gza-code-review-full

审查 · 50
已收录

Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions

Verified installs0
Stars11
版本1.0.0
质量57/100 · 有潜力
信任50/100 · Do not auto-install
审计69/100 · 需审查

供给资产档案

编程与开发 Agent

代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。

浏览赛道

场景

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

适配 Agent

Claude Code + Cursor + CLI

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add mhawthorne/gza --skill gza-code-review-full

维护状态

新鲜

距上次推送 1 天

风险

需审查

Dependency or permission surface needs review

GitHub 质量

11

57/100 质量 · 58/100 信任

覆盖标签

编程GitHub automation编程 Agentagent-skill

审查说明

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

有潜力
57

有用的候选项,但采用前应与替代方案比较。

信任

Do not auto-install
50

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

审计

需审查
69

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

仅限沙盒

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

11 个 GitHub Stars

仓库活跃度

11 个 Star,1 个 Fork

维护状态

距上次推送 1 天

许可证

MIT

安装

npx skills add mhawthorne/gza --skill gza-code-review-full

安装安全性

标准软件包或运行时安装路径

权限范围

secrets or environment access, shell or command execution

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

打开 JSON

适用任务

  • GitHub automation 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects
  • Inspect repository metadata

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

安装决策

命令
npx skills add mhawthorne/gza --skill gza-code-review-full
策略
阻止
人工审查

信任与风险

信任
50/100
审计
69/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add mhawthorne/gza --skill gza-code-review-full

不适用场景

  • 需要厂商支持 SLA 的团队
  • production agents without a repository review
  • Low GitHub adoption signal
  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • 高风险权限提示:Shell or command execution, Secrets or environment access

Agent 安全 v2

25/100 · 避免自动安装

Blocked for auto-install阻止

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

安装目标

在你的 Agent 工作流中安装此 Skill

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-full

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use gza-code-review-full in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-full%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install
Install command: npx skills add mhawthorne/gza --skill gza-code-review-full
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use gza-code-review-full for this task. Review https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install, then install with: npx skills add mhawthorne/gza --skill gza-code-review-full

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

56/100

GitHub automation

平台

Claude Code, Cursor

审计报告

需审查 · 69/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

Needs validation for GitHub automation

在将它加入 Agent 工作流前先人工审查仓库。

56
就绪度
审查
阶段

栈中角色

需要验证

主要匹配

GitHub automation

信任标签

需要人工审查

安装路径

命令已就绪

适用场景

  • GitHub automation 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects

证据

  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 57/100 质量档案
  • 1 个 OpenAgentSkill 交互事件

先审查

  • Low GitHub adoption signal
  • Skill is highly specific to the gza codebase, limiting reusability for other projects.

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

50
OpenAgentSkill 信任评分

GitHub 采用度

修复

11 个 GitHub Stars

Star/Fork 活跃度

修复

11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

距上次推送 1 天

许可证清晰度

通过

MIT

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 11 GitHub stars
  • Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

Choose a stronger alternative or inspect the source manually before any install attempt.

质量档案

有潜力 适用于 Agent 工作流的候选

有用的候选项,但采用前应与替代方案比较。

57
GitHub Stars
11
新鲜度
1 天前
安装就绪
许可证
MIT
安装前审查: Low GitHub adoption signal · Skill is highly specific to the gza codebase, limiting reusability for other projects.

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: gza-code-review-full description: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions allowed-tools: Read, Glob, Grep, Bash(uv run pytest:*), Bash(uv run python:*), Bash(uv run mypy:*), Bash(ls:*), Bash(wc:*) version: 1.0.0 public: false ---

# Full Codebase Code Review

Perform a comprehensive code review of the gza codebase, suitable for pre-release assessment. This review covers: 1. Unit test coverage 2. Functional test coverage 3. Code duplication 4. Component interaction patterns 5. Error handling consistency 6. API/interface consistency 7. Configuration and hardcoding audit 8. Logging and observability 9. Resource management 10. Type safety

## When to Use

- Before a release to assess codebase health - When you want a comprehensive quality check - To identify areas needing more tests or refactoring

## Output

Write findings to `reviews/<timestamp>-code-review-full-<model>.md` in the project root, where `<timestamp>` is the current date/time in `YYYYmmddHHMMSS` format and `<model>` is a short identifier for the model performing the review (e.g., `reviews/20260305114139-code-review-full-opus-4-6.md`). Use your own model name/ID to derive the short identifier.

## Process

### Step 1: Inventory the codebase

Map out the source modules and test files:

1. **List all source modules:** ```bash ls -la src/gza/*.py ls -la src/gza/providers/*.py ```

2. **List all test files:** ```bash ls -la tests/*.py ls -la tests_integration/*.py 2>/dev/null || echo "No integration tests dir" ```

3. **Create a mapping** of source file → test file(s): - `db.py` → `test_db.py` - `cli.py` → `test_cli.py` - etc.

