{"slug":"mhawthorne-gza-code-review-full","name":"gza-code-review-full","description":"Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions","long_description":"---\nname: gza-code-review-full\ndescription: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions\nallowed-tools: Read, Glob, Grep, Bash(uv run pytest:*), Bash(uv run python:*), Bash(uv run mypy:*), Bash(ls:*), Bash(wc:*)\nversion: 1.0.0\npublic: false\n---\n\n# Full Codebase Code Review\n\nPerform a comprehensive code review of the gza codebase, suitable for pre-release assessment. This review covers:\n1. Unit test coverage\n2. Functional test coverage\n3. Code duplication\n4. Component interaction patterns\n5. Error handling consistency\n6. API/interface consistency\n7. Configuration and hardcoding audit\n8. Logging and observability\n9. Resource management\n10. Type safety\n\n## When to Use\n\n- Before a release to assess codebase health\n- When you want a comprehensive quality check\n- To identify areas needing more tests or refactoring\n\n## Output\n\nWrite findings to `reviews/<timestamp>-code-review-full-<model>.md` in the project root, where `<timestamp>` is the current date/time in `YYYYmmddHHMMSS` format and `<model>` is a short identifier for the model performing the review (e.g., `reviews/20260305114139-code-review-full-opus-4-6.md`). Use your own model name/ID to derive the short identifier.\n\n## Process\n\n### Step 1: Inventory the codebase\n\nMap out the source modules and test files:\n\n1. **List all source modules:**\n   ```bash\n   ls -la src/gza/*.py\n   ls -la src/gza/providers/*.py\n   ```\n\n2. **List all test files:**\n   ```bash\n   ls -la tests/*.py\n   ls -la tests_integration/*.py 2>/dev/null || echo \"No integration tests dir\"\n   ```\n\n3. **Create a mapping** of source file → test file(s):\n   - `db.py` → `test_db.py`\n   - `cli.py` → `test_cli.py`\n   - etc.\n\n4. **Identify untested modules** - source files with no corresponding test file\n\n### Step 2: Assess unit test coverage\n\nFor each source module:\n\n1. **Read the source file** to understand its public interface (functions, classes, methods)\n\n2. **Read the corresponding test file** (if exists)\n\n3. **Check coverage by listing:**\n   - Functions/methods that ARE tested\n   - Functions/methods that are NOT tested\n   - Edge cases that aren't covered (error paths, boundary conditions)\n\n4. **Run the tests** to verify they pass:\n   ```bash\n   uv run pytest tests/ -v --tb=short\n   ```\n\nFocus especially on:\n- **`db.py`** - Core task storage, critical for correctness\n- **`cli.py`** - User-facing commands, all subcommands should have tests\n- **`runner.py`** - Task execution logic\n- **`git.py`** - Git operations (mocked tests preferred)\n- **`github.py`** - GitHub integration\n\n### Step 3: Assess functional test coverage\n\nFunctional tests verify end-to-end workflows. Check for:\n\n1. **Core workflows that should have integration tests:**\n   - Creating a task → running it → verifying completion\n   - Task dependencies (task B waits for task A)\n   - PR creation workflow\n   - Review workflow\n   - Improve workflow\n\n2. **Read `tests_integration/`** (if exists) to see what's covered\n\n3. **Identify missing functional tests** - workflows documented in AGENTS.md that aren't tested\n\n### Step 4: Analyze code duplication\n\nLook for patterns of duplicated code:\n\n1. **Search for similar code blocks:**\n   - Similar function signatures doing similar things\n   - Copy-pasted error handling\n   - Repeated patterns that could be extracted\n\n2. **Check specific areas prone to duplication:**\n   - CLI command handlers (do they share common patterns that could be unified?)\n   - Database queries (repeated query patterns)\n   - Git operations (similar git command sequences)\n\n3. **Use grep to find suspicious patterns:**\n   ```bash\n   # Find similar function definitions\n   grep -n \"def.*task\" src/gza/*.py\n\n   # Find repeated patterns\n   grep -n \"subprocess.run\" src/gza/*.py\n   grep -n \"click.echo\" src/gza/cli.py\n   ```\n\n4. **Read AGENTS.md** section on \"Single code path principle\" and verify it's followed\n\n### Step 5: Check error handling consistency\n\nReview how errors are handled across the codebase:\n\n1. **Identify error handling patterns:**\n   ```bash\n   # Find exception raising\n   grep -n \"raise \" src/gza/*.py\n\n   # Find try/except blocks\n   grep -n \"except \" src/gza/*.py\n\n   # Find custom exceptions\n   grep -rn \"class.*Exception\" src/gza/\n   grep -rn \"class.*Error\" src/gza/\n   ```\n\n2. **Check for consistency:**\n   - Are errors handled uniformly? (always raise vs sometimes return None)\n   - Are custom exceptions used where appropriate vs generic `Exception`?\n   - Do error messages provide actionable information?