requesting-code-review
Use when requesting independent code review, after implementation slices, before merging high-risk work, or when verification exposes evidence, baseline, architecture, compatibility, or retirement uncertainty.
Install
npx skills add https://github.com/GanyuanRan/Aegis/tree/main/skills/requesting-code-review
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install ganyuanran-aegis@llmmart
git clone https://github.com/GanyuanRan/Aegis.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole ganyuanran/aegis collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Requesting Code Review
Dispatch a reviewer subagent using the canonical code-reviewer.md template to
catch issues before they cascade. The reviewer gets precisely crafted context
for evaluation — never your session's history. This keeps the reviewer focused
on the work product, not your thought process, and preserves your own context
for continued work.
This skill is the canonical review-request workflow for method-pack implementation work. Use it to request review only after you have enough evidence, enough context, and a clear authority boundary for what the reviewer is being asked to assess.
Core principle: Review early, review often.
Findings First: Reviews lead with concrete findings before summary. Use bugs first, risk first, tests first. Strengths and general assessment are still useful, but they must not bury correctness, evidence, architecture, or retirement problems.
Review readiness is not merge approval. A review can reduce uncertainty and
recommend readiness, but it does not replace verification-before-completion
and does not grant completion authority.
When to Request Review
Mandatory:
- After each task in subagent-driven development
- After completing major feature
- Before merge to main
Optional but valuable:
- When stuck (fresh perspective)
- Before refactoring (baseline check)
- After fixing complex bug
Required Outputs
Before you leave this workflow, you must be able to state:
- What exact scope is being reviewed
- What plan, requirement, or contract defines success
- What Product / Requirement Baseline defines accepted behavior and non-goals
- What Architecture / Runtime Boundary Baseline defines the expected architecture state
- What fresh evidence already exists
- What compatibility boundary must still hold
- What old owner / fallback / patch stays, shrinks, or retires
- What the reviewer must specifically validate
- Whether the reviewer is providing advisory review only, or also any higher-level merge recommendation
- Aegis Visibility: why findings-first ordering, evidence sufficiency, baseline alignment, compatibility, or retirement risk matters for this review request
- Semantic context scope: which relevant canonical terms, deprecated aliases, or public naming boundaries the review must preserve
Review in this method pack is advisory and evidence-oriented. It is not authoritative completion by itself.
How to Request
1. Gather minimum review inputs:
- What was implemented
- What requirement / plan / spec / ADR it should match
- What baseline / current authority docs the diff must align with, including requirements/product alignment and architecture/current-authority alignment
- What evidence already exists (tests, commands, logs, screenshots, diff summary)
- What compatibility boundary or risk deserves reviewer attention
- Whether there is any old path, fallback, duplicate owner, or temporary patch that should retire
- Whether the diff contains durable architecture decisions that need ADR Auto Backfill or baseline sync findings
- Whether
recording-architecture-decisionswas used, or should be used, when an ADR action or baseline sync closure is in scope - Relevant active
CONTEXT.mdlanguage when public/domain naming is in scope; passive reading does not load active modeling
If you cannot answer these, stop and gather them before dispatching review.
2. Define the Git review scope:
# Before the coordinator's task commit
REVIEW_SCOPE=working-tree
BASE_SHA=$(git rev-parse HEAD)
# Or for already committed work
REVIEW_SCOPE=committed-range
BASE_SHA=<known-start>
HEAD_SHA=$(git rev-parse HEAD)
For working-tree review, identify task-owned untracked paths explicitly. Do not stage merely to make them visible to a reviewer.
3. Dispatch reviewer subagent:
Use the Task tool with a general-purpose reviewer subagent. Fill the canonical
template at requesting-code-review/code-reviewer.md; do not rely on a
separate named agent prompt.
Placeholders:
{WHAT_WAS_IMPLEMENTED}- What you just built{PLAN_OR_REQUIREMENTS}- What it should do{EVIDENCE}- Fresh tests, commands, logs, or verification already available{COMPATIBILITY_BOUNDARY}- What existing behavior or interfaces must not break{RETIREMENT_NOTES}- Old owner / fallback / patch / duplicate branch and expected disposition{REVIEW_SCOPE}-working-treeorcommitted-range{BASE_SHA}- Starting commit{HEAD_SHA}- Ending commit, orWORKTREE{DESCRIPTION}- Brief summary
4. Act on feedback:
- Fix Critical issues immediately
- Fix Important issues before proceeding
- Note Minor issues for later
- Push back if reviewer is wrong (with reasoning)
- If feedback reveals evidence gaps, run the missing verification instead of arguing from confidence
- If feedback reveals Design Defect / Implementation Drift, stale logic, or a legacy alias such as architecture drift, decide explicitly whether to repair now, correct the baseline, or record retirement conditions
Example
[Just completed Task 2: Add verification function]
You: Let me request code review before proceeding.
