plugins/sdlc-utils/skills/review/SKILL.md
Code review practices and quality checks. Use when the user asks to "review code", "review a PR", "code review", "check code quality", "review changes", "score this code", or when evaluating code for merge readiness. Covers review checklists, scoring criteria, feedback conventions, and iterative improvement until quality thresholds are met.
npx skillsauth add nsheaps/ai-mktpl reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Structured code review for evaluating and improving code quality before merge.
Evaluate code across these dimensions, scoring each 0-100:
| Category | What to check | | ----------------- | ------------------------------------------------- | | Simplicity | Is the code as simple as it can be? | | Correctness | Does it do what the spec says? | | Security | Are there vulnerabilities or unsafe patterns? | | Performance | Are there obvious performance issues? | | Maintainability | Can someone else understand and modify this? | | Pattern adherence | Does it follow existing codebase conventions? | | Test coverage | Are changes covered by tests? | | Documentation | Are public APIs and non-obvious logic documented? |
| Score | Status | Meaning | | ------ | ------ | --------------------------- | | >= 85% | Pass | Ready to merge | | 70-84% | Warn | Should address before merge | | < 70% | Block | Must address before merge |
For each category:
If scores are below threshold, the author addresses feedback and requests re-review. Repeat until all categories pass.
| Verdict | When | | --------------- | ------------------------------------------------- | | Approve | All categories >= 85%, no P0 or P1 issues | | Comment | Only P2 follow-ups remain | | Request Changes | Any category < 70% or security/correctness issues |
| Anti-Pattern | Instead | | ----------------------- | ------------------------------------------ | | Rubber-stamping | Actually read and evaluate the code | | Nitpicking style only | Focus on substance (correctness, security) | | Vague feedback | Give specific, actionable comments | | Reviewing only the diff | Understand the full context |
tools
Manually reproduce what the github-app plugin's SessionStart hook does to make a GitHub App installation token usable in the current session — materialize the PEM, generate the token, isolate GH_CONFIG_DIR, write the runtime env file, and wire CLAUDE_ENV_FILE so every Bash call sees GH_TOKEN/GITHUB_TOKEN. Use when the hook did not run, the token is missing from the environment, or a shell/teammate needs the token wired up by hand. <example>GH_TOKEN isn't set even though github-app is configured</example> <example>the github-app SessionStart hook didn't run, set up the token manually</example> <example>wire the github app token into CLAUDE_ENV_FILE</example> <example>gh keeps falling back to the wrong account, isolate GH_CONFIG_DIR</example>
tools
Manually configure the GitHub App bot git identity the way the github-app plugin's SessionStart hook does — resolve the app slug and bot user ID, build the <slug>[bot] name and noreply email, set GIT_AUTHOR_*/GIT_COMMITTER_* env vars, and write an isolated GIT_CONFIG_GLOBAL with the gh auth git-credential helper. Use when commits are attributed to the wrong account, "Author identity unknown" appears, or git identity must be set up by hand. <example>my commits are showing up as the handler, not the bot</example> <example>git says Author identity unknown after the github-app hook ran</example> <example>configure the github app bot git identity manually</example> <example>set up the gh credential helper for git push</example>
tools
Manages spec files for requirements capture and validation
tools
# Bash Chaining Alternatives This skill teaches you how to work around the bash command chaining restriction enforced by this plugin. ## Why Chaining is Blocked The `bash-command-rejection` plugin blocks these operators: | Operator | Name | Why Blocked | | -------- | ---------- | ----------------------------------------------------------------------------------- | | `&&` | AND chain | Runs cmd2 only if cmd1 su