Run structured AI code review as an advisory closeout gate for local diffs, PR branches, or commits when the user asks for autoreview, Codex review, second-model review, or pre-ship validation.
66
79%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./Skills/agent-ops/autoreview/SKILL.mdRun the bundled structured review helper as a closeout check. This is code review, not Guardian auto_review approval routing.
Codex review is the default when no engine is set. It usually delivers the best review results and should remain the normal final closeout engine.
references/discovery-interview.md when the request is underspecified.Before running the helper, record the target mode, reviewed SHA or local state, base/ref freshness, owner checkout or authorized repair worktree, changed-file boundary, and which evidence lanes are in scope: autoreview, local proof, hosted PR/review, and delivery.
For branch or PR work, bind the helper to the actual base and reviewed SHA. A clean local diff never substitutes for a current branch/PR review.
If a delegated repair, receipt, or test lives in another worktree, verify that the artifact is visible and valid in the owner checkout before relying on it. Otherwise classify blocked_context_mismatch; do not re-label an inaccessible artifact as passing evidence.
Keep one small finding ledger while triaging: finding_id, source, classification (accepted, rejected, or blocked), disposition, owner, evidence, and next_step. Valid dispositions are patch_here, hand_off, follow_up, reject, and blocked.
Treat review output as advisory. Never blindly apply it.
Verify every finding by reading the real code path and adjacent files.
Read dependency docs/source/types when the finding depends on external behavior.
Reject unrealistic edge cases, speculative risks, broad rewrites, and fixes that over-complicate the codebase.
Prefer small fixes at the right ownership boundary; no refactor unless it clearly improves the bug class.
When an accepted finding shows a bug class or repeated pattern, inspect the current PR scope for sibling instances before fixing.
Patch an accepted finding here only when it is in scope and this checkout owns the change. Otherwise record hand_off, follow_up, reject, or blocked in the finding ledger instead of silently broadening the review lane.
Keep going until the structured review lane returns no accepted/actionable findings only while the work remains inside the original task scope. That result is not merge, hosted-review, or delivery readiness.
If a review-triggered fix changes code, rerun focused tests in the owner checkout and rerun the structured review helper against the repair SHA or local state.
When a user asks for PR or readiness follow-through, query current-head review-thread and check state after the autoreview run. Report that hosted lane separately and route its mutations to the PR workflow owner; autoreview does not resolve threads, push, or merge.
For security-audit suppression changes, verify accepted findings remain auditable: suppressed findings stay in structured output, active output keeps an unsuppressible suppression notice, and aggregate findings cannot hide unrelated active risk.
Never switch or override the requested review engine/model. If the review hits model capacity, retry the same command a few times with the same engine/model.
Be patient with large bundles. Structured review can take up to 30 minutes while the model call is active, especially with Codex tools or web search.
Treat heartbeat lines like review still running: ... elapsed=... pid=... as healthy progress, not a hang. Let the helper continue while heartbeats are advancing. Pass --stream-engine-output when live engine text is useful; Codex and Claude filter tool/file chatter, other engines pass raw output through.
Do not kill a review just because it has been quiet for 2-5 minutes, or because it is still running under the 30-minute window. Inspect the process only after missing multiple expected heartbeats, after 30 minutes, or after an obviously failed subprocess; prefer letting the same helper command finish.
Tools are useful in review mode. The helper allows read-only inspection tools and web search by default so reviewers can check dependency contracts, upstream docs, and current behavior.
Security perspective is always included, but it should not cripple legitimate functionality. Report security findings only when the change creates a concrete, actionable risk or removes an important safety check.
For regression provenance, if no blamed PR is traceable, use the blamed commit as the provenance: commit SHA, date, and author username. Do not guess a merger or frame missing PR metadata as a separate finding.
Do not invoke built-in codex review, nested reviewers, or reviewer panels from inside the review. The helper builds one bundle, calls one selected engine, validates one structured result, and stops.
Stop as soon as the helper exits 0 with no accepted/actionable findings. Do not run an extra review just to get a nicer "clean" line, a second opinion, or clearer closeout wording.
Treat the helper's successful exit plus absence of actionable findings as a clean autoreview lane result, even if the underlying Codex CLI output is terse. Keep hosted checks, review threads, approval, merge, and delivery claims separate.
