or QA audit with cited evidence
  • Reviewing accessibility, performance or observability across a large subsystem
  • Auditing supply-chain risk or the provenance of AI-generated code
  • Producing an enhancement catalog from a codebase review

Example prompts

  • “Run a full security and supply-chain review of this repository and write the report without touching any source.”
  • “Audit the checkout subsystem for accessibility and performance problems, with a quote for every finding.”
  • “Do an AI-slop review of ./src and list anything that looks generated and never verified.”

Requirements

  • Python, to run the init and validation scripts
  • A writable .swarm folder, ideally git-ignored

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. references/review-protocol-v8.2.md - authoritative workflow, phases, track contracts, and standards.
  2. assets/jsonl-schemas.md - exact parseable block formats for inventory, candidates, validation, critic, and coverage artifacts.
  3. assets/review-report-template.md - final review-report.md structure.
  4. references/full-v7-source-prompt.md - full source prompt and long track checklists; load only when the concise protocol is insufficient…

What it can do on your machine

Read from SKILL.md and the folder at commit a69d1a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Review Swarm loads about 2.8k tokens when it runs, and up to ~39k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~39k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ZaxbyHub/opencode-swarm at commit a69d1a9, republished under its MIT licence (© ZaxbyHub). 1,393 words, ~2,790 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-review-swarm/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
codebase-review-swarm
description
Run a rigorous, quote-grounded codebase review or security/QA/accessibility/performance/AI-slop/enhancement audit. Use for full-repo or large-subsystem review reports; not for normal implementation. Performs Phase 0 inventory, selected exhaustive tracks with non-diluting depth, coverage closure, reviewer/critic validation, and writes .swarm/review-v8 artifacts without modifying source files.
audience
swarm-plugin
license
MIT
metadata.version
8.2.0
metadata.generated
2026-06-08
metadata.source_prompt
codebase-review-swarm-prompt-v7
metadata.artifact_root
.swarm/review-v8/runs/<run_id>/

Codebase Review Swarm

Use this skill when the user asks for a deep codebase audit, full QA review, security review, supply-chain review, AI-slop/provenance review, UI/accessibility review, performance/observability review, or enhancement catalog. Do not use it for ordinary bug fixing, feature implementation, or quick PR comments unless the user explicitly wants the full evidence-gated review workflow.

You are the Architect/orchestrator. You produce a verified review report and supporting artifacts. You do not modify source files. Source edits, automatic fixes, dependency upgrades, and remediation patches are out of scope unless the user starts a separate implementation task after the report.

Graph-first evidence contract

Start review scope with repo_map graph_health and a targeted source-bearing context_pack. For security, trust-boundary, and data-flow tracks, add route_trace and data_trace. Graph evidence is advisory only. If freshness is stale or inconclusive, confidence is low, source is missing, the language is unsupported/dynamic, the graph is absent, or an action fails, inspect the direct source and searches before accepting a finding.

Load order

Read these files before executing:

  1. references/review-protocol-v8.2.md - authoritative workflow, phases, track contracts, and standards.
  2. assets/jsonl-schemas.md - exact parseable block formats for inventory, candidates, validation, critic, and coverage artifacts.
  3. assets/review-report-template.md - final review-report.md structure.
  4. references/full-v7-source-prompt.md - full source prompt and long track checklists; load only when the concise protocol is insufficient for a selected track or output format.

Optional deterministic helpers:

  • scripts/init-review-run.py creates the .swarm/review-v8/runs/<run_id>/ artifact tree and warns if .swarm/ is not ignored.
  • scripts/validate-skill-package.py checks the local skill package shape.

