gza-code-review-interactive

审查 · 60
已收录

Review changes on current branch and output a structured review. Optionally post to PR with --pr flag, or apply non-blocking follow-ups inline with --apply-followups.

Verified installs0
Stars11
版本2.4.0
质量57/100 · 有潜力
信任60/100 · 仅限沙盒
审计73/100 · 需审查

供给资产档案

编程与开发 Agent

代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。

浏览赛道

场景

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

适配 Agent

Claude Code + CLI + Codex

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add mhawthorne/gza --skill gza-code-review-interactive

维护状态

新鲜

今天有推送

风险

需审查

Permission surface may require sandboxing

GitHub 质量

11

57/100 质量 · 68/100 信任

覆盖标签

编程GitHub automation编程 Agentagent-skill

审查说明

Permission surface may require sandboxing · The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

有潜力
57

有用的候选项,但采用前应与替代方案比较。

信任

仅限沙盒
60

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

审计

需审查
73

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

安装前需人工审查

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

11 个 GitHub Stars

仓库活跃度

11 个 Star,1 个 Fork

维护状态

今天有推送

许可证

MIT

安装

npx skills add mhawthorne/gza --skill gza-code-review-interactive

安装安全性

标准软件包或运行时安装路径

权限范围

shell or command execution, filesystem or document access

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

打开 JSON

适用任务

  • GitHub automation 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects
  • Inspect repository metadata

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

安装决策

命令
npx skills add mhawthorne/gza --skill gza-code-review-interactive
策略
审查
人工审查

信任与风险

信任
60/100
审计
73/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add mhawthorne/gza --skill gza-code-review-interactive

不适用场景

  • 需要厂商支持 SLA 的团队
  • production agents without a repository review
  • Low GitHub adoption signal
  • The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).
  • 高风险权限提示:Shell 或命令执行

Agent 安全 v2

37/100 · 避免自动安装

实验性审查

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

Browser automation

Skill may drive a browser or interact with web pages.

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

  • 高风险权限提示:Shell 或命令执行
  • Permission surface may require sandboxing

安装目标

在你的 Agent 工作流中安装此 Skill

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-interactive

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use gza-code-review-interactive in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-interactive%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-interactive/install
Install command: npx skills add mhawthorne/gza --skill gza-code-review-interactive
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use gza-code-review-interactive for this task. Review https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-interactive/install, then install with: npx skills add mhawthorne/gza --skill gza-code-review-interactive

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

56/100

GitHub automation

平台

Claude Code

审计报告

需审查 · 73/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

Needs validation for GitHub automation

在将它加入 Agent 工作流前先人工审查仓库。

56
就绪度
审查
阶段

栈中角色

需要验证

主要匹配

GitHub automation

信任标签

需要人工审查

安装路径

命令已就绪

适用场景

  • GitHub automation 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects

证据

  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 57/100 质量档案
  • 1 个 OpenAgentSkill 交互事件

先审查

  • Low GitHub adoption signal
  • The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

仅限沙盒

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

60
OpenAgentSkill 信任评分

GitHub 采用度

修复

11 个 GitHub Stars

Star/Fork 活跃度

修复

11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

今天有推送

许可证清晰度

通过

MIT

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • GitHub adoption: 11 GitHub stars
  • Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
  • Permission surface: shell or command execution, filesystem or document access
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

质量档案

有潜力 适用于 Agent 工作流的候选

有用的候选项,但采用前应与替代方案比较。

57
GitHub Stars
11
新鲜度
今天
安装就绪
许可证
MIT
安装前审查: Low GitHub adoption signal · The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: gza-code-review-interactive description: Review changes on current branch and output a structured review. Optionally post to PR with --pr flag, or apply non-blocking follow-ups inline with --apply-followups. allowed-tools: Bash(git:*), Bash(gh:*), Bash(uv run:*), Read, Edit, Write, Glob, Grep, Agent, AskUserQuestion version: 2.4.0 public: true ---

# Interactive Code Review

Review committed changes on the current feature branch and output a structured review.

Requires being on a non-main branch with commits ahead of main. If not, stop and tell the user: "Switch to a feature branch with commits to review. This skill reviews committed changes on feature branches (git diff main...HEAD)."

## Arguments

- `--pr` — Post the review as a PR comment (requires an existing PR on the branch) - `--apply-followups` — After the review, apply all non-blocking follow-ups inline without prompting. Has no effect if the verdict is `CHANGES_REQUESTED` (blockers exist) or if the review reports no follow-ups. Without this flag, the skill prompts the user interactively before applying. - No arguments — Just output the review locally, no PR interaction. If follow-ups exist, prompt the user once at the end (see Step 6).

