# Review Findings

> Addresses and fixes findings from a QA code review. Reads the review report, fixes critical and warning issues, and prepares for re-verification. Delegates to the Forja (Dev) agent.

- **Type:** Skill
- **Install:** `agentstack add skill-davepoon-buildwithclaude-review-findings`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [davepoon](https://agentstack.voostack.com/s/davepoon)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [davepoon](https://github.com/davepoon)
- **Source:** https://github.com/davepoon/buildwithclaude/tree/main/plugins/agent-triforce/skills/review-findings
- **Website:** https://www.buildwithclaude.com

## Install

```sh
agentstack add skill-davepoon-buildwithclaude-review-findings
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Review Findings

Addresses and fixes QA findings using the Forja (Dev) agent.

## When to Use This Skill

- After receiving a code review from Centinela (QA)
- When a review report has findings that need to be addressed
- Fixing critical and warning issues before re-verification

## What This Skill Does

1. Runs the SIGN IN checklist
2. Reads the review report and understands each finding's root cause
3. Plans fix order: Critical first, then Warnings
4. Implements fixes with updated tests for each finding
5. Scans for dead code after all fixes
6. Runs Implementation Complete and Pre-Delivery checklists (TIME OUT)
7. Verifies every Critical finding addressed, every Warning addressed or deferred with justification
8. Prepares a fix report for QA re-verification

## How to Use

### Basic Usage

```
/review-findings
```

### With Specific Review

```
/review-findings docs/reviews/user-auth-review.md
```

## Example

**User**: `/review-findings docs/reviews/webhook-system-review.md`

**Output**:
- All Critical findings fixed with tests
- All Warning findings fixed or explicitly deferred with justification
- Fix report documenting what was changed and why
- Ready for QA re-verification

## Tips

- If no review is specified, the most recent review in `docs/reviews/` is used
- The agent understands root causes before writing any fix
- Conflicting fixes are identified and planned around during the pre-fix phase

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [davepoon](https://github.com/davepoon)
- **Source:** [davepoon/buildwithclaude](https://github.com/davepoon/buildwithclaude)
- **License:** MIT
- **Homepage:** https://www.buildwithclaude.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-davepoon-buildwithclaude-review-findings
- Seller: https://agentstack.voostack.com/s/davepoon
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