Non-negotiable invariants

  1. No Quote, No Claim. Every repo-derived factual claim must cite exact relative file path, line or range, verbatim excerpt, and what the excerpt proves.
  2. Coverage closure. Every selected-track coverage unit must end REVIEWED, NOT_APPLICABLE, SKIPPED_WITH_REASON, or BLOCKED. A final report is forbidden while any selected-track unit is UNASSIGNED or UNREVIEWED.
  3. Depth scales with focus and never dilutes with breadth. Selecting one track concentrates effort into that track: increase coverage granularity, caller/callee tracing, deterministic tool use, runtime validation attempts, test/claim comparison, and critic passes for that domain. Selecting multiple tracks or all tracks does not permit any track to be shallower than it would be in a single-track run; decompose into more passes, smaller batches, or sequential waves instead.
  4. Candidates are not findings. Explorer output is candidate evidence only. Reviewer validation filters false positives. Critic validation is mandatory for CRITICAL/HIGH defects and all report-eligible enhancements. Final whole-report critic must PASS before completion.
  5. Deterministic before judgment. Mechanically check imports, manifests, lockfiles, package existence, route wiring, CLI scripts, framework signatures, public exports, and test assertions before subjective reasoning. Run safe SAST, dependency scanners, linters, typecheckers, tests, or MCP/security scanners when available and relevant.
  6. Disproof required. Every candidate records the alternative interpretation that would make it wrong and where that interpretation was checked. CRITICAL/HIGH candidates lacking a clear disproof model must be downgraded before validation.
  7. Runtime validation when runtime matters. Static review is insufficient for routing, auth/session state, async ordering, database state, feature flags, bundling, rendering, LLM/tool execution, MCP permissions, or cross-platform shell behavior. Run the smallest safe validation or mark the item UNVERIFIED.
  8. Separate defects from enhancements. Defects are shipped behavior that is wrong, unsafe, broken, misleading, or materially incomplete. Enhancements improve working code without implying breakage. Do not duplicate the same root issue in both forms.
  9. Evidence-based AI slop only. Never report "looks generated" findings. Quote concrete repeated patterns, phantom APIs/dependencies, confident stubs, stale API usage, excessive churn, mock-only tests, or unmodified scaffold defaults.
  10. Quality over speed. Parallelize only independent scopes. If quality and concurrency conflict, quality wins.
  11. No fixed budget compression. Never fit the review to an assumed time/token budget by sampling selected scopes, increasing batch size, reducing validation, or omitting low-salience files. When scope is large, split work; when splitting is insufficient, mark precise coverage units BLOCKED or SKIPPED_WITH_REASON rather than producing a weaker report.

Current standards to apply

Use these baselines unless repository policy explicitly requires stricter or older controls:

  • OWASP ASVS 5.0.0 for web application control review.
  • OWASP Top 10 for LLM Applications 2025 for LLM, agent, RAG, and model-output security.
  • SLSA v1.2 and OpenSSF Scorecard checks for build/release provenance and repository hygiene.
  • WCAG 2.2 AA for UI accessibility.
  • OpenTelemetry semantic model: traces, metrics, logs, baggage/context propagation where applicable.

Execution outline

  1. Run Phase 0 inventory in the strict dependency order from references/review-protocol-v8.2.md and write the source-of-truth packet.
  2. Stop after Phase 0 and ask the user to choose review mode unless the original request already selected tracks and explicitly authorized continuing.
  3. Build coverage units for the selected tracks and write a review-depth-plan.md that proves each selected track receives full-depth treatment.
  4. Generate candidates by selected track only, using exact scope assignments and quoted evidence. Focused selections must expand depth within selected tracks; multi-track selections must add waves, not dilute depth.
  5. Validate candidates in small local reasoning batches.
  6. Run inline critic for CRITICAL/HIGH defects, enhancement critic for all kept enhancements, and final whole-report critic.
  7. Write review-report.md only after coverage closure and final critic PASS.
  8. Final response reports only the run path, selected tracks, counts summary, highest-risk items, coverage limitations, and confirmation that no source files were modified.
Show full SKILL.md (533 more words)Show less

Pre-flight: PR Branch Checkout Before Explorer Dispatch

When the review target is a PR branch or commit range, complete this before any explorer or candidate-generation dispatch:

  1. Verify the working tree is clean with git status --porcelain. If uncommitted changes exist, you (the orchestrator) must handle them before any explorer/candidate dispatch — use prepare_pr_workflow_checkout (the controller-owned path; it preserves every dirty path — including untracked files when called with no paths argument — and returns a recovery command), or a git worktree (see running-tests skill precedent). Note: git branch tmp/save-<topic> only moves the HEAD ref — it does not record or preserve uncommitted working-tree changes, so do not rely on it to save dirty work. Never delegate git stash, git reset, git checkout -- ., or git restore to subagents — these are worktree-global operations that destroy sibling agents' in-flight work under parallel execution.
  2. Fetch and check out the PR head branch locally. Explorer agents read the working-tree filesystem (Read/Glob/Grep), not git history, so reviewing a PR while the base branch is checked out produces invalid candidates.
  3. Record the exact commit range (base_ref..head_ref) in the source-of-truth packet and pass that range in every explorer/candidate-generation delegation so agents have revision context for targeted git show inspection.

Subagent prohibition — must reach every subagent prompt: Include this line verbatim in every explorer/candidate-generation lane or subagent dispatch prompt: "You are a subagent sharing a worktree with sibling agents. You MUST NOT run git stash, git reset, git checkout -- ., git restore, or any other worktree-global destructive git command. These destroy sibling agents' in-flight work without error."

Async advisory lanes

When selected-track inventory or candidate generation decomposes into independent read-only units, launch those units with dispatch_lanes_async when available. Record each returned batch_id, then continue architect-owned deterministic work that does not depend on lane output: update the coverage ledger shell, run safe local tools, prepare validation shards, and document unresolved coverage units. Do not mark coverage REVIEWED, promote candidates to findings, or write the final report from running lanes.

Incremental collection: While lanes are running, poll with collect_lane_results (without wait or wait: false) to check progress and process any settled lanes immediately — call retrieve_lane_output for full text when output_ref is present, extract candidates, update coverage ledger entries, validate output quality — while continuing independent work between polls. Only use wait: true if lanes are still pending and no more independent architect work remains.

