bundles/dev-workflow/skills/full-code-review/SKILL.md
Fan-out PR review across three parallel dimension agents (structural, security, devex/flag-hygiene), adversarially verify every finding, and synthesize a single prioritized verdict via a strongest-tier judge. Use when asked for a full, comprehensive, or end-to-end review of a branch or PR — after /code-review passes correctness, this skill covers the orthogonal dimensions it does not: security depth, structural health, devex regressions, and feature-flag hygiene. In retro mode (a commit log is passed in) it adds a cross-commit lens and emits a prioritized backlog instead of a merge verdict.
npx skillsauth add shipshitdev/library full-code-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Orchestrated, multi-dimension PR/branch review. Runs structural, security, and devex/flag-hygiene reviewers in parallel, adversarially verifies every finding, then synthesizes one prioritized verdict. Read-only — this skill reports, it does not edit.
/code-review ultra has already
passed correctness — but structural health, feature-flag hygiene, devex
regressions, or security depth still need a dedicated pass.Do not invoke for a quick diff check — use /code-review for that. Do not
invoke deslop or refactor-code from within this skill; it reviews, it
does not apply changes.
The correctness review harness (/code-review ultra on Claude Code, or the
platform's equivalent review gate) owns: correctness bugs, repo instruction-file
rule violations, historical context. Trust it on correctness. This skill does
not re-run bug detection — that is fully owned by the harness.
This skill owns the orthogonal dimensions the harness does not cover:
| Dimension | What This Adds | |---|---| | Security depth | OWASP rubric, secret scanning, privilege escalation paths, timing attacks — not just diff-visible auth issues | | Structural health | Module cohesion, circular deps, abstraction altitude, dead-code introduction, API surface sprawl | | DevEx / flag hygiene | Internal-API breaking changes, type inference degradation, missing changelog, docs divergence, flags without cleanup tickets, always-on constants | | Test quality signal | Tests asserting behavior not just execution; hollow snapshots; missing contract tests | | Cross-commit (retro only) | Duplication reintroduced across separate commits, optimizations compounding over the window, a bug fix whose root cause recurs in untouched siblings, switch/flag forests that grew commit-by-commit — patterns invisible to any single-diff pass |
Explicitly excluded to avoid overlap: bug detection, repo rule validation, confidence-scoring/false-positive loop — those are owned by the harness. Do not add a correctness reviewer here.
Inputs:
HEAD vs
origin/main when not specified.COMMIT_LOG (SHAs + messages + per-file stat over a window),
passed by review-dispatch retro. Its presence switches the run to retro.Outputs:
retro-backlog (never blocks anything) — findings
bucketed bug / optimization / refactor / other and ranked by (impact × recurrence)
÷ effort, for scheduling as follow-up work.Creates/Modifies:
External Side Effects:
Confirmation Required:
Delegates To:
security-audit for security dimension prompt.Before invoking the Workflow script, gather the diff scope so reviewer agents have concrete file/line context:
# Identify the base and head
git fetch --all --prune
git rev-parse --abbrev-ref HEAD
# Diff stat for scope awareness
git diff --stat origin/main...HEAD 2>/dev/null || git diff --stat HEAD~1...HEAD
# Full diff (passed into agent prompts)
git diff origin/main...HEAD 2>/dev/null || git diff HEAD~1...HEAD
If a PR number is available, also fetch PR metadata:
gh pr view <number> --json baseRefName,headRefName,changedFiles,additions,deletions
gh pr diff <number>
Store the diff text as DIFF and the file list as CHANGED_FILES — both are
redacted for secret-like values before they are injected into reviewer agent
prompts in the Workflow script below.
Resolve scripts/full-code-review.js from this skill's installed directory.
Run it only when the active harness supports its agent, parallel, and log
workflow API; otherwise perform the same dimension, refutation, and synthesis
steps with available delegation tools. Model selection stays with the harness;
the script's role labels do not override the configured provider or model.
Pass DIFF and CHANGED_FILES as context strings embedded in each reviewer prompt.
For a retro, also pass COMMIT_LOG — its presence adds the cross-commit reviewer
and switches synthesis to backlog mode. Everything else is unchanged.
After the Workflow completes, render output in this format:
Full Code Review — <branch or PR>
Verdict: <APPROVE | REQUEST CHANGES | BLOCK>
<one-sentence rationale>
Findings (<N> verified, <M> dropped):
[rank]. [SEVERITY] [dimension] — <file>:<line>
Finding: <one sentence>
Evidence: <redacted code snippet or file/line reference>
Fix: <stack-idiomatic remediation>
Overlap: flagged by <dimension(s)>
...
Dimensions reviewed: structural, security, devex
Adversarial pass: <N raw> → <M surviving>
For a retro (mode: retro), render a backlog instead — no APPROVE/BLOCK line,
findings grouped by bucket, ranked within each:
Commit Retro — <window> (<N> commits)
Theme: <one-sentence highest-leverage theme>
Bugs shipped this window:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>, <sha>)
Fix: <remediation>
Optimizations:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>)
Fix: <remediation>
Refactors:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>, <sha>, <sha>)
Fix: <consolidation>
Other follow-ups:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>)
Fix: <remediation>
Dimensions reviewed: structural, security, devex, cross-commit
Adversarial pass: <N raw> → <M surviving>
/code-review for a simple typo or config fix.deslop, refactor-code, or any mutating skill from within this review — this skill is read-only.Read thermo-nuclear-code-quality-review procedure when the request calls for the exhaustive review workflow. Apply the authorized scope and mode of this entry point to every step. Resolve other skills through this distribution’s active catalog; resolve resources relative to the installed skill directory.
development
Coordinates a weekly engineering review of board accuracy, recent code changes, operational health, and scoped cleanup. Use for a recurring repository health review or a review of the last several days.
testing
Audits project board configuration and prepares explicitly requested setup, copy, or normalization changes while preserving the existing workflow and provider boundaries. Use when inspecting a board's fields, columns, scope, or configuration.
testing
Reconciles a project board with current work and delivery evidence, reports incomplete coverage and metadata gaps, and applies only approved provider-supported field changes. Use when auditing board drift, reviewing blocked work, or assessing upcoming delivery.
development
Walk through how a subsystem works. Use for "how does X work", code walkthroughs before changing something, and placement or ownership questions. Explains architecture, runtime flow, and onboarding mental models. Can critique architecture. Use why for motivation.