\n   - Are exceptions caught too broadly? (`except Exception` vs specific types)\n\n3. **Look for problematic patterns:**\n   - Silent failures (bare `except:` or `except: pass`)\n   - Swallowed exceptions without logging\n   - Inconsistent error return values (None vs empty list vs raise)\n   - Missing error handling on I/O operations\n\n4. **Document findings:**\n   - List any inconsistencies in error handling approach\n   - Note functions that should raise but return None (or vice versa)\n   - Identify error messages that aren't helpful for debugging\n\n### Step 6: Check API/interface consistency\n\nReview function signatures and naming conventions:\n\n1. **Check naming consistency:**\n   ```bash\n   # Find all public function definitions\n   grep -n \"^def \" src/gza/*.py\n   grep -n \"    def \" src/gza/*.py | grep -v \"__\"\n   ```\n\n2. **Look for inconsistencies:**\n   - Similar operations with different names (`get_task` vs `fetch_task` vs `retrieve_task`)\n   - Parameter ordering inconsistencies (does `db` come first or last?)\n   - Return type inconsistencies (objects vs dicts vs tuples)\n\n3. **Check function signatures:**\n   - Do similar functions have similar signatures?\n   - Are there functions with too many parameters (>5)?\n   - Are boolean parameters used where enums would be clearer?\n\n4. **Review public interfaces:**\n   - Are module `__all__` exports defined?\n   - Is it clear what's public vs private? (underscore prefix convention)\n   - Are there functions that should be private but aren't?\n\n### Step 7: Audit configuration and hardcoding\n\nLook for magic values that should be configurable:\n\n1. **Find hardcoded values:**\n   ```bash\n   # Find numeric literals (potential magic numbers)\n   grep -En \"[^a-zA-Z_][0-9]{2,}[^0-9]\" src/gza/*.py\n\n   # Find string literals that might be paths or config\n   grep -n '\"/.*\"' src/gza/*.py\n   grep -n \"'/.*'\" src/gza/*.py\n   ```\n\n2. **Check for:**\n   - Magic numbers (timeouts, retry counts, limits)\n   - Hardcoded file paths\n   - Hardcoded URLs or endpoints\n   - Default values that should be configurable\n\n3. **Review path handling:**\n   - Are paths constructed safely using `pathlib`?\n   - Are there string concatenations for paths? (`dir + \"/\" + file`)\n   - Are relative vs absolute paths handled correctly?\n\n4. **Check configuration loading:**\n   - Is `config.py` the single source for configuration?\n   - Are there config values scattered in other modules?\n   - Are defaults documented?\n\n### Step 8: Review logging and observability\n\nAssess the ability to debug and monitor the system:\n\n1. **Check logging usage:**\n   ```bash\n   # Find logging calls\n   grep -n \"logging\\.\" src/gza/*.py\n   grep -n \"logger\\.\" src/gza/*.py\n   grep -n \"log\\.\" src/gza/*.py\n\n   # Find print statements (should these be logs?)\n   grep -n \"print(\" src/gza/*.py\n   ```\n\n2. **Assess logging quality:**\n   - Is there consistent logging for key operations?\n   - Can you trace a task's execution through the logs?\n   - Are log levels used appropriately? (debug vs info vs warning vs error)\n   - Are there operations that fail silently without logging?\n\n3. **Check for sensitive data exposure:**\n   ```bash\n   # Look for potential credential logging\n   grep -in \"api.key\\|token\\|password\\|secret\\|credential\" src/gza/*.py\n   ```\n   - Are API keys, tokens, or passwords properly excluded from logs?\n   - Are there any `repr()` or `str()` methods that might expose secrets?\n\n4. **Review error logging:**\n   - Are exceptions logged with stack traces where needed?\n   - Are error messages actionable?\n   - Is there enough context to debug issues?\n\n### Step 9: Check resource management\n\nLook for resource leaks and cleanup issues:\n\n1. **Check file handling:**\n   ```bash\n   # Find file operations\n   grep -n \"open(\" src/gza/*.py\n   grep -n \"with open\" src/gza/*.py\n   ```\n   - Are all file opens using context managers (`with`)?\n   - Are there any `open()` calls without corresponding `close()`?\n\n2. **Check database connections:**\n   ```bash\n   grep -n \"connect(\" src/gza/*.py\n   grep -n \"cursor\" src/gza/*.py\n   ```\n   - Are database connections properly closed?\n   - Are cursors managed with context managers?\n   - Is there connection pooling or is it connect-per-operation?\n\n3. **Check subprocess management:**\n   ```bash\n   grep -n \"subprocess\" src/gza/*.py\n   grep -n \"Popen\" src/gza/*.py\n   ```\n   - Are subprocesses properly waited on?\n   - Are there potential zombie processes?\n   - Are stdin/stdout/stderr handles closed?\n\n4. **Check for memory issues:**\n   - Are there unbounded caches or growing lists?\n   - Are large objects cleaned up after use?\n   - Are there circular references that prevent garbage collection?\n\n5. **Check temp file cleanup:**\n   ```bash\n   grep -n \"tempfile\\|mktemp\\|NamedTemporaryFile\" src/gza/*.py\n   ```\n   - Are temp files cleaned up after use?\n   - Are temp directories removed?