All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

specialistsapi-contract.md

≈590 tokens on demand. Your agent reads this file only when SKILL.md points to it.

API Contract Specialist Review Checklist

Scope: When SCOPE_API=true Output: JSON objects, one finding per line. Schema: {"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"api-contract","summary":"...","fix":"...","fingerprint":"path:line:api-contract","specialist":"api-contract"} Optional: line, fix, fingerprint, evidence, test_stub. If no findings: output NO FINDINGS and nothing else.


Categories

Breaking Changes

  • Removed fields from response bodies (clients may depend on them)
  • Changed field types (string → number, object → array)
  • New required parameters added to existing endpoints
  • Changed HTTP methods (GET → POST) or status codes (200 → 201)
  • Renamed endpoints without maintaining the old path as a redirect/alias
  • Changed authentication requirements (public → authenticated)

Versioning Strategy

  • Breaking changes made without a version bump (v1 → v2)
  • Multiple versioning strategies mixed in the same API (URL vs header vs query param)
  • Deprecated endpoints without a sunset timeline or migration guide
  • Version-specific logic scattered across controllers instead of centralized

Error Response Consistency

  • New endpoints returning different error formats than existing ones
  • Error responses missing standard fields (error code, message, details)
  • HTTP status codes that don't match the error type (200 for errors, 500 for validation)
  • Error messages that leak internal implementation details (stack traces, SQL)

Rate Limiting & Pagination

  • New endpoints missing rate limiting when similar endpoints have it
  • Pagination changes (offset → cursor) without backwards compatibility
  • Changed page sizes or default limits without documentation
  • Missing total count or next-page indicators in paginated responses

Documentation Drift

  • OpenAPI/Swagger spec not updated to match new endpoints or changed params
  • README or API docs describing old behavior after changes
  • Example requests/responses that no longer work
  • Missing documentation for new endpoints or changed parameters

Backwards Compatibility

  • Clients on older versions: will they break?
  • Mobile apps that can't force-update: does the API still work for them?
  • Webhook payloads changed without notifying subscribers
  • SDK or client library changes needed to use new features

Source: SKILL.md on GitHub

2 warningstoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    A comprehensive code review skill for the gstack ecosystem that automates PR analysis, security auditing, and design reviews using specialist subagents and local helper tools.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.