Code Review Specialist
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .claude/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .claude/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .agents/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .agents/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .cursor/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .cursor/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ZaxbyHub/opencode-swarm.git --path .opencode/skills/codebase-review-swarm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .gemini/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .gemini/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .github/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .github/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ZaxbyHub/opencode-swarm codebase-review-swarm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/codebase-review-swarm .opencode/skills/codebase-review-swarm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebase-review-swarm" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/codebase-review-swarm into .opencode/skills/codebase-review-swarm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-review-swarm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebase-review-swarmRuns an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
This is for full-repository or large-subsystem reviews, not for ordinary implementation or quick PR comments. The agent acts as architect and orchestrator, producing a verified review report and supporting artifacts under .swarm/review-v8, and never edits source, upgrades dependencies or applies fixes. It starts from graph evidence (a repo map health check, a context pack, and route and data traces for security tracks) but treats the graph as advisory and falls back to reading the source when the graph is stale, missing or inconclusive.
Two invariants drive the work. No quote, no claim: every factual claim cites an exact path, line range and verbatim excerpt. Coverage closure: every unit in a chosen track must end reviewed, not applicable, skipped with a reason or blocked before a report is allowed. The process runs a Phase 0 inventory, selected exhaustive tracks, reviewer and critic validation and coverage closure. A protocol, JSONL schemas and a report template are read first, init-review-run.py creates the run folder and a second script checks the package shape.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a69d1a9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebase Review Swarm loads about 2.8k tokens when it runs, and up to ~39k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,393 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ZaxbyHub/opencode-swarm at commit a69d1a9, republished under its MIT licence (© ZaxbyHub). 1,393 words, ~2,790 tokens.
.claude/skills/codebase-review-swarm/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Use this skill when the user asks for a deep codebase audit, full QA review, security review, supply-chain review, AI-slop/provenance review, UI/accessibility review, performance/observability review, or enhancement catalog. Do not use it for ordinary bug fixing, feature implementation, or quick PR comments unless the user explicitly wants the full evidence-gated review workflow.
You are the Architect/orchestrator. You produce a verified review report and supporting artifacts. You do not modify source files. Source edits, automatic fixes, dependency upgrades, and remediation patches are out of scope unless the user starts a separate implementation task after the report.
Start review scope with repo_map graph_health and a targeted source-bearing context_pack. For security, trust-boundary, and data-flow tracks, add route_trace and data_trace. Graph evidence is advisory only. If freshness is stale or inconclusive, confidence is low, source is missing, the language is unsupported/dynamic, the graph is absent, or an action fails, inspect the direct source and searches before accepting a finding.
Read these files before executing:
references/review-protocol-v8.2.md - authoritative workflow, phases, track contracts, and standards.assets/jsonl-schemas.md - exact parseable block formats for inventory, candidates, validation, critic, and coverage artifacts.assets/review-report-template.md - final review-report.md structure.references/full-v7-source-prompt.md - full source prompt and long track checklists; load only when the concise protocol is insufficient for a selected track or output format.Optional deterministic helpers:
scripts/init-review-run.py creates the .swarm/review-v8/runs/<run_id>/ artifact tree and warns if .swarm/ is not ignored.scripts/validate-skill-package.py checks the local skill package shape.REVIEWED, NOT_APPLICABLE, SKIPPED_WITH_REASON, or BLOCKED. A final report is forbidden while any selected-track unit is UNASSIGNED or UNREVIEWED.UNVERIFIED.BLOCKED or SKIPPED_WITH_REASON rather than producing a weaker report.Use these baselines unless repository policy explicitly requires stricter or older controls:
references/review-protocol-v8.2.md and write the source-of-truth packet.review-depth-plan.md that proves each selected track receives full-depth treatment.review-report.md only after coverage closure and final critic PASS.When the review target is a PR branch or commit range, complete this before any explorer or candidate-generation dispatch:
git status --porcelain. If
uncommitted changes exist, you (the orchestrator) must handle them
before any explorer/candidate dispatch — use prepare_pr_workflow_checkout
(the controller-owned path; it preserves every dirty path — including
untracked files when called with no paths argument — and returns a recovery
command), or a git worktree (see running-tests skill precedent). Note:
git branch tmp/save-<topic> only moves the HEAD ref — it does not record or
preserve uncommitted working-tree changes, so do not rely on it to save dirty
work. Never delegate git stash, git reset, git checkout -- .,
or git restore to subagents — these are worktree-global operations that
destroy sibling agents' in-flight work under parallel execution.Read/Glob/Grep), not git history, so reviewing
a PR while the base branch is checked out produces invalid candidates.base_ref..head_ref) in the source-of-truth
packet and pass that range in every explorer/candidate-generation delegation
so agents have revision context for targeted git show inspection.Subagent prohibition — must reach every subagent prompt:
Include this line verbatim in every explorer/candidate-generation lane
or subagent dispatch prompt:
"You are a subagent sharing a worktree with sibling agents. You MUST
NOT run git stash, git reset, git checkout -- ., git restore,
or any other worktree-global destructive git command. These destroy
sibling agents' in-flight work without error."
When selected-track inventory or candidate generation decomposes into independent read-only units, launch those units with dispatch_lanes_async when available. Record each returned batch_id, then continue architect-owned deterministic work that does not depend on lane output: update the coverage ledger shell, run safe local tools, prepare validation shards, and document unresolved coverage units. Do not mark coverage REVIEWED, promote candidates to findings, or write the final report from running lanes.
Incremental collection: While lanes are running, poll with collect_lane_results (without wait or wait: false) to check progress and process any settled lanes immediately — call retrieve_lane_output for full text when output_ref is present, extract candidates, update coverage ledger entries, validate output quality — while continuing independent work between polls. Only use wait: true if lanes are still pending and no more independent architect work remains.
At every coverage, validation, and synthesis boundary, all lanes in the relevant batch must be settled before proceeding. Missing, stale, cancelled, or failed lanes are coverage gaps that must be closed before proceeding — they map to the existing BLOCKED invariant (#2 Coverage Closure) but with stricter resolution: (1) retry max 2 times with materially different parameters; (2) if retries fail, deploy a verified equivalent alternative (same agent type, same prompt, same scope, same isolation — different dispatch mechanism acceptable when equivalence is verified, including Task-tool dispatch as the final fallback when lane tools do not work); (3) if no equivalent exists, the coverage unit becomes BLOCKED and the architect must surface the lane failure to the user before producing a report. SKIPPED_WITH_REASON is not acceptable for dispatch-lane failures — it must be BLOCKED with an explicit retry/equivalent/escalation trail, and no degraded review report is written.
© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (scripts, references, assets) in .opencode/skills/codebase-review-swarm of ZaxbyHub/opencode-swarm.
Open the folder on GitHubat commit a69d1a9
Codebase Review Swarm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebase Review Swarm this skillZaxbyHub/opencode-swarm | 496 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Code Review Specialistluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT | |
| Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~2k | Automated safety check: Pass | Custom licence | |
| ReviewThank-you-Linus/Linus-Dashboard | 211 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Code Review Specialist in Vietnameseluongnv89/claude-howto | 42k | — | ~474 | Automated safety check: Pass | MIT | |
| Code Reviewerforyourhealth111-pixel/Vibe-Skills | 3.6k | — | ~1.4k | Automated safety check: Notes | Apache-2.0 |
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
Thank-you-Linus/Linus-Dashboard
Review code quality, security, and maintainability before committing.
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, then reports findings in a fixed template with a rating, severity levels and suggested fixes.
foryourhealth111-pixel/Vibe-Skills
Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
ZaxbyHub/opencode-swarm
Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.
ZaxbyHub/opencode-swarm
Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.
ZaxbyHub/opencode-swarm
Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.
ZaxbyHub/opencode-swarm
Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.
ZaxbyHub/opencode-swarm
Monitor a pull request after creation and act autonomously on pushed PR activity.
ZaxbyHub/opencode-swarm
Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.
Categories
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files. This is for full-repository or large-subsystem reviews, not for ordinary implementation or quick PR comments.swarm/review-v8, and never edits source, upgrades dependencies or applies fixes.
Codebase Review Swarm fits situations like: running a full-repository security or QA audit with cited evidence; reviewing accessibility, performance or observability across a large subsystem; auditing supply-chain risk or the provenance of AI-generated code; producing an enhancement catalog from a codebase review.
Run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a claude-code`. Or copy the skill folder (.opencode/skills/codebase-review-swarm in ZaxbyHub/opencode-swarm) into .claude/skills/codebase-review-swarm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a codex`. Or copy the skill folder (.opencode/skills/codebase-review-swarm in ZaxbyHub/opencode-swarm) into .agents/skills/codebase-review-swarm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill codebase-review-swarm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-review-swarm, .gemini/skills/codebase-review-swarm, .github/skills/codebase-review-swarm and .opencode/skills/codebase-review-swarm in your project.
Going by SKILL.md and its folder, Codebase Review Swarm needs Python for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python, to run the init and validation scripts; A writable .swarm folder, ideally git-ignored.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Codebase Review Swarm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 36k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codebase Review Swarm: Code Review Specialist (luongnv89/claude-howto, 42k stars), Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Review (Thank-you-Linus/Linus-Dashboard, 211 stars) and Code Review Specialist in Vietnamese (luongnv89/claude-howto, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 496 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 11, 2026.
Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.