4. **Identify untested modules** - source files with no corresponding test file

### Step 2: Assess unit test coverage

For each source module:

1. **Read the source file** to understand its public interface (functions, classes, methods)

2. **Read the corresponding test file** (if exists)

3. **Check coverage by listing:** - Functions/methods that ARE tested - Functions/methods that are NOT tested - Edge cases that aren't covered (error paths, boundary conditions)

4. **Run the tests** to verify they pass: ```bash uv run pytest tests/ -v --tb=short ```

Focus especially on: - **`db.py`** - Core task storage, critical for correctness - **`cli.py`** - User-facing commands, all subcommands should have tests - **`runner.py`** - Task execution logic - **`git.py`** - Git operations (mocked tests preferred) - **`github.py`** - GitHub integration

### Step 3: Assess functional test coverage

Functional tests verify end-to-end workflows. Check for:

1. **Core workflows that should have integration tests:** - Creating a task → running it → verifying completion - Task dependencies (task B waits for task A) - PR creation workflow - Review workflow - Improve workflow

2. **Read `tests_integration/`** (if exists) to see what's covered

3. **Identify missing functional tests** - workflows documented in AGENTS.md that aren't tested

### Step 4: Analyze code duplication

Look for patterns of duplicated code:

1. **Search for similar code blocks:** - Similar function signatures doing similar things - Copy-pasted error handling - Repeated patterns that could be extracted

2. **Check specific areas prone to duplication:** - CLI command handlers (do they share common patterns that could be unified?) - Database queries (repeated query patterns) - Git operations (similar git command sequences)

3. **Use grep to find suspicious patterns:** ```bash # Find similar function definitions grep -n "def.*task" src/gza/*.py

# Find repeated patterns grep -n "subprocess.run" src/gza/*.py grep -n "click.echo" src/gza/cli.py ```

4. **Read AGENTS.md** section on "Single code path principle" and verify it's followed

### Step 5: Check error handling consistency

Review how errors are handled across the codebase:

1. **Identify error handling patterns:** ```bash # Find exception raising grep -n "raise " src/gza/*.py

# Find try/except blocks grep -n "except " src/gza/*.py

# Find custom exceptions grep -rn "class.*Exception" src/gza/ grep -rn "class.*Error" src/gza/ ```

2. **Check for consistency:** - Are errors handled uniformly? (always raise vs sometimes return None) - Are custom exceptions used where appropriate vs generic `Exception`? - Do error messages provide actionable information? - Are exceptions caught too broadly? (`except Exception` vs specific types)

3. **Look for problematic patterns:** - Silent failures (bare `except:` or `except: pass`) - Swallowed exceptions without logging - Inconsistent error return values (None vs empty list vs raise) - Missing error handling on I/O operations

4. **Document findings:** - List any inconsistencies in error handling approach - Note functions that should raise but return None (or vice versa) - Identify error messages that aren't helpful for debugging

### Step 6: Check API/interface consistency

Review function signatures and naming conventions:

1. **Check naming consistency:** ```bash # Find all public function definitions grep -n "^def " src/gza/*.py grep -n " def " src/gza/*.py | grep -v "__" ```

2. **Look for inconsistencies:** - Similar operations with different names (`get_task` vs `fetch_task` vs `retrieve_task`) - Parameter ordering inconsistencies (does `db` come first or last?) - Return type inconsistencies (objects vs dicts vs tuples)

3. **Check function signatures:** - Do similar functions have similar signatures? - Are there functions with too many parameters (>5)? - Are boolean parameters used where enums would be clearer?

4. **Review public interfaces:** - Are module `__all__` exports defined? - Is it clear what's public vs private? (underscore prefix convention) - Are there functions that should be private but aren't?

### Step 7: Audit configuration and hardcoding

Look for magic values that should be configurable:

1. **Find hardcoded values:** ```bash # Find numeric literals (potential magic numbers) grep -En "[^a-zA-Z_][0-9]{2,}[^0-9]" src/gza/*.py

# Find string literals that might be paths or config grep -n '"/.*"' src/gza/*.py grep -n "'/.*'" src/gza/*.py ```

2. **Check for:** - Magic numbers (timeouts, retry counts, limits) - Hardcoded file paths - Hardcoded URLs or endpoints - Default values that should be configurable

3. **Review path handling:** - Are paths constructed safely using `pathlib`? - Are there string concatenations for paths? (`dir + "/" + file`) - Are relative vs absolute paths handled correctly?

4. **Check configuration loading:** - Is `config.py` the single source for configuration? - Are there config values scattered in other modules? - Are defaults documented?

### Step 8: Review logging and observability

Assess the ability to debug and monitor the system:

1. **Check logging usage:** ```bash # Find logging calls grep -n "logging\." src/gza/*.py grep -n "logger\." src/gza/*.py grep -n "log\." src/gza/*.py

# Find print statements (should these be logs?) grep -n "print(" src/gza/*.py ```

2. **Assess logging quality:** - Is there consistent logging for key operations? - Can you trace a task's execution through the logs? - Are log levels used appropriately? (debug vs info vs warning vs error) - Are there operations that fail silently without logging?

3. **Check for sensitive data exposure:** ```bash # Look for potential credential logging grep -in "api.key\|token\|password\|secret\|credential" src/gza/*.py ``` - Are API keys, tokens, or passwords properly excluded from logs? - Are there any `repr()` or `str()` methods that might expose secrets?

