gza-code-review-full
Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
适配 Agent
Claude Code + Cursor + CLI
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add mhawthorne/gza --skill gza-code-review-full
维护状态
新鲜
距上次推送 1 天
风险
需审查
Dependency or permission surface needs review
GitHub 质量
11
57/100 质量 · 58/100 信任
覆盖标签
审查说明
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
仅限沙盒
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
11 个 GitHub Stars
仓库活跃度
11 个 Star,1 个 Fork
维护状态
距上次推送 1 天
许可证
MIT
安装
npx skills add mhawthorne/gza --skill gza-code-review-full
安装安全性
标准软件包或运行时安装路径
权限范围
secrets or environment access, shell or command execution
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- Skill is highly specific to the gza codebase, limiting reusability for other projects.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Inspect repository metadata
适用 Agent
安装决策
- 命令
- npx skills add mhawthorne/gza --skill gza-code-review-full
- 策略
- 阻止
- 人工审查
- 是
信任与风险
- 信任
- 50/100
- 审计
- 69/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- Skill is highly specific to the gza codebase, limiting reusability for other projects.
- 高风险权限提示:Shell or command execution, Secrets or environment access
替代 Skill
Code Review
168.6K Stars
npx skills add mattpocock/skills --skill code-review
替代 Skill
Grill With Docs
164.7K Stars
npx skills add mattpocock/skills --skill grill-with-docs
替代 Skill
To Spec
164.7K Stars
npx skills add mattpocock/skills --skill to-spec
替代 Skill
To Tickets
176.7K Stars
npx skills add mattpocock/skills --skill to-tickets
Agent 安全 v2
25/100 · 避免自动安装
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
高
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- 高风险权限提示:Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-fullAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20gza-code-review-full%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20gza-code-review-full%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/mhawthorne-gza-code-review-full/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use gza-code-review-full in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-full%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install
Install command: npx skills add mhawthorne/gza --skill gza-code-review-full
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/mhawthorne-gza-code-review-full/install
LLM 文本格式
/api/skills/mhawthorne-gza-code-review-full/install?format=text
寻找替代方案
/api/skills/search?q=gza-code-review-full&limit=3
Agent 提示词
Use gza-code-review-full for this task. Review https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install, then install with: npx skills add mhawthorne/gza --skill gza-code-review-fullRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Agent 决策面板
Needs validation for GitHub automation
在将它加入 Agent 工作流前先人工审查仓库。
栈中角色
需要验证
主要匹配
GitHub automation
信任标签
需要人工审查
安装路径
命令已就绪
适用场景
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 57/100 质量档案
- 1 个 OpenAgentSkill 交互事件
先审查
- Low GitHub adoption signal
- Skill is highly specific to the gza codebase, limiting reusability for other projects.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub 采用度
修复11 个 GitHub Stars
Star/Fork 活跃度
修复11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 1 天
许可证清晰度
通过MIT
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Skill is highly specific to the gza codebase, limiting reusability for other projects.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 11 GitHub stars
- Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
Choose a stronger alternative or inspect the source manually before any install attempt.
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
工作流匹配
加入完整工作流
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Grill With Docs
A relentless interview that pressure-tests a plan against the codebase, sharpens domain language, and updates CONTEXT.md and ADRs when decisions become durable.
To Spec
Turn the current conversation and codebase context into a structured implementation spec, then publish it to the configured project issue tracker.
To Tickets
Break a plan, spec, or conversation into independently actionable tracer-bullet tickets with explicit blocking relationships.
