ce-code-review
everyinc/compound-engineering-plugin
Structured code review for bugs, regressions, tests, and standards. Use before PRs or when asked for review; interactive mode can fix locally, while mode:agent reports only for pipeline callers.
...Expand allAbout ce-code-review
A structured code-review skill that evaluates code changes using dynamically selected reviewer personas. It spawns parallel sub-agents that return structured JSON, then merges and deduplicates their findings into a single report. It is meant to run before creating a pull request, after finishing a task during iterative implementation, or whenever feedback on a change is needed, and it can be invoked standalone or embedded inside a larger workflow.
Two operating modes share the same review pipeline. In default interactive mode it produces a Markdown report with pipe-delimited finding tables and an actionable-findings summary, and it applies safe, verified fixes and commits them when the pre-review working tree was clean. In mode:agent (with mode:headless as a deprecated alias) it is report-only: it returns one JSON object as a deterministic contract for programmatic and cross-harness callers and never mutates the working tree, leaving the caller to apply. A core operating principle is 'apply locally; never push' — it never pushes, opens PRs, or files tickets in any mode. It also avoids blocking prompts and never switches branches; passing a PR number, URL, or branch name selects review scope only, not permission to mutate the tree. Arguments are parsed for tokens such as base:
Findings use a P0-P3 severity scale answering urgency, while autofix_class (gated_auto, manual, advisory) and owner describe the shape of follow-up rather than granting apply permission. Synthesis owns the final route, chooses the more conservative route on disagreement, and rejects unsafe classes such as safe_auto. A quick-review short-circuit can defer to the harness's built-in review for fast, light reviews, but mode:agent always runs the full multi-agent pipeline and returns JSON.
FAQ
What is the difference between default mode and mode:agent?
Default interactive mode returns a Markdown report and applies safe, verified fixes (committing them when the tree was clean). mode:agent is report-only: it returns a single JSON object and never mutates the working tree, leaving the caller to apply.
Does the skill ever push my changes or open a pull request?
No. A core principle is 'apply locally; never push' — it never pushes, opens PRs, or files tickets in any mode, because push is the outward step the user owns.
If I pass a PR number or branch name, will it check that branch out?
No. Passing a PR number, URL, or branch name selects review scope only. It never runs gh pr checkout, git checkout, or git switch; to review local work on a branch you must check it out yourself.
What does the severity scale mean and how does it relate to auto-fixing?
Severities run P0 (critical, must fix before merge) through P3 (minor, user's discretion) and answer urgency. The autofix_class and owner fields describe follow-up shape, not apply permission — the apply decision is judgment made during synthesis.
Can I get a quick review instead of the full multi-agent pipeline?
Yes, when arguments indicate a quick, fast, or light review and mode:agent is not active, it runs the harness's built-in code review and stops. mode:agent always bypasses this short-circuit and runs the full pipeline.
All Files
24 filesreferences/personas/julik-frontend-races-reviewer.md3.2 KBViewreferences/personas/maintainability-reviewer.md4.8 KBViewreferences/personas/previous-comments-reviewer.md3.3 KBViewreferences/personas/reliability-reviewer.md3.3 KBViewreferences/personas/swift-ios-reviewer.md10.5 KBViewreferences/review-output-template.md12.6 KBViewreferences/validator-template.md5.1 KBViewreferences/action-class-rubric.md1.5 KBViewreferences/findings-schema.json8.4 KBViewreferences/personas/adversarial-reviewer.md7.8 KBViewreferences/personas/api-contract-reviewer.md3.3 KBViewreferences/personas/data-migration-reviewer.md4.8 KBViewreferences/diff-scope.md2.4 KBViewreferences/persona-catalog.md5.4 KBViewreferences/personas/agent-native-reviewer.md9.1 KBViewreferences/personas/correctness-reviewer.md3.5 KBViewreferences/personas/deployment-verification-agent.md4.9 KBViewreferences/personas/learnings-researcher.md16.1 KBViewreferences/personas/performance-reviewer.md3.5 KBViewreferences/personas/project-standards-reviewer.md6.6 KBViewreferences/personas/security-reviewer.md3.7 KBViewreferences/personas/testing-reviewer.md3.8 KBViewreferences/subagent-template.md20.5 KBViewSKILL.md67.0 KBViewSetup
Run this once at the start of this invocation, before any subagent dispatch, and follow the directives it prints — except where one conflicts with this skill's own rules on asking the user questions, whether those rules are scoped to a non-interactive mode or apply in every mode, in which case this skill's rules win and no blocking question is asked. Run the fence exactly as written, as its own command: do not pipe or filter it (no head, tail, or grep), do not truncate its output, and do not bundle it into a batch with other commands. Its output opens with a === skill context header and ends with CE_CONTEXT_END; if you received one of those lines without the other, the output was truncated — rerun the fence verbatim once. That recovery is the only rerun: otherwise do not rerun it within the same invocation; a later invocation of this or any other skill runs its own. If no Node runtime is available the skill proceeds unchanged.
