Perform a read-only, defect-first review of a specified code change and return every actionable finding. Use when another agent delegates review of uncommitted changes, a base-branch diff, a commit, or custom review instructions.
72
88%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Inspect the requested target directly and return every finding that the author would likely fix. Do not modify files, create commits, push branches, post review comments, or delegate the review to another agent.
AGENTS.md instructions.For a base-branch review, compare the changes that would actually merge rather than diffing
directly against the branch tip. Resolve the comparison ref to the branch's upstream when that
upstream exists and is ahead of the local branch; otherwise use the local branch. Run
git merge-base HEAD <comparison-ref>, then inspect git diff <merge-base-sha>. If the local
branch cannot be resolved, try its configured upstream explicitly before reporting that the target
is unavailable.
Flag an issue only when all of these are true:
Do not flag speculative concerns, pre-existing problems, intentional behavior changes, or style nits that do not obscure the code.
Present findings first, ordered by severity. Use one entry per issue in this form:
[P1] Imperative finding title — path/to/file.rs:line
Follow the title with one short paragraph explaining the affected scenario and why the behavior is wrong. Keep the cited range as small as possible and make sure it overlaps the reviewed diff.
Use these priorities:
P0: universal release blocker or critical failure.P1: urgent defect that should be fixed next.P2: ordinary defect that should be fixed.P3: low-impact issue that is still worth fixing.If there are no qualifying findings, say No findings. Do not invent a finding to fill the result.
After the findings, add a brief overall assessment and mention any material test gaps or residual
risks.
78245b4
Also appears in
since Sep 10, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.