概览
--- name: gza-code-review-full description: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions allowed-tools: Read, Glob, Grep, Bash(uv run pytest:*), Bash(uv run python:*), Bash(uv run mypy:*), Bash(ls:*), Bash(wc:*) version: 1.0.0 public: false ---
# Full Codebase Code Review
Perform a comprehensive code review of the gza codebase, suitable for pre-release assessment. This review covers: 1. Unit test coverage 2. Functional test coverage 3. Code duplication 4. Component interaction patterns 5. Error handling consistency 6. API/interface consistency 7. Configuration and hardcoding audit 8. Logging and observability 9. Resource management 10. Type safety
## When to Use
- Before a release to assess codebase health - When you want a comprehensive quality check - To identify areas needing more tests or refactoring
## Output
Write findings to `reviews/<timestamp>-code-review-full-<model>.md` in the project root, where `<timestamp>` is the current date/time in `YYYYmmddHHMMSS` format and `<model>` is a short identifier for the model performing the review (e.g., `reviews/20260305114139-code-review-full-opus-4-6.md`). Use your own model name/ID to derive the short identifier.
## Process
### Step 1: Inventory the codebase
Map out the source modules and test files:
1. **List all source modules:** ```bash ls -la src/gza/*.py ls -la src/gza/providers/*.py ```
2. **List all test files:** ```bash ls -la tests/*.py ls -la tests_integration/*.py 2>/dev/null || echo "No integration tests dir" ```
3. **Create a mapping** of source file → test file(s): - `db.py` → `test_db.py` - `cli.py` → `test_cli.py` - etc.
4. **Identify untested modules** - source files with no corresponding test file
### Step 2: Assess unit test coverage
For each source module:
1. **Read the source file** to understand its public interface (functions, classes, methods)
2. **Read the corresponding test file** (if exists)
3. **Check coverage by listing:** - Functions/methods that ARE tested - Functions/methods that are NOT tested - Edge cases that aren't covered (error paths, boundary conditions)
4. **Run the tests** to verify they pass: ```bash uv run pytest tests/ -v --tb=short ```
Focus especially on: - **`db.py`** - Core task storage, critical for correctness - **`cli.py`** - User-facing commands, all subcommands should have tests - **`runner.py`** - Task execution logic - **`git.py`** - Git operations (mocked tests preferred) - **`github.py`** - GitHub integration
### Step 3: Assess functional test coverage
Functional tests verify end-to-end workflows. Check for:
1. **Core workflows that should have integration tests:** - Creating a task → running it → verifying completion - Task dependencies (task B waits for task A) - PR creation workflow - Review workflow - Improve workflow
2. **Read `tests_integration/`** (if exists) to see what's covered
3. **Identify missing functional tests** - workflows documented in AGENTS.md that aren't tested
### Step 4: Analyze code duplication
Look for patterns of duplicated code:
1. **Search for similar code blocks:** - Similar function signatures doing similar things - Copy-pasted error handling - Repeated patterns that could be extracted
2. **Check specific areas prone to duplication:** - CLI command handlers (do they share common patterns that could be unified?) - Database queries (repeated query patterns) - Git operations (similar git command sequences)
3. **Use grep to find suspicious patterns:** ```bash # Find similar function definitions grep -n "def.*task" src/gza/*.py
# Find repeated patterns grep -n "subprocess.run" src/gza/*.py grep -n "click.echo" src/gza/cli.py ```
4. **Read AGENTS.md** section on "Single code path principle" and verify it's followed
### Step 5: Check error handling consistency
Review how errors are handled across the codebase:
1. **Identify error handling patterns:** ```bash # Find exception raising grep -n "raise " src/gza/*.py
# Find try/except blocks grep -n "except " src/gza/*.py
# Find custom exceptions grep -rn "class.*Exception" src/gza/ grep -rn "class.*Error" src/gza/ ```
2. **Check for consistency:** - Are errors handled uniformly? (always raise vs sometimes return None) - Are custom exceptions used where appropriate vs generic `Exception`? - Do error messages provide actionable information? - Are exceptions caught too broadly? (`except Exception` vs specific types)
3. **Look for problematic patterns:** - Silent failures (bare `except:` or `except: pass`) - Swallowed exceptions without logging - Inconsistent error return values (None vs empty list vs raise) - Missing error handling on I/O operations
4. **Document findings:** - List any inconsistencies in error handling approach - Note functions that should raise but return None (or vice versa) - Identify error messages that aren't helpful for debugging
### Step 6: Check API/interface consistency
Review function signatures and naming conventions:
1. **Check naming consistency:** ```bash # Find all public function definitions grep -n "^def " src/gza/*.py grep -n " def " src/gza/*.py | grep -v "__" ```
2. **Look for inconsistencies:** - Similar operations with different names (`get_task` vs `fetch_task` vs `retrieve_task`) - Parameter ordering inconsistencies (does `db` come first or last?) - Return type inconsistencies (objects vs dicts vs tuples)
3. **Check function signatures:** - Do similar functions have similar signatures? - Are there functions with too many parameters (>5)? - Are boolean parameters used where enums would be clearer?
