# Code Review

> >-

- **Type:** Skill
- **Install:** `agentstack add skill-maxedapps-agent-skills-code-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [maxedapps](https://agentstack.voostack.com/s/maxedapps)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [maxedapps](https://github.com/maxedapps)
- **Source:** https://github.com/maxedapps/agent-skills/tree/main/skills/code-review

## Install

```sh
agentstack add skill-maxedapps-agent-skills-code-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Code Review

## Hard rules

- Scope from user/task only. Unclear → **ask**. Don’t widen.
- Inspect thoroughly; report selectively. Candidate ≠ finding.
- **“No material findings” is valid.**
- No source edits unless asked. Don’t clobber owner git/worktree state.
- Main agent assigns final findings/scores/verdicts. Child handoffs = evidence.
- **Delegate by default** into bounded read-only lanes when safe. “Small/easy” ≠ skip.
- Leverage subagents — built-in, extensions/plugins, or skills. Follow `use-subagents` policy; use the host’s selected launcher (on Pi without native `subagent_*`, `use-pi-subagents`).

### Admit a finding only if

- concrete failure
- realistic reachability
- practical impact
- safeguards considered
- action justified now

Omit nits, hypotheticals, and low-impact noise. Don’t hide them in caveats.

## Loads

| When | Read |
|---|---|
| Broad or deep dimension review | [`references/review-dimensions.md`](references/review-dimensions.md) first |
| Vs plan/tracker/design/acceptance | [`references/plan-backed-review.md`](references/plan-backed-review.md) first |
| Standalone report | [`assets/review-report-template.md`](assets/review-report-template.md) before write |

## Flow

1. Fix scope/authority/output — ask if needed.
2. Load conditional resources.
3. Inspect targets, callers, tests, config, diffs. Note skips + confidence limits.
4. **Delegate** review lanes by default (correctness, security, tests, plan-matrix, …).
5. Run checks/repros that raise confidence; preserve owner state.
6. Admit → score → cap findings.
7. Optional `decomplex` only if complexity-focused and report writable; else built-in simplicity. Don’t merge contracts.
8. Write `.reviews/.md` (unless chat-only/no-write) or return handoff.
9. Cleanup any workflow runtime/process state.

## Scores and caps

| | |
|---|---|
| Severity | `S4` critical · `S3` high · `S2` medium · `S1` low · `S0` optional |
| Confidence | `C3` confirmed · `C2` supported · `C1` tentative (not a finding yet) |

Per finding: scores · location · evidence · impact · smallest safe fix/validation.

**Caps:** all `S4`; ≤5 other material `S3`/`S2`; no `S1`/`S0` by default. Overflow → one `not review-ready` caveat. Deduplicate root causes.

## Plan-backed

When authority exists: full matrix + four verdicts (baseline · compliance · quality beyond baseline · tests/validation) per plan-backed ref.

## Embedded follow-up

States: `Clear` · `Changes required` · `Human decision required` · `Blocked`

- Preserve finding IDs.
- Only accepted fixes, disputed dispositions, affected boundaries, fix-caused/exposed issues.
- Need a material delta between rounds.

## Fixes (only if explicitly requested)

Read callers → smallest fix → update tests → validate → summarize.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [maxedapps](https://github.com/maxedapps)
- **Source:** [maxedapps/agent-skills](https://github.com/maxedapps/agent-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-maxedapps-agent-skills-code-review
- Seller: https://agentstack.voostack.com/s/maxedapps
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
