plugins/lisa/skills/lisa-quality-review/SKILL.md
Code quality review checklist. Correctness, coding philosophy compliance, test coverage, documentation quality. Findings ranked by severity in plain English.
npx skillsauth add codyswanngt/lisa lisa-quality-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Review code quality for changed files. Explain all findings in plain English as if speaking to someone with no programming background.
For each changed file, evaluate:
Correctness -- Does the code do what the task says? Logic errors, off-by-one mistakes, missing edge cases?
Coding philosophy -- Immutability patterns (no let, no mutations, functional transformations)? Correct function structure (variables, side effects, return)?
Test coverage -- Tests present? Testing behavior, not implementation details? Edge cases covered?
Documentation -- JSDoc on new functions explaining "why"? Preambles on new files?
Code clarity -- Readable variable names? Unnecessary complexity? Could a new team member understand this?
Design source -- For UI surfaces, does each changed file say where its design came from? Run the deterministic gate rather than judging by eye:
node "${CLAUDE_PLUGIN_ROOT:-.}/scripts/design-source-gate.mjs" --base=main --head=HEAD
Exit 1 is a Critical finding under the design-source-of-truth rule -- the change is blocked until every UI surface either cites a Figma node (DESIGN-SOURCE: <figma-url>, the preferred fix -- sync it back) or carries the exception marker DESIGN-SOURCE: none — not in Figma. The gate fails closed: an unreadable file or an uncomputable diff is a FAIL, not a pass. Host design-system rules (figma-design-system, design-system, use-the-design-library, or the project's equivalent) stay authoritative about what to build; this checks only that the source is declared. If the gate script is absent, say so in the review rather than skipping silently.
Review the same surfaces against the design-value-binding rule as well — it asks the orthogonal question of whether each value is bound to what the design system publishes, not whether the source is declared. A literal in an axis the project publishes variables for is a Critical finding; the identical literal in an axis with no variable collection is correct and must not be flagged. Aesthetic disagreement is never a finding under this rule. Cite the rule; do not restate its conditions here.
Rank findings by severity:
Broken logic or violates hard project rules.
Could cause problems later or reduce maintainability.
Minor improvements, not blocking.
For each finding:
What: The function changes the original list instead of creating a new one. Why: Other code using that list could see unexpected changes, causing hard-to-track bugs. Where:
src/utils/transform.ts:42Fix: Use[...items].sort()instead ofitems.sort()to create a copy first.
bun run test to confirm tests passdevelopment
Prepare a machine — a fresh laptop or a throwaway container — to run coding agents, before any repository exists. Detects which of Lisa's supported agents (Claude Code, Codex, Cursor, OpenCode, Antigravity, Copilot) are already installed, asks which credential manager the machine uses (Bitwarden, 1Password, Doppler, Vault, AWS, or none), and installs only what is missing, each by its vendor's own preferred method. Idempotent, headless by default, and emits a Dockerfile for a spin-up/spin-down environment. Run it on a new machine, in a container, or before cloning anything.
tools
Provision and verify a remote execution environment for a host project — Codex Cloud today, other remote surfaces as they are added. Generates a repository-owned setup script that installs the declared toolchain, materializes secrets through lisa-secrets-access, and runs the project's own hook. Provisions by API where one exists, by driving the vendor console where one does not, and by emitting exact config otherwise — then proves the result with the same read-back regardless of which tier did the work. Use before dispatching any work with executionEnv.
tools
Bring a developer's machine in line with the toolchain the project declares. Reports every tool in remoteEnv.tools that is missing, outdated, or unpinned for this platform, and installs the missing ones into ~/.local/bin from the same pinned, checksummed entries the remote surfaces use — but only when asked. Same manifest, same pins, same installers as lisa-setup-remote-env; what differs is consent and that the pin is a floor rather than an equality. Run it on a fresh checkout, after a manifest change, or when a tool fails at the moment of use.
tools
Route one unit of work to a remote execution surface. Reads the executionEnv parameter (local by default, codex-cloud or claude-web today), verifies the environment is provisioned and bound to this repository, submits a thin skill invocation, records the task identifier to .lisa/remote-dispatch.json, and exits without polling. Routing only — the remote runs the identical skill from the identical repository. Composable and inline: other skills invoke it via the Skill tool rather than users calling it directly.