universal/process/code-review-standards/SKILL.md
Severity-tagged code review checklist (CRITICAL/HIGH/MEDIUM/LOW) used by code-critic agent
npx skillsauth add bobmatnyc/claude-mpm-skills code-review-standardsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill defines the structured checklist that the code-critic agent applies during
Stage 4 of the code production pipeline. The checklist is severity-tagged so that PM
and engineer both know exactly which findings block delivery and which are advisory.
Engineers may load this skill for self-review before requesting a critic pass.
The checklist exists because unstructured code review in multi-agent systems produces inconsistent signal: one critic dispatch flags naming; another flags security; neither flags the same things. Severity tagging makes the review deterministic across dispatches.
eval, exec, unrestricted pickle.loads)Efficiency (see criteria-efficiency.md):
+=SELECT * / over-fetching in production query pathsTransferability (see criteria-transferability.md):
if/else if chains (3+ branches on one key) replaced by switch/match or dispatch mapswitch/match — extract inner switch to a named functionCritic output MUST begin with the verdict on the first line, followed by the finding table, followed by a summary paragraph.
First line format:
VERDICT: APPROVE
or
VERDICT: WARN
or
VERDICT: BLOCK
Finding table format:
| Severity | File | Line | Issue | Required Fix |
|----------|------|------|-------|--------------|
| CRITICAL | auth.py | 47 | Hardcoded API key sk-... | Move to env var; add to .env.example |
| HIGH | fetcher.py | 23 | requests.get() called inside async def | Replace with await httpx.AsyncClient().get() |
| MEDIUM | parser.py | 88 | Function is 34 lines | Extract _parse_headers() helper |
Verdict definitions:
| Verdict | Condition | PM Action | |---------|-----------|-----------| | APPROVE | Zero CRITICAL, zero HIGH findings | Proceed to Stage 5 (Security) | | WARN | Zero CRITICAL, one or more HIGH findings | Proceed to Stage 5 with findings logged to docs handoff | | BLOCK | Any CRITICAL finding (one or more) | Halt pipeline; surface findings to user; await user direction |
APPROVE means the implementation is ready for security review. MEDIUM and LOW findings in an APPROVE review are passed to the Documentation agent as notes — they do not block delivery but are preserved for future reference.
WARN means the implementation has structural issues that should be fixed but do not represent exploitable defects or correctness failures. PM proceeds to security review and appends the WARN finding table to the documentation handoff message. PM also logs the findings (KB entry or todo) so they are not silently dropped.
BLOCK means the implementation has at least one defect that, if shipped, creates a security vulnerability, data loss risk, or silent failure mode. PM halts the pipeline immediately, presents the critic finding table verbatim to the user, and awaits explicit direction. PM MUST NOT auto-retry the engineer without user input.
A clean review is a valid review. Do not manufacture findings.
Only report issues with >80% confidence they are real problems. Do not flag:
When confidence is below 80%, note the concern as a question in the summary paragraph
rather than as a finding in the table. Example: "The process_batch() function did not
appear to handle empty input — verify whether the caller guarantees non-empty batches."
This filter prevents the critic from becoming a noise generator that trains PM to ignore findings. Each finding in the table should be actionable: engineer reads it, knows exactly what to fix, and can do so without asking for clarification.
For detailed criteria with examples:
The Efficiency and Transferability criteria are derived from CAST Highlight code quality indicators (https://doc.casthighlight.com/), paraphrased with original examples.
tools
Xquik X data automation API - Use REST or MCP for tweet search, user lookup, follower exports, media downloads, monitors, webhooks, giveaway draws, and confirmation-gated X actions.
tools
LinkedIn automation via the Linked API CLI - fetch profiles, search people and companies, send messages, manage connections, create posts, react, comment, and run Sales Navigator and custom workflows. Use when the user wants to interact with LinkedIn.
tools
MCP (Model Context Protocol) server build and evaluation guide, including local conventions for tool surfaces, config, and testing
tools
MCP (Model Context Protocol) - Build AI-native servers with tools, resources, and prompts. TypeScript/Python SDKs for Claude Desktop integration.