Skip to content
Back to skills

Review

ASecurity

Review code changes, pull requests, patches, or a scoped code area for actionable correctness, security, compatibility, and test risks with file and line evidence. Use for review or audit requests; do not use for general proofreading, feature implementation, or debugging a reported failure when the user wants a fix.

  • 20 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsdebuggingsecuritydocumentation

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 3, 2026

npx -y skills add bigduu/Bamboo-agent --skill review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/bigduu-review/badge)](https://www.skillsdirectory.com/skills/bigduu-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: review
description: Review code changes, pull requests, patches, or a scoped code area for actionable correctness, security, compatibility, and test risks with file and line evidence. Use for review or audit requests; do not use for general proofreading, feature implementation, or debugging a reported failure when the user wants a fix.
---

# Review

Review the requested scope without changing it unless the user explicitly asks for fixes.

1. Resolve the exact diff, files, revision, and repository instructions in scope.
2. Read enough surrounding code, tests, and public contracts to judge behavior rather than style in isolation.
3. Check correctness, data loss, security boundaries, concurrency, error handling, compatibility, and missing tests in proportion to risk.
4. Validate suspected problems with concrete control flow, a focused command, or another direct source of evidence. For language, library, or runtime semantics, run a minimal reproducer or consult authoritative documentation instead of relying on memory. This is a hard gate: if neither verification path is available, omit the claim or state it only as an unverified coverage limit, never as a finding. Do not report speculation as a finding.
5. Distinguish defects from documented behavior and unspecified caller expectations. Do not report a language primitive's normal semantics, a hypothetical contract, or a style preference unless the reviewed code or its callers establish that the behavior is wrong.
6. Report only actionable findings, ordered by severity. Give each finding a precise file and line, impact, trigger, and evidence. Calibrate severity to demonstrated reachability and impact; do not label a local panic or edge case critical without evidence of a critical boundary.

If no actionable findings remain, say so plainly. Always summarize validation performed and residual risks or untested paths. If tools, permissions, or missing artifacts limit coverage, identify the limit instead of implying a complete review.

Files in this skill

  • SKILL.md2 KB
  • agents/bamboo.yaml173 B
  • agents/openai.yaml195 B
  • evals/scenarios.json1.2 KB
  • evals/trigger-evals.json1.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…