4. **Review error logging:** - Are exceptions logged with stack traces where needed? - Are error messages actionable? - Is there enough context to debug issues?

### Step 9: Check resource management

Look for resource leaks and cleanup issues:

1. **Check file handling:** ```bash # Find file operations grep -n "open(" src/gza/*.py grep -n "with open" src/gza/*.py ``` - Are all file opens using context managers (`with`)? - Are there any `open()` calls without corresponding `close()`?

2. **Check database connections:** ```bash grep -n "connect(" src/gza/*.py grep -n "cursor" src/gza/*.py ``` - Are database connections properly closed? - Are cursors managed with context managers? - Is there connection pooling or is it connect-per-operation?

3. **Check subprocess management:** ```bash grep -n "subprocess" src/gza/*.py grep -n "Popen" src/gza/*.py ``` - Are subprocesses properly waited on? - Are there potential zombie processes? - Are stdin/stdout/stderr handles closed?

4. **Check for memory issues:** - Are there unbounded caches or growing lists? - Are large objects cleaned up after use? - Are there circular references that prevent garbage collection?

5. **Check temp file cleanup:** ```bash grep -n "tempfile\|mktemp\|NamedTemporaryFile" src/gza/*.py ``` - Are temp files cleaned up after use? - Are temp directories removed?

### Step 10: Assess type safety

Review type hints and type correctness:

1. **Check type hint coverage:** ```bash # Find functions without return type hints grep -n "def.*):$" src/gza/*.py

# Find functions with type hints grep -n "def.*) ->" src/gza/*.py ```

2. **Run mypy (if configured):** ```bash uv run mypy src/gza/ --ignore-missing-imports 2>&1 | head -100 ```

3. **Look for type safety issues:** - Functions with `Any` types that could be more specific - `Optional` types without proper `None` checks - Type: ignore comments (are they justified?) - Inconsistent types (function returns `str | None` but callers don't check)

4. **Check for common type issues:** ```bash # Find potential None issues grep -n "\.get(" src/gza/*.py # dict.get returns Optional grep -n "or None" src/gza/*.py grep -n "if.*is None" src/gza/*.py ```

### Step 11: Analyze component interaction patterns

Understand how modules interact and assess the clarity of these interactions:

1. **Map the import graph:** ```bash grep -h "^from gza" src/gza/*.py | sort | uniq -c | sort -rn grep -h "^import gza" src/gza/*.py | sort | uniq -c | sort -rn ```

2. **Identify the layering:** - Which modules are "lower level" (few dependencies)? - Which are "higher level" (many dependencies)? - Are there circular dependencies?

3. **Check separation of concerns:** - Does `cli.py` only handle CLI concerns, delegating to other modules? - Does `db.py` only handle database concerns? - Does `runner.py` only handle execution concerns?

4. **Look for unclear interfaces:** - Functions with too many parameters - Functions that do too many things - Tight coupling between modules that should be loosely coupled

5. **Document the interaction patterns:** ``` cli.py → db.py (task CRUD) cli.py → runner.py (task execution) runner.py → providers/* (AI execution) runner.py → git.py (git operations) etc. ```

### Step 12: Compile the review report

Create a structured report at `reviews/code-review-full.md`:

```markdown # Gza Code Review - Pre-Release Assessment

Date: YYYY-MM-DD Reviewer: Claude

## Executive Summary

[2-3 sentence overview of codebase health]

## Test Coverage

### Unit Tests

| Module | Test File | Coverage Assessment | |--------|-----------|---------------------| | db.py | test_db.py | Good - covers CRUD, queries | | cli.py | test_cli.py | Partial - missing `gza pr` tests | | ... | ... | ... |

#### Well-Tested Areas - [List modules/features with good coverage]

#### Under-Tested Areas - [List modules/featur

技术详情

版本
1.0.0
许可证
MIT
最近更新
2026年8月21日
发布时间
2026年8月21日

决策摘要

需要验证

56
就绪
审查
阶段

仓库近期活跃

审计

安装审查

安装与采用审查

69
需审查
安全性
68/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 gza-code-review-full 准备的场景化草稿,可手动发布到 X。

策展说明
gza-code-review-full: Comprehensive pre-release code review assessing test coverage, code duplication, and componen...

11 stars

https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for gza-code-review-full:
https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x

Install: npx skills add mhawthorne/gza --skill gza-code-review-full
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
mhawthorne
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 mhawthorne,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=listed&label=Listed)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=trust&label=Trust)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=audit&label=Audit)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)

作者

M

mhawthorne

@mhawthorne

平台适配

健康信号

GitHub Stars
11
质量评分
31/100
最近 GitHub 推送
2026年8月21日
框架提示
未知
OpenAgentSkill 浏览量
1
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

Do not auto-install

50
  • GitHub 采用度11 个 GitHub Stars修复
  • Star/Fork 活跃度11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息修复
  • 近期维护距上次推送 1 天通过
  • 许可证清晰度MIT通过
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险command execution surface, credential or environment access修复