BASE_SHA=$(git log --oneline | grep "Task 1" | head -1 | awk '{print $1}')
HEAD_SHA=$(git rev-parse HEAD)
[Dispatch reviewer subagent using requesting-code-review/code-reviewer.md]
WHAT_WAS_IMPLEMENTED: Verification and repair functions for conversation index
PLAN_OR_REQUIREMENTS: Task 2 from docs/aegis/plans/deployment-plan.md
EVIDENCE: pytest tests/index/test_verify.py -v -> 12 passed
COMPATIBILITY_BOUNDARY: Existing index format and CLI flags must remain stable
RETIREMENT_NOTES: Legacy repair fallback still exists in old helper; remove once new path covers all four issue types
BASE_SHA: a7981ec
HEAD_SHA: 3df7661
DESCRIPTION: Added verifyIndex() and repairIndex() with 4 issue types
[Subagent returns]:
Strengths: Clean architecture, real tests
Issues:
Important: Missing progress indicators
Minor: Magic number (100) for reporting interval
Assessment: Ready to proceed
You: [Fix progress indicators]
[Continue to Task 3]
Integration with Workflows
Subagent-Driven Development:
- Review after EACH task
- Catch issues before they compound
- Fix before moving to next task
Executing Plans:
- Review after each batch (3 tasks)
- Get feedback, apply, continue
Ad-Hoc Development:
- Review before merge
- Review when stuck
What the Reviewer Must Check
The review request must prompt the reviewer to inspect at least:
- Findings First: bugs first, risk first, tests first
- evidence sufficiency
- baseline / current authority alignment
- requirements/product alignment against accepted problem, success evidence, and non-goals
- architecture/current-authority alignment against owner, contract, source-of-truth, compatibility, and retirement boundaries
- Design Defect / Implementation Drift classification with
scope: requirements | architecture | both - legacy phrase mapping: baseline defect, architecture defect, and architecture drift must map back to Design Defect / Implementation Drift rather than becoming parallel result vocabularies
- duplicate owner risk
- compatibility boundary
- missing ADR Auto Backfill or baseline sync findings for durable architecture decisions
- missing
recording-architecture-decisionshandoff when ADR action or baseline sync closure is in scope - unverified claims or missing proof
- old logic that should retire, stay temporarily, or converge
- public-name drift, deprecated-term re-entry, or a semantic change recorded in
code/docs without composing
establishing-project-context
If the review only asks “is this code good?”, it is underspecified.
Red Flags
Never:
- Skip review because "it's simple"
- Ignore Critical issues
- Proceed with unfixed Important issues
- Argue with valid technical feedback
- Treat reviewer approval as equivalent to authoritative completion
- Ask for review without sharing what evidence already exists
- Add new logic without telling the reviewer what happens to the old path
If reviewer wrong:
- Push back with technical reasoning
- Show code/tests that prove it works
- Request clarification
Review Boundaries
- Review can recommend merge readiness, residual risk, and follow-up work
- Review cannot grant authoritative completion by itself
- Review should reduce uncertainty, not hide it
See template at: requesting-code-review/code-reviewer.md
Files (aegis)
-
code-reviewer.md 6.9 KB
# Code Review Agent You are reviewing code changes for production readiness. **Your task:** 1. Review {WHAT_WAS_IMPLEMENTED} 2. Compare against {PLAN_OR_REQUIREMENTS} 3. Check evidence, code quality, architecture, testing 4. Categorize issues by severity 5. Assess review readiness and residual risk ## What Was Implemented {DESCRIPTION} ## Requirements/Plan {PLAN_OR_REQUIREMENTS} ## Baseline / Current Authority Identify the baseline or current authority refs supplied by the caller. If none were supplied for non-trivial work, flag that as a review evidence gap instead of inventing an authority source. ## Existing Evidence {EVIDENCE} ## Compatibility Boundary {COMPATIBILITY_BOUNDARY} ## Retirement Notes {RETIREMENT_NOTES} ## Git Review Scope **Scope:** {REVIEW_SCOPE} **Base:** {BASE_SHA} **Head:** {HEAD_SHA} For `committed-range`: ```bash git diff --stat {BASE_SHA}..{HEAD_SHA} git diff {BASE_SHA}..