Install
$ agentstack add skill-sakhilchawla-skillkit-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Code Review
Review the current branch's changes against the base branch (default: main).
Phase 1: Gather Context
- Determine the base branch: use $ARGUMENTS if provided, otherwise detect main/master
- Run
git diff ...HEAD --statto see changed files - Run
git diff ...HEADto see the full diff - Read any modified files in full for surrounding context
Phase 2: Critical Review (MUST complete first)
Check for issues that would block merging. For each finding, cite the file and line.
Security: SQL injection, XSS, command injection, hardcoded secrets, unsafe deserialization Correctness: Logic errors, null access, race conditions, missing error handling Data Loss: Destructive operations without confirmation, missing transactions Breaking Changes: Public API changes, removed exports, changed behavior
Phase 3: Suggestions Review
Performance: N+1 queries, unnecessary re-renders, missing memoization Maintainability: Dead code, duplicated logic, complex functions, missing types Testing: Untested critical paths, brittle assertions, missing edge cases
Output Format
## Critical Issues (must fix before merge)
- [CRITICAL] : —
## Warnings (should fix)
- [WARNING] : —
## Suggestions (consider)
- [SUGGESTION] : —
## Summary
Rules
- Never approve code with Critical issues
- Be specific: cite file, line, and the problematic code
- Suggest fixes, not just problems
- If the diff is clean, say so — do not invent issues
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sakhilchawla
- Source: sakhilchawla/skillkit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.