code-review

审查 · 59
已收录

Review local git changes before opening a PR or merging. First review all local tracked and untracked files; if none exist, review the current branch against a requested base branch or the Git Town parent branch. Use zero to three review subagents only when risk, diff size, langu

Verified installs0
Stars13
版本1.0.0
质量58/100 · 有潜力
信任59/100 · Do not auto-install
审计73/100 · 需审查

供给资产档案

研究与知识工作

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

浏览赛道

场景

研究 Agent

I need my agent to research a topic, compare sources, and produce a concise report.

适配 Agent

Claude Code + CLI + Codex

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review

维护状态

新鲜

距上次推送 5 天

风险

需审查

Dependency or permission surface needs review

GitHub 质量

13

58/100 质量 · 67/100 信任

覆盖标签

研究研究 Agentagent-skill

审查说明

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

有潜力
58

有用的候选项,但采用前应与替代方案比较。

信任

Do not auto-install
59

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

审计

需审查
73

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

安装前需人工审查

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

13 个 GitHub Stars

仓库活跃度

13 个 Star,0 个 Fork

维护状态

距上次推送 5 天

许可证

MIT

安装

npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review

安装安全性

标准软件包或运行时安装路径

权限范围

secrets or environment access, shell or command execution

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 13 GitHub stars

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

打开 JSON

适用任务

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects
  • 检索来源

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

安装决策

命令
npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review
策略
阻止
人工审查

信任与风险

信任
59/100
审计
73/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review

不适用场景

  • 需要厂商支持 SLA 的团队
  • production agents without a repository review
  • Low GitHub adoption signal
  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent 安全 v2

29/100 · 避免自动安装

Blocked for auto-install阻止

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

安装目标

在你的 Agent 工作流中安装此 Skill

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install rijkvanzanten-code-review

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use code-review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/rijkvanzanten-code-review/install
Install command: npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use code-review for this task. Review https://www.openagentskill.com/api/skills/rijkvanzanten-code-review/install, then install with: npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

59/100

研究 Agent

平台

Claude Code

审计报告

需审查 · 73/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

Fallback candidate for Research agents

先用此 Skill 做原型验证,并保留备选方案。

59
就绪度
原型验证
阶段

栈中角色

备选候选

主要匹配

研究 Agent

信任标签

先做原型验证

安装路径

命令已就绪

适用场景

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects

证据

  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 58/100 质量档案
  • 6 个 OpenAgentSkill 交互事件

先审查

  • Low GitHub adoption signal

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次研究 Agent任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

59
OpenAgentSkill 信任评分

GitHub 采用度

修复

13 个 GitHub Stars

Star/Fork 活跃度

修复

13 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

距上次推送 5 天

许可证清晰度

通过

MIT

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 13 GitHub stars
  • Stars/forks activity: 13 stars, 0 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

Choose a stronger alternative or inspect the source manually before any install attempt.

质量档案

有潜力 适用于 Agent 工作流的候选

有用的候选项,但采用前应与替代方案比较。

58
GitHub Stars
13
新鲜度
5 天前
安装就绪
许可证
MIT
安装前审查: Low GitHub adoption signal

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: code-review description: Review local git changes before opening a PR or merging. First review all local tracked and untracked files; if none exist, review the current branch against a requested base branch or the Git Town parent branch. Use zero to three review subagents only when risk, diff size, language specificity, or uncertainty justifies the token cost, then report high-confidence bugs, regressions, risky assumptions, and missing tests. Use when the user asks for code review, local review, branch sanity check, pre-PR review, or review of work-in-progress changes. ---

# Code Review

## Overview

Review local changes as a reviewer, not as an implementer. Prefer the smallest current review surface: local worktree changes first, then branch changes against a base branch only when the worktree has no tracked or untracked changes. When no base branch is named, use the Git Town parent branch before falling back to the default branch. Local worktree review includes staged tracked changes, unstaged tracked changes, and untracked files. Start with a local review pass, then use zero to three language/risk-specific subagents only when they are likely to improve review quality enough to justify the token cost. Do not run tests or linters unless the user explicitly changes the scope.

Invoking this skill is permission to use review subagents when useful; it is not a requirement to spawn them. A local-only review is valid for small, obvious, low-risk, or already well-tested diffs.

## Scope

Determine review depth from the request:

- Default to lightweight review. - Switch to in-depth review when the user explicitly asks for deeper review.