\n\n### Step 10: Assess type safety\n\nReview type hints and type correctness:\n\n1. **Check type hint coverage:**\n   ```bash\n   # Find functions without return type hints\n   grep -n \"def.*):$\" src/gza/*.py\n\n   # Find functions with type hints\n   grep -n \"def.*) ->\" src/gza/*.py\n   ```\n\n2. **Run mypy (if configured):**\n   ```bash\n   uv run mypy src/gza/ --ignore-missing-imports 2>&1 | head -100\n   ```\n\n3. **Look for type safety issues:**\n   - Functions with `Any` types that could be more specific\n   - `Optional` types without proper `None` checks\n   - Type: ignore comments (are they justified?)\n   - Inconsistent types (function returns `str | None` but callers don't check)\n\n4. **Check for common type issues:**\n   ```bash\n   # Find potential None issues\n   grep -n \"\\.get(\" src/gza/*.py  # dict.get returns Optional\n   grep -n \"or None\" src/gza/*.py\n   grep -n \"if.*is None\" src/gza/*.py\n   ```\n\n### Step 11: Analyze component interaction patterns\n\nUnderstand how modules interact and assess the clarity of these interactions:\n\n1. **Map the import graph:**\n   ```bash\n   grep -h \"^from gza\" src/gza/*.py | sort | uniq -c | sort -rn\n   grep -h \"^import gza\" src/gza/*.py | sort | uniq -c | sort -rn\n   ```\n\n2. **Identify the layering:**\n   - Which modules are \"lower level\" (few dependencies)?\n   - Which are \"higher level\" (many dependencies)?\n   - Are there circular dependencies?\n\n3. **Check separation of concerns:**\n   - Does `cli.py` only handle CLI concerns, delegating to other modules?\n   - Does `db.py` only handle database concerns?\n   - Does `runner.py` only handle execution concerns?\n\n4. **Look for unclear interfaces:**\n   - Functions with too many parameters\n   - Functions that do too many things\n   - Tight coupling between modules that should be loosely coupled\n\n5. **Document the interaction patterns:**\n   ```\n   cli.py → db.py (task CRUD)\n   cli.py → runner.py (task execution)\n   runner.py → providers/* (AI execution)\n   runner.py → git.py (git operations)\n   etc.\n   ```\n\n### Step 12: Compile the review report\n\nCreate a structured report at `reviews/code-review-full.md`:\n\n```markdown\n# Gza Code Review - Pre-Release Assessment\n\nDate: YYYY-MM-DD\nReviewer: Claude\n\n## Executive Summary\n\n[2-3 sentence overview of codebase health]\n\n## Test Coverage\n\n### Unit Tests\n\n| Module | Test File | Coverage Assessment |\n|--------|-----------|---------------------|\n| db.py | test_db.py | Good - covers CRUD, queries |\n| cli.py | test_cli.py | Partial - missing `gza pr` tests |\n| ... | ... | ... |\n\n#### Well-Tested Areas\n- [List modules/features with good coverage]\n\n#### Under-Tested Areas\n- [List modules/featur","tagline":"Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions","category":"coding-agents","tags":["agent-skill"],"author":"mhawthorne","verified":false,"attribution":{"status":"registry_indexed","statusLabel":"Registry indexed","shortLabel":"REGISTRY INDEXED","sourceLabel":"recursive skill source sync","sourceDetail":"mhawthorne/gza","creatorName":"mhawthorne","creatorUrl":"https://github.com/mhawthorne","sourceUrl":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","indexedBy":"OpenAgentSkill community index","claimUrl":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full#claim-this-skill","claimCta":"Claim this skill","trustNote":"This listing was indexed from public sources and is not marked official until a maintainer claim is approved.","publicNote":"Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals."},"stats":{"stars":11,"forks":1,"verified_installs":0,"successful_runs":0,"total_outcomes":0,"rating":0,"review_count":0,"quality_score":30.8},"quality":{"score":57,"tier":"promising","label":"Promising","summary":"Useful candidate, but compare it with alternatives before adopting.","signals":[{"label":"GitHub stars","value":"11","tone":"neutral"},{"label":"Freshness","value":"1d ago","tone":"positive"},{"label":"Install ready","value":"Yes","tone":"positive"},{"label":"License","value":"MIT","tone":"neutral"}],"warnings":["Low GitHub adoption signal","Skill is highly specific to the gza codebase, limiting reusability for other projects."]