# Skill Review

> Review and promote skill drafts that skill-curator staged from past sessions. Use when the user runs /skill-review, says "review my skill drafts", "promote a staged skill", or asks what skills the self-improvement loop proposed. Lists drafts under ~/.claude/skill-proposals/, runs the writing-skills quality bar on each, then promotes the approved ones into ~/.claude/skills/ or rejects them.

- **Type:** Skill
- **Install:** `agentstack add skill-dwarvesf-dwarves-kit-skill-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [dwarvesf](https://agentstack.voostack.com/s/dwarvesf)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [dwarvesf](https://github.com/dwarvesf)
- **Source:** https://github.com/dwarvesf/dwarves-kit/tree/master/skills/skill-review

## Install

```sh
agentstack add skill-dwarvesf-dwarves-kit-skill-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# skill-review (the promote gate)

skill-curator's background reviewer stages skill drafts under `~/.claude/skill-proposals/`. It
NEVER writes `~/.claude/skills/`. This skill is the human gate that promotes a vetted draft into the
live library. `bin/skill-review` (from `lib/skill-curator/`, put it on PATH or invoke by its full
path) is the only writer of `~/.claude/skills/`.

## Flow

1. **List** the staged drafts:
   ```bash
   skill-review list      # tab-separated: \t
   ```
   If "(no staged drafts)", stop and say so.

2. **For each draft**, read `~/.claude/skill-proposals//SKILL.md` and vet it. **Run the
   `superpowers:writing-skills` checklist** (this skill does NOT reimplement it , delegate):
   - Is the name class-level (not a PR number, error string, codename, or today-only artifact)?
   - Is the `description` a real trigger (what class of task + when), so a future agent matches it?
   - Is it a genuine reusable pattern, or environment-dependent / a complaint that will rot into a
     refusal? Drop the latter.
   - **Secret scan**: confirm no token / key / credential is in the body. `promote` also refuses a
     draft that still contains one, but check first.
   - Would this be better as a PATCH to an existing umbrella, or a `references/` add, than a new
     skill? If so, reject and patch by hand.

3. **Decide per draft** (always show the user the draft and your read before acting):
   - Approve -> `skill-review promote ` (moves it into `~/.claude/skills//`; refuses to
     overwrite a live skill without `--force`).
   - Reject -> `skill-review reject ` (moves it to `_rejected/`, recoverable, never deleted).

4. **Report** what was promoted vs rejected, and any draft you left staged for the user to decide.

## Rules

- Never promote a draft you have not read and vetted against writing-skills.
- Never `--force` overwrite a live skill without explicitly confirming with the user first.
- Promotion is the ONLY path a draft enters `~/.claude/skills/`. The reviewer cannot (it runs with
  no write tool). Keep it that way.
- An optional `auto_promote` config knob (default OFF) can auto-pass the lowest-risk class only
  (a `references/` add to an existing umbrella) via `skill-review auto`; everything else is manual.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [dwarvesf](https://github.com/dwarvesf)
- **Source:** [dwarvesf/dwarves-kit](https://github.com/dwarvesf/dwarves-kit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-dwarvesf-dwarves-kit-skill-review
- Seller: https://agentstack.voostack.com/s/dwarvesf
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
