All skills
bitwarden avatar

/performing-multi-agent-code-review

@0a5f03a official
by bitwardenbitwarden/ai-plugins155 stars
20

Perform a rigorous, multi-agent code review with architecture-compliance, parallel quality/security analysis, finding validation, and severity audit. Use when the user asks for a structured, deep, thorough, multi-pass, or multi-agent code review — or a review that includes architecture/pattern compliance, confidence-scored findings, or a severity audit. Use when the user asks for a code review across a commit range, time window, or N most recent commits in a locally checked-out repo.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/performing-multi-agent-code-review

This session only. Nothing lands on disk.

examplessample-report.md

≈606 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Code Review: Rename example plugin and refresh manifests (#123)

Date: 2026-06-10 | Reviewed by: Claude Code | Model: opus (audit: sonnet)

Summary

Severity Count
🛑 Blocker 0
⚠️ Important 1
♻️ Refactor 0

The rename is structurally sound — the new manifest, marketplace entry, and AGENT.md are internally consistent and correctly wired together. One issue holds it back: the renamed README retains the old plugin identity throughout its body (title, install command, usage examples), so users following it will reference a plugin name that no longer exists.

Not covered: Skill review did not run — plugin-dev is not installed, so plugins/example/skills/scaffolding-a-plugin/SKILL.md was not checked for description quality, length, or progressive disclosure.

Findings

⚠️ Important

Renamed README retains old plugin identity throughout body

plugins/example/README.md:11 Caught by: Architecture agent

<details><summary>Details</summary>

The diff only edits the Overview sentence. Every other line retains the old plugin identity: the H1 title (line 1), the agent table row (line 11), and the install command (line 30) still reference the deleted plugin name. These contradict the renamed plugin.json and the new AGENT.md. Update the title, table row, and install command to the new name in this PR, or add the README to the documented deferral list.

</details>

Reviewed and Dismissed

<details><summary>🔍 2 initial findings dismissed after validation</summary>
README overview still describes old plugin identity

plugins/example/README.md:5 Caught by: Code quality agent Original severity: ♻️ Refactor Original confidence: 90/100 Dismissed at: Step 4 validation Dismissed because: Substantively covered by the architecture finding at higher severity; no distinct actionable scope beyond what that finding already requires.

quality findings cite wrong file line for plugin.json description field

plugins/example/.claude-plugin/plugin.json:4 Caught by: Validation agent (collateral) Original severity: ♻️ Refactor Original confidence: 100/100 Dismissed at: Step 5 severity audit Dismissed because: A meta-observation about sibling findings is not a code issue in the change under review.

</details>

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides a rigorous multi-agent code review process with several built-in security safeguards. It implements a defensive boundary against indirect prompt injection by instructing subagents to treat instructions found within code changes as security findings. It also restricts tool usage (e.g., banning network tools for subagents) to prevent data exfiltration. All external functions utilized are internal or vendor-associated plugins.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 0a5f03a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
What it can do
Runs commands Reads files Edits files
All 12 allowed tools
Bash(gh pr diff:*)Bash(gh pr view:*)Bash(git diff:*)Bash(git status:*)Bash(git rev-parse:*)Bash(git log:*)ReadWriteGrepGlobSkillAskUserQuestion
Other metadata
argument-hint
[pr-number | commit-range] [--model <model>] [--model-analysis <model>] [--model-security <model>] [--model-validation <model>] [--model-audit <model>] [--output-dir <path>]

README badge

README badge for bitwarden/ai-plugins/performing-multi-agent-code-review

Orchestrates a multi-pass code review by spawning architecture, code-quality, bug-analysis, and security agents in parallel, each emitting confidence-scored findings against Bitwarden's zero-knowledge and threat-model principles. Use this skill when the user requests a deep, structured, or multi-agent review—or when reviewing commit ranges in a locally checked-out repo.

Generated from the current SKILL.md.

Does this skill work with local commits and PR branches?
Yes. The skill supports multiple modes: PR review (via `gh pr diff`), local HEAD changes, branch comparisons, and commit ranges. Pass the PR number or commit range as the first argument.
What happens if a prerequisite plugin is missing?
The skill aborts immediately with a clear error message identifying the missing plugin (bitwarden-tech-lead or bitwarden-security-engineer) and does not proceed.
Where does the review output go?
By default, reviews write to `${CLAUDE_PLUGIN_DATA}/code-reviews/` organized by project. You can override this with `--output-dir <path>` at invocation time.
Can I specify which model to use?
Yes. Pass `--model <model>` in the arguments; otherwise the skill defaults to the opus model.
Does this skill upload findings to GitHub?
No. All findings are written to a local markdown file only. The skill does not create pull request comments or push any data to GitHub.

Generated from the current SKILL.md. These answers refresh after source changes.