Review change
Sixteen Claude Code skills for the parts of shipping I'd rather not do myself: ADRs, specs, audits, PR composition, review iteration.
npx -y skills add 0xdeafcafe/skills --skill review-changeAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when the user says "review the change", "/review-change", "audit my working tree", "what's wrong with what I've got staged", "review without fixing", or asks Claude to audit the working tree's diff read-only without modifying files, committing, or pushing. Read-only mirror of /drive-change — same slice/fan-out/merge/verify pipeline, same finding-format output, never edits or commits. Always runs /review-code + /review-test + /review-feature + /review-security; adds /review-ux when UI extensions are touched. Produces a single terminal report grouped by severity. Use /drive-change when you want Claude to apply the fixes; use /review-change when you want the verdict and intend to act on it yourself.
SKILL.md
6.6 KB, as published. Nobody here has run it
review-change
Read-only audit of the working tree's diff. Drives the change through the full agent pipeline (slice → fan-out → merge → verify) and emits findings in the structured format. Never edits, never commits, never pushes.
This is the read-only twin of /drive-change. Same audit, no writes.
For PR audit (instead of working tree), use /review-pr.
Phase 0 — Scope
Determine the change scope. Default:
git diff HEAD(committed-but-unpushed + uncommitted-but-tracked changes)- plus staged-but-not-committed changes (
git diff --cached) - plus untracked files (
git status --porcelain | awk '/^\?\?/ {print $2}')
Where a sensible base exists, compare against the merge-base with the default branch:
base=$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD origin/master 2>/dev/null)
[ -n "$base" ] && git diff "$base"...HEAD
Apply exclusions: lockfiles, dist/, build/, generated/, __generated__/, *.pb.*, binary blobs, fixtures, vendored code.
If the scope is empty (no diff, no staged, no untracked), exit early with No changes to review.
Phase 1 — Pull the change envelope
Build a references/change-envelope.md-shaped block:
### Diff— concatenation ofgit diffoutputs from Phase 0, plus per-untracked-file synthesized "all-additions" diffs (diff --no-index /dev/null <file>)### Files— flat list of paths### Language hints— derive from extensions, group by top-level directory### Pre-fetched outlines— when LSP available,outlineper file (seereferences/language-tooling.md)### LSP edges— when LSP available,references+call_hierarchyon changed symbols
If no LSPs are available, omit Pre-fetched outlines and LSP edges.
Phase 2 — Triage
Apply the adaptive routing logic:
files_changed = files from Phase 0 minus exclusions
loc_changed = sum of additions + deletions
top_dirs = unique first path segments
if len(files_changed) <= 5 and loc_changed <= 200:
mode = "tiny"
elif len(files_changed) <= 30 and loc_changed <= 1500 and len(top_dirs) <= 3:
mode = "small"
else:
mode = "large"
Record mode under a ## Triage heading along with the counts. Branch:
tiny→ Phase 4 only (single Opus pass with reviewer prompts inlined).small→ Phases 4 + 5 (no slice, no verifier).large→ full pipeline (Phases 3 + 4 + 5 + 6).
Phase 3 — Slice (large only)
Invoke agents/orchestrate-slice.md via Task:
Readthe agent file.- Concatenate with the change envelope from Phase 1.
Task(subagent_type: "general-purpose", model: "opus", prompt: ..., timeout_ms: 240000, description: "Slice working-tree diff").- Parse the JSON fence.
On parse failure or timeout, emit a P0 meta-finding and fall back to single-slice mode. Never treat as zero slices.
Phase 4 — Fan-out to /review-* specialists
For each slice (or whole diff in small/tiny mode), invoke read-only specialists in parallel via Skill:
- Always:
/review-hygiene,/review-code,/review-test,/review-feature,/review-security - Conditional:
/review-ux(UI files touched),/review-spec(.featureor ADR files touched)
Each specialist receives a change envelope scoped to its slice.
Phase 5 — Merge (per slice)
Invoke agents/orchestrate-merge.md via Task per slice:
Readthe agent file.- Concatenate with:
### Reviewer outputs### Slice metadata—{ slice_name, files }### Sensitivity patterns—Read('references/sensitivity-paths.md')### Finding schema—Read('references/finding-format.schema.json')
Task(subagent_type: "general-purpose", model: "opus", prompt: ..., timeout_ms: 120000).- Parse:
work_packets,judgment_findings,discarded,drifted_reviewers.
In /review-change's read-only mode, work_packets are not dispatched — they appear in the report as "could be fixed mechanically."
Phase 6 — Verify (large only)
Invoke agents/orchestrate-verify.md via Task:
Readthe agent file.- Concatenate with
### Slices,### Per-slice findings,### Diff,### LSP availability. Task(subagent_type: "general-purpose", model: "opus", prompt: ..., timeout_ms: 120000).- Parse:
findings,contracts_verified.
Append verifier findings to the merger output for the final report.
Phase 7 — Terminal report
Print findings grouped by severity:
[P0] [security] auth/session.ts:147 — refresh tokens stored in localStorage
why: XSS-readable; one DOM injection exfiltrates every active session.
fix: replace localStorage.setItem(...) with cookieStore.set
reviewers: review-security, review-code
Summary footer:
- Total findings by severity
- Drifted reviewers
- Judgment findings (decisions for the user)
- Cross-slice contract status (large mode only)
- Work packets that could be applied mechanically (with
/drive-changeto act on them)
No --comment mode — this skill doesn't have a PR to comment on. Use /review-pr for that.
Operating rules
- Read-only is non-negotiable.
Edit,Write,git commit,git pushare not inallowed-tools. Structural guard. - Untracked files are in scope. The user often hasn't staged or committed yet. Synthesize an "all-additions" diff for each untracked file.
- Findings are always structured. Skip rather than prose.
Composing with other skills
- Calls:
/review-hygiene,/review-code,/review-test,/review-feature,/review-security,/review-ux(conditionally),/review-spec(conditionally) — viaSkill. - Invokes:
agents/orchestrate-slice.md,agents/orchestrate-merge.md,agents/orchestrate-verify.md— viaTask. - Sibling:
/review-pr(PR audit),/drive-change(writes),/drive-plan(composes /review-change as its Phase 3).