4. **Review public interfaces:** - Are module `__all__` exports defined? - Is it clear what's public vs private? (underscore prefix convention) - Are there functions that should be private but aren't?
### Step 7: Audit configuration and hardcoding
Look for magic values that should be configurable:
1. **Find hardcoded values:** ```bash # Find numeric literals (potential magic numbers) grep -En "[^a-zA-Z_][0-9]{2,}[^0-9]" src/gza/*.py
# Find string literals that might be paths or config grep -n '"/.*"' src/gza/*.py grep -n "'/.*'" src/gza/*.py ```
2. **Check for:** - Magic numbers (timeouts, retry counts, limits) - Hardcoded file paths - Hardcoded URLs or endpoints - Default values that should be configurable
3. **Review path handling:** - Are paths constructed safely using `pathlib`? - Are there string concatenations for paths? (`dir + "/" + file`) - Are relative vs absolute paths handled correctly?
4. **Check configuration loading:** - Is `config.py` the single source for configuration? - Are there config values scattered in other modules? - Are defaults documented?
### Step 8: Review logging and observability
Assess the ability to debug and monitor the system:
1. **Check logging usage:** ```bash # Find logging calls grep -n "logging\." src/gza/*.py grep -n "logger\." src/gza/*.py grep -n "log\." src/gza/*.py
# Find print statements (should these be logs?) grep -n "print(" src/gza/*.py ```
2. **Assess logging quality:** - Is there consistent logging for key operations? - Can you trace a task's execution through the logs? - Are log levels used appropriately? (debug vs info vs warning vs error) - Are there operations that fail silently without logging?
3. **Check for sensitive data exposure:** ```bash # Look for potential credential logging grep -in "api.key\|token\|password\|secret\|credential" src/gza/*.py ``` - Are API keys, tokens, or passwords properly excluded from logs? - Are there any `repr()` or `str()` methods that might expose secrets?
4. **Review error logging:** - Are exceptions logged with stack traces where needed? - Are error messages actionable? - Is there enough context to debug issues?
### Step 9: Check resource management
Look for resource leaks and cleanup issues:
1. **Check file handling:** ```bash # Find file operations grep -n "open(" src/gza/*.py grep -n "with open" src/gza/*.py ``` - Are all file opens using context managers (`with`)? - Are there any `open()` calls without corresponding `close()`?
2. **Check database connections:** ```bash grep -n "connect(" src/gza/*.py grep -n "cursor" src/gza/*.py ``` - Are database connections properly closed? - Are cursors managed with context managers? - Is there connection pooling or is it connect-per-operation?
3. **Check subprocess management:** ```bash grep -n "subprocess" src/gza/*.py grep -n "Popen" src/gza/*.py ``` - Are subprocesses properly waited on? - Are there potential zombie processes? - Are stdin/stdout/stderr handles closed?
4. **Check for memory issues:** - Are there unbounded caches or growing lists? - Are large objects cleaned up after use? - Are there circular references that prevent garbage collection?
5. **Check temp file cleanup:** ```bash grep -n "tempfile\|mktemp\|NamedTemporaryFile" src/gza/*.py ``` - Are temp files cleaned up after use? - Are temp directories removed?
