plugins/lisa-cursor/skills/lisa-review-local/SKILL.md
This skill should be used when performing a code review on local changes on the current branch compared to the main branch. It uses multiple parallel agents to check for bugs, CLAUDE.md compliance, git history context, previous PR comments, and code comment adherence, then scores and filters findings by confidence level.
npx skillsauth add codyswanngt/lisa lisa-review-localInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Provide a code review for the local changes on the current branch compared to the main branch.
Apply the convergent-review rule throughout this skill: reviewers bias toward
merge, block only concrete correctness/security/data-loss/contract failures, and
must label every finding with severity, blocking status, failure scenario,
evidence, and fix. Lint-owned style, formatting, taste, and speculative
maintainability feedback are non-blocking unless a repository rule or work item
explicitly makes them release criteria. A blocking finding without a concrete
failure scenario is malformed and must be filtered out.
To do this, follow these steps precisely:
git branch --show-current to get the current branch namegit log main..HEAD --oneline to see commits on this branchgit diff main...HEAD --stat to see changed filesgit log main..HEAD --format="%s%n%b" to get commit messagesgit diff main...HEAD to get the full diffgit diff main...HEAD), then do a shallow scan for obvious bugs. Avoid reading extra context beyond the changes, focusing just on the changes themselves. Focus on large bugs, and avoid small issues and nitpicks. Ignore likely false positives.
c. Agent #3: Read the git blame and history of the code modified, to identify any bugs in light of that historical context
d. Agent #4: Read previous pull requests that touched these files, and check for any comments on those pull requests that may also apply to the current changes.
e. Agent #5: Read code comments in the modified files, and make sure the changes comply with any guidance in the comments.
Each agent must apply the severity bar from convergent-review and return only findings that include a concrete failure scenario and evidence. Non-blocking observations may be summarized separately, but must not be presented as required changes.convergent-review blocker classes. Keep it only as non-blocking context if it is useful.Examples of false positives, for steps 4 and 5:
Notes:
gh commands for remote PRs)<branch-name>Reviewed X commits with changes to Y files.
Found 3 issues:
<brief description of bug> (CLAUDE.md says "<...>")
path/to/file.ts:L10-L15<brief description of bug> (some/other/CLAUDE.md says "<...>")
path/to/other-file.ts:L25-L30<brief description of bug> (bug due to <reasoning>)
path/to/another-file.ts:L5-L8<branch-name>Reviewed X commits with changes to Y files.
No issues found. Checked for bugs and CLAUDE.md compliance.
tools
Configure the official SonarQube plugin + MCP as Lisa's single Sonar substrate across every supported coding agent. Installs/updates the SonarQube CLI, authenticates (browser login on a dev machine, or SONARQUBE_CLI_TOKEN headless), selects the Test Manager target, runs `sonar integrate <agent>` for each supported agent (Claude, Codex, Cursor, Copilot, Antigravity) and wires the MCP for OpenCode, then writes only non-secret policy to .lisa.config.json. Separate from the CI SonarCloud scan gate, which is unchanged.
tools
Configure the official SonarQube plugin + MCP as Lisa's single Sonar substrate across every supported coding agent. Installs/updates the SonarQube CLI, authenticates (browser login on a dev machine, or SONARQUBE_CLI_TOKEN headless), selects the Test Manager target, runs `sonar integrate <agent>` for each supported agent (Claude, Codex, Cursor, Copilot, Antigravity) and wires the MCP for OpenCode, then writes only non-secret policy to .lisa.config.json. Separate from the CI SonarCloud scan gate, which is unchanged.
tools
Configure the official SonarQube plugin + MCP as Lisa's single Sonar substrate across every supported coding agent. Installs/updates the SonarQube CLI, authenticates (browser login on a dev machine, or SONARQUBE_CLI_TOKEN headless), selects the Test Manager target, runs `sonar integrate <agent>` for each supported agent (Claude, Codex, Cursor, Copilot, Antigravity) and wires the MCP for OpenCode, then writes only non-secret policy to .lisa.config.json. Separate from the CI SonarCloud scan gate, which is unchanged.
tools
Configure the official SonarQube plugin + MCP as Lisa's single Sonar substrate across every supported coding agent. Installs/updates the SonarQube CLI, authenticates (browser login on a dev machine, or SONARQUBE_CLI_TOKEN headless), selects the Test Manager target, runs `sonar integrate <agent>` for each supported agent (Claude, Codex, Cursor, Copilot, Antigravity) and wires the MCP for OpenCode, then writes only non-secret policy to .lisa.config.json. Separate from the CI SonarCloud scan gate, which is unchanged.