{HEAD_SHA} ``` For `working-tree`, review tracked staged/unstaged changes and caller-declared task-owned untracked paths without mutating Git: ```bash git status --short git diff --stat {BASE_SHA} git diff {BASE_SHA} ``` Do not stage, commit, branch, create/remove worktrees, or edit the implementation. ## Findings First Lead with findings. Use bugs first, risk first, tests first. Do not bury correctness, evidence, architecture, compatibility, or retirement problems under a broad summary. If there are no findings, say that clearly and name the remaining test gaps or residual risk. ## Review Checklist **Code Quality:** - Clean separation of concerns? - Proper error handling? - Type safety (if applicable)? - DRY principle followed? - Edge cases handled? **Architecture:** - Sound design decisions? - Canonical owner clear? - Any duplicated owner, stale fallback, or compatibility layer still carrying real logic? - Does the change solve the problem at the highest appropriate owner/contract layer? - Is any caller-side fallback masking a missing source-of-truth or contract fix? - Scalability considerations? - Performance implications? - Security concerns? **Baseline / Current Authority:** - Were baseline / current authority refs supplied when the work was non-trivial? - Is requirements/product alignment clear against the accepted problem, acceptance evidence, and non-goals? - Does the diff align with the baseline ownership map, contract inventory, and dependency direction? - Does architecture/current-authority alignment hold for canonical owner, contract, source-of-truth, compatibility, and retirement boundaries? - If not aligned, classify as Design Defect / Implementation Drift and state `scope: requirements | architecture | both`. - If legacy phrasing appears, map baseline defect, architecture defect, and architecture drift back to Design Defect / Implementation Drift. - If not aligned, is this intentional architecture change? - If intentional, is ADR Auto Backfill or baseline sync needed? - If an ADR action or baseline sync closure is in scope, did the caller use or plan to use `recording-architecture-decisions` before claiming completion? **Evidence Sufficiency:** - Do the provided tests / commands / logs actually prove the claimed behavior? - Is any important claim still unsupported? - Are there unverified assumptions being presented as facts? **Testing:** - Tests actually test logic (not mocks)? - Edge cases covered? - Integration tests where needed? - All tests passing? **Requirements:** - All plan requirements met? - Implementation matches spec? - No scope creep? - Breaking changes documented? **Compatibility / Retirement:** - Existing behavior preserved where required? - Old path / fallback / patch disposition is explicit? - Any stale logic should be removed now or given a clear retirement trigger? **Readiness / Residual Risk:** - Migration strategy (if schema changes)? - Backward compatibility considered? - Documentation complete? - No obvious bugs? - Any Design Defect / Implementation Drift still unresolved, including findings described with legacy aliases? ## Output Format ### Issues #### Critical (Must Fix) [Bugs, security issues, data loss risks, broken functionality] #### Important (Should Fix) [Architecture problems, missing features, poor error handling, test gaps, stale fallback risk] #### Minor (Nice to Have) [Code style, optimization opportunities, documentation improvements] **For each issue:** - File:line reference - What's wrong - Why it matters - How to fix (if not obvious) ### Strengths [What's well done? Be specific.] ### Recommendations [Improvements for code quality, architecture, or process] ### Evidence Review [What the supplied evidence proves, and what remains unverified] ### Assessment **Ready to merge?** [Yes/No/With fixes] **Authority note:** [Advisory review only; not authoritative completion] **Reasoning:** [Technical assessment in 1-2 sentences] ## Critical Rules **DO:** - Categorize by actual severity (not everything is Critical) - Be specific (file:line, not vague) - Explain WHY issues matter - Acknowledge strengths - Give clear verdict - Distinguish missing evidence from missing code - Call out Design Defect / Implementation Drift, compatibility alias mapping, and retirement debt explicitly **DON'T:** - Say "looks good" without checking - Mark nitpicks as Critical - Give feedback on code you didn't review - Be vague ("improve error handling") - Avoid giving a clear verdict - Treat passing tests alone as full completion - Ignore old logic that should retire or converge - Judge Design Defect / Implementation Drift or compatibility aliases without checking baseline or current authority refs ## Example Output ``` ### Issues #### Important 1. **Missing help text in CLI wrapper** - File: index-conversations:1-31 - Issue: No --help flag, users won't discover --concurrency - Fix: Add --help case with usage examples 2. **Date validation missing** - File: search.ts:25-27 - Issue: Invalid dates silently return no results - Fix: Validate ISO format, throw error with example #### Minor 1. **Progress indicators** - File: indexer.ts:130 - Issue: No "X of Y" counter for long operations - Impact: Users don't know how long to wait ### Strengths - Clean database schema with proper migrations (db.ts:15-42) - Comprehensive test coverage (18 