## Process

### Step 1: Verify branch state

1. Check current branch: `git branch --show-current` - If on `main` or `master`, stop and tell the user to switch to a feature branch 2. Check for uncommitted changes: `git status --porcelain` - If there are uncommitted changes, warn the user but proceed with reviewing committed changes 3. Check if branch has commits ahead of main: `git log main..HEAD --oneline` - If no commits ahead, stop and tell the user there's nothing to review

### Step 2: Find PR (only if --pr flag is set)

1. Look up existing PR: `gh pr view --json number,url,title 2>/dev/null` 2. If no PR exists, stop and tell the user to create one first (do NOT create a PR automatically) 3. Capture the PR number and URL

### Step 3: Capture review context in the parent session

Capture canonical ask context before spawning the reviewer: - If the caller already provided a `## Review scope:` section, pass it through unchanged, along with any `## Original plan context (out of scope except for the review scope):` section. - Otherwise, if the caller already provided exactly one canonical ask section (`## Original plan:` or `## Original request:`), pass that section through unchanged. - Otherwise, try to resolve ask context from the branch's linked gza task chain (`uv run gza show <TASK_ID>` / `uv run gza log <TASK_ID>` is preferred once you identify the task for this branch). - If linked ask content exists but is unavailable on this machine, pass an explicit unavailable-content marker section (for example, `## Original plan:` followed by `(plan task <TASK_ID> exists but content unavailable on this machine - flag as blocker)`). - If no retrievable plan or request exists for this branch, pass no ask section and let the reviewer state: `No plan or request provided.`

Then capture the committed diff: - If the caller already provided diff context, use that as-is and do not reconstruct it. Otherwise, collect the committed branch diff once in the parent session: ```bash git diff main...HEAD ``` Pass this diff to the subagent as `## Implementation diff context`.

### Step 4: Run the review

Spawn a **general-purpose Agent** subagent to perform the review. Give it this prompt (include the captured diff context):

---

You are reviewing a pull request. Your job is to read the project review guidelines, examine the diff, and produce a structured review.

**Step 1**: Read `REVIEW.md` from the project root for review guidelines and criteria.

**Step 2**: Start with a repo-rules/learnings pass: compare the diff and behavior against AGENTS.md, REVIEW.md, project docs, and `.gza/learnings.md`; call out violations or regressions explicitly. Keep this review stack-agnostic. If project verification instructions are missing, state that explicitly in assumptions/risks.

**Step 3**: The provided diff is authoritative - do not use git commands to reconstruct, re-derive, or expand it. You may read unchanged source files when surrounding context is needed to judge correctness.

**Step 3.5**: When you need to verify behavior that isn't visible in the diff (e.g., whether a CLI command exists, how a called function works, what a referenced method does), use the Read, Grep, or Glob tools to check the current codebase. Do not guess or assume — verify.

**Step 3.7**: If `## Review scope:` is present, grade ask-adherence against that section only and use any original-plan-context section only for boundaries/contracts. Otherwise, review the diff against the provided canonical ask context (`## Original plan:` or `## Original request:`). If ask content is marked unavailable, call that out as a blocker. If neither ask section is provided, state `No plan or request provided.`

