Install
$ agentstack add skill-smartwhale8-claude-playbook-review ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Review all uncommitted changes in this project. $ARGUMENTS
Process
- Gather changes: Run
git diff --stagedfor staged changes, orgit diffif nothing is staged. Also checkgit statusfor new untracked files.
- Check each changed file against the project rules (
.claude/rules/*.md):
### Code Quality
- Is there dead code, unused imports, or commented-out code?
- Are there bandaid fixes or workarounds instead of root-cause solutions?
- Is anything over-engineered for what it needs to do?
### Architecture
- Does this follow existing patterns in the codebase?
- Is there duplicate logic that should use an existing shared component or utility?
- Are dependencies pointing in the right direction (inward, not outward)?
### Consistency
- Does the code match the style and structure of similar files in the project?
- For frontend: are spacing, colors, and component usage consistent with the rest of the UI?
- For backend: are error handling, response format, and validation patterns consistent?
### Reuse
- Could any new component, function, or pattern already exist in the codebase? Search before approving.
- If something similar exists, flag it — it should be reused or extracted into a shared utility.
### Security
- Any hardcoded secrets, credentials, or API keys?
- Is user input validated at the boundary?
- Are there SQL injection, XSS, or other OWASP risks?
### Performance
- Any N+1 query patterns (database calls inside loops)?
- Any unbounded queries missing LIMIT/pagination?
- Frontend: unnecessary re-renders, missing debounce on inputs?
- Verdict: Provide one of:
- Ready to commit — no issues found
- Minor issues — list them, but committing is acceptable after acknowledging
- Needs changes — list specific issues that must be fixed before committing
For each issue, provide: the file, the line(s), what's wrong, and what the fix should be.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: smartwhale8
- Source: smartwhale8/claude-playbook
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.