Skip to content
Back to skills

Crew Review

ASecurity

Review pass — review + security + quality gates.

  • 24 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsgocode-reviewsecurityperformance

Security analysis

A100/100

Scanned October 3, 2026

npx -y skills add crewforth/crewforth --skill crew-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Crew Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Crew Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/crewforth-crew-review/badge)](https://www.skillsdirectory.com/skills/crewforth-crew-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: crew-review
description: Review pass — review + security + quality gates.
metadata:
  kind: command
---
# /crew-review
Run the change set through the review trio (read-only). **The audits go out in parallel; the reviewer closes.**
1. **At once, in ONE message** — several `Agent` calls, because none of these writes code and so there is
   nothing to serialise:
   - @agent-crew-security-expert (security-scan) — auth/IDOR/injection/secret; findings with severity.
   - @agent-crew-performance-expert (`performance`) — hot path, query/loop, render, payload. Reports
     **candidates** (reasoned) and **findings** (measured) separately; an unmeasured claim is never a verdict.
   - @agent-crew-privacy-agent (`privacy-compliance`) — **when the diff touches personal data**: legal basis,
     minimisation, retention, transfer.
2. (if SonarQube is in use) **sonarqube-check** — 0/0/0/0 gate (language-agnostic).
3. **Last, once 1-2 leave no blocker:** @agent-crew-review-agent (crew-code-review) — "does it improve overall
   code health": the plan (what changed, the risks), then findings with a severity and a category. "Clean" means
   what crew-code-review means by it: **no critical or high finding open**. A medium or low audit finding does not
   hold the reviewer back; hand it over in the reviewer's prompt and keep it in the report. A critical or high one
   stops here: report it, leave the fix to its owner, and run the reviewer on the fixed diff. It is the closing
   reviewer in every writing agent's Coordination ("at closure, report findings to crew-review-agent"), so it
   reads a diff the audits have already cleared of blockers — not the other way round.

Each agent returns a **short summary** to the main thread; raw output goes to `docs/` if needed. Do NOT modify code;
collect findings in severity order, and leave the fix to the relevant expert.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…