Code Review — Yosemite Crew
SkillSecurityLets your agent review code changes for quality, security, accessibility, and style issues.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Code Review — Yosemite Crew skill
About this capability
Use when reviewing code, auditing a PR, or doing an adversarial review of a change. Runs quality, security, accessibility, and convention checks specific to this codebase.
What this skill tells your AI
The instructions your AI receives, as published by yosemitecrew/yosemite-crew in .agents/skills/code-review/SKILL.md and read by ahel’s review.
Description
Use this skill when reviewing code, checking a PR, or performing an adversarial review of changes. Runs through quality, security, accessibility, and convention checks specific to this codebase.
TRIGGER: when asked to review code, check a PR, or audit changes in any part of this monorepo.
Review Checklist
Universal (all apps)
- No secrets, tokens, or
.envvalues in code - TypeScript: no
any, no unnecessary type assertions - Conventional commit message format (scope must match root policy in
AGENTS.mdandcommitlint.config.cjs) - No
console.login production code (use Winston for backend, remove for frontend/mobile) - No new
eslint-disablecomments — fix the root cause - No new files when editing an existing file would suffice
- No duplicate imports in any file
Frontend Specific
- New UI uses existing
src/app/ui/components before creating new ones - Tailwind tokens used — no hardcoded colors or arbitrary values without justification
- No new Bootstrap classes added
- Sonar rules not violated (see
frontend-sonarskill) - Semantic HTML — no
<div role="...">where a native element exists - Keyboard accessibility — interactive elements have
tabIndexandonKeyDown - No
<button>nested inside<button> - Zustand store used correctly — no duplicated state across stores
- Cognitive complexity ≤ 15 per function/component
- No nested ternaries inline in JSX
- useState destructured correctly; no empty first slot
Backend Specific
- Business logic in service layer, not controller
- All
req.bodyinputs validated with Zod - No raw database queries outside model/service layer
- Background work enqueued via BullMQ, not processed inline
- Stripe webhook handlers verify signature
Mobile Specific
- User-visible strings use
t()from i18next - Navigation uses typed route names
- Redux for shared/persisted state;
useStatefor ephemeral UI state - Native permissions requested before use
How to Run a Review
- Read the changed files.
- Run through the relevant checklist sections above.
- For frontend changes, run:
npx tsc --noemit+pnpm --filter frontend run lint. - For frontend changes, run targeted tests for every modified file:
pnpm --filter frontend run test -- --testPathPatterns="<ModifiedFile>". Verify no existing tests are broken by the change. - For each issue found, state: file + line, the rule violated, and the fix.
- Summarize: blocking issues vs. suggestions.
Signals
- GitHub stars
- 2k
- Forks
- 83
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
code-review-yosemitecrew- Source
- github.com/yosemitecrew/yosemite-crew