All skills
acedergren avatar

/review-all

@9d099e9

Use when preparing a PR or completing a phase of work and needing a full-spectrum code review. Runs security, API audit, and scope reviewers in parallel and synthesizes findings into a single go/no-go report. Read-only β€” no file modifications. Keywords: pre-PR review, security audit, API audit, scope review, code review, merge check. Triggers on "review all changes" or "run pre-PR review".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/review-all

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ102 tokens always: the name and description. β‰ˆ597 when used: this file.

Review All

When to Use

Load this skill when the user request matches the frontmatter description for Review All.

Comprehensive pre-PR review: run specialized reviewers in parallel, synthesize into a single report. Read-only β€” no changes.

NEVER

  • Never let any reviewer edit files during this pipeline β€” read-only is non-negotiable.
  • Never report duplicate findings separately when two reviewers flag the same line β€” merge into one finding.
  • Never review the whole repository when the user only changed a narrow diff β€” scope to changed files.
  • Never use this as a substitute for lint, typecheck, or tests β€” it complements them, runs after them.
  • Never run this for implementation tasks or auto-remediation requests β€” wrong tool.

Pipeline

Step 1: Identify changed files

git diff --name-only main...HEAD
# On main: git diff --name-only HEAD~5
# Or: bash scripts/detect-review-range.sh

Step 2: Launch parallel review agents

Spawn all agents simultaneously via Task tool:

Agent Type Scope Checks
Security Reviewer security-reviewer (custom) Changed files only OWASP Top 10, IDOR, injection, auth gaps
API Route Auditor Explore agent Routes + types dirs Schema coverage, type drift, auth hooks
Scope Auditor Explore agent git diff output Out-of-scope modifications, formatting-only noise

Add project-specific reviewers as needed (DB query reviewer, framework reviewer).

Step 3: Synthesize report

## Pre-PR Review Report

### Summary
| Reviewer  | Findings | Critical | Warnings |
|-----------|----------|----------|----------|
| Security  | 2        | 0        | 2        |
| API Audit | 3        | 1        | 2        |
| Scope     | 1        | 0        | 1        |

### Critical Issues (must fix before merge)
[CRITICAL/HIGH findings with file:line references]

### Warnings (consider fixing)
[MEDIUM/LOW findings]

### Clean Areas
[What passed with no issues]

Step 4: Verdict

End with one clear statement:

  • READY TO MERGE β€” No critical issues, warnings acceptable
  • NEEDS FIXES β€” Critical issues found; list exactly what must change
  • NEEDS DISCUSSION β€” Architectural concerns or ambiguous scope

Arguments

  • (empty): Review changes vs main
  • HEAD~3: Review last 3 commits
  • --security-only: Only security reviewer

Source: SKILL.md on GitHub

1 warning5mo5 checks Β· Risk SAFE
  • Gen Agent Trust Hub6mo

    This skill is a pre-PR review pipeline that coordinates specialized agents to audit code changes identified via Git. It operates in a read-only manner and does not perform any network requests, credential access, or file modifications, making it safe for use in development environments.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW Β· No issues

  • Runlayer6mo

    1/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 Β· 2 sections analyzed

Signed by skilld at 9d099e9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago

README badge

README badge for acedergren/agentic-tools/review-all