},"trust":{"version":"trust-score-v5","score":50,"base_score":58,"outcome_confidence":0,"tier":"risk","label":"Do not auto-install","summary":"Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.","recommendedAction":"Choose a stronger alternative or inspect the source manually before any install attempt.","decision":{"install_policy":"sandbox_only","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["50/100 Trust Score v5","58/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":30,"weight":0.13,"status":"fail","detail":"11 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":32,"weight":0.08,"status":"fail","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"1d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":38,"weight":0.12,"status":"fail","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":18,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"fail","label":"GitHub adoption","detail":"11 GitHub stars"},{"status":"fail","label":"Stars/forks activity","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"1d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"fail","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"pass","label":"OpenAgentSkill usage","detail":"1 views, 0 install copies"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"11 GitHub stars","repoActivity":"11 stars, 1 forks","lastPushed":"1d since push","license":"MIT","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","install":"npx skills add mhawthorne/gza --skill gza-code-review-full","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"sandbox_only"},"installReadiness":{"ready":true,"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","policy":"sandbox_only","label":"Sandbox only","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","1d since push","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"sandbox_only","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v3","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["coding-agents","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add mhawthorne/gza --skill gza-code-review-full","trust_score":50,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["coding-agents","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":58,"tier":"review","label":"Manual review","summary":"Potentially useful, but at least one trust signal needs human inspection."}}},"trust_score_v5":{"version":"trust-score-v5","score":50,"base_score":58,"outcome_confidence":0,"tier":"risk","label":"Do not auto-install","summary":"Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.","recommendedAction":"Choose a stronger alternative or inspect the source manually before any install attempt.","decision":{"install_policy":"sandbox_only","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["50/100 Trust Score v5","58/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":30,"weight":0.13,"status":"fail","detail":"11 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":32,"weight":0.08,"status":"fail","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"1d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":38,"weight":0.12,"status":"fail","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":18,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"fail","label":"GitHub adoption","detail":"11 GitHub stars"},{"status":"fail","label":"Stars/forks activity","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"1d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"fail","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"pass","label":"OpenAgentSkill usage","detail":"1 views, 0 install copies"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"11 GitHub stars","repoActivity":"11 stars, 1 forks","lastPushed":"1d since push","license":"MIT","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","install":"npx skills add mhawthorne/gza --skill gza-code-review-full","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"sandbox_only"},"installReadiness":{"ready":true,"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","policy":"sandbox_only","label":"Sandbox only","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","1d since push","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"sandbox_only","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v3","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["coding-agents","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add mhawthorne/gza --skill gza-code-review-full","trust_score":50,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["coding-agents","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":58,"tier":"review","label":"Manual review","summary":"Potentially useful, but at least one trust signal needs human inspection."}}},"trust_score_v4":{"version":"trust-score-v4","score":58,"tier":"review","label":"Manual review","summary":"Potentially useful, but at least one trust signal needs human inspection.","recommendedAction":"Inspect the repository, license, and recent activity before connecting it to agent workflows.","dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":30,"weight":0.13,"status":"fail","detail":"11 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":32,"weight":0.08,"status":"fail","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"1d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":38,"weight":0.12,"status":"fail","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":18,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"fail","label":"GitHub adoption","detail":"11 GitHub stars"},{"status":"fail","label":"Stars/forks activity","detail":"11 stars, 1 