bundles/dev-workflow/skills/full-code-review/SKILL.md
Fan-out PR review across three parallel dimension agents (structural, security, devex/flag-hygiene), adversarially verify every finding, and synthesize a single prioritized verdict via a strongest-tier judge. Use when asked for a full, comprehensive, or end-to-end review of a branch or PR — after /code-review passes correctness, this skill covers the orthogonal dimensions it does not: security depth, structural health, devex regressions, and feature-flag hygiene. In retro mode (a commit log is passed in) it adds a cross-commit lens and emits a prioritized backlog instead of a merge verdict.
npx skillsauth add shipshitdev/library full-code-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Orchestrated, multi-dimension PR/branch review. Runs structural, security, and devex/flag-hygiene reviewers in parallel, adversarially verifies every finding, then synthesizes one prioritized verdict. Read-only — this skill reports, it does not edit.
/code-review ultra has already
passed correctness — but structural health, feature-flag hygiene, devex
regressions, or security depth still need a dedicated pass.Do not invoke for a quick diff check — use /code-review for that. Do not
invoke de-slop or refactor-code from within this skill; it reviews, it
does not apply changes.
The correctness review harness (/code-review ultra on Claude Code, or the
platform's equivalent review gate) owns: correctness bugs, repo instruction-file
rule violations, historical context. Trust it on correctness. This skill does
not re-run bug detection — that is fully owned by the harness.
This skill owns the orthogonal dimensions the harness does not cover:
| Dimension | What This Adds | |---|---| | Security depth | OWASP rubric, secret scanning, privilege escalation paths, timing attacks — not just diff-visible auth issues | | Structural health | Module cohesion, circular deps, abstraction altitude, dead-code introduction, API surface sprawl | | DevEx / flag hygiene | Internal-API breaking changes, type inference degradation, missing changelog, docs divergence, flags without cleanup tickets, always-on constants | | Test quality signal | Tests asserting behavior not just execution; hollow snapshots; missing contract tests | | Cross-commit (retro only) | Duplication reintroduced across separate commits, optimizations compounding over the window, a bug fix whose root cause recurs in untouched siblings, switch/flag forests that grew commit-by-commit — patterns invisible to any single-diff pass |
Explicitly excluded to avoid overlap: bug detection, repo rule validation, confidence-scoring/false-positive loop — those are owned by the harness. Do not add a correctness reviewer here.
Inputs:
HEAD vs
origin/main when not specified.COMMIT_LOG (SHAs + messages + per-file stat over a window),
passed by review-dispatch retro. Its presence switches the run to retro.Outputs:
retro-backlog (never blocks anything) — findings
bucketed bug / optimization / refactor / other and ranked by (impact × recurrence)
÷ effort, for scheduling as follow-up work.Creates/Modifies:
External Side Effects:
Confirmation Required:
Delegates To:
security-audit for security dimension prompt.Before invoking the Workflow script, gather the diff scope so reviewer agents have concrete file/line context:
# Identify the base and head
git fetch --all --prune
git rev-parse --abbrev-ref HEAD
# Diff stat for scope awareness
git diff --stat origin/main...HEAD 2>/dev/null || git diff --stat HEAD~1...HEAD
# Full diff (passed into agent prompts)
git diff origin/main...HEAD 2>/dev/null || git diff HEAD~1...HEAD
If a PR number is available, also fetch PR metadata:
gh pr view <number> --json baseRefName,headRefName,changedFiles,additions,deletions
gh pr diff <number>
Store the diff text as DIFF and the file list as CHANGED_FILES — both are
redacted for secret-like values before they are injected into reviewer agent
prompts in the Workflow script below.
Invoke the Workflow tool with the script at ${CLAUDE_SKILL_DIR}/scripts/full-code-review.js.
Pass DIFF and CHANGED_FILES as context strings embedded in each reviewer prompt.
For a retro, also pass COMMIT_LOG — its presence adds the cross-commit reviewer
and switches synthesis to backlog mode. Everything else is unchanged.
After the Workflow completes, render output in this format:
Full Code Review — <branch or PR>
Verdict: <APPROVE | REQUEST CHANGES | BLOCK>
<one-sentence rationale>
Findings (<N> verified, <M> dropped):
[rank]. [SEVERITY] [dimension] — <file>:<line>
Finding: <one sentence>
Evidence: <redacted code snippet or file/line reference>
Fix: <stack-idiomatic remediation>
Overlap: flagged by <dimension(s)>
...
Dimensions reviewed: structural, security, devex
Adversarial pass: <N raw> → <M surviving>
For a retro (mode: retro), render a backlog instead — no APPROVE/BLOCK line,
findings grouped by bucket, ranked within each:
Commit Retro — <window> (<N> commits)
Theme: <one-sentence highest-leverage theme>
Bugs shipped this window:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>, <sha>)
Fix: <remediation>
Optimizations:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>)
Fix: <remediation>
Refactors:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>, <sha>, <sha>)
Fix: <consolidation>
Other follow-ups:
[rank]. [SEVERITY] <file> — <finding> (commits: <sha>)
Fix: <remediation>
Dimensions reviewed: structural, security, devex, cross-commit
Adversarial pass: <N raw> → <M surviving>
/code-review for a simple typo or config fix.de-slop, refactor-code, or any mutating skill from within this review — this skill is read-only.development
TypeScript refactoring and modernization guidelines from a principal specialist perspective. This skill should be used when refactoring, reviewing, or modernizing TypeScript code to ensure type safety, compiler performance, and idiomatic patterns. Triggers on tasks involving TypeScript type architecture, narrowing, generics, error handling, or migration to modern TypeScript features.
tools
Resolves TypeScript and JavaScript problems across type-level programming, performance, monorepo management, migration, and modern tooling. Invoke when diagnosing "type instantiation excessively deep" errors, migrating JS to TS, configuring strict tsconfig, debugging module resolution, or choosing between Biome/ESLint/Turborepo/Nx.
tools
Turborepo monorepo build system guidance. Triggers on: `turbo.json`, task pipelines, `dependsOn`, caching, remote cache, the `turbo` CLI, `--filter`, `--affected`, CI optimization, environment variables, internal packages, monorepo structure, and package boundaries. Use when the user configures tasks or workflows, creates packages, sets up a monorepo, shares code between apps, runs changed packages, debugs cache behavior, or works in an `apps/` plus `packages/` workspace.
tools
Provides Tailwind CSS v4 performance optimization and best practices guidelines. Triggers when writing, reviewing, or refactoring Tailwind CSS v4 code; when working with Tailwind configuration, @theme directive, utility classes, responsive design, dark mode, container queries, or CSS generation optimization.