Determine review range in this order:

1. Check local tracked and untracked changes:

```bash git diff --cached -U10 git diff -U10 git diff --cached --name-only git diff --name-only git ls-files --others --exclude-standard ```

2. If any staged tracked, unstaged tracked, or untracked files exist, review all of them as `local changes`. - Include staged tracked changes from `git diff --cached -U10`. - Include unstaged tracked changes from `git diff -U10`. - Include untracked file contents by reading the files directly or producing a pseudo-diff against `/dev/null`. - Do not exclude untracked files just because they are not staged. 3. If there are no local tracked or untracked changes, review the current branch against the base branch named by the user. 4. If the user did not name a base branch, resolve the current branch's parent with Git Town:

```bash CURRENT_BRANCH=$(git rev-parse --abbrev-ref HEAD) BASE_BRANCH=$(git-town config get-parent "$CURRENT_BRANCH" 2>/dev/null || true) ```

5. If Git Town does not return a parent branch, fall back to `main`, then `origin/main`.

For branch review, compute:

```bash CURRENT_BRANCH=$(git rev-parse --abbrev-ref HEAD) BASE_BRANCH="${USER_BASE_BRANCH:-$(git-town config get-parent "$CURRENT_BRANCH" 2>/dev/null || true)}" if [ -z "$BASE_BRANCH" ]; then BASE_BRANCH=main fi if ! git rev-parse --verify "$BASE_BRANCH" >/dev/null 2>&1 && git rev-parse --verify origin/main >/dev/null 2>&1; then BASE_BRANCH=origin/main fi BASE=$(git merge-base HEAD "$BASE_BRANCH") git diff -U10 "$BASE" git diff --name-only "$BASE" ```

If the named base, Git Town parent, and fallback default branches cannot be resolved, stop and ask for a valid base branch.

## Workflow

1. Check for staged tracked, unstaged tracked, and untracked files. 2. If any local changes exist, build the review packet from the staged diff, unstaged diff, and untracked file contents. Do not include branch commits in this mode. 3. If no local tracked or untracked changes exist, resolve the base branch from the user's request, or use `git-town config get-parent "$(git rev-parse --abbrev-ref HEAD)"` when no base is requested, then build the branch review diff from the merge base. 4. In local changes mode, list untracked files with `git ls-files --others --exclude-standard` and include their contents in the review packet. 5. Build a compact review scope: - review mode: `local changes` or `branch` - base branch and merge base, when in branch mode - inferred intent in one sentence - risk focus in one sentence - changed file list - untracked file list and confirmation that untracked file contents are included when in local changes mode 6. Do a local review pass first. Read surrounding files only where needed to understand behavior, contracts, and tests. 7. Decide whether subagents are worth it. Use zero to three reviewers based on the rubric below. 8. If using subagents, send each a narrow packet with only the files, diff excerpts, contract context, and risk lens it needs. Launch multiple selected reviewers in parallel, collect outputs, and close each subagent once its result is captured. 9. Validate or disprove returned findings against source before reporting. 10. Produce findings with high confidence only.

If subagents are unavailable, continue locally. Mention that only if it materially affects confidence or the user explicitly asked for subagents. For in-depth review, prefer more local source context before adding reviewers by default.

## Sub-Agent Selection

Use 0-3 reviewers total. Do not spawn reviewers merely because a language matches. Pick the smallest reviewer set that addresses real risk:

- `0` reviewers: docs-only changes, tiny diffs, mechanical renames, obvious follow-up fixes, generated updates, or low-risk code where the local pass gives high confidence. - `1` reviewer: normal non-trivial code change with one dominant risk or one language/framework-specific concern. - `2` reviewers: meaningful behavior change with two independent risk areas, such as Rust API shape plus tests, Vue reactivity plus accessibility, or public API contract plus security. - `3` reviewers: large/cross-module diffs, auth/security/data mutation, external APIs, migrations, concurrency, or explicit deep/adversarial review.

Prefer a language-specific reviewer when language/framework details are the dominant risk. Prefer generic risk reviewers when correctness, security, contracts, reliability, or testing are more important than language mechanics.

Use these plugin agents when available from the `rolling-wave-engineering` plugin:

- `correctness-reviewer`: default for behavior-changing code, logic, state, and regression risk. - `testing-reviewer`: default when behavior changes, tests changed, or coverage is uncertain. - `maintainability-reviewer`: default for non-trivial code changes or existing-file complexity. - `typescript-reviewer`: when files include `.ts`, `.tsx`, or TypeScript blocks in Vue SFCs. - `vue-reviewer`: when files include `.vue`, Vue composables, Pinia stores, Vue Router, or Nuxt files. - `rust-reviewer`: when files include `.rs`, `Cargo.toml`, `Cargo.lock`, `build.rs`, Rust FFI/bindgen code, unsafe Rust, async Rust, or concurrency-heavy Rust. - `security-reviewer`: when changes touch auth, permissions, public endpoints, secrets, user input, rendering untrusted content, or URL handling. - `api-contract-reviewer`: when changes touch API routes, request/response types, serializers, exported types, or public interfaces. - `reliability-reviewer`: when changes touch retries, timeouts, async handlers, jobs, cleanup, lifecycle, or error handling. - `adversarial-reviewer`: when the diff is large or touches high-risk areas such as auth, data mutation, external APIs, or cross-cutting state.

Use these document/spec reviewers only when reviewing rolling-wave docs, specs, plans, or slice artifacts rather than code:

- `coherence-reviewer` - `scope-guardian-reviewer` - `feasibility-reviewer` - `spec-flow-analyzer`

Fallback split when plugin agents are unavailable:

- Correctness and regressions - Contracts and data flow - Coverage and operational risk

Each sub-agent should be told to report only high-confidence findings in its assigned lens and to skip style-only comments or speculative refactors. Keep prompts narrow; do not ask every reviewer to review the whole diff.

Require each sub-agent to return a compact structured shape:

```json { "reviewer": "agent-name", "findings": [ { "severity": "P1|P2|P3", "file": "path", "line": 42, "title": "short issue", "why": "why this matters", "confidence": "high|medium", "pre_existing": false } ], "testing_gaps": [], "residual_risks": [] } ```

## Review Focus

Prioritize:

- Behavioral regressions - Incorrect edge-case handling - Broken assumptions across call sites or data flow - Missing validation, authorization, or error handling - State, caching, concurrency, or lifecycle bugs - Schema, API, and backward-compatibility risks - Missing or insufficient tests where the change meaningfully alters behavior

Distribute those priorities through selected specialists instead of asking every agent to cover everything.

Deprioritize:

- Pure style nits - Speculative refactors - Comments about formatting unless they hide a real problem

Do not invent issues to fill space. If no actionable findings are present, say so plainly and mention any residual uncertainty or testing gaps.

## Output

Present findings first, ordered by severity. For each finding, include:

- Severity - File reference and line reference when available - Short explanation of the issue and why it matters

After findings, include:

- Open questions or assumptions, if any - Brief change summary only if useful

Apply these filters before reporting:

- Report only issues you would defend with high confidence. - Medium-confidence findings may be reported only if two reviewers independently flag the same issue or it is a possible P0/P1 class defect. - Skip low-signal nits unless the user asked for exhaustive review. - Prefer a smaller set of sharp findings over a broad, noisy list. - Treat findings as duplicates when they cite the same file, nearby lines within about 3 lines, and the same underlying failure. Merge them, keep the higher severity, and note both reviewers if useful. - Re-check any borderline finding against the source before surfacing it. - Before reporting, verify cited lines, calibrate severity, remove linter/formatter-only issues, and ensure every finding has a concrete failure mode. - Put pre-existing issues in a separate `Pre-existing` section and do not count them against the reviewed change.

State the review mode explicitly: `local changes` or `branch changes against <base>`. If untracked files exist in local changes mode, include them in a `Coverage / Scope` note and state that their contents were reviewed. Include reviewer usage briefly: `Reviewers: 0 local-only`, `Reviewers: 1 <name>`, etc. End with `Verdict: Ready`, `Verdict: Ready with fixes`, or `Verdict: Not ready`.

## Constraints

- Perform code review only. - Do not modify files unless the user changes the task. - Do not run tests or linters. - Do not post to GitHub or any external system.

技术详情

版本
1.0.0
许可证
MIT
最近更新
2026年8月20日
发布时间
2026年8月20日

决策摘要

备选候选

59
就绪
原型验证
阶段

仓库近期活跃

审计

安装审查

安装与采用审查

73
需审查
安全性
74/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 code-review 准备的场景化草稿,可手动发布到 X。

策展说明
code-review: Review local git changes before opening a PR or merging. First review all local tracked and u...

13 stars

https://www.openagentskill.com/skills/rijkvanzanten-code-review?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for code-review:
https://www.openagentskill.com/skills/rijkvanzanten-code-review?ref=x

Install: npx skills add rijkvanzanten/rolling-wave-engineering --skill code-review
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
rijkvanzanten
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 rijkvanzanten,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/rijkvanzanten-code-review?metric=listed&label=Listed)](https://www.openagentskill.com/skills/rijkvanzanten-code-review)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/rijkvanzanten-code-review?metric=trust&label=Trust)](https://www.openagentskill.com/skills/rijkvanzanten-code-review)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/rijkvanzanten-code-review?metric=audit&label=Audit)](https://www.openagentskill.com/skills/rijkvanzanten-code-review/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/rijkvanzanten-code-review?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/rijkvanzanten-code-review)

作者

R

rijkvanzanten

@rijkvanzanten

平台适配

健康信号

GitHub Stars
13
质量评分
32/100
最近 GitHub 推送
2026年8月17日
框架提示
未知
OpenAgentSkill 浏览量
5
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

Do not auto-install

59
  • GitHub 采用度13 个 GitHub Stars修复
  • Star/Fork 活跃度13 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息修复
  • 近期维护距上次推送 5 天通过
  • 许可证清晰度MIT通过
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险command execution surface, credential or environment access检查