tests, all edge cases) - Good error handling with fallbacks (summarizer.ts:85-92) ### Recommendations - Add progress reporting for user experience - Consider config file for excluded projects (portability) ### Evidence Review - The provided test output shows the core verification path passes. - No evidence was supplied for invalid date handling, so that claim remains unverified. ### Assessment **Ready to merge: With fixes** **Authority note:** Advisory review only; final completion still depends on the owning workflow and fresh verification gates. **Reasoning:** Core implementation is solid with good architecture and tests. Important issues (help text, date validation) are easily fixed and don't affect core functionality. ``` -
SKILL.md 8.6 KB
--- name: requesting-code-review description: "Use when requesting independent code review, after implementation slices, before merging high-risk work, or when verification exposes evidence, baseline, architecture, compatibility, or retirement uncertainty." --- # Requesting Code Review Dispatch a reviewer subagent using the canonical `code-reviewer.md` template to catch issues before they cascade. The reviewer gets precisely crafted context for evaluation — never your session's history. This keeps the reviewer focused on the work product, not your thought process, and preserves your own context for continued work. This skill is the canonical review-request workflow for method-pack implementation work. Use it to request review only after you have enough evidence, enough context, and a clear authority boundary for what the reviewer is being asked to assess. **Core principle:** Review early, review often. **Findings First:** Reviews lead with concrete findings before summary. Use bugs first, risk first, tests first. Strengths and general assessment are still useful, but they must not bury correctness, evidence, architecture, or retirement problems. Review readiness is not merge approval. A review can reduce uncertainty and recommend readiness, but it does not replace `verification-before-completion` and does not grant completion authority. ## When to Request Review **Mandatory:** - After each task in subagent-driven development - After completing major feature - Before merge to main **Optional but valuable:** - When stuck (fresh perspective) - Before refactoring (baseline check) - After fixing complex bug ## Required Outputs Before you leave this workflow, you must be able to state: 1. **What exact scope is being reviewed** 2. **What plan, requirement, or contract defines success** 3. **What Product / Requirement Baseline defines accepted behavior and non-goals** 4. **What Architecture / Runtime Boundary Baseline defines the expected architecture state** 5. **What fresh evidence already exists** 6. **What compatibility boundary must still hold** 7. **What old owner / fallback / patch stays, shrinks, or retires** 8. **What the reviewer must specifically validate** 9. **Whether the reviewer is providing advisory review only, or also any higher-level merge recommendation** 10. **Aegis Visibility**: why findings-first ordering, evidence sufficiency, baseline alignment, compatibility, or retirement risk matters for this review request 11. **Semantic context scope**: which relevant canonical terms, deprecated aliases, or public naming boundaries the review must preserve Review in this method pack is advisory and evidence-oriented. It is not authoritative completion by itself. ## How to Request **1. Gather minimum review inputs:** - What was implemented - What requirement / plan / spec / ADR it should match - What baseline / current authority docs the diff must align with, including requirements/product alignment and architecture/current-authority alignment - What evidence already exists (tests, commands, logs, screenshots, diff summary) - What compatibility boundary or risk deserves reviewer attention - Whether there is any old path, fallback, duplicate owner, or temporary patch that should retire - Whether the diff contains durable architecture decisions that need ADR Auto Backfill or baseline sync findings - Whether `recording-architecture-decisions` was used, or should be used, when an ADR action or baseline sync closure is in scope - Relevant active `CONTEXT.md` language when public/domain naming is in scope; passive reading does not load active modeling If you cannot answer these, stop and gather them before dispatching review. **2. Define the Git review scope:** ```bash # Before the coordinator's task commit REVIEW_SCOPE=working-tree BASE_SHA=$(git rev-parse HEAD) # Or for already committed work REVIEW_SCOPE=committed-range BASE_SHA=<known-start> HEAD_SHA=$(git rev-parse HEAD) ``` For working-tree review, identify task-owned untracked paths