universal/process/code-review-standards/SKILL.md
Severity-tagged code review checklist (CRITICAL/HIGH/MEDIUM/LOW) used by code-critic agent
npx skillsauth add bobmatnyc/claude-mpm-skills code-review-standardsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill defines the structured checklist that the code-critic agent applies during
Stage 4 of the code production pipeline. The checklist is severity-tagged so that PM
and engineer both know exactly which findings block delivery and which are advisory.
Engineers may load this skill for self-review before requesting a critic pass.
The checklist exists because unstructured code review in multi-agent systems produces inconsistent signal: one critic dispatch flags naming; another flags security; neither flags the same things. Severity tagging makes the review deterministic across dispatches.
eval, exec, unrestricted pickle.loads)Critic output MUST begin with the verdict on the first line, followed by the finding table, followed by a summary paragraph.
First line format:
VERDICT: APPROVE
or
VERDICT: WARN
or
VERDICT: BLOCK
Finding table format:
| Severity | File | Line | Issue | Required Fix |
|----------|------|------|-------|--------------|
| CRITICAL | auth.py | 47 | Hardcoded API key sk-... | Move to env var; add to .env.example |
| HIGH | fetcher.py | 23 | requests.get() called inside async def | Replace with await httpx.AsyncClient().get() |
| MEDIUM | parser.py | 88 | Function is 34 lines | Extract _parse_headers() helper |
Verdict definitions:
| Verdict | Condition | PM Action | |---------|-----------|-----------| | APPROVE | Zero CRITICAL, zero HIGH findings | Proceed to Stage 5 (Security) | | WARN | Zero CRITICAL, one or more HIGH findings | Proceed to Stage 5 with findings logged to docs handoff | | BLOCK | Any CRITICAL finding (one or more) | Halt pipeline; surface findings to user; await user direction |
APPROVE means the implementation is ready for security review. MEDIUM and LOW findings in an APPROVE review are passed to the Documentation agent as notes — they do not block delivery but are preserved for future reference.
WARN means the implementation has structural issues that should be fixed but do not represent exploitable defects or correctness failures. PM proceeds to security review and appends the WARN finding table to the documentation handoff message. PM also logs the findings (KB entry or todo) so they are not silently dropped.
BLOCK means the implementation has at least one defect that, if shipped, creates a security vulnerability, data loss risk, or silent failure mode. PM halts the pipeline immediately, presents the critic finding table verbatim to the user, and awaits explicit direction. PM MUST NOT auto-retry the engineer without user input.
A clean review is a valid review. Do not manufacture findings.
Only report issues with >80% confidence they are real problems. Do not flag:
When confidence is below 80%, note the concern as a question in the summary paragraph
rather than as a finding in the table. Example: "The process_batch() function did not
appear to handle empty input — verify whether the caller guarantees non-empty batches."
This filter prevents the critic from becoming a noise generator that trains PM to ignore findings. Each finding in the table should be actionable: engineer reads it, knows exactly what to fix, and can do so without asking for clarification.
For detailed criteria with examples:
development
Axum (Rust) web framework patterns for production APIs: routers/extractors, state, middleware, error handling, tracing, graceful shutdown, and testing
development
Optimize web performance using Core Web Vitals, modern patterns (View Transitions, Speculation Rules), and framework-specific techniques
development
Best practices for documenting APIs and code interfaces, eliminating redundant documentation guidance per agent.
development
Comprehensive API design patterns covering REST, GraphQL, gRPC, versioning, authentication, and modern API best practices