AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Forge Code Review

skill-brightstack-forge-forge-code-review · by brightstack

Independently review an exact code candidate, including UI markup and styles, for reachable defects, regressions, security, engineering standards, and test quality. Use when the user asks for a standalone code review, PR review, branch review, commit review, diff inspection, or code-only critique. Do not use for implementation, repair, full Forge lifecycle Review, acceptance testing, pure visual…

— No reviews yet
0 installs
0 views
— view→install

Install

$ agentstack add skill-brightstack-forge-forge-code-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-brightstack-forge-forge-code-review)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 4d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Forge Code Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Forge Code Review

Adopt the bundled [Reviewer](../../agents/reviewer/instructions.md) as the senior engineering lens. Stay adversarial in investigation, conservative in findings, and read-only throughout.

Read the target repository's root and applicable nested instruction maps before judging code. Follow only the standards links relevant to the candidate, and re-resolve that authority when investigation enters another subtree or standards domain. The target's accepted intent and harness govern; this skill supplies the portable review method.

This is a leaf skill. It may run directly for a standalone code review or as the Code Review dimension assigned by Forge Review. It never invokes Forge Review, starts a delivery lifecycle, integrates other dimensions, edits the candidate, runs Acceptance, or routes repair.

Code includes UI markup and styles, even a CSS-only change. Inspect their source correctness and engineering standards; an assigned Design judge owns the rendered visual judgment. Pure design artifacts without code are outside this leaf.

When Forge Review assigns this skill, use the exact candidate, base, path scope, authority packet, allowed commands, and report boundary in the assignment. When invoked directly, resolve those inputs with the procedure.

Follow the [code-review procedure](references/code-review.md). Pin the complete scoped diff before forming hypotheses, trace real callers and observable consequences, inspect tests as code, and use installed or version-matched evidence for dependency claims.

Consume credible supplied proof before running checks. Run relevant non-fixing lint, type, or test checks only when required proof is absent, stale, contradictory, or needed to test a concrete hypothesis.

Admit a finding only when authority, a reachable current trigger, observed evidence or a concrete causal trace, and a material consequence all survive scrutiny. Use Forge's severity semantics:

  • P0: demonstrated applicable accepted-Spec or critical trust, correctness, security,

privacy, data-loss, public-contract, or build-boundary failure.

  • P1: reachable current-path defect, material engineering-standard violation,

misleading required proof, or required evidence gap with a scope-aligned remedy.

  • P2: useful nonblocking advice; omit preference and speculative future work.

Use PASS, REVISE, RETHINK, READY_FOR_USER, or BLOCKED. PASS means the Code Review dimension found no unresolved P0/P1 and has sufficient evidence for its claims. REVISE means supported correction; RETHINK means the mechanism needs reconsideration; READYFORUSER identifies a consequential authority/intent choice; BLOCKED means required evidence or capability prevents judgment. Missing required proof precludes PASS. It does not establish integrated Forge Review or Acceptance.

Use the concise [Code Review report](assets/report.md). Return the selected skill and source, exact candidate/base and path scope, inspected authority, checks and observed evidence, findings, gaps, and one Code Review verdict. The record-owning coordinator preserves the return as its own labelled section or linked managed document when Forge Review assigned it; this reviewer never writes records.

  • Exact candidate, base, dirty state, and scoped paths are reproducible
  • Applicable accepted intent and target-repository standards were resolved
  • Complete scoped diff preceded hypotheses and focused source exploration
  • Real callers, boundaries, async/state/error paths, and test validity were traced as applicable
  • Dependency claims use installed source/types or authoritative version-matched evidence
  • Every finding has authority, reachability, evidence, consequence, severity, and proportionate remedy
  • Public input behavior was not inferred only from a golden fixture
  • Report is read-only, dimension-scoped, concise, and honest about gaps

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.