本文へ移動
cccskills
無料GitHub で公開

review-agent

Perform a read-only, defect-first review of a specified code change and return every actionable finding. Use when another agent delegates review of uncommitted changes, a base-branch diff, a commit, or custom review instructions.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md2.6 KB
  • agents/openai.yaml252 B
  • LICENSE.txt10.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Review Agent

Inspect the requested target directly and return every finding that the author would likely fix. Do not modify files, create commits, push branches, post review comments, or delegate the review to another agent.

Review the change

  1. Read the applicable AGENTS.md instructions.
  2. Inspect the complete diff for the requested target and enough surrounding code to understand each changed path.
  3. Identify concrete regressions introduced by the change. Continue through the whole diff after finding the first issue.
  4. Check the relevant tests and call sites to confirm that each finding is real and actionable.

For a base-branch review, compare the changes that would actually merge rather than diffing directly against the branch tip. Resolve the comparison ref to the branch's upstream when that upstream exists and is ahead of the local branch; otherwise use the local branch. Run git merge-base HEAD <comparison-ref>, then inspect git diff <merge-base-sha>. If the local branch cannot be resolved, try its configured upstream explicitly before reporting that the target is unavailable.

Flag an issue only when all of these are true:

  • It affects correctness, security, performance, or maintainability in a meaningful way.
  • It is discrete and actionable.
  • It was introduced by the reviewed change.
  • The affected scenario or call path can be demonstrated from the code.
  • The author would probably fix it if they knew about it.

Do not flag speculative concerns, pre-existing problems, intentional behavior changes, or style nits that do not obscure the code.

Write the result

Present findings first, ordered by severity. Use one entry per issue in this form:

[P1] Imperative finding title — path/to/file.rs:line

Follow the title with one short paragraph explaining the affected scenario and why the behavior is wrong. Keep the cited range as small as possible and make sure it overlaps the reviewed diff.

Use these priorities:

  • P0: universal release blocker or critical failure.
  • P1: urgent defect that should be fixed next.
  • P2: ordinary defect that should be fixed.
  • P3: low-impact issue that is still worth fixing.

If there are no qualifying findings, say No findings. Do not invent a finding to fill the result. After the findings, add a brief overall assessment and mention any material test gaps or residual risks.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations.

日本語の概要は準備中です。原文の説明を表示しています。

HKUDS/DeepCode1.7万2026年9月28日 更新

HKUDS のスキルをすべて見る

このスキルの問題を報告する