Code Review Task Card

SkillDev tools

The code review skill is an opt-in agent skill that runs a merge-readiness review of a chosen scope, such as files, commits, or a pull request diff. It launches separate code-reviewer and architect passes in parallel, rates every finding by severity with file-and-line evidence, and combines their verdicts into a single APPROVE, REQUEST CHANGES, or COMMENT recommendation.

Available today. Use it from your connected AI after setup.

Have the scope ready: the files, commit, PR, or diff to review.

Then ask your AI: use the Code Review Task Card skill

What your AI can do with it

  • Review a chosen scope: files, commits, PR, or whole diff
  • Launch code-reviewer and architect passes in parallel
  • Rate findings CRITICAL, HIGH, MEDIUM, or LOW with file:line evidence
  • Check security, quality, performance, and maintainability
  • Return APPROVE, REQUEST CHANGES, or COMMENT verdict
  • Report independent review unavailable if a lane fails

Getting started

  1. Have the scope ready: the files, commit, PR, or diff to review.
  2. Provide requirements, acceptance criteria, and any test or CI evidence.
  3. Record the scope with git status --short, git diff --stat, and git diff -- <scope>.
  4. Ask the agent for a code review so the skill activates.
  5. If the agent says continue, let it advance the current verified review step.

What this skill tells your AI

The instructions your AI receives, as published by yeachan-heo/oh-my-codex in skills/code-review/SKILL.md and read by ahel’s review.

Use this explicit opt-in for a merge-readiness review. Shared operating invariants live in templates/AGENTS.md; this card only defines review-specific behavior.

When to use

  • The user asks for a code review or quality/security assessment.
  • A change is ready for review before merge, or a major feature needs an independent review.
  • Do not activate this card for implementation, broad planning, or automatic cleanup.

Inputs

  • Scope: the requested files, commit, PR, or whole diff.
  • Requirements/specification, acceptance criteria, and relevant test/CI evidence.
  • Existing review artifacts and known risks, if any.
  • If the user says continue, advance the current verified review step rather than restarting discovery.

Start by recording the scope:

git status --short
git diff --stat
git diff -- <scope>

Execution

  1. Identify changed files and review boundaries; do not silently widen the scope.
  2. Launch the code-reviewer and architect agents in parallel. Both lanes run in parallel on a clean context with explicit scope and artifacts. If either lane cannot be launched or does not return evidence, report independent review unavailable; do not substitute the current/authoring lane, and do not approve or mark the review merge-ready.
  3. Respect the user's current model and reasoning/effort selection. Do not pass model or reasoning_effort overrides in review-lane calls.
task(
  agent_type="code-reviewer",
  prompt="CODE REVIEW TASK

Review the supplied scope for spec compliance, security, quality, performance, and maintainability.
Return files reviewed, severity-rated findings with file:line evidence and concrete fixes,
and a recommendation: APPROVE / REQUEST CHANGES / COMMENT. Do not review architecture.
Scope: [scope and artifacts]"
)

task(
  agent_type="architect",
  prompt="ARCHITECTURE / DEVIL'S-ADVOCATE REVIEW TASK

Review the same scope for boundaries, interfaces, hidden coupling, long-term tradeoffs,
and the strongest counterargument against approval. Return file:line evidence,
recommendations, and Architectural Status: CLEAR / WATCH / BLOCK.
Scope: [scope and artifacts]"
)

Review taxonomy

  • code-reviewer checks Security, Code Quality, Performance, Best Practices, and Maintainability.
  • Rate each finding: CRITICAL (security or data-loss blocker), HIGH (bug/major smell), MEDIUM (important improvement), or LOW (style/suggestion).
  • architect checks explicit boundaries/interfaces, hidden coupling, long-horizon tradeoffs, and devil's-advocate concerns. Status is CLEAR, WATCH (non-blocking concern), or BLOCK (merge blocker).
  • Every finding names file:line, issue, risk, and a concrete fix; distinguish facts from suggestions.

State/HUD Phase Contract

  • Standalone $code-review relies on hook-owned skill-active-state.json (skill:"code-review", phase:"planning"); do not create code-review-state.json.
  • Inside Autopilot, keep mode:"autopilot" active with current_phase:"code-review" / skill-active phase:"code-review"; do not activate a peer workflow.
  • On clean review, persist the artifact under Autopilot handoff_artifacts.code_review before moving to ultraqa. On non-clean review, persist findings and use rework or ralplan as appropriate.
omx state write --input '{"mode":"autopilot","active":true,"current_phase":"code-review"}' --json

Final Synthesis and gate

Architectural Status Contract

Combine the code-reviewer recommendation and architect status. Approval requires explicit evidence from both independent lanes; missing or failed delegation is a blocking unavailable-review state, not an approval fallback. The final report must make architect blockers impossible to miss.

  • If architect status is BLOCK, final recommendation is REQUEST CHANGES.
  • Else if code-reviewer recommendation is REQUEST CHANGES, final recommendation is REQUEST CHANGES.
  • Else if architect status is WATCH, final recommendation is COMMENT.
  • Else final recommendation follows the code-reviewer lane.

Approval criteria: APPROVE only when code-reviewer returns APPROVE, architect status is CLEAR, and both independent lanes returned evidence. REQUEST CHANGES for a blocker, unresolved high/critical finding, or unavailable lane. COMMENT may record non-blocking findings.

Do not self-review as a fallback. If the code-reviewer or architect path is missing, unavailable, skipped, or fails, block approval until independent lane evidence exists. On the supported omx ralph CLI compatibility path, findings may trigger automatic fix follow-up without another permission prompt; plain code-review itself remains read-only and does not promise auto-fix.

Evidence/output contract

Return a concise report containing:

CODE REVIEW REPORT
Files Reviewed: <count>
Total Issues: 0
Architectural Status: CLEAR | WATCH | BLOCK
CRITICAL (0) | HIGH (0) | MEDIUM (0) | LOW (0)
Findings: file:line -> issue, risk, concrete fix (or none)
ARCHITECTURE WATCHLIST: concern, status, recommendation (or none)
- code-reviewer recommendation: COMMENT
- architect status: WATCH
- final recommendation: COMMENT
RECOMMENDATION: COMMENT

Replace the illustrative counts and verdict with observed values. Include scope, lane evidence/artifact references, unresolved risks, and validation gaps.

Exit condition

Stop when the scoped diff has two independent lane results and a deterministic final recommendation. Report APPROVE only under the approval criteria; otherwise leave a bounded REQUEST CHANGES, COMMENT, or unavailable-review result. Never claim merge-ready without the required evidence.

Signals

GitHub stars
33k
Forks
3k
Last commit
Oct 2026

Questions

What is a code review skill?
An opt-in agent skill that runs a merge-readiness review of a chosen scope. It launches code-reviewer and architect passes in parallel and returns one combined verdict.
What is a code review claude skill?
The same skill used with a Claude-based agent. It reviews the supplied scope, rates findings by severity with file:line evidence, and recommends APPROVE, REQUEST CHANGES, or COMMENT.
What is a code review agent skill?
A skill that guides an AI agent through a structured review: scope, parallel reviewer and architect lanes, severity-rated findings, and a single merge-readiness recommendation.
Advanced
Item type
skill
Key
code-review-yeachan-heo
Source
github.com/yeachan-heo/oh-my-codex