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"1d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"fail","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add mhawthorne/gza --skill gza-code-review-full"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"pass","label":"OpenAgentSkill usage","detail":"1 views, 0 install copies"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern"],"warnings":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"evidence":{"stars":"11 GitHub stars","repoActivity":"11 stars, 1 forks","lastPushed":"1d since push","license":"MIT","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","install":"npx skills add mhawthorne/gza --skill gza-code-review-full","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"installReadiness":{"ready":true,"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","policy":"sandbox_only","label":"Sandbox only","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","1d since push"]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"sandbox_only","reason":"Human review or sandbox validation is required before automatic installation."},"bestFor":["coding-agents","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"outcome_stats":null,"safety":{"score":25,"level":"avoid_auto_install","label":"Avoid automatic install","safety_tier":{"tier":"blocked","label":"Blocked for auto-install","badge":"BLOCKED","summary":"This skill should not be selected by an agent without explicit human security review.","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","auto_install_policy":"block","reasons":["Metadata combines secrets access with shell or command execution","High-risk permission hints: Shell or command execution, Secrets or environment access"]},"auto_install_allowed":false,"human_review_required":true,"blocked":true,"audit_risk":"needs_review","permission_hints":[{"id":"shell","label":"Shell or command execution","reason":"Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.","severity":"high"},{"id":"network","label":"Network access","reason":"Skill likely fetches remote pages, APIs, repositories, or external services.","severity":"medium"},{"id":"filesystem","label":"Filesystem access","reason":"Skill may read or write project files, documents, generated artifacts, or local workspace state.","severity":"medium"},{"id":"secrets","label":"Secrets or environment access","reason":"Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.","severity":"high"},{"id":"database","label":"Database access","reason":"Skill may inspect schemas, query databases, or work with persistent stores.","severity":"medium"}],"policy_warnings":["High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review"],"constraints_applied":{"max_risk":"medium","needs_install_command":true,"min_stars":0}},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","badge":"BLOCKED","auto_install_policy":"block","auto_install_allowed":false,"blocked":true,"human_review_required":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","reasons":["Metadata combines secrets access with shell or command execution","High-risk permission hints: Shell or command execution, Secrets or environment access"]},"eval":{"version":"openagentskill-skill-eval-v1","status":"failed","score":57,"risk_level":"high","decision":{"recommendation":"do_not_auto_install","reason":"Trust score: Potentially useful, but at least one trust signal needs human inspection.","auto_install_allowed":false,"policy":"block","human_review_required":true},"blockers":["Trust score: Potentially useful, but at least one trust signal needs human inspection.","Agent safety gate: This skill should not be selected by an agent without explicit human security review.","Permission surface: secrets or environment access, shell or command execution"],"warnings":["Audit score: Needs review","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Skill is highly specific to the gza codebase, limiting reusability for other projects.","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).","The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata"],"validation_plan":["Inspect repository, README/SKILL.md, license, and recent commits before production use.","Install in an isolated workspace or sandbox with no production secrets available.","Run the smallest representative task and record files touched, commands run, network access, and outputs.","Compare the selected skill against at least one alternative when the eval status is review or failed.","Promote only after the agent reports a successful verification result and unresolved warnings are accepted."],"checks":[{"id":"task_fit","label":"Task fit","status":"pass","score":94,"required_for_auto_install":true,"detail":"Task wording matches this skill metadata.","evidence":["Evaluate gza-code-review-full before installing it in an agent workflow","coding-agents","GitHub automation workflows; Claude Code teams; builders willing