ai-toolkit-rules
Mandatory engineering, security, testing, git, performance, quality, and response rules.…
Reviews code for quality, security, correctness. Triggers: code review, quality review, security review, review PR, review branch.
$ npx -y skills add softspark/ai-toolkit --skill review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Reviews code for quality, security, correctness. Triggers: code review, quality review, security review, review PR, review branch.
name: review description: "Reviews code for quality, security, correctness. Triggers: code review, quality review, security review, review PR, review branch." user-invocable: true effort: high argument-hint: "[target: branch, pr, file path, or staged changes]" agent: code-reviewer context: fork allowed-tools: Read, Grep, Glob, Bash
$ARGUMENTS
Reviews code changes for quality and issues.
Collect every failing signal up front, then review the diff in full **anyway**:
| Signal | How to read it | |--------|----------------| | Merge conflict with base | `gh pr view --json mergeable,mergeStateStatus` or `git merge-tree` | | Failing CI checks | `gh pr checks` or the platform equivalent | | Lint / typecheck failure | the project's own commands |
Each failing signal becomes a `blocker` finding. **None of them ends the run.**
A review that aborts on the first red signal spends the whole cycle repeating what the tracker already displayed, while the finding that would have told the author something new never gets written. One invocation produces the most complete picture of the change that it can.
Before starting manual review, run the diff analyzer script to get a structured risk assessment:
python3 ${CLAUDE_SKILL_DIR}/scripts/diff-analyzer.py [base_branch]
# Default base branch: main
# Example: python3 ${CLAUDE_SKILL_DIR}/scripts/diff-analyzer.py developThe script outputs JSON with:
If the script reports `parallel_review_recommended: true`, use the Parallel Review (Agent Teams) mode below.
---
For significant PRs or large changesets, create a parallel review team:
Create an agent team to review [target]: - Teammate 1 (security-auditor): "Review for security vulnerabilities, auth issues, injection risks, secret leaks. Report with severity ratings." Use Opus. - Teammate 2 (performance-optimizer): "Check for N+1 queries, memory leaks, unnecessary allocations, caching opportunities. Report with impact ratings." Use Opus. - Teammate 3 (test-engineer): "Validate test coverage, edge cases, mock quality, missing assertions. Report coverage gaps." Use Opus. Each reviewer should report findings independently. Do NOT modify files.
After all reviewers complete: 1. Synthesize findings into unified Code Review Report 2. Prioritize by severity (blocker > major > minor > nit) 3. Issue verdict per the verdict rule below — not by impression
> **When to use**: PRs with >5 files changed, cross-module changes, security-sensitive code. > **READ-ONLY**: No teammate should modify files during review.
---
1. **Reads** changed files 2. **Analyzes** for issues 3. **Checks** best practices 4. **Reports** findings
| Target | What's Reviewed | |--------|-----------------| | (none) | Staged changes | | `branch` | Branch vs main | | `pr` | Pull request changes | | `file.ts` | Specific file |
AI coding toolkit with machine-enforced safety, 116 skills, 44 agents, lifecycle hooks, persona presets, opt-in plugin packs, and benchmark tooling.
Repo: softspark/ai-toolkit
Mandatory engineering, security, testing, git, performance, quality, and response rules.…
Searches past coding sessions for observations, decisions, context. Triggers: mem-search,…
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. Triggers: a11y, accessibility, WCAG,…
Creates new specialized agents with frontmatter, tools, delegation. Triggers: new agent,…
Analyzes code quality, complexity, patterns across codebase. Triggers: quality report,…
API design: naming, versioning, pagination, idempotency, OpenAPI, error contracts and safe…