All skills
bitwarden avatar

/performing-multi-agent-code-review

@0a5f03a official
by bitwardenbitwarden/ai-plugins155 stars
20

Perform a rigorous, multi-agent code review with architecture-compliance, parallel quality/security analysis, finding validation, and severity audit. Use when the user asks for a structured, deep, thorough, multi-pass, or multi-agent code review — or a review that includes architecture/pattern compliance, confidence-scored findings, or a severity audit. Use when the user asks for a code review across a commit range, time window, or N most recent commits in a locally checked-out repo.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/performing-multi-agent-code-review

This session only. Nothing lands on disk.

referencesreport-template.md

≈775 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Report Template

Model Header

{model} is the resolved global model's nickname, never a dated model ID. When any stage's resolved model differs from the global model — including the audit's sonnet default — list each differing stage in parentheses:

**Model:** opus                              <!-- all stages at global -->
**Model:** opus (audit: sonnet)   <!-- differing stages listed -->

Severity Icons

  • 🛑 Blocker — Must fix before merge
  • ⚠️ Important — Potential issue, should fix
  • ♻️ Refactor — Code restructuring needed

Source-Agent Friendly Names

Every finding carries a source_agent value (per finding-shape.md). Render it on each finding using the friendly label below — it tells the reader which subagent caught the issue, which aids triage and per-agent calibration.

source_agent Rendered label
architect Architecture agent
quality Code quality agent
bug Bug analysis agent
security Security & logic agent
config Claude configuration agent
skill Skill review agent
validation Validation agent (collateral)

Template

# Code Review: {PR title} (#{number}) <!-- or "Code Review: Local Changes — {YYYY-MM-DD}" -->

**Date:** {YYYY-MM-DD} | **Reviewed by:** Claude Code | **Model:** {model}

## Summary

| Severity     | Count |
| ------------ | ----- |
| 🛑 Blocker   | {n}   |
| ⚠️ Important | {n}   |
| ♻️ Refactor  | {n}   |

{1-5 sentences for overall assessment.}

<!-- Only when a changed SKILL.md went unreviewed; name just the files not covered. A review that translated to zero findings is a pass, not a gap. Omit entirely otherwise. -->

**Not covered:** {What the review did not look at, and why, naming each file. E.g. "Skill review did not run — `plugin-dev` is not installed, so `plugins/example/skills/doing-a-thing/SKILL.md` and `plugins/example/skills/doing-another/SKILL.md` were not checked for description quality, length, or progressive disclosure."}

## Findings

### 🛑 Blockers

#### {One-line summary (<100 chars)}

`{file/path.ext}:{line}`
**Caught by:** {Friendly agent label}

  <details><summary>Details</summary>
  {Explanation, why it matters, suggested fix. Include code snippets where helpful.}
  </details>

### ⚠️ Important

### ♻️ Refactor

<!-- Only if there are rejected findings. Omit entirely if all confirmed. -->

## Reviewed and Dismissed

   <details><summary>🔍 {n} initial findings dismissed after validation</summary>

   <!-- Repeat the stanza below once per dismissed finding. -->

#### {One-line summary}

`{file/path.ext}:{line}`
**Caught by:** {Friendly agent label}
**Original severity:** {🛑|⚠️|♻️} {Blocker|Important|Refactor}
**Original confidence:** {n}/100
**Dismissed at:** {Step 4 validation | Step 5 severity audit}
**Dismissed because:** {One-sentence rejection reason}

   </details>

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides a rigorous multi-agent code review process with several built-in security safeguards. It implements a defensive boundary against indirect prompt injection by instructing subagents to treat instructions found within code changes as security findings. It also restricts tool usage (e.g., banning network tools for subagents) to prevent data exfiltration. All external functions utilized are internal or vendor-associated plugins.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 0a5f03a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
What it can do
Runs commands Reads files Edits files
All 12 allowed tools
Bash(gh pr diff:*)Bash(gh pr view:*)Bash(git diff:*)Bash(git status:*)Bash(git rev-parse:*)Bash(git log:*)ReadWriteGrepGlobSkillAskUserQuestion
Other metadata
argument-hint
[pr-number | commit-range] [--model <model>] [--model-analysis <model>] [--model-security <model>] [--model-validation <model>] [--model-audit <model>] [--output-dir <path>]

README badge

README badge for bitwarden/ai-plugins/performing-multi-agent-code-review

Orchestrates a multi-pass code review by spawning architecture, code-quality, bug-analysis, and security agents in parallel, each emitting confidence-scored findings against Bitwarden's zero-knowledge and threat-model principles. Use this skill when the user requests a deep, structured, or multi-agent review—or when reviewing commit ranges in a locally checked-out repo.

Generated from the current SKILL.md.

Does this skill work with local commits and PR branches?
Yes. The skill supports multiple modes: PR review (via `gh pr diff`), local HEAD changes, branch comparisons, and commit ranges. Pass the PR number or commit range as the first argument.
What happens if a prerequisite plugin is missing?
The skill aborts immediately with a clear error message identifying the missing plugin (bitwarden-tech-lead or bitwarden-security-engineer) and does not proceed.
Where does the review output go?
By default, reviews write to `${CLAUDE_PLUGIN_DATA}/code-reviews/` organized by project. You can override this with `--output-dir <path>` at invocation time.
Can I specify which model to use?
Yes. Pass `--model <model>` in the arguments; otherwise the skill defaults to the opus model.
Does this skill upload findings to GitHub?
No. All findings are written to a local markdown file only. The skill does not create pull request comments or push any data to GitHub.

Generated from the current SKILL.md. These answers refresh after source changes.