All skills
bitwarden avatar

/performing-multi-agent-code-review

@0a5f03a official
by bitwardenbitwarden/ai-plugins155 stars
20

Perform a rigorous, multi-agent code review with architecture-compliance, parallel quality/security analysis, finding validation, and severity audit. Use when the user asks for a structured, deep, thorough, multi-pass, or multi-agent code review — or a review that includes architecture/pattern compliance, confidence-scored findings, or a severity audit. Use when the user asks for a code review across a commit range, time window, or N most recent commits in a locally checked-out repo.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/performing-multi-agent-code-review

This session only. Nothing lands on disk.

referencesdiscovery-standards.md

≈394 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Discovery Standards

Loaded by the orchestrator in Step 1. The Hygiene Sweep is invoked by name from the Step 2 architect and Step 3 Agent 1 (code quality) prompts. The Line Number Accuracy rule is propagated verbatim into every Step 2–5 subagent prompt.

Hygiene Sweep

Agent 1 (code quality) performs a hygiene sweep of the diff before submitting findings; the Step 2 architect applies the same sweep within its scope. When referenced, look specifically for:

  • Dead code added by this PR — allowlist/registry/lookup-table entries added for features that don't flow through the validated entry point; unused imports; unreachable branches.
  • Stale references — documentation, comments, error messages, or assertions in this diff that contradict the same diff's implementation.
  • Cross-site inconsistency — a new call site that differs from established sibling sites in a way not explained by the change (e.g., four platform dialogs where three carry a title and the fourth silently drops it).

This is not an exhaustive checklist — surface anything diff-visible that a senior engineer would flag in a real review.

Line Number Accuracy

Cite actual file line numbers, not positions within the diff. Derive them from the hunk header:

  • Parse @@ -A,B +C,D @@ — +C is the starting file line for the hunk. New files use @@ -0,0 +1,N @@, so C=1.
  • From +C, count + lines and context lines (no prefix) up to your target. Skip - lines, @@ lines, and ---/+++ lines.

Never guess. Always derive from the hunk header.

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides a rigorous multi-agent code review process with several built-in security safeguards. It implements a defensive boundary against indirect prompt injection by instructing subagents to treat instructions found within code changes as security findings. It also restricts tool usage (e.g., banning network tools for subagents) to prevent data exfiltration. All external functions utilized are internal or vendor-associated plugins.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 0a5f03a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
What it can do
Runs commands Reads files Edits files
All 12 allowed tools
Bash(gh pr diff:*)Bash(gh pr view:*)Bash(git diff:*)Bash(git status:*)Bash(git rev-parse:*)Bash(git log:*)ReadWriteGrepGlobSkillAskUserQuestion
Other metadata
argument-hint
[pr-number | commit-range] [--model <model>] [--model-analysis <model>] [--model-security <model>] [--model-validation <model>] [--model-audit <model>] [--output-dir <path>]

README badge

README badge for bitwarden/ai-plugins/performing-multi-agent-code-review

Orchestrates a multi-pass code review by spawning architecture, code-quality, bug-analysis, and security agents in parallel, each emitting confidence-scored findings against Bitwarden's zero-knowledge and threat-model principles. Use this skill when the user requests a deep, structured, or multi-agent review—or when reviewing commit ranges in a locally checked-out repo.

Generated from the current SKILL.md.

Does this skill work with local commits and PR branches?
Yes. The skill supports multiple modes: PR review (via `gh pr diff`), local HEAD changes, branch comparisons, and commit ranges. Pass the PR number or commit range as the first argument.
What happens if a prerequisite plugin is missing?
The skill aborts immediately with a clear error message identifying the missing plugin (bitwarden-tech-lead or bitwarden-security-engineer) and does not proceed.
Where does the review output go?
By default, reviews write to `${CLAUDE_PLUGIN_DATA}/code-reviews/` organized by project. You can override this with `--output-dir <path>` at invocation time.
Can I specify which model to use?
Yes. Pass `--model <model>` in the arguments; otherwise the skill defaults to the opus model.
Does this skill upload findings to GitHub?
No. All findings are written to a local markdown file only. The skill does not create pull request comments or push any data to GitHub.

Generated from the current SKILL.md. These answers refresh after source changes.