### Step 10: Assess type safety
Review type hints and type correctness:
1. **Check type hint coverage:** ```bash # Find functions without return type hints grep -n "def.*):$" src/gza/*.py
# Find functions with type hints grep -n "def.*) ->" src/gza/*.py ```
2. **Run mypy (if configured):** ```bash uv run mypy src/gza/ --ignore-missing-imports 2>&1 | head -100 ```
3. **Look for type safety issues:** - Functions with `Any` types that could be more specific - `Optional` types without proper `None` checks - Type: ignore comments (are they justified?) - Inconsistent types (function returns `str | None` but callers don't check)
4. **Check for common type issues:** ```bash # Find potential None issues grep -n "\.get(" src/gza/*.py # dict.get returns Optional grep -n "or None" src/gza/*.py grep -n "if.*is None" src/gza/*.py ```
### Step 11: Analyze component interaction patterns
Understand how modules interact and assess the clarity of these interactions:
1. **Map the import graph:** ```bash grep -h "^from gza" src/gza/*.py | sort | uniq -c | sort -rn grep -h "^import gza" src/gza/*.py | sort | uniq -c | sort -rn ```
2. **Identify the layering:** - Which modules are "lower level" (few dependencies)? - Which are "higher level" (many dependencies)? - Are there circular dependencies?
3. **Check separation of concerns:** - Does `cli.py` only handle CLI concerns, delegating to other modules? - Does `db.py` only handle database concerns? - Does `runner.py` only handle execution concerns?
4. **Look for unclear interfaces:** - Functions with too many parameters - Functions that do too many things - Tight coupling between modules that should be loosely coupled
5. **Document the interaction patterns:** ``` cli.py → db.py (task CRUD) cli.py → runner.py (task execution) runner.py → providers/* (AI execution) runner.py → git.py (git operations) etc. ```
### Step 12: Compile the review report
Create a structured report at `reviews/code-review-full.md`:
```markdown # Gza Code Review - Pre-Release Assessment
Date: YYYY-MM-DD Reviewer: Claude
## Executive Summary
[2-3 sentence overview of codebase health]
## Test Coverage
### Unit Tests
| Module | Test File | Coverage Assessment | |--------|-----------|---------------------| | db.py | test_db.py | Good - covers CRUD, queries | | cli.py | test_cli.py | Partial - missing `gza pr` tests | | ... | ... | ... |
#### Well-Tested Areas - [List modules/features with good coverage]
#### Under-Tested Areas - [List modules/featur
技术详情
- 版本
- 1.0.0
- 许可证
- MIT
- 最近更新
- 2026年8月21日
- 发布时间
- 2026年8月21日
决策摘要
需要验证
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 gza-code-review-full 准备的场景化草稿,可手动发布到 X。
gza-code-review-full: Comprehensive pre-release code review assessing test coverage, code duplication, and componen... 11 stars https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x
可选:带安装命令的回复
Listing + install path for gza-code-review-full: https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x Install: npx skills add mhawthorne/gza --skill gza-code-review-full
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- mhawthorne
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 mhawthorne,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/audit)
[](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)作者
mhawthorne
@mhawthorne
健康信号
- GitHub Stars
- 11
- 质量评分
- 31/100
- 最近 GitHub 推送
- 2026年8月21日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 1
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
Do not auto-install
- GitHub 采用度11 个 GitHub Stars修复
- Star/Fork 活跃度11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息修复
- 近期维护距上次推送 1 天通过
- 许可证清晰度MIT通过
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, credential or environment access修复
相关 Skill
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsGrill With Docs
A relentless interview that pressure-tests a plan against the codebase, sharpens domain language, and updates CONTEXT.md and ADRs when decisions become durable.
164.7K StarsTo Spec
Turn the current conversation and codebase context into a structured implementation spec, then publish it to the configured project issue tracker.
164.7K StarsTo Tickets
Break a plan, spec, or conversation into independently actionable tracer-bullet tickets with explicit blocking relationships.
176.7K Stars