to evaluate younger projects"]},{"id":"install_path","label":"Install path","status":"pass","score":92,"required_for_auto_install":true,"detail":"Install handoff is available.","evidence":["npx skills add mhawthorne/gza --skill gza-code-review-full"]},{"id":"install_safety","label":"Install command safety","status":"pass","score":92,"required_for_auto_install":true,"detail":"standard package or runtime install path","evidence":["npx skills add mhawthorne/gza --skill gza-code-review-full"]},{"id":"trust_score","label":"Trust score","status":"fail","score":58,"required_for_auto_install":true,"detail":"Potentially useful, but at least one trust signal needs human inspection.","evidence":["Manual review","11 GitHub stars","MIT"]},{"id":"audit_score","label":"Audit score","status":"warn","score":69,"required_for_auto_install":true,"detail":"Needs review","evidence":["Dependency or permission surface needs review"]},{"id":"agent_safety_gate","label":"Agent safety gate","status":"fail","score":25,"required_for_auto_install":true,"detail":"This skill should not be selected by an agent without explicit human security review.","evidence":["Do not auto-install. Inspect the source, dependencies, and permission surface first.","Metadata combines secrets access with shell or command execution"]},{"id":"readme_skillmd_completeness","label":"README/SKILL.md completeness","status":"pass","score":86,"required_for_auto_install":false,"detail":"Metadata includes enough usage and workflow context","evidence":["Strong README/SKILL.md context"]},{"id":"license_clarity","label":"License clarity","status":"pass","score":86,"required_for_auto_install":true,"detail":"MIT","evidence":["MIT"]},{"id":"recent_maintenance","label":"Recent maintenance","status":"pass","score":100,"required_for_auto_install":false,"detail":"1d since push","evidence":["1d since push"]},{"id":"permission_surface","label":"Permission surface","status":"fail","score":18,"required_for_auto_install":true,"detail":"secrets or environment access, shell or command execution","evidence":["Shell or command execution: high","Network access: medium","Filesystem access: medium"]},{"id":"alternatives","label":"Alternatives available","status":"info","score":55,"required_for_auto_install":false,"detail":"No close alternatives were found in the current shortlist.","evidence":[]}],"endpoints":{"web":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/evals","api":"/api/agent/evals?slug=mhawthorne-gza-code-review-full","text":"/api/agent/evals?slug=mhawthorne-gza-code-review-full&format=text"}},"agent_readable_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"mhawthorne-gza-code-review-full","name":"gza-code-review-full","description":"Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions","category":"coding-agents","url":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","github_repo":"mhawthorne/gza"},"suited_tasks":["GitHub automation workflows","Claude Code teams","builders willing to evaluate younger projects","Inspect repository metadata","Compare code changes","Write concise engineering summaries","Inspect source files","Explain architecture"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-full"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"gza-code-review-full\" agent skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"gza-code-review-full\" as a Claude Code skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"gza-code-review-full\" from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/mhawthorne-gza-code-review-full"},"trust":{"score":58,"label":"Manual review","version":"trust-score-v4","install_policy":"sandbox_only","evidence":{"stars":"11 GitHub stars","repoActivity":"11 stars, 1 forks","lastPushed":"1d since push","license":"MIT","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","install":"npx skills add mhawthorne/gza --skill gza-code-review-full","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["coding-agents","agent-skill"],"known_risks":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":69,"risk_level":"needs_review","risk_label":"Needs review","warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Skill is highly specific to the gza codebase, limiting reusability for other projects.","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).","The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution"]},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","auto_install_policy":"block","auto_install_allowed":false,"human_review_required":true,"blocked":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first."