skills/ HoangNguyen0403/agent-skills-standard

common-review-policy

Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves. Use when review findings feel inconsistent or noisy, or when tuning an automated reviewer.

0
Installs
—
Rating
—
Success rate
3
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

3 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 4c3d241b13714e40… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Review Policy Standard

Priority: P1 (HIGH)

Every pull request gets the same passes in the same order. A review that varies by reviewer or by day is not a control.

1. The Policy File

  • Location: docs/review-policy.md, tracked in the repository and reviewed like code.
  • code-review and review-ticket load it when present; its severity and skip rules override their defaults.
  • Owned by the technical lead. Absent the file, the workflow defaults apply and the review says so.
  • Load references/review-policy-template.md when drafting or auditing the file.

2. Required Passes

Declare the passes and their order. Each pass names what it checks and what it explicitly ignores.

PassChecksOut of scope
Correctnesslogic, edge cases, requirement coveragestyle
Securityinjection, secrets, authorization, trust boundariestheoretical risk with no path
Testsnew logic covered, failure paths assertedcoverage percentage targets
Complianceaudit, data classification, licenceproduct decisions

3. Severity Ladder

  • Blocker: merge causes a defect, breach, or data loss. Concrete path required.
  • Major: real risk or requirement gap the author must resolve or explicitly accept.
  • Nit: everything else, including style, naming, and preference. Minor and Suggestion collapse into Nit.
  • Confidence: a finding without evidence is needs validation, never a silent drop and never a Blocker.
  • One ladder per repository. Workflows that use a longer list map onto these three before publishing.

4. Noise Control

  • Skip list: generated code, vendored dependencies, lockfiles, and snapshots. Name them as globs.
  • Nit cap: a fixed maximum per review. Over the cap, keep the highest-signal nits and drop the rest.
  • Lead with risk: Blocker and Major first, nits last, praise never.
  • Deduplicate by root cause: one finding per cause, listing the affected locations.

5. Tuning and Feedback

  • Review the policy monthly: rate a sample of findings as useful or noise, then adjust cap, skip list, and pass scope.
  • Recurring Blockers mean a missing standard. Route them to retro-learn so the preventing skill and its evals absorb the rule.
  • Record each tuning change in the policy file so severity drift is visible.

6. Separation of Duties

  • The agent reviews and proposes; a human approves. The agent never approves its own change.
  • Approval is enforced by branch protection, not by the reviewing agent's verdict.
  • Publishing findings to a ticket or pull request needs operator approval, and never happens from untrusted review context.

Anti-Patterns

  • No per-reviewer severity: One ladder, defined in the policy file.
  • No unbounded nits: Cap them and keep the highest signal.
  • No reviewing generated code: Put it in the skip list.
  • No Blocker without a path: Downgrade to needs validation.
  • No agent self-approval: A human approves through branch protection.
  • No silent policy drift: Record every tuning change in the file.

Red Flags

  • Stop if the review opens with praise: Lead with Blocker and Major findings.
  • Stop if the same Blocker recurs across reviews: Route it to retro-learn instead of re-reporting it.
  • Stop if severity is chosen to force attention: Rank by consequence, not by urgency.

References

Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:

  • docs/review-policy.md
  • Blocker, Major, Nit
  • skip list
  • nit cap
  • needs validation
  • monthly tuning
  • branch protection

Files

3
12.4 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from HoangNguyen0403/agent-skills-standard8

android-agp-upgrade

Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.

Scan passed 0
android-architecture

Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow implementation to their spec

Scan passed 0
android-background-work

Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.

Scan passed 0
android-compose

Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.

Scan passed 0
android-compose-migration

Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.

Scan passed 0
android-concurrency

Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes, persistence/notifications, and unit-test reci

Scan passed 0
android-deployment

Configure release signing, R8 obfuscation, and App Bundle publishing for Android. Use when setting up signing configs, enabling minification, adding ProGuard keep rules, or preparing for Play Store submission.

Scan passed 0
android-design-system

Enforce Material Design 3 theming and design token usage in Jetpack Compose. Use when implementing M3 components, color schemes, typography, or design tokens.

Scan passed 0

Related methodology skillsscan passed