/review-gate
Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate,
$ npx -y skills add majiayu000/spellbook --skill review-gate --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/review-gate
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate,
SKILL.md
review-gate.SKILL.mdname: review-gate
description: "Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate, commit gate, push gate, or PR readiness. Produces a concise review pack, records risks and verification, and blocks landing until a human explicitly approves or approves with required fixes."
Review Gate
Use this skill as the last-mile safety checkpoint for agent-generated changes. It complements PR review tools; it does not replace code review, CI, or human approval.
Use `assets/review-pack-template.md` when the user needs a reusable review pack shape.
When To Run
Run before any of these actions when an agent-generated diff is involved:
- commit
- push
- open or update a PR
- merge or land
- apply a generated patch to user files when the user has not already approved
that exact implementation path
Read-only review, planning, issue triage, and local exploration do not require this gate unless the next step would land or publish changes.
Operating Contract
- Direct actions: inspect diffs, collect verification evidence, and draft the
review pack.
- Escalate before: commit, push, PR creation, merge, branch deletion, or
applying a generated patch when the user has not approved that exact action.
- Evidence-backed pushback: block landing when verification is stale, sensitive
surfaces lack review, or approval is ambiguous.
- Feedback loop: convert repeated review findings into new checklist items,
verification commands, or Review Pack risk prompts.
Gate States
| State | Meaning | Allowed next action | | --- | --- | --- | | `draft_pack` | Review pack is being assembled. | Inspect diff and verification only. | | `needs_fixes` | Blocking risks or missing evidence exist. | Patch and rerun the gate. | | `awaiting_human` | Pack is complete but no human approval exists. | Stop before commit, push, PR, merge, or apply. | | `approved` | Human explicitly approved the pack in the current thread. | Proceed with the named action only. | | `approved_with_fixes` | Human approved after specific fixes. | Apply fixes, verify, and record evidence before landing. |
Agents must not self-approve. Prior CI success, a reviewer lane, or a green local test is evidence for the pack, not approval.
Gotchas
- Approval is action-specific. "Commit it" does not mean "merge it."
- A reviewer lane is independent evidence, not human approval.
- If a fix changes the diff after approval, refresh verification and update the
pack before landing.
Review Pack
Produce this compact pack:
review_gate:
- intent:
- diff_summary:
- files_changed:
- driving_skill_or_issue:
- risks:
- missing_tests_or_verification:
- commands_run:
- evidence:
- open_questions:
- approval_needed_for:
- decision:
Keep findings ranked by severity. Include exact file paths, PR numbers, issue numbers, command names, and current head SHA when available.
Decision Rules
- If verification is stale, missing, or tied to a different head SHA, set
`needs_fixes`.
- If the diff touches auth, payments, secrets, permissions, `innerHTML`, `eval`,
shell execution, generated registry, hooks, or high-context files, call that out explicitly.
- If user approval is ambiguous, set `awaiting_human` and ask for the named
action only.
- If the user approves, do exactly the approved action. A commit approval is not
automatically a merge approval.
- If a required fix changes the diff, rerun the relevant verification and update
the pack before landing.
Integration Points
`flowguard` should call this gate at landing checkpoints. Queue skills may use a reviewer lane for independent findings, but the Review Gate still records the human-facing pack and approval state.
For GitHub PRs, combine this gate with current remote truth:
- PR head SHA
- check rollup
- merge state
- GraphQL reviewThreads
- linked issue intent
Verification
For Spellbook changes, the pack usually cites:
git diff --check
python3 ./scripts/validate_skills.py --check
python3 ./scripts/audit_skill_quality.py skill-name
Use project-specific tests for code changes. If a command cannot run, report the precondition and keep the decision out of `approved`.
Read more
name: review-gate description: "Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate, commit gate, push gate, or PR readiness. Produces a concise review pack, records risks and verification, and blocks landing until a human explicitly approves or approves with required fixes."
Review Gate
Use this skill as the last-mile safety checkpoint for agent-generated changes. It complements PR review tools; it does not replace code review, CI, or human approval.
Use `assets/review-pack-template.md` when the user needs a reusable review pack shape.
When To Run
Run before any of these actions when an agent-generated diff is involved:
- commit
- push
- open or update a PR
- merge or land
- apply a generated patch to user files when the user has not already approved
that exact implementation path
Read-only review, planning, issue triage, and local exploration do not require this gate unless the next step would land or publish changes.
Operating Contract
- Direct actions: inspect diffs, collect verification evidence, and draft the
review pack.