explicitly. Do not stage merely to make them visible to a reviewer. **3. Dispatch reviewer subagent:** Use the Task tool with a general-purpose reviewer subagent. Fill the canonical template at `requesting-code-review/code-reviewer.md`; do not rely on a separate named agent prompt. **Placeholders:** - `{WHAT_WAS_IMPLEMENTED}` - What you just built - `{PLAN_OR_REQUIREMENTS}` - What it should do - `{EVIDENCE}` - Fresh tests, commands, logs, or verification already available - `{COMPATIBILITY_BOUNDARY}` - What existing behavior or interfaces must not break - `{RETIREMENT_NOTES}` - Old owner / fallback / patch / duplicate branch and expected disposition - `{REVIEW_SCOPE}` - `working-tree` or `committed-range` - `{BASE_SHA}` - Starting commit - `{HEAD_SHA}` - Ending commit, or `WORKTREE` - `{DESCRIPTION}` - Brief summary **4. Act on feedback:** - Fix Critical issues immediately - Fix Important issues before proceeding - Note Minor issues for later - Push back if reviewer is wrong (with reasoning) - If feedback reveals evidence gaps, run the missing verification instead of arguing from confidence - If feedback reveals Design Defect / Implementation Drift, stale logic, or a legacy alias such as architecture drift, decide explicitly whether to repair now, correct the baseline, or record retirement conditions ## Example ``` [Just completed Task 2: Add verification function] You: Let me request code review before proceeding. BASE_SHA=$(git log --oneline | grep "Task 1" | head -1 | awk '{print $1}') HEAD_SHA=$(git rev-parse HEAD) [Dispatch reviewer subagent using requesting-code-review/code-reviewer.md] WHAT_WAS_IMPLEMENTED: Verification and repair functions for conversation index PLAN_OR_REQUIREMENTS: Task 2 from docs/aegis/plans/deployment-plan.md EVIDENCE: pytest tests/index/test_verify.py -v -> 12 passed COMPATIBILITY_BOUNDARY: Existing index format and CLI flags must remain stable RETIREMENT_NOTES: Legacy repair fallback still exists in old helper; remove once new path covers all four issue types BASE_SHA: a7981ec HEAD_SHA: 3df7661 DESCRIPTION: Added verifyIndex() and repairIndex() with 4 issue types [Subagent returns]: Strengths: Clean architecture, real tests Issues: Important: Missing progress indicators Minor: Magic number (100) for reporting interval Assessment: Ready to proceed You: [Fix progress indicators] [Continue to Task 3] ``` ## Integration with Workflows **Subagent-Driven Development:** - Review after EACH task - Catch issues before they compound - Fix before moving to next task **Executing Plans:** - Review after each batch (3 tasks) - Get feedback, apply, continue **Ad-Hoc Development:** - Review before merge - Review when stuck ## What the Reviewer Must Check The review request must prompt the reviewer to inspect at least: - Findings First: bugs first, risk first, tests first - evidence sufficiency - baseline / current authority alignment - requirements/product alignment against accepted problem, success evidence, and non-goals - architecture/current-authority alignment against owner, contract, source-of-truth, compatibility, and retirement boundaries - Design Defect / Implementation Drift classification with `scope: requirements | architecture | both` - legacy phrase mapping: baseline defect, architecture defect, and architecture drift must map back to Design Defect / Implementation Drift rather than becoming parallel result vocabularies - duplicate owner risk - compatibility boundary - missing ADR Auto Backfill or baseline sync findings for durable architecture decisions - missing `recording-architecture-decisions` handoff when ADR action or baseline sync closure is in scope - unverified claims or missing proof - old logic that should retire, stay temporarily, or converge - public-name drift, deprecated-term re-entry, or a semantic change recorded in code/docs without composing `establishing-project-context` If the review only asks “is this code good?”, it is underspecified. ## Red Flags **Never:** - Skip review because "it's simple" - Ignore Critical issues - Proceed with unfixed Important issues - Argue with valid technical feedback - Treat reviewer approval as equivalent to authoritative completion - Ask for review without sharing what evidence already exists - Add new logic without telling the reviewer what happens to the old path **If reviewer wrong:** - Push back with technical reasoning - Show code/tests that prove it works - Request clarification ## Review Boundaries - Review can recommend merge readiness, residual risk, and follow-up work - Review cannot grant authoritative completion by itself - Review should reduce uncertainty, not hide it See template at: requesting-code-review/code-reviewer.md
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.