Code Review Skill
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions.
$ npx skills add zhinjs/zhin --skill zhin-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zhinjs/zhin zhin-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/zhin-audit .claude/skills/zhin-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .claude/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zhinjs/zhin --skill zhin-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zhinjs/zhin zhin-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/zhin-audit .agents/skills/zhin-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .agents/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhinjs/zhin --skill zhin-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zhinjs/zhin zhin-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/zhin-audit .cursor/skills/zhin-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .cursor/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zhinjs/zhin.git --path .github/skills/zhin-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zhinjs/zhin --skill zhin-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zhinjs/zhin zhin-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/zhin-audit .gemini/skills/zhin-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .gemini/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zhinjs/zhin zhin-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zhinjs/zhin --skill zhin-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/zhin-audit .github/skills/zhin-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .github/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhinjs/zhin --skill zhin-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zhinjs/zhin zhin-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/zhin-audit .opencode/skills/zhin-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "zhin-audit" agent skill from https://github.com/zhinjs/zhin/tree/main/.github/skills/zhin-audit into .opencode/skills/zhin-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "zhin-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
zhin-auditAudit Zhin.js changes for security, performance, lifecycle, and architecture regressions.
Zhin Audit is an agent skill from zhinjs/zhin. Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. Use for release review, security review, performance review, architecture review, or change-based code audit.
Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/architecture-checklist.md`, `references/performance-checklist.md` and `references/security-checklist.md`).
It sits in Security, covering Security review, Software architecture and Performance reviews. The repository describes itself as: AI-native TypeScript bot framework — one codebase for 20+ chat platforms (QQ, Discord, Telegram, Slack, WeChat…). Opt-in AI agent with MCP, tools & security policies. <10MB core. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f38698f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Zhin Audit loads about 596 tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 114 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
范围与未验证边界。不要粘贴 token、`.env`、用户 ID 或完整敏感请求。Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zhinjs/zhin at commit f38698f, republished under its MIT licence (© zhinjs). 114 words, ~596 tokens.
.claude/skills/zhin-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.先建立当前分支事实,再给结论。仓库的 AGENTS.md、docs/concepts/architecture.md、目标包
package.json 和现有 harness 是契约来源;不要从旧类名或旧目录推断实现。
根据 diff 选择门禁,常用入口:
pnpm check:architecture
pnpm check:domain-module-boundaries
pnpm check:harness-paths
pnpm check:adapter-endpoint-boundaries
pnpm check:no-removed-plugin-api
pnpm check:runtime-config-boundaries
pnpm check:agent-tool-authoring-boundaries
pnpm check:skill-authoring-boundaries
pnpm check:agent-authoring-boundaries
pnpm check:hook-authoring-boundaries
pnpm check:plugin-capability-publish包内变更先跑 pnpm --filter <pkg> test / build。发布前再根据影响面扩大到
pnpm check:all;不要用静态搜索代替测试,也不要把环境故障写成代码缺陷。
plugin.ts default-export definePlugin();能力位于命名目录的
index.ts(x)。已移除的 usePlugin/getPlugin 不得回归。context.resources;能力执行上下文直接 context.use(token)。
generation 状态不能退回模块级 latest-value 单例。requiresApproval: never | on-risk | once | always;权限、审批与
Shell/文件/网络专用策略是不同层。builtin 安全检查统一进入
packages/im/agent/src/security/policy-facade.ts 的 runToolPolicies。defineAdapter({ capabilities, create }) 的
{ client, connect, activate?, send } 契约;WS/SSE 生命周期用 createEndpointLifecycle。Message.$reply / Adapter.sendMessage 必须经过
renderSendMessage → before.sendMessage → AdapterIndex/Endpoint。pages/<name>/index.tsx 默认导出组件并命名导出 meta = definePage(...)。问题按 P0–P3 排序。每项包含:触发条件、实际影响、证据位置、建议修复。无问题时明确说明已覆盖
范围与未验证边界。不要粘贴 token、.env、用户 ID 或完整敏感请求。
© zhinjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .github/skills/zhin-audit of zhinjs/zhin.
Open the folder on GitHubat commit f38698f
Zhin Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Zhin Audit this skillzhinjs/zhin | 136 | — | ~596 | Automated safety check: Notes | MIT | |
| Code Review Skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Audit Fullyonatangross/orchestkit | 292 | — | ~3.5k | Automated safety check: Notes | MIT | |
| Code Reviewerrevfactory/harness-100 | 1.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Audit Flowzebbern/claude-code-guide | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | |
| Chatting With AWS Devops Agentaws/agent-toolkit-for-aws | 2.8k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
yonatangross/orchestkit
Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.
revfactory/harness-100
Full pipeline for automated code review. An agent skill from revfactory/harness-100.
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
aws/agent-toolkit-for-aws
Have a fast, conversational analysis with the AWS DevOps Agent.
borghei/Claude-Skills
Solutions architecture for technical pre-sales. An agent skill from borghei/Claude-Skills.
zhinjs/zhin
Refactor existing Zhin.js plugins into a cleaner standard structure.
zhinjs/zhin
Migrate legacy Zhin.js plugins and projects to the convention-based Plugin Runtime — from usePlugin/getPlugin/addCommand/addMiddleware/addComponent/addTool/addCron/declareConfig/useContext and…
zhinjs/zhin
Implement Zhin.js plugins with Plugin Runtime. An agent skill from zhinjs/zhin.
zhinjs/zhin
使用 gh CLI 处理内置 GitHub Tool 未覆盖的 Issue、PR、Release、Workflow、搜索和 API 操作。
zhinjs/zhin
企业微信平台管理能力。当用户在企业微信中请求用户信息查询、部门架构查询、 发送文本消息时使用。即使用户没有提到企业微信,只要上下文是企业微信/WeCom 场景且涉及用户查询、部门管理或消息发送,就应触发。
zhinjs/zhin
签到积分系统查询能力。当用户想查看自己的积分、签到排行榜、连签天数、 或了解签到奖励时使用。日常签到通过聊天命令触发,此技能提供积分查询的 AI 工具。
Categories
Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. Zhin Audit is an agent skill from zhinjs/zhin.js changes for security, performance, lifecycle, and architecture regressions.
Zhin Audit fits situations like: security review; performance review; architecture review; change-based code audit.
Run `npx skills add zhinjs/zhin --skill zhin-audit -a claude-code`. Or copy the skill folder (.github/skills/zhin-audit in zhinjs/zhin) into .claude/skills/zhin-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zhinjs/zhin --skill zhin-audit -a codex`. Or copy the skill folder (.github/skills/zhin-audit in zhinjs/zhin) into .agents/skills/zhin-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhinjs/zhin --skill zhin-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zhin-audit, .gemini/skills/zhin-audit, .github/skills/zhin-audit and .opencode/skills/zhin-audit in your project.
Going by SKILL.md and its folder, Zhin Audit needs the command-line tools its instructions call (pnpm).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Zhin Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 596 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Zhin Audit: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Audit Full (yonatangross/orchestkit, 292 stars), Code Reviewer (revfactory/harness-100, 1.3k stars) and Audit Flow (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zhinjs (a GitHub organization) maintains it in zhinjs/zhin, which has 136 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 10, 2026.
Source: zhinjs/zhin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.