},"quality":{"score":57,"label":"Promising"},"supply":{"track":"Coding and developer agents","scenario":"GitHub automation","maintenance":"1d since push","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","production agents without a repository review","Low GitHub adoption signal","Skill is highly specific to the gza codebase, limiting reusability for other projects.","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage)."],"agent_contract":{"task_input":"Use gza-code-review-full in an agent workflow","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","install_policy":"block","minimum_review_before_use":["Trust: 58/100 Manual review","Audit: 69/100 Needs review","Safety: 25/100 Avoid automatic install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"mhawthorne-gza-code-review-full (gza-code-review-full)","install_command":"npx skills add mhawthorne/gza --skill gza-code-review-full","risk_summary":"Needs review; Blocked for auto-install; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"mhawthorne-gza-code-review-full","task":"Use gza-code-review-full in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full","api":"https://www.openagentskill.com/api/agent/skills/mhawthorne-gza-code-review-full","audit":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=mhawthorne-gza-code-review-full&task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install","manifest":"https://www.openagentskill.com/api/registry/manifest/mhawthorne-gza-code-review-full"}},"machine_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"mhawthorne-gza-code-review-full","name":"gza-code-review-full","description":"Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions","category":"coding-agents","url":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","github_repo":"mhawthorne/gza"},"suited_tasks":["GitHub automation workflows","Claude Code teams","builders willing to evaluate younger projects","Inspect repository metadata","Compare code changes","Write concise engineering summaries","Inspect source files","Explain architecture"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-full"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"gza-code-review-full\" agent skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"gza-code-review-full\" as a Claude Code skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"gza-code-review-full\" from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/mhawthorne-gza-code-review-full"},"trust":{"score":58,"label":"Manual review","version":"trust-score-v4","install_policy":"sandbox_only","evidence":{"stars":"11 GitHub stars","repoActivity":"11 stars, 1 forks","lastPushed":"1d since push","license":"MIT","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","install":"npx skills add mhawthorne/gza --skill gza-code-review-full","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["coding-agents","agent-skill"],"known_risks":["Skill is highly specific to the gza codebase, limiting reusability for other projects.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":69,"risk_level":"needs_review","risk_label":"Needs review","warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Skill is highly specific to the gza codebase, limiting reusability for other projects.","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).","The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution"]},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","auto_install_policy":"block","auto_install_allowed":false,"human_review_required":true,"blocked":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first."},"quality":{"score":57,"label":"Promising"},"supply":{"track":"Coding and developer agents","scenario":"GitHub automation","maintenance":"1d since push","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","production agents without a repository review","Low GitHub adoption signal","Skill is highly specific to the gza codebase, limiting reusability for other projects.","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage)."],"agent_contract":{"task_input":"Use gza-code-review-full in an agent workflow","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","install_policy":"block","minimum_review_before_use":["Trust: 58/100 Manual review","Audit: 69/100 Needs review","Safety: 25/100 Avoid automatic install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"mhawthorne-gza-code-review-full (gza-code-review-full)","install_command":"npx skills add mhawthorne/gza --skill gza-code-review-full","risk_summary":"Needs review; Blocked for auto-install; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"mhawthorne-gza-code-review-full","task":"Use gza-code-review-full in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full","api":"https://www.openagentskill.com/api/agent/skills/mhawthorne-gza-code-review-full","audit":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=mhawthorne-gza-code-review-full&task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20gza-code-review-full%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install","manifest":"https://www.openagentskill.com/api/registry/manifest/mhawthorne-gza-code-review-full"}},"supply_profile":{"track":{"slug":"coding","label":"Coding and developer agents","shortLabel":"Coding","description":"Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills."},"scenario":{"label":"GitHub automation","description":"I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.","useCases":[{"slug":"github-automation","title":"GitHub automation"},{"slug":"coding-agents","title":"Coding agents"},{"slug":"research-agents","title":"Research agents"}]},"applicableAgents":["Claude Code","Cursor","CLI","Codex"],"install":{"ready":true,"command":"npx skills add mhawthorne/gza --skill gza-code-review-full","primaryTarget":"CLI","targetCount":4},"githubQuality":{"stars":11,"starsLabel":"11","forks":1,"license":"MIT","qualityScore":57,"trustScore":58,"auditScore":69},"maintenance":{"status":"fresh","label":"1d since push","daysSincePush":1,"lastPushedAt":"2026-08-21T20:11:47+00:00"},"risk":{"level":"needs_review","label":"Needs review","requiresReview":true,"notes":["Dependency or permission surface needs review","Permission surface may require sandboxing","Skill is highly specific to the gza codebase, limiting reusability for other projects.","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).","The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied."]},"coverageTags":["Coding","GitHub automation","coding-agents","agent-skill"]},"audit":{"audit_score":69,"risk_level":"needs_review","risk_label":"Needs review","quality_score":57,"trust_score":58,"maintenance_score":100,"security_score":68,"install_score":92,"warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Skill is highly specific to the gza codebase, limiting reusability for other projects.","Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).","The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied.","Low GitHub adoption signal","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","GitHub adoption: 11 GitHub stars","Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"quality_signals":{"model":"v2","star_score":7.55,"usage_score":0,"review_score":5.25,"metadata_score":3,"freshness_score":15},"platforms":["Claude Code","Cursor"],"use_cases":[{"slug":"github-automation","title":"GitHub automation","url":"https://www.openagentskill.com/use-cases/github-automation"},{"slug":"coding-agents","title":"Coding agents","url":"https://www.openagentskill.com/use-cases/coding-agents"},{"slug":"research-agents","title":"Research agents","url":"https://www.openagentskill.com/use-cases/research-agents"},{"slug":"workflow-automation","title":"Workflow automation","url":"https://www.openagentskill.com/use-cases/workflow-automation"}],"stacks":[{"slug":"coding-review-agent","title":"Coding review agent","url":"https://www.openagentskill.com/collections/coding-review-agent"},{"slug":"research-report-agent","title":"Research report agent","url":"https://www.openagentskill.com/collections/research-report-agent"},{"slug":"content-growth-agent","title":"Content growth agent","url":"https://www.openagentskill.com/collections/content-growth-agent"}],"install":"npx skills add mhawthorne/gza --skill gza-code-review-full","install_targets":[{"id":"openagentskill-cli","label":"CLI","title":"OpenAgentSkill CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-full","description":"Resolve policy, run the source installer safely, and report a verified install receipt.","copyLabel":"Copy command"},{"id":"codex","label":"Codex","title":"Codex install prompt","kind":"agent-prompt","value":"Install the \"gza-code-review-full\" agent skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Give Codex a repo-aware install prompt when the skill is not available through a local CLI.","copyLabel":"Copy prompt"},{"id":"claude-code","label":"Claude Code","title":"Claude Code skill prompt","kind":"agent-prompt","value":"Add \"gza-code-review-full\" as a Claude Code skill from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this prompt to ask Claude Code to add the skill and explain the local activation steps.","copyLabel":"Copy prompt"},{"id":"cursor","label":"Cursor","title":"Cursor rule prompt","kind":"agent-prompt","value":"Turn \"gza-code-review-full\" from https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"mhawthorne-gza-code-review-full\",\"task\":\"Install gza-code-review-full\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this when installing as Cursor project rules or reusable agent instructions.","copyLabel":"Copy prompt"}],"repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","github_repo":"mhawthorne/gza","version":"1.0.0","license":"MIT","urls":{"web":"https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full","repository":"https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full","api":"/api/agent/skills/mhawthorne-gza-code-review-full","install_api":"/api/skills/mhawthorne-gza-code-review-full/install"},"meta":{"created_at":"2026-08-21T20:36:07.17243+00:00","updated_at":"2026-08-21T20:36:07.17243+00:00","agent_friendly":true}}