/pith-review
One-shot structured code review. Use when reviewing a PR, diff, file, or function. Format: one line per issue. No summaries. Does not persist.
$ npx -y skills add abhisekjha/pith --skill pith-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/pith-review
Context preview
The summary Claude sees to decide when to auto-load this skill.
One-shot structured code review. Use when reviewing a PR, diff, file, or function. Format: one line per issue. No summaries. Does not persist.
SKILL.md
pith-review.SKILL.mdname: pith-review
description: >
One-shot structured code review. Use when reviewing a PR, diff, file, or function.
Format: one line per issue. No summaries. Does not persist.
One line per issue. Exact format:
`L<line>: <SEVERITY> <what is wrong>. Fix: <exact change>.`
Severity levels
- `BUG` — incorrect behavior, will break in normal use
- `RISK` — correct now but fragile, will break under specific conditions
- `SEC` — security vulnerability (injection, auth bypass, data exposure, etc.)
- `PERF` — measurable performance problem
- `NIT` — style, naming, minor readability improvement
- `Q` — genuine question about intent, not a criticism
Rules
- One line per issue. Hard limit.
- No preamble. No "Overall this looks good." No trailing summary.
- If no issues: single line `No issues found.`
- File prefix only when reviewing multiple files: `auth.ts L42: BUG ...`
- Fix must be specific. Not "handle this better" — the actual change.
- SEC issues: describe the attack vector, not just "this is insecure."
Examples
L42: BUG token.exp compared in wrong unit (seconds vs ms). Fix: token.exp * 1000 < Date.now()
L87: SEC /auth endpoint has no rate limiting — brute-force viable. Fix: add express-rate-limit, max 10/min per IP
L103: RISK db.query() not wrapped in try/catch — uncaught rejection crashes server. Fix: wrap, return 500
L118: NIT variable named `data` — too generic. Fix: rename to `userProfile`
L201: Q Why is this cached for 24h? Stale user data seems risky here.
For a file with no path given
Start each line with the line number only: `L42: BUG ...`
For multiple files
Prefix with filename: `routes/auth.ts L42: BUG ...`
One-shot. Does not persist.
Read more
name: pith-review description: > One-shot structured code review. Use when reviewing a PR, diff, file, or function. Format: one line per issue. No summaries. Does not persist.
One line per issue. Exact format:
`L<line>: <SEVERITY> <what is wrong>. Fix: <exact change>.`
Severity levels
- `BUG` — incorrect behavior, will break in normal use
- `RISK` — correct now but fragile, will break under specific conditions
- `SEC` — security vulnerability (injection, auth bypass, data exposure, etc.)
- `PERF` — measurable performance problem
- `NIT` — style, naming, minor readability improvement
- `Q` — genuine question about intent, not a criticism
Rules
- One line per issue. Hard limit.
- No preamble. No "Overall this looks good." No trailing summary.
- If no issues: single line `No issues found.`
- File prefix only when reviewing multiple files: `auth.ts L42: BUG ...`
- Fix must be specific. Not "handle this better" — the actual change.
- SEC issues: describe the attack vector, not just "this is insecure."
Examples
L42: BUG token.exp compared in wrong unit (seconds vs ms). Fix: token.exp * 1000 < Date.now() L87: SEC /auth endpoint has no rate limiting — brute-force viable. Fix: add express-rate-limit, max 10/min per IP L103: RISK db.query() not wrapped in try/catch — uncaught rejection crashes server. Fix: wrap, return 500 L118: NIT variable named `data` — too generic. Fix: rename to `userProfile` L201: Q Why is this cached for 24h? Stale user data seems risky here.
For a file with no path given
Start each line with the line number only: `L42: BUG ...`
For multiple files
Prefix with filename: `routes/auth.ts L42: BUG ...`
One-shot. Does not persist.
Status: stable — not actively adding features. Bug fixes welcome via issues. Token compression hooks for Claude Code. Install once, works in every session, zero config.
Repo: abhisekjha/pith
Other skills on pith.
- /pith-arch
One-shot architecture decision format. Use for technology choices, design decisions, system design questions. Format: Decision / Options table / Choice / Risks / Next. Does not persist.
Open skill - /pith-commit
One-shot commit message generator. Conventional Commits format, subject ≤50 chars. Use when writing a git commit message for staged changes. Does not persist.
Open skill - /pith-debug
One-shot structured debug format. Use when diagnosing errors, unexpected behavior, crashes, or failures. Format: Problem / Cause / Fix / Verify — 4 fields, no prose. Does not persist.
Open skill - /pith-graph
Run the Pith wiki graph generator for the current project. Scans wiki/ for .md files, extracts [[wikilinks]], and opens an interactive force-directed graph in the browser as wiki-graph.html.
Open skill - /pith-install
Install Pith into Claude Code. Copies hooks, patches settings.json, registers slash commands (/pith, /budget, /focus), and records the plugin root so hooks can resolve paths.
Open skill - /pith-plan
One-shot planning format. Use for feature planning, task breakdown, sprint planning, implementation plans. Format: Goal / Steps / Risks / Done-when. Does not persist.
Open skill

