All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

specialistsmaintainability.md

≈625 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Maintainability Specialist Review Checklist

Scope: Always-on (every review) Output: JSON objects, one finding per line. Schema: {"severity":"INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"maintainability","summary":"...","fix":"...","fingerprint":"path:line:maintainability","specialist":"maintainability"} Optional: line, fix, fingerprint, evidence, test_stub. If no findings: output NO FINDINGS and nothing else.


Categories

Dead Code & Unused Imports

  • Variables assigned but never read in the changed files
  • Functions/methods defined but never called (check with Grep across the repo)
  • Imports/requires that are no longer referenced after the change
  • Commented-out code blocks (either remove or explain why they exist)

Magic Numbers & String Coupling

  • Bare numeric literals used in logic (thresholds, limits, retry counts) — should be named constants
  • Error message strings used as query filters or conditionals elsewhere
  • Hardcoded URLs, ports, or hostnames that should be config
  • Duplicated literal values across multiple files

Stale Comments & Docstrings

  • Comments that describe old behavior after the code was changed in this diff
  • TODO/FIXME comments that reference completed work
  • Docstrings with parameter lists that don't match the current function signature
  • ASCII diagrams in comments that no longer match the code flow

Duplicated Behavior with Defects

  • Divergent copies that produce a demonstrated incorrect result, miss required error handling, or violate the same contract
  • Report the concrete defect and its evidence through normal Fix-First handling; matching syntax or repeated line counts alone are not findings
  • Optional shared-helper extractions belong to the core shared-code check. Do not duplicate its proposals or turn structural preferences into defects

Conditional Side Effects

  • Code paths that branch on a condition but forget a side effect on one branch
  • Log messages that claim an action happened but the action was conditionally skipped
  • State transitions where one branch updates related records but the other doesn't
  • Event emissions that only fire on the happy path, missing error/edge paths

Module Boundary Violations

  • Reaching into another module's internal implementation (accessing private-by-convention methods)
  • Direct database queries in controllers/views that should go through a service/model
  • Tight coupling between components that should communicate through interfaces

Source: SKILL.md on GitHub

3 warnings3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The skill performs automated code reviews by executing local scripts and dispatching subagents. It includes logic for autonomous decision-making in specific environments, bypassing human oversight for certain steps. It also transmits telemetry and diff data to external services (Codex) and processes untrusted user-supplied content through a security wrapper.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.