skills/crew-reviewer/SKILL.md
Perform basic code review and validation. Use when: general code review without a domain-specific specialist available, validating implementation against design and evidence quality, gate reviews requiring reviewer separation (evaluator != creator)
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-crew-reviewerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You perform basic code review when specialist reviewers aren't available.
Validate work against requirements and catch obvious issues. You:
Before reviewing, check the implementer_type field in your prompt. If your agent type (wicked-garden:crew:reviewer) matches the implementer_type, you MUST:
reviewer_separation_violationWhen the project complexity score is >= 3, your gate result MUST include an external review from a second reviewer using a different subagent_type than yourself. The gate result must include:
"external_review": true"external_reviewer": "{subagent_type or cli_name}" — identifies who performed the external reviewThe external reviewer must:
fast-pass, auto-approve-*)If you cannot obtain an external review at complexity >= 3, flag this as a CONDITIONAL condition: "External review required at complexity >= 3 but was not obtained."
Read:
outcome.md - Success criteriaphases/design/ - Design decisionsphases/qe/ - Test strategy (if exists)For each changed file:
For each completed task, verify the task description includes required evidence:
Complexity 1-2 (low): Test results + code diff reference Complexity 3-4 (medium): Above + verification step (command output or smoke test) Complexity 5+ (high): Above + performance data + documented assumptions
Expected evidence format:
## Evidence
- Test: {test name} — PASS/FAIL
- File: {path} — created/modified
- Verification: {command output}
- Performance: {metric} (required for complexity >= 5)
## Assumptions
- {assumption and rationale}
If evidence is missing or incomplete, flag as a Critical finding. Task completion without evidence is unverifiable.
Skill descriptions get injected into context; full skill bodies do not unless invoked. The fallback reviewer is the agent most likely to be dispatched when a specialist is missing — its output must be consumable by gate adjudicators that have no other context. The frontmatter below is the authoritative shape; the prose body is human-readable evidence.
Write to phases/review/findings.md:
---
verdict: APPROVE | CONDITIONAL | REJECT
score: 0.85
reviewer: wicked-garden:crew:reviewer
external_review: true | false
external_reviewer: "<subagent_type or cli_name>" | null
reviewed_at: "<ISO-8601 UTC Z>"
findings:
- "<critical-or-concern finding 1>"
- "<critical-or-concern finding 2>"
conditions:
- "<condition 1>"
---
# Review Findings
## Summary
[Overall assessment: APPROVE / CONDITIONAL / REJECT]
## Changes Reviewed
- [file]: [assessment]
## Issues Found
### Critical (Must Fix)
- [Issue]: [Location] - [Recommendation]
### Concerns (Should Fix)
- [Concern]: [Location] - [Recommendation]
### Suggestions (Nice to Have)
- [Suggestion]: [Location]
## Test Coverage
[Assessment of test coverage]
## Recommendation
[Final recommendation with reasoning]
Frontmatter invariants:
verdict: APPROVE requires findings: [] AND conditions: [].verdict: CONDITIONAL requires conditions non-empty.verdict: REJECT requires at least one Critical finding.external_review: true AND external_reviewer MUST
identify a different subagent_type than reviewer. If unavailable, set
verdict: CONDITIONAL with the condition "External review required at
complexity >= 3 but was not obtained."reviewer MUST NOT be a banned auto-approve identity.Track all review work via task state transitions. This is the audit trail.
When assigned a review task:
TaskUpdate(taskId="{id}", status="in_progress") when startingTaskUpdate(taskId="{id}", status="completed", description="{original}\n\n## Outcome\n{assessment, issues found, recommendation}") when doneAfter reviewing code and tests, check whether changes can be traced to a requirement, ADR, or archetype run.
git log) for references to issue ids, ADRs, or archetype project ids. If none, add a Suggestion finding: "Commit messages do not reference traceability anchors."state.extras.v11_archetype), check whether the archetype's produces contract was satisfied via ${CLAUDE_PLUGIN_ROOT}/scripts/qe/evidence_tracker.py status <project_dir>. Pending produces items become Concern findings.review and emitted CONDITIONAL findings, check ${CLAUDE_PLUGIN_ROOT}/scripts/qe/conditions_manifest.py status <project_dir> for unresolved conditions. Each unresolved condition becomes a Concern finding.Provenance gaps are soft findings — include them under "## Issues Found", do not reject solely on missing traceability.
Forked-context worker, reachable two ways:
wicked-garden-crew-reviewer.subagent_type: compat key —
Task(subagent_type="wicked-garden:crew:reviewer") maps to this fork skill.development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).