plugins/sdlc-utils/skills/iterate-until-good/SKILL.md
Evaluates code on a PR or branch across many categories, scores each, and iterates (local review+fix loop) until all categories score > 85%. Uses the scm-utils review skills for the review portion of each iteration.
npx skillsauth add nsheaps/ai-mktpl iterate-until-goodInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A local review-and-fix loop. For the user's requested target (branch, PR, repo, etc), run a review across all categories, fix issues, and repeat until every category scores > 85%. Any category below 70% is a hard block.
Cross-reference: The review portion of each iteration uses the granular review skills in
scm-utils(review-code, review-diff, review-commits, review-commit-messages, review-pr-contents). CI-based review follows the same iterative pattern but usesscm-utils:code-reviewfor the review bot workflow.
CRITICAL: This skill improvement depends on your iteration after you utilize it. If any part of this can be improved, please submit a Pull Request to this skill on https://github.com/nsheaps/ai-mktpl. If you choose to contribute, please use a background agent to perform the updates. Future AI agents and humans thank you!
Evaluate across these dimensions, scoring each 0-100:
| Category | What to check | | ----------------- | ------------------------------------------------- | | Simplicity | Is the code as simple as it can be? | | Correctness | Does it do what the spec says? | | Flexibility | Can it adapt to reasonable future changes? | | Usability | Is the API/interface intuitive? | | Security | Are there vulnerabilities or unsafe patterns? | | Pattern adherence | Does it follow existing codebase conventions? | | Documentation | Are public APIs and non-obvious logic documented? | | Quality assurance | General engineering practices and best practices |
Also factor in: PR title/body, commit messages, commit history, and the commit history relation to its base branch.
Launch a run_in_background:true Task sub-agent for each category. Each agent should:
.claude/pr-reviews/$org/$repo/$prNumber/$epoch/$category/REPORT.mdWhen all agents complete, review each report and create one overall report:
🚨 < 70%, ⚠️ < 85%, ✅ >= 85%⚠️, maximum overall score is 94%🔕, for info-only use ℹ️Address all findings below threshold. Use scm-utils:fix-review-findings for guidance.
Repeat from Step 1 until all categories pass.
Agentic mode (empowered to post reviews): Leave inline comments as individual comment-only reviews, then a final review with <details>/<summary> and shields.io badges for scoring.
Interactive CLI: Provide links to files on GitHub or locally.
| Score | Status | Action | | ------ | ------ | --------------------------- | | >= 85% | Pass | Ready to merge | | 70-84% | Warn | Should address before merge | | < 70% | Block | Must address before merge |
tools
Manually reproduce what the github-app plugin's SessionStart hook does to make a GitHub App installation token usable in the current session — materialize the PEM, generate the token, isolate GH_CONFIG_DIR, write the runtime env file, and wire CLAUDE_ENV_FILE so every Bash call sees GH_TOKEN/GITHUB_TOKEN. Use when the hook did not run, the token is missing from the environment, or a shell/teammate needs the token wired up by hand. <example>GH_TOKEN isn't set even though github-app is configured</example> <example>the github-app SessionStart hook didn't run, set up the token manually</example> <example>wire the github app token into CLAUDE_ENV_FILE</example> <example>gh keeps falling back to the wrong account, isolate GH_CONFIG_DIR</example>
tools
Manually configure the GitHub App bot git identity the way the github-app plugin's SessionStart hook does — resolve the app slug and bot user ID, build the <slug>[bot] name and noreply email, set GIT_AUTHOR_*/GIT_COMMITTER_* env vars, and write an isolated GIT_CONFIG_GLOBAL with the gh auth git-credential helper. Use when commits are attributed to the wrong account, "Author identity unknown" appears, or git identity must be set up by hand. <example>my commits are showing up as the handler, not the bot</example> <example>git says Author identity unknown after the github-app hook ran</example> <example>configure the github app bot git identity manually</example> <example>set up the gh credential helper for git push</example>
tools
Manages spec files for requirements capture and validation
tools
# Bash Chaining Alternatives This skill teaches you how to work around the bash command chaining restriction enforced by this plugin. ## Why Chaining is Blocked The `bash-command-rejection` plugin blocks these operators: | Operator | Name | Why Blocked | | -------- | ---------- | ----------------------------------------------------------------------------------- | | `&&` | AND chain | Runs cmd2 only if cmd1 su