# Review Code

> >

- **Type:** Skill
- **Install:** `agentstack add skill-gtrabanco-agentic-workflow-review-code`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [gtrabanco](https://agentstack.voostack.com/s/gtrabanco)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [gtrabanco](https://github.com/gtrabanco)
- **Source:** https://github.com/gtrabanco/agentic-workflow/tree/main/skills/review-code

## Install

```sh
agentstack add skill-gtrabanco-agentic-workflow-review-code
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Review Code (internal)

Composed by `review-change` / `product-audit` within their conversation — on any
agent, follow this file inline as the routed step. **Findings only; never edits,
never refactors.**

## Scope

The diff or path/glob the caller passes; default the current change vs the
default branch. State the scope at the top of the returned table.

## Checklist (evaluate EVERY item — none is optional; n/a must be stated)

✓ No logic errors on the changed paths (trace each modified function's inputs →
  outputs, including boundary values)
✓ Every error path is handled — no swallowed exceptions, no empty catch, no
  silently-ignored return codes
✓ No duplicated logic (a changed block does not re-implement an existing
  helper — cite the existing one if it does)
✓ No dead code introduced (unused functions, params, imports, unreachable
  branches)
✓ No leftover TODO/FIXME/HACK markers in the diff
✓ Naming and file conventions match the project's docs (read them first; cite
  the convention violated)
✓ No new abstraction beyond what the SPEC requires (an interface/base class
  with one implementation is a finding)
✓ No new dependency not justified in the SPEC
✓ Simplification: any changed block that can lose lines without losing
  behavior (cite before/after)
✓ Edge cases the SPEC's dev scenarios name are actually handled in code, not
  just in tests

## Return exactly

```
REVIEW CODE — scope: 

| # | Finding | Sev | Evidence | Suggested fix |
|---|---------|-----|----------|---------------|
| 1 |   | critical|major|minor |  |  |

Checklist:  evaluated,  pass,  findings,  n/a ()
Summary: 
Decision: PASS | FAIL
```

FAIL if any critical or major finding is open; PASS otherwise. Minor findings
never block — they route to the caller's triage step.

## Done when

- Every checklist item was evaluated with evidence (file:line or command output)
  or explicitly marked n/a with the reason.
- The fixed-format block above is returned — nothing more, nothing less — and
  no code was changed.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [gtrabanco](https://github.com/gtrabanco)
- **Source:** [gtrabanco/agentic-workflow](https://github.com/gtrabanco/agentic-workflow)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-gtrabanco-agentic-workflow-review-code
- Seller: https://agentstack.voostack.com/s/gtrabanco
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
