Audit GitHub Actions that run AI agents for prompt injection, unsafe interpolation, sandbox gaps, and permissive actor rules. Use for agentic CI workflows, not general application code review.
日本語の概要は準備中です。原文の説明を表示しています。
Agents should invoke this skill for code reviews, linting/formatting setup, maintainability checks, complexity concerns, warning cleanup, coding standards, or quality gates in Rust, TypeScript, Python, shell, and mixed repos.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Structured code review and quality enforcement across common tech stacks. Checklists, linting strategies, and metrics to keep codebases healthy.
Standard clippy configuration (in Cargo.toml or .clippy.toml):
[lints.clippy]
cognitive_complexity = "warn"
pedantic = { level = "deny", priority = -1 }
nursery = { level = "deny", priority = -1 }
unwrap_used = "deny"
Standard commands:
cargo fmt
cargo clippy --all-targets --all-features -- -D warnings
cargo check
cargo test -- --test-threads=1
Key rules to enforce:
.unwrap() in non-test code (use ? or .expect("reason"))#[warn(missing_docs)])#[must_use] on functions that return values that should be checked#[allow(...)], always add a comment explaining why#[allow(...)], fix the issue insteadRecommended tsconfig.json strictness:
{
"compilerOptions": {
"strict": true,
"noUncheckedIndexedAccess": true,
"noImplicitReturns": true,
"noFallthroughCasesInSwitch": true,
"exactOptionalPropertyTypes": true
}
}
Key rules to enforce:
any — use unknown and type guards instead// @ts-ignore — fix the type issue or use // @ts-expect-error with explanationconst over let, never use varRecommended pyproject.toml:
[tool.ruff]
target-version = "py312"
line-length = 88
[tool.ruff.lint]
select = ["E", "F", "W", "I", "N", "UP", "ANN", "B", "A", "C4", "DTZ", "ISC", "PIE", "PT", "RET", "SIM", "TCH", "ARG", "PTH", "ERA"]
[tool.mypy]
strict = true
warn_return_any = true
warn_unreachable = true
Key rules to enforce:
pathlib.Path over os.pathuv as package managerexcept: — always catch specific exceptionsCorrectness:
Clarity:
Architecture:
Testing:
Security (flag for a security follow-up if concerns found):
cargo fmt appliedcargo clippy clean (pedantic + nursery).unwrap() outside tests? with proper error types#[allow(...)] includes explanatory commentany typesselect_related/prefetch_related)Measures the number of independent paths through code. Recommended threshold: < 25.
| Complexity | Risk Level | Action |
|---|---|---|
| 1-10 | Low | Simple, well-structured code |
| 11-20 | Moderate | Consider simplification if growing |
| 21-24 | High | Refactoring recommended |
| 25+ | Violation | Must refactor before merge |
How to reduce:
Measures how many variables interact within a function. Recommended threshold: < 25.
How to reduce:
| Language | Tool | Command |
|---|---|---|
| Rust | cargo clippy (cognitive_complexity) | Built into clippy config |
| TypeScript | eslint-plugin-sonarjs | Configure complexity rule |
| Python | radon | radon cc <file> -s -a |
| Python | ruff | Rule C901 (mccabe complexity) |
When delivering a code review:
## Code Review: [PR/File/Module]
**Date:** YYYY-MM-DD
### Summary
[1-2 sentences: overall quality assessment]
### Findings
| # | Severity | File | Line(s) | Finding | Suggestion |
|---|---|---|---|---|---|
| 1 | High | src/app.rs | 45-67 | Cyclomatic complexity 28 (limit: 25) | Extract match arms into helper functions |
| 2 | Medium | src/ui.rs | 120 | Unwrap without context | Use `.expect("reason")` or `?` |
### Positive Observations
[What's well-written — acknowledge good code]
### Metrics
- Linter: [clean / N warnings]
- Tests: [pass / fail]
- Complexity: [within limits / violations noted above]
### Security Notes
[Items to flag for follow-up, if any]
AGENTS.md/CLAUDE.md execution policies.code-reviewer skill for adversarial review of a focused change set, and design-patterns for fixing complexity violations through better structure.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Audit GitHub Actions that run AI agents for prompt injection, unsafe interpolation, sandbox gaps, and permissive actor rules. Use for agentic CI workflows, not general application code review.
日本語の概要は準備中です。原文の説明を表示しています。
Audit and improve project-rules files (AGENTS.md, CLAUDE.md, .agents/instructions, local overrides) so the agent keeps accurate project context. Use when the user asks to check, audit, review, update, improve, or fix their AGENTS.md or CLAUDE.md, mentions "project rules maintenance" or "agent context optimization", or when the codebase has changed enough that the rules file may be stale. Scans the repository for every rules file, grades each against a quality rubric, outputs a quality report, and applies targeted edits only after user approval.
日本語の概要は準備中です。原文の説明を表示しています。
Capture learnings from the current session into the project-rules file (AGENTS.md, CLAUDE.md, or local override) so future sessions benefit. Use when the user says "revise the rules", "update AGENTS.md / CLAUDE.md with what we just learned", "save this to project memory", "remember this for next time", or at the end of a productive session when valuable context has emerged that is not yet documented. This complements agents-md-improver — improver audits, while this one captures.
日本語の概要は準備中です。原文の説明を表示しています。
Operational rubric that turns "don't make AI slop" into observable properties, severity levels, evidence requirements, and repair actions for interface design. Use as the reference rubric when building or reviewing marketing sites, product interfaces, dashboards, portfolios, or e-commerce pages, especially alongside frontend-design.
日本語の概要は準備中です。原文の説明を表示しています。
Design a feature architecture by analyzing existing codebase patterns and conventions, then provide a comprehensive implementation blueprint with specific files to create or modify, component designs, data flows, and a build sequence. Use this skill when the user asks for an architecture design, an implementation plan for a non-trivial feature, or when dispatched as a sub-task during feature-dev architecture phase.
日本語の概要は準備中です。原文の説明を表示しています。
Deeply analyze an existing codebase feature by tracing execution paths, mapping architecture layers, understanding patterns and abstractions, and documenting dependencies. Use this skill when you need to understand how a feature works before modifying or extending it, when dispatched as a sub-task during feature-dev exploration, or when the user asks "how does X work in this codebase".
日本語の概要は準備中です。原文の説明を表示しています。