Multi-reviewer panels are opt-in only. Use them when explicitly requested or when risk justifies the extra spend; the main agent still verifies every accepted finding before fixing.
If rejecting a finding as intentional/not worth fixing, add a brief inline code comment only when it explains a real invariant or ownership decision that future reviewers should know.
If gh/Gitcrawl reports database disk image is malformed, run gitcrawl doctor --json once to let the portable cache repair before retrying review; use live GitHub only when repair fails and freshness requires it.
If Gitcrawl reports a portable manifest mismatch, source/runtime DB health error, or stale portable-store checkout, run gitcrawl doctor --json and inspect source_db_health, runtime_db_health, and portable_store_status before falling back to live GitHub.
Do not push just to review. Push only when the user requested push/ship/PR update.
Autoreview is a closeout gate, not permission to rewrite the task.
Before the first review, freeze a scope baseline: original request or issue, target branch, intended behavior, owner boundary, changed files, and non-test LOC. For inherited or already-bloated branches, use the intended PR diff as the baseline rather than accepting all existing branch drift.
Before patching a finding, classify it:
Stop patching and report the scope break instead of continuing when:
After the two-cycle pause, continue only when every remaining accepted finding is still an in-scope blocker. Otherwise preserve the useful analysis, identify the smallest safe landed subset if one exists, and open or request a follow-up for the larger fix. Do not keep committing speculative fixes just to satisfy the reviewer.
Do not stack or push review-triggered fix commits while scope classification or focused proof is unresolved. Keep exploratory edits local until the cycle is proven in scope; if scope breaks, remove them from the landing lane instead of preserving them as branch history.
Critical exceptions must be explicit: active data loss, crash, broken install/upgrade, release blocker, or concrete security exposure. If the exception is not one of those, it is not critical enough to blow up scope.
On release, beta, stable, hotfix, signing, notarization, appcast, package-publish, or release-check work, use freeze discipline even when the branch name is not release-like:
main, not reasons to broaden the release branch.main.Dirty local work:
<autoreview-helper> --mode localUse this only when the patch is actually unstaged/staged/untracked in the
current checkout. --mode uncommitted is accepted as an alias for --mode local.
For committed, pushed, or PR work, point the helper at the commit
or branch diff instead; do not force dirty modes just
because the helper docs mention dirty work first. A clean local review
only proves there is no local patch.
Branch/PR work:
<autoreview-helper> --mode branch --base origin/mainOptional review context is first-class:
<autoreview-helper> --mode branch --base origin/main --prompt-file /tmp/review-notes.md --dataset /tmp/evidence.jsonIf an open PR exists, use its actual base:
base=$(gh pr view --json baseRefName --jq .baseRefName)
<autoreview-helper> --mode branch --base "origin/$base"Committed single change:
<autoreview-helper> --mode commit --commit HEADor with the helper:
Skills/agent-ops/autoreview/scripts/autoreview --mode commit --commit HEADUse commit review for already-landed or already-pushed work on main. Reviewing
clean main against origin/main is usually an empty diff after push. For a
small stack, review each commit explicitly or review the branch before merging
with --base.
Format first if formatting can change line locations. Then it is OK to run tests and review in parallel:
scripts/autoreview --parallel-tests "<focused test command>"On Windows, the default --parallel-tests shell preserves the platform cmd.exe
semantics used by Python shell=True. Use --parallel-tests-shell powershell
or --parallel-tests-shell pwsh when the focused test command is PowerShell-specific.
Tradeoff: tests may force code changes that stale the review. If tests or review lead to code edits, rerun the affected tests and rerun review until no accepted/actionable findings remain. Once that rerun exits cleanly, stop; do not spend another long review cycle on redundant confirmation.
Run multiple reviewers against one frozen bundle:
<autoreview-helper> --reviewers codex,claude--panel is shorthand for Codex plus Claude unless --engine changes the first reviewer:
<autoreview-helper> --panelSet reviewer models and thinking/effort explicitly:
<autoreview-helper> --reviewers codex,claude --model codex=gpt-5.1 --thinking codex=high --model claude=sonnet --thinking claude=maxInline syntax is also supported:
<autoreview-helper> --reviewers codex:gpt-5.1:high,claude:sonnet:maxCodex maps thinking to model_reasoning_effort and accepts low, medium,
high, or xhigh. Claude maps thinking to --effort and also accepts max.
Engines without a real thinking knob reject --thinking.
Run the helper directly so target selection, engine choice, structured validation, and exit status all stay in one path. If output is noisy, summarize the completed helper output after it returns; do not ask another agent or reviewer to rerun the review.
PATH entries outside the reviewed checkout and rejects executable shadowing from the reviewed repo.--parallel-tests is an explicit operator command boundary. Treat it as trusted user input for the selected repo, not as reviewer output or arbitrary web content.If the review engine, git metadata, PR base, auth, sandbox permissions, Tessl workspace/project link, or owner-worktree context is unavailable, stop with blocked_runtime, blocked_validation, blocked_setup, or blocked_context_mismatch and include the exact command and useful stderr.
Run the narrowest gate first and classify a failure before continuing. Safety, authority, secret, or destructive-action failures stop the lane. An in-scope source defect is patched and re-proved in its owner checkout. A command, setup, or wrong-worktree failure gets one deterministic repo-contract correction and one rerun of the affected gate. Hosted checks, review threads, approval, and merge state remain separate evidence lanes and may be reported as blocked without erasing independently passing local autoreview proof.
Run, in order:
python3 -m py_compile Skills/agent-ops/autoreview/scripts/autoreview Skills/agent-ops/autoreview/scripts/test-review-harness.py
Skills/agent-ops/autoreview/scripts/autoreview --help
Skills/agent-ops/autoreview/scripts/autoreview --mode commit --commit HEAD --dry-run
./bin/ask skills audit Skills/agent-ops/autoreview --level strict --json --robot
./bin/ask evals run Skills/agent-ops/autoreview --mode smoke --json --robotRun Tessl only through the repo eval wrapper against staged input under /tmp; never point Tessl at this live repo source tree.
main often reviews nothing; use commit mode for already-landed changes.references/contract.yamlreferences/evals.yamlreferences/discovery-interview.mdreferences/task-profile.jsonagents/openai.yaml| Skill | When to use together |
|---|---|
| [[evals-router]] | Design eval coverage and judge-calibration checks for review workflows. |
| [[pr-green-sweep]] | Carry review findings through CI, PR, and merge follow-through. |
OpenClaw repo-local helper:
Skills/agent-ops/autoreview/scripts/autoreview --helpOn native Windows, invoke the extensionless Python helper through Python:
python Skills\agent-ops\autoreview\scripts\autoreview --helpThe smoke harness has thin shell wrappers over a shared Python implementation:
Skills/agent-ops/autoreview/scripts/test-review-harness --fixture benign --engine codexSkills\agent-ops\autoreview\scripts\test-review-harness.ps1 -Fixture benign -Engine codexThe helper:
--mode uncommitted as an alias for --mode localgh pr view worksorigin/main for non-main branches--engine codex, claude, droid, and copilot; default is AUTOREVIEW_ENGINE or codex; Codex should remain the default when nothing is setgit, gh, reviewer, and PowerShell shell commands from absolute PATH entries only, never from the reviewed checkout; explicit relative --*-bin paths are resolved from the reviewed repository root--mode commit --commit <ref> for already-committed work, especially clean main after landing--mode auto or forced to --mode branch for PR/branch work; do not force --mode local after committing--output, --json-output, or live streamed engine stderr is set--dry-run, --parallel-tests, --parallel-tests-shell, --prompt, --prompt-file, --dataset, --no-tools, --no-web-search, and commit refs--stream-engine-output or AUTOREVIEW_STREAM_ENGINE_OUTPUT=1 for live engine text while preserving structured validation; Codex and Claude hide tool/file event details, emit compact activity summaries, and report usage at turn completion--panel / --reviewers, plus per-engine --model and --thinkingcodex exec with read-only sandbox and structured outputreview still running: <engine> elapsed=<seconds>s pid=<pid> to stderr at long-running intervals while waiting for the selected review engine, unless streamed output or compact Codex activity has been visible recentlyautoreview clean: no accepted/actionable findings reported when the selected review command exits 0; this proves only the autoreview laneInclude:
Do not run another review solely to improve the final report wording. If the final helper run exited 0 and produced no accepted/actionable findings, report that exact run as clean for the autoreview lane only.
f1f2f21
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.