- Escalate before: commit, push, PR creation, merge, branch deletion, or
applying a generated patch when the user has not approved that exact action.
- Evidence-backed pushback: block landing when verification is stale, sensitive
surfaces lack review, or approval is ambiguous.
- Feedback loop: convert repeated review findings into new checklist items,
verification commands, or Review Pack risk prompts.
Gate States
| State | Meaning | Allowed next action | | --- | --- | --- | | `draft_pack` | Review pack is being assembled. | Inspect diff and verification only. | | `needs_fixes` | Blocking risks or missing evidence exist. | Patch and rerun the gate. | | `awaiting_human` | Pack is complete but no human approval exists. | Stop before commit, push, PR, merge, or apply. | | `approved` | Human explicitly approved the pack in the current thread. | Proceed with the named action only. | | `approved_with_fixes` | Human approved after specific fixes. | Apply fixes, verify, and record evidence before landing. |
Agents must not self-approve. Prior CI success, a reviewer lane, or a green local test is evidence for the pack, not approval.
Gotchas
- Approval is action-specific. "Commit it" does not mean "merge it."
- A reviewer lane is independent evidence, not human approval.
- If a fix changes the diff after approval, refresh verification and update the
pack before landing.
Review Pack
Produce this compact pack:
review_gate: - intent: - diff_summary: - files_changed: - driving_skill_or_issue: - risks: - missing_tests_or_verification: - commands_run: - evidence: - open_questions: - approval_needed_for: - decision:
Keep findings ranked by severity. Include exact file paths, PR numbers, issue numbers, command names, and current head SHA when available.
Decision Rules
- If verification is stale, missing, or tied to a different head SHA, set
`needs_fixes`.
- If the diff touches auth, payments, secrets, permissions, `innerHTML`, `eval`,
shell execution, generated registry, hooks, or high-context files, call that out explicitly.
- If user approval is ambiguous, set `awaiting_human` and ask for the named
action only.
- If the user approves, do exactly the approved action. A commit approval is not
automatically a merge approval.
- If a required fix changes the diff, rerun the relevant verification and update
the pack before landing.
Integration Points
`flowguard` should call this gate at landing checkpoints. Queue skills may use a reviewer lane for independent findings, but the Review Gate still records the human-facing pack and approval state.
For GitHub PRs, combine this gate with current remote truth:
- PR head SHA
- check rollup
- merge state
- GraphQL reviewThreads
- linked issue intent
Verification
For Spellbook changes, the pack usually cites:
git diff --check python3 ./scripts/validate_skills.py --check python3 ./scripts/audit_skill_quality.py skill-name
Use project-specific tests for code changes. If a command cannot run, report the precondition and keep the decision out of `approved`.
Cross-runtime skills for Claude Code, Codex, and multi-agent workflows.
Repo: majiayu000/spellbook
Other skills on spellbook.
- /agentsmd-optimize
Audit AND optimize a CLAUDE.md / AGENTS.md instruction file — score it against the five high-leverage patterns, flag anti-patterns, then apply approved fixes in place. Use when the user says 优化 CLAUDE.md / 优化 AGENTS.md / optimize my agent doc / 帮我改 claudemd, or after an audit
Open skill - /agentsmd-scaffold
Generate or update repository-specific AGENTS.md instruction files from real repo evidence. Use when asked to create, design, scaffold, split, or improve root or scoped AGENTS.md files for Codex/Claude/agent workflows, especially when a repo needs directory-specific rules,
Open skill - /api-design
REST/GraphQL/gRPC API design best practices. Use when designing APIs, defining contracts, handling versioning. Covers OpenAPI 3.2, GraphQL Federation, gRPC streaming.
Open skill - /app-ui-design
Mobile app UI design expert for iOS and Android. Use when designing app interfaces, creating design systems, ensuring accessibility, or following platform guidelines. Covers Material Design 3, Human Interface Guidelines, color theory, typography, and 2025 trends.
Open skill - /app-user-story-qa
End-to-end app feature inventory and user-story testing workflow with a canonical tracker. Use when the user asks to audit every feature, derive expected behavior from code, test user journeys, or explicitly fix and retest documented UX or logistical defects.
Open skill - /architecture-foundation
Design architecture foundations before implementation. Use when asked to design or refactor architecture, choose Rust/Go crate, package, module, runtime, workflow, or service boundaries, compare mature project architecture, prevent stacked one-off PRs, audit migration debt in
Open skill