SKILL_DIR="<absolute path of the directory containing the SKILL.md you just read>";NODE="$(for c in node nodejs; do command -v "$c" >/dev/null 2>&1 && "$c" -e '' >/dev/null 2>&1 && { echo "$c"; break; }; done)";if [ -n "$NODE" ]; then"$NODE" "$SKILL_DIR/scripts/context.mjs" || echo "context script failed; continue with the skill's normal behavior";elseecho "no Node runtime; continue with the skill's normal behavior";fi
Artifact Root
Resolve the CE artifact root <root> before composing any artifact path.
- Read
docs_rootfrom<repo-root>/.compound-engineering/config.yamlonly (<repo-root>=git rev-parse --show-toplevel). Do not read it fromconfig.local.yaml. Unset -><root>isdocs, exactly as before. - Validate a set value: a repo-relative directory whose real, symlink-resolved path stays inside the repo and is neither the repo root nor under
.git/. Otherwise stop with an error namingdocs_rootand the value -- never fall back todocs. - Use
<root>as the sole artifact location: create it if absent, compose each path as<root>/<subdir>with this skill's own subdirectory, and never also readdocs.
Execution spine
Follow these steps in order; the references supply the detail but never change the order. Each reference named below is a required read for its step: load it before doing that step's work.
- Read
references/modes-and-output.mdfirst. It settles what the arguments mean, which argument conflicts stop the run before any reviewer is dispatched, whether the quick-review short-circuit applies, and what this invocation returns. - Stage 1. Read
references/scope.mdand resolve the reviewed diff, the scope mode, and the deterministic scope signals. - Stage 2. Read
references/intent-and-plan.md, write the intent summary every reviewer receives, and discover the plan Stage 6 verifies requirements against. - Stage 3. Read
references/persona-catalog.mdandreferences/select-and-route.md, then select the risk-driven reviewer roster, discover applicable standards paths, and bind the adversarial route. - Stage 3d. When adversarial is selected for a local reviewed tree, start and persist the sanctioned cross-model job that
references/cross-model-review.mddefines, before any local persona dispatch. Invoking this skill is itself the authorization for its configured or allowlisted peer route, once you have made the required disclosure of the recipient and of the code that leaves the machine. Do not ask the user to confirm a second time, and do not skip the peer because the user did not repeat that authorization. An explicit user prohibition on external review overrides it, as does a checkout that setscross_model_review_mode: offwith no live opt-in; both are resolved before you bind a route. A started peer replaces the local adversarial persona at this stage, and only a real failure to scope, allowlist, reach, authenticate, or start it leaves the local fallback in the roster; a later stage may still restore the local reviewer under the conditions that reference states. - Stage 4. Read
references/dispatch-reviewers.md. Dispatch the materialized local roster as one foreground concurrent batch sized to the host's active-agent cap, and collect every reviewer before synthesis however this host returns them: one blocking wait where same-message calls run concurrently, repeated non-polling collection waits where the subagent primitive is asynchronous, and serial dispatch where neither applies. Detaching local review into a polled background job is forbidden. The cross-model peer is the only detached work, and it may overlap this batch. - Stages 5 and 6. Once the reviewer returns are ready, read
references/finish-review.md. Fold in the peer once, run the documented findings mechanics, and run every validator the reference selects; only then return the