**Step 4**: Write a structured review with these sections:

```markdown ## Summary

<Provide 3-5 bullets summarizing the review> <Then answer this checklist with exactly 6 bullets in `Yes/No - ...` form and one short evidence clause each:> <- Did I check the diff against AGENTS.md and `.gza/learnings.md` and flag any violations/regressions?> <- Did I check for silent broad-exception fallbacks that mask errors while changing user/agent-visible state?> <- Did I check for misleading output (contradictory UI/prompt/context signals)?> <- Was a `## Review scope:` section provided, and if so did I grade ask-adherence against that scope while treating sibling slices as non-blocking unless they break an explicit contract? Otherwise, was an `## Original plan:` or `## Original request:` section provided, and did I verify ask-adherence against it while calling out intentional deviations? If neither was provided, did I state "No plan or request provided."?> <- Did I require targeted regression tests that match each failure mode (not generic "add tests")?> <- If config, CLI, or operator-facing behavior changed, did I verify docs/help/release-note impact?>

## Blockers

<Use ### B1, ### B2, ... for blockers. If none, write "None."> <Each blocker should include Evidence:, Open-state citation:, Impact:, Required fix:, Required tests:> <Class-of-issue enumeration: when one blocker is an instance of a repeated code-surface pattern (lookup table, classifier, dispatcher, schema/field mapping, multi-field validator, or parallel per-field/per-type handling), audit for analogous gaps before writing the blocker. The audit boundary is the affected file plus any other files in the same module (the same depth-3 path under `src/`) that were touched by the diff, plus any obvious same-module sibling of the affected file.> <Report all still-open gaps for that same class in one blocker, with every affected `path:line` or `path:start-end` citation included in `Open-state citation:` regardless of file, and a `Required fix:` that closes the whole class.> <Do not create one blocker per field, branch, case, table row, or file unless the required fixes are materially different.> <Do not expand the audit beyond the same module, and do not expand isolated one-off defects - this rule applies only after you have found a repeated-pattern blocker shape.> <Reserve BLOCKER for: correctness defects, behavior regressions, repository/rules violations, missing observability for user/agent-visible fallbacks, and misleading output/contradictory signals.> <Treat unexplained deviations from the provided review scope, plan, or request as BLOCKER.> <If `## Review scope:` is present, grade ask-adherence against that section only. Use any original plan context section only to understand boundaries and integration contracts.> <Do not raise blockers solely because deferred sibling slices from the original plan are not implemented; only raise blockers when in-scope work is missing/broken or the diff violates an explicit integration contract described in the review scope or plan context.> <Treat silent broad-exception fallbacks as BLOCKER when they can alter user/agent-visible state without clear warning/error surfacing.> <Treat misleading output (UI/prompt/context contradictions) as BLOCKER when it can cause incorrect operator or agent decisions.> <If config/CLI/operator-facing behavior changed, missing or incorrect docs/help/release-note updates are BLOCKER when they can mislead operators.> <Use FOLLOWUP for actionable low-risk debt that should be tracked but should not block merge.> <For each blocker, give a clear closure condition so an improve task can resolve all blockers in one pass.> <For class-of-issue blockers, the closure condition must cover every enumerated instance across all cited paths, not just the first example.> <Every BLOCKER must be falsifiable: `Evidence:` and `Open-state citation:` must show the current still-open state, and `Required fix:` must describe the concrete change needed to close it.> <Do not write a `BLOCKER` unless you can cite the current code or current diff proving the issue is still open.> <Prior review text, improve lineage, or task history are not sufficient evidence for a blocker.> <Improve-lineage context may justify a narrow current-source anti-regression check for repeated blocker shapes the latest improve was expected to close, but it is only a pointer to inspect the current code/diff. It is not independent blocker evidence and must not substitute for current proof on this diff.> <Review current code, diff, and scope only.> <Do not run or evaluate `verify_command`; verification is handled elsewhere.> <Do not create blockers because verification failed, timed out, was skipped, or was unavailable.> <If code has a test-quality issue, cite the concrete code/test issue directly rather than runner verify status.> <Severity shorthand: `BLOCKER` means merge-blocking; `FOLLOWUP` means non-gating but task-worthy; `NIT` is omitted from canonical output.> <Do not add a per-finding `Severity:` line; the `## Blockers` and `## Follow-Ups` sections are the severity field.> <Derive the final verdict from the findings:> <cannot classify safely -> `NEEDS_DISCUSSION`> <Borderline cases must include a one-sentence rubric justification in `Impact:`, `Required fix:`, or `Recommended follow-up:`> <A broad exception that can mask visible state or swallow a user/agent-visible failure is a `BLOCKER`.> <An adjacent-path coverage sweep that would strengthen confidence without proving the current slice unsafe is a `FOLLOWUP`.> <Open-state citation must contain one or more current-source references in `path:line` or `path:start-end` form; backticked citations and comma-separated multiple citations are allowed.>

## Follow-Ups

<Use ### F1, ### F2, ... for non-blocking actionable follow-ups. If none, write "None."> <Each follow-up should include Evidence:, Impact:, Recommended follow-up:, Recommended tests:> <Do not include NIT findings in canonical output.>

## Questions / Assumptions

<Bullet list of open questions/assumptions. If none, write "None.">

## Verdict

<Brief justification> <Verdict is derived from the findings: no blockers/no follow-ups -> APPROVED; no blockers/at least one follow-up -> APPROVED_WITH_FOLLOWUPS; any blocker -> CHANGES_REQUESTED; cannot classify safely -> NEEDS_DISCUSSION.> Verdict: APPROVED|APPROVED_WITH_FOLLOWUPS|CHANGES_REQUESTED|NEEDS_DISCUSSION ```

Do not rename, omit, or reorder these sections.

If a PR number is provided, post the review as a PR comment: ```bash gh pr comment <PR_NUMBER> --body "<review content>" ```

Use a heredoc for the body to handle multi-line content properly.

If no PR number is provided, just output the review directly.

---

Pass the authoritative diff context (`## Implementation diff context`), the `## Review scope:` section when available, otherwise the canonical ask context section (exactly one of `## Original plan:` or `## Original request:` when available), and the PR number (if `--pr` was used and a

技术详情

版本
2.4.0
许可证
MIT
最近更新
2026年8月21日
发布时间
2026年8月21日

决策摘要

需要验证

56
就绪
审查
阶段

仓库近期活跃

审计

安装审查

安装与采用审查

73
需审查
安全性
75/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 gza-code-review-interactive 准备的场景化草稿,可手动发布到 X。

策展说明
gza-code-review-interactive: Review changes on current branch and output a structured review. Optionally post to PR with -...

11 stars

https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for gza-code-review-interactive:
https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive?ref=x

Install: npx skills add mhawthorne/gza --skill gza-code-review-interactive
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
mhawthorne
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 mhawthorne,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-interactive?metric=listed&label=Listed)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-interactive?metric=trust&label=Trust)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-interactive?metric=audit&label=Audit)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-interactive?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-interactive)

作者

M

mhawthorne

@mhawthorne

平台适配

健康信号

GitHub Stars
11
质量评分
31/100
最近 GitHub 推送
2026年8月21日
框架提示
未知
OpenAgentSkill 浏览量
1
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

仅限沙盒

60
  • GitHub 采用度11 个 GitHub Stars修复
  • Star/Fork 活跃度11 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息修复
  • 近期维护今天有推送通过
  • 许可证清晰度MIT通过
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险命令执行范围信息