Skip to content
Back to skills

Code Review

ASecurity

Independently assess the complete delivered Change, or provide explicitly requested interim advice. One whole-change gate precedes final Verify; corrections are reassessed within that gate.

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
developmentgosqlcode-reviewdocumentation

Works with

  • cli

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned October 7, 2026

npx -y skills add xiongxianfei/rigorloop --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/xiongxianfei-code-review/badge)](https://www.skillsdirectory.com/skills/xiongxianfei-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review
description: Independently assess the complete delivered Change, or provide explicitly requested interim advice. One whole-change gate precedes final Verify; corrections are reassessed within that gate.
---

# Code Review

Identify scope first: formal whole-change review or optional advisory assessment. An advisory review reports findings and advice about inspected subjects, carries no formal judgment, and cannot advance the lifecycle or replace whole-change review. Serious findings still require owned action.

For the mandatory gate, assess the complete delivered scope against accepted IR/SRs, applicable ARs, reviewed System/Architecture Design and accepted delivery intent. Include relevant code, tests, configuration, migration/recovery behavior, generated outputs, skill instructions and documentation, including cross-milestone and cross-Module interactions. The scope is not merely the latest milestone.

Use a reviewer who did not author the implementation being approved. Record actual contributors and the basis for independence; role labels and hashes cannot establish it. Inspect the actual diff and sufficient context, evidence and failure behavior to judge the current result. Do not silently repair the reviewed subjects and approve your own repairs.

Record findings with scope, required outcome, accountable owner and relevant evidence. Route implementation defects to implement, wrong requirements to requirement-analysis, logical behavior to system-design, and allocation/Interface defects to architecture-design. Findings survive omission and a later clean submission until explicitly dispositioned.

After corrections, inspect changed subjects and affected interactions, determine what earlier coverage remains applicable, and maintain adequate whole-change coverage. Do not automatically reread every unchanged file or rerun unaffected tests. Broader or uncertain effects justify broader reassessment. Earlier approval retains its original meaning; current reliance requires an explicit supported disposition.

Use the code-purpose Review to record the actual assessment and applicability. One gate may contain several attempts. Do not settle milestone state or create a second gate for a single milestone. Hand applicable whole-change approval to distinct final Verify.

## Recording boundary

For Change-managed work, read the packaged operational interface reference before relying on or updating current state. Use supported CLI tasks and the inspected opaque revision; skills do not use SQL or edit runtime storage. An isolated invocation keeps its requested scope. Installation alone does not adopt workflow policy.

## Resource map

- READ `references/operational-recording.md` when inspecting or recording Change-managed work.
- READ `references/targeted-recording-v2.schema.json` when constructing a recording request.
- READ `references/rigorloop-records-v4.schema.json` when checking the types used by that request.

- READ `references/boundary-first-method-v1.md` when the project applies its boundary first method v1 criteria to this invocation.

- READ `references/requirement-to-delivery-model.md` when the project applies its requirement to delivery model criteria to this invocation.

- READ `references/review-assessment.md` when the project applies its review assessment criteria to this invocation.

- READ `references/review-reliance.md` when the project applies its review reliance criteria to this invocation.

- READ `references/test-maintenance.md` when the project applies its test maintenance criteria to this invocation.

- READ `references/test-quality.md` when the project applies its test quality criteria to this invocation.

## Expected output

Report the actual scoped outcome, governing basis, changed subjects or recorded judgment, material gaps and the next authorized action. Distinguish progress, review approval, final verification and external publication; claim only outcomes supported by this invocation.

Files in this skill

  • SKILL.md19.8 KB
  • assets/material-finding.md445 B
  • assets/review-result-skeleton.md1 KB
  • references/boundary-first-method-v1.md6.2 KB
  • references/requirement-to-delivery-model.md2.7 KB
  • references/workflow-managed-automated-review.md6.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…