A skill your agent uses when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.

MITAuto-check: notesDevelopment

Install Cr

skills CLI
$ npx skills add ZhangShenao/harness9 --skill cr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZhangShenao/harness9 cr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZhangShenao/harness9.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cr .claude/skills/cr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cr
GitHub stars
141
Token cost
~304 tokens
SKILL.md length
55 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.

  • Works in 4 steps: 收集变更范围 → 逐文件审查 → 检查敏感文件 → …
  • The user invokes /cr
  • SKILL.md covers Overview, 执行步骤 and 注意事项
  • Calls git

What it does

Cr is an agent skill from ZhangShenao/harness9. Use when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.

Its SKILL.md is about 300 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. The repository describes itself as: Local-First · 轻量级 · 功能完备 · 生产可用的通用 Agent 框架. The licence is MIT.

When your agent uses it

  • The user invokes /cr
  • Requests a code review
  • Before committing to verify correctness
  • Modified code in the working tree

Example prompts

  • “/cr”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 收集变更范围
  2. 逐文件审查
  3. 检查敏感文件
  4. 输出 Review 报告

What it can do on your machine

Read from SKILL.md and the folder at commit 6d2ae52. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cr loads about 304 tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 55 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~304

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    - `.env`、`*.pem`、`*credentials*`、`*secret*`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZhangShenao/harness9 at commit 6d2ae52, republished under its MIT licence (© ZhangShenao). 55 words, ~304 tokens.

Download SKILL.mdSave it as .claude/skills/cr/SKILL.md (or your agent's skills folder).
name
cr
description
Use when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.

cr — Code Review

Overview

对当前工作区所有新增或修改的代码执行详细的 Code Review,按严重级别输出问题,不做任何修改。

执行步骤

1. 收集变更范围
bash
git status          # 查看新增 / 修改 / 删除的文件列表
git diff            # 未暂存的改动
git diff --cached   # 已暂存的改动

将两者合并视为本次 Review 的完整范围。

2. 逐文件审查

对每个变更文件,依次检查:

维度检查点
正确性逻辑错误、边界条件、空值/类型异常
安全性SQL 注入、XSS、命令注入、敏感信息硬编码、不安全的默认值
可维护性函数/类职责单一、命名清晰、不必要的复杂度
性能N+1 查询、不必要的循环、大对象复制
测试覆盖关键路径是否有对应测试,新代码是否破坏现有测试
依赖安全新引入的第三方包是否合理,版本是否锁定
3. 检查敏感文件

若 git status 中出现以下类型的文件,单独标注,不得进入后续提交:

  • .env、*.pem、*credentials*、*secret*
  • 包含明文密码、API Key 的配置文件
4. 输出 Review 报告

按以下格式输出,无问题的级别可省略:

## Code Review 报告

### 🔴 Critical(必须修复,阻断提交)
- `文件路径:行号` — 问题描述

### 🟡 Warning(建议修复)
- `文件路径:行号` — 问题描述

### 🔵 Suggestion(可选优化)
- `文件路径:行号` — 建议描述

### ✅ 总结
- 变更文件数:N
- 通过提交:是 / 否(存在 Critical 问题时为否)

注意事项

  • 只审查,不修改代码
  • Critical 问题存在时,明确说明不建议提交,等待用户确认修复
  • 若变更集为空(git status 无输出),告知用户当前无需 Review

© ZhangShenao, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cr of ZhangShenao/harness9.

Open the folder on GitHubat commit 6d2ae52

Compare with similar skills

Cr next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cr compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cr this skillZhangShenao/harness9141—~304Automated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow155k—~3.5kAutomated safety check: NotesMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    155k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from ZhangShenao/harness9

  • Architecture Overview

    ZhangShenao/harness9

    A skill your agent uses when asked about harness9 architecture, module design, or how components interact — explains the system design

    141 GitHub stars~717 tokensUpdated today
    Auto-check passed
  • Debugging Guide

    ZhangShenao/harness9

    A skill your agent uses when debugging Go errors, test failures, or unexpected behavior — step-by-step diagnosis approach

    141 GitHub stars~563 tokensUpdated today
    Auto-check passed
  • Go Coding Standards

    ZhangShenao/harness9

    A skill your agent uses when writing or reviewing Go code — explains harness9 project coding conventions and patterns

    141 GitHub stars~719 tokensUpdated today
    Auto-check passed
  • Commit

    ZhangShenao/harness9

    A skill your agent uses when the user invokes /commit or asks to commit changes, after a code review has been completed and the changes are confirmed ready to stage and commit to git.

    141 GitHub stars~327 tokensUpdated today
    Auto-check: notes
  • PR

    ZhangShenao/harness9

    A skill your agent uses when the user invokes /pr or asks to push changes and open a pull request, after commits are ready to be pushed to a remote branch and merged into the main branch.

    141 GitHub stars~423 tokensUpdated today
    Auto-check passed
  • Autodev

    ZhangShenao/harness9

    Feature auto-development — clarify requirements, generate spec, dispatch dev sub-agent to implement and merge into current branch

    141 GitHub stars~606 tokensUpdated today
    Auto-check: notes

Categories

Questions about Cr

What does Cr do?

A skill your agent uses when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree. Cr is an agent skill from ZhangShenao/harness9. Use when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.

When should I use Cr?

Cr fits situations like: the user invokes /cr; requests a code review; before committing to verify correctness; modified code in the working tree.

How do I install Cr in Claude Code?

Run `npx skills add ZhangShenao/harness9 --skill cr -a claude-code`. Or copy the skill folder (skills/cr in ZhangShenao/harness9) into .claude/skills/cr in your project. Claude Code loads it when a task matches its description.

How do I install Cr in Codex?

Run `npx skills add ZhangShenao/harness9 --skill cr -a codex`. Or copy the skill folder (skills/cr in ZhangShenao/harness9) into .agents/skills/cr in your project. Codex loads it when a task matches its description.

Can I use Cr in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZhangShenao/harness9 --skill cr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cr, .gemini/skills/cr, .github/skills/cr and .opencode/skills/cr in your project.

What does Cr need to run?

Going by SKILL.md and its folder, Cr needs the command-line tools its instructions call (git).

Does Cr access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cr safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cr use?

Cr is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cr use?

About 304 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cr?

Skills that share tags, products or a category with Cr: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 155k stars) and Mole Bug Patterns (tw93/Mole, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cr?

ZhangShenao (a GitHub user) maintains it in ZhangShenao/harness9, which has 141 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.

Source: ZhangShenao/harness9 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.