# Yocto Recipe Review

> Review and improve Yocto/OpenEmbedded recipes, bbappends, bbclasses, package splits, dependencies, licensing, source fetching, patch handling, install logic, systemd/init integration, PACKAGECONFIG, and modern BitBake override syntax. Use for .bb, .bbappend, .bbclass, recipe diffs, recipe modernization, packaging errors, or metadata code review.

- **Type:** Skill
- **Install:** `agentstack add skill-higangssh-yocto-agent-skills-yocto-recipe-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Higangssh](https://agentstack.voostack.com/s/higangssh)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Higangssh](https://github.com/Higangssh)
- **Source:** https://github.com/Higangssh/yocto-agent-skills/tree/main/skills/yocto-recipe-review

## Install

```sh
agentstack add skill-higangssh-yocto-agent-skills-yocto-recipe-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Yocto Recipe Review

Use this skill for `.bb`, `.bbappend`, and `.bbclass` review. Optimize for release-aware, reproducible, package-correct metadata.

## Review Checklist

Inspect:

```bitbake
SUMMARY
DESCRIPTION
HOMEPAGE
LICENSE
LIC_FILES_CHKSUM
SRC_URI
SRCREV
S
inherit
DEPENDS
PACKAGECONFIG
do_configure
do_compile
do_install
FILES:${PN}
RDEPENDS:${PN}
SYSTEMD_SERVICE:${PN}
```

## Findings to Prioritize

- old override syntax in a modern layer without a release reason
- missing or vague `LICENSE` and `LIC_FILES_CHKSUM`
- `${AUTOREV}` in production metadata
- missing `DEPENDS` for headers, libraries, generated code tools, or `-native` tools
- runtime dependency added to `DEPENDS` instead of `RDEPENDS:`
- installed files not covered by `FILES:*`
- installing outside `${D}`
- host path or host tool contamination
- unnecessary `INSANE_SKIP`
- patch entries with missing upstream status or fuzz
- bbappend that is too version-specific or too broad for the intended target

## Modern Syntax

Prefer:

```bitbake
FILES:${PN} += "${bindir}/tool"
RDEPENDS:${PN} += "bash"
PACKAGECONFIG:append = " feature"
do_install:append() {
    install -d ${D}${bindir}
}
```

Avoid `_append`, `_prepend`, `_remove`, and old package override syntax unless the target release requires it.

## References

- Read [../../references/bitbake/variables-core.md](../../references/bitbake/variables-core.md) for variable semantics.
- Read [../../references/bitbake/classes-core.md](../../references/bitbake/classes-core.md) for class-specific review.
- Read [../../references/yocto/qa-errors.md](../../references/yocto/qa-errors.md) for package QA risks.
- Use [../../references/shared/official-doc-map.md](../../references/shared/official-doc-map.md) to route official docs.

## Output

Lead with code-review findings:

```text
Findings:
- [severity] file:line issue and Yocto impact

Suggested metadata:
...

Validation:
- bitbake -e 
- bitbake -c patch 
- bitbake 
- bitbake 
```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Higangssh](https://github.com/Higangssh)
- **Source:** [Higangssh/yocto-agent-skills](https://github.com/Higangssh/yocto-agent-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-higangssh-yocto-agent-skills-yocto-recipe-review
- Seller: https://agentstack.voostack.com/s/higangssh
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