At every coverage, validation, and synthesis boundary, all lanes in the relevant batch must be settled before proceeding. Missing, stale, cancelled, or failed lanes are coverage gaps that must be closed before proceeding — they map to the existing BLOCKED invariant (#2 Coverage Closure) but with stricter resolution: (1) retry max 2 times with materially different parameters; (2) if retries fail, deploy a verified equivalent alternative (same agent type, same prompt, same scope, same isolation — different dispatch mechanism acceptable when equivalence is verified, including Task-tool dispatch as the final fallback when lane tools do not work); (3) if no equivalent exists, the coverage unit becomes BLOCKED and the architect must surface the lane failure to the user before producing a report. SKIPPED_WITH_REASON is not acceptable for dispatch-lane failures — it must be BLOCKED with an explicit retry/equivalent/escalation trail, and no degraded review report is written.

© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references, assets) in .opencode/skills/codebase-review-swarm of ZaxbyHub/opencode-swarm.

  • SKILL.md
  • INSTALL.md
  • README.md
  • agents/openai.yaml
  • assets/jsonl-schemas.md
  • assets/review-report-template.md
  • references/compatibility-and-research-notes.md
  • references/full-v7-source-prompt.md
  • references/review-protocol-v8.2.md
  • scripts/init-review-run.py
  • scripts/validate-skill-package.py

Open the folder on GitHubat commit a69d1a9

Compare with similar skills

Codebase Review Swarm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Review Swarm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Review Swarm this skillZaxbyHub/opencode-swarm496—~2.8kAutomated safety check: PassMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence
ReviewThank-you-Linus/Linus-Dashboard211—~1.5kAutomated safety check: PassMIT
Code Review Specialist in Vietnameseluongnv89/claude-howto42k—~474Automated safety check: PassMIT
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Review

    Thank-you-Linus/Linus-Dashboard

    Review code quality, security, and maintainability before committing.

    211 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Reviews code for security, performance, quality and maintainability, then reports findings in a fixed template with a rating, severity levels and suggested fixes.

    42k GitHub stars~474 tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes

More from ZaxbyHub/opencode-swarm

All 91 skills in this repo
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    496 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Commit and PR Publishing for Codex

    ZaxbyHub/opencode-swarm

    Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.

    496 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Durable Session State

    ZaxbyHub/opencode-swarm

    Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.

    496 GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Swarm PR Feedback Closer

    ZaxbyHub/opencode-swarm

    Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.

    496 GitHub stars~14k tokensUpdated today
    Auto-check passed
  • Swarm PR Subscribe

    ZaxbyHub/opencode-swarm

    Monitor a pull request after creation and act autonomously on pushed PR activity.

    496 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Bundle Safety

    ZaxbyHub/opencode-swarm

    Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.

    496 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Codebase Review Swarm

What does Codebase Review Swarm do?

Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files. This is for full-repository or large-subsystem reviews, not for ordinary implementation or quick PR comments.swarm/review-v8, and never edits source, upgrades dependencies or applies fixes.

When should I use Codebase Review Swarm?

Codebase Review Swarm fits situations like: running a full-repository security or QA audit with cited evidence; reviewing accessibility, performance or observability across a large subsystem; auditing supply-chain risk or the provenance of AI-generated code; producing an enhancement catalog from a codebase review.

How do I install Codebase Review Swarm in Claude Code?

Run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a claude-code`. Or copy the skill folder (.opencode/skills/codebase-review-swarm in ZaxbyHub/opencode-swarm) into .claude/skills/codebase-review-swarm in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Review Swarm in Codex?

Run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a codex`. Or copy the skill folder (.opencode/skills/codebase-review-swarm in ZaxbyHub/opencode-swarm) into .agents/skills/codebase-review-swarm in your project. Codex loads it when a task matches its description.

Can I use Codebase Review Swarm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-review-swarm, .gemini/skills/codebase-review-swarm, .github/skills/codebase-review-swarm and .opencode/skills/codebase-review-swarm in your project.

What does Codebase Review Swarm need to run?

Going by SKILL.md and its folder, Codebase Review Swarm needs Python for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python, to run the init and validation scripts; A writable .swarm folder, ideally git-ignored.

Does Codebase Review Swarm access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codebase Review Swarm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codebase Review Swarm use?

Codebase Review Swarm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Review Swarm use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 36k tokens, read only when the agent opens those files.

What are the alternatives to Codebase Review Swarm?

Skills that share tags, products or a category with Codebase Review Swarm: Code Review Specialist (luongnv89/claude-howto, 42k stars), Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Review (Thank-you-Linus/Linus-Dashboard, 211 stars) and Code Review Specialist in Vietnamese (luongnv89/claude-howto, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Review Swarm?

ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 496 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 11, 2026.

Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.