CtrlK
BlogDocsLog inGet started
Tessl Logo

local-review

Code review the current PR (or branch diff against main) for bugs, security, and AGENTS.md compliance. MUST use when asked to review code.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplar of operational skill writing: terse, fully executable, and structured as a clear four-step delegation workflow with validation checkpoints, fallbacks, exact output formats, and ready-to-run gh/git commands. It also discloses depth correctly by delegating the review policy to REVIEW.md/AGENTS.md rather than inlining it.

DimensionReasoningScore

Conciseness

The body is lean and purely operational: it never explains what code review is or how gh/git work, and every section (steps, prompt template, output format, posting commands) is directly load-bearing. The one explanatory paragraph ("Why a subagent") exists to enforce a behavioral constraint — running in a fresh context — rather than to teach, so every token earns its place per anchor 5. Not 4: there is no over-explanation to trim.

5 / 5

Actionability

Guidance is copy-paste executable throughout: concrete commands (`gh pr view <n>`, `git rev-parse <branch>`, `gh pr diff <N>`, `git diff main...<branch>`, `gh api repos/{owner}/{repo}/pulls/{pr}/reviews`), a complete subagent prompt template, and an exact output format covering both the findings and no-findings cases. This matches anchor 5 ('fully executable; copy-paste ready; covers the common cases') better than 4, which anticipates gaps.

5 / 5

Workflow Clarity

The four steps are clearly sequenced with explicit checkpoints: step 1 verifies the PR/branch exists (`gh pr view <n>` / `git rev-parse <branch>`) before delegating; step 2 includes a fallback when the purpose-built subagent type is unavailable; and the subagent template embeds self-validation ("is this definitely a real issue a senior engineer would flag? Discard if uncertain"). This matches anchor 5's 'explicit validation steps; feedback loops for error recovery' — not 4, since no checkpoint is merely implicit. The skill is read-only (posting is a separate opt-in step), so the destructive/batch cap does not apply.

5 / 5

Progressive Disclosure

The body is a well-organized single file (~90 lines) with clearly headed sections, and it externalizes depth exactly where it should: the full review policy lives in REVIEW.md and AGENTS.md files, referenced one level deep and clearly signaled ("the review policy lives in REVIEW.md", "read REVIEW.md first for the policy"). No bundle files exist to misplace, and nothing that belongs in a separate file is inlined — anchor 5. Not 4: navigation and placement have no gaps.

5 / 5

Total

20

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concrete description that states both what the skill does and when to use it, in an appropriately terse voice. Its main limitation is the single narrow trigger phrase ("when asked to review code"), which under-covers the natural ways users request PR/diff reviews, and the omission of the test-coverage and comment-posting aspects of the skill.

Suggestions

Broaden the trigger clause to cover natural phrasings, e.g. "Use when asked to review code, review a PR, or review changes/diff before merging".

Mention the test coverage assessment and optional inline-comment posting (--comment) so the description matches the skill's actual scope.

Keep the 'MUST use' directive but ensure it doesn't crowd out the trigger synonyms that help discovery.

DimensionReasoningScore

Specificity

The description names the domain ("Code review the current PR (or branch diff against main)") and enumerates three concrete review actions ("for bugs, security, and AGENTS.md compliance"). It stops short of comprehensive coverage — test coverage assessment and comment posting (both in the body) go unmentioned — matching anchor 4 ('several specific actions; minor gaps') rather than 5.

4 / 5

Completeness

The 'what' is explicit ("Code review the current PR (or branch diff against main) for bugs, security, and AGENTS.md compliance") and the 'when' is explicit ("MUST use when asked to review code"). The trigger clause is narrower than the skill's actual scope — users asking to "review this PR" or "review my changes" are not covered — so anchor 4 ('both present; when could be more explicit or specific') fits better than 5.

4 / 5

Trigger Term Quality

Natural terms like "code review", "PR", "branch diff against main", "bugs", and "security" are present and map to what a user would actually say. Common phrasings such as "review my changes", "review this diff", or "review the branch" are missing, which fits anchor 4 ('good keyword coverage; a few natural terms missing') better than 5's 'comprehensive coverage including synonyms'.

4 / 5

Distinctiveness Conflict Risk

The PR/branch-diff scope and AGENTS.md compliance focus carve out a clear niche that distinguishes it from generic code-review or security-audit skills. There is minor overlap risk with other review-oriented skills (e.g., a generic PR review skill), placing it at anchor 4 ('mostly distinct; minor overlap risk') rather than 5's 'minimal conflict risk'.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
windmill-labs/windmill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.