All skills
bitwarden avatar

/performing-multi-agent-code-review

@0a5f03a official
by bitwardenbitwarden/ai-plugins155 stars
20

Perform a rigorous, multi-agent code review with architecture-compliance, parallel quality/security analysis, finding validation, and severity audit. Use when the user asks for a structured, deep, thorough, multi-pass, or multi-agent code review — or a review that includes architecture/pattern compliance, confidence-scored findings, or a severity audit. Use when the user asks for a code review across a commit range, time window, or N most recent commits in a locally checked-out repo.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/performing-multi-agent-code-review

This session only. Nothing lands on disk.

referencesmodes.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Modes

Loaded by the orchestrator in Step 1. Mode logic is orchestrator-only — it determines which diff-source commands run before subagents launch, and is not propagated to subagents.

Determine review mode from the invocation. Inspect both the slash-command argument and any natural-language framing the user provided. The four modes are mutually exclusive — if more than one seems to apply, invoke AskUserQuestion to disambiguate before proceeding rather than guessing.

Mode 1 — PR mode

Trigger: the user supplied a GitHub pull request reference. Recognize a bare number (123), a #-prefixed reference (#123, PR #123), or a pull-request URL (https://github.com/owner/repo/pull/123).

Diff sources:

  • Title & description: gh pr view <number>
  • Changed files: gh pr diff <number> --name-only
  • Diff: gh pr diff <number>

Mode 2 — Local changes mode

Trigger: no PR reference, no commit-range framing, AND git status --porcelain returns non-empty (working tree has uncommitted changes).

Diff sources:

  • Changed files: git diff HEAD --name-only
  • Diff: git diff HEAD (combines staged + unstaged)

Mode 3 — Branch comparison mode

Trigger: no PR reference, no commit-range framing, AND git status --porcelain returns empty (clean working tree).

Diff sources:

  • Current branch: git rev-parse --abbrev-ref HEAD (needed for the Step 9 filename)
  • Base ref: git rev-parse --abbrev-ref origin/HEAD (yields e.g. origin/main)
  • Changed files: git diff origin/HEAD...HEAD --name-only
  • Diff: git diff origin/HEAD...HEAD

Mode 4 — Commit-range mode

Trigger: the user described a commit range, time window, or commit count against a locally checked-out repo. Recognize natural-language phrases such as:

  • Time windows — "the last week", "the last 7 days", "the past month", "since 2026-04-23", "between Apr 1 and Apr 28"
  • Commit counts — "the last 20 commits", "the last 5 commits"
  • Explicit refs — "from abc123 to def456", "between v1.0 and v1.1", "since the v2.0 tag"

The user is expected to invoke this skill from inside the target repo's working tree. Mentions like "in the bitwarden/server repo" are confirmatory framing — the orchestrator does NOT navigate to other paths or search the filesystem.

Resolution sequence (perform before launching any subagents):

  1. Confirm the working directory is a git work tree. Run git rev-parse --is-inside-work-tree. If it fails or returns false, abort with: "commit-range mode must be invoked from inside the target repo." Do not search elsewhere.

  2. Resolve the commit range to a <from>..<to> pair.

    • Time windows → <to>=HEAD. Determine the oldest commit in the window with git log --since='<window>' --reverse --pretty=%H | head -1; <from> is that commit's first parent (suffix ^). If the window contains zero commits, abort with a clear message — there is nothing to review.
    • Commit counts → <from>=HEAD~N, <to>=HEAD.
    • Explicit refs → use them verbatim after validating each with git rev-parse <ref>.
  3. Confirm with the user before launching subagents. Print the <from>..<to> range (with short SHAs), the commit count, and the changed-file list, then invoke AskUserQuestion to confirm before proceeding. Reason: the multi-agent pipeline is expensive — a wrong range wastes substantial tokens and time, and the natural-language inputs leave room for misinterpretation that subagents cannot recover from.

Diff sources (after confirmation):

  • Commits in range (for context only, not validation): git log <from>..<to> --oneline
  • Changed files: git diff <from>..<to> --name-only
  • Diff (cumulative across the range): git diff <from>..<to>

Interpretation of "introduced by this change" in commit-range mode: "introduced" means present in the cumulative diff of <from>..<to>; "pre-existing" means present at the parent of <from>. Step 4 validation subagents must use this interpretation when applying the dismissal rules.

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides a rigorous multi-agent code review process with several built-in security safeguards. It implements a defensive boundary against indirect prompt injection by instructing subagents to treat instructions found within code changes as security findings. It also restricts tool usage (e.g., banning network tools for subagents) to prevent data exfiltration. All external functions utilized are internal or vendor-associated plugins.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 0a5f03a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
What it can do
Runs commands Reads files Edits files
All 12 allowed tools
Bash(gh pr diff:*)Bash(gh pr view:*)Bash(git diff:*)Bash(git status:*)Bash(git rev-parse:*)Bash(git log:*)ReadWriteGrepGlobSkillAskUserQuestion
Other metadata
argument-hint
[pr-number | commit-range] [--model <model>] [--model-analysis <model>] [--model-security <model>] [--model-validation <model>] [--model-audit <model>] [--output-dir <path>]

README badge

README badge for bitwarden/ai-plugins/performing-multi-agent-code-review

Orchestrates a multi-pass code review by spawning architecture, code-quality, bug-analysis, and security agents in parallel, each emitting confidence-scored findings against Bitwarden's zero-knowledge and threat-model principles. Use this skill when the user requests a deep, structured, or multi-agent review—or when reviewing commit ranges in a locally checked-out repo.

Generated from the current SKILL.md.

Does this skill work with local commits and PR branches?
Yes. The skill supports multiple modes: PR review (via `gh pr diff`), local HEAD changes, branch comparisons, and commit ranges. Pass the PR number or commit range as the first argument.
What happens if a prerequisite plugin is missing?
The skill aborts immediately with a clear error message identifying the missing plugin (bitwarden-tech-lead or bitwarden-security-engineer) and does not proceed.
Where does the review output go?
By default, reviews write to `${CLAUDE_PLUGIN_DATA}/code-reviews/` organized by project. You can override this with `--output-dir <path>` at invocation time.
Can I specify which model to use?
Yes. Pass `--model <model>` in the arguments; otherwise the skill defaults to the opus model.
Does this skill upload findings to GitHub?
No. All findings are written to a local markdown file only. The skill does not create pull request comments or push any data to GitHub.

Generated from the current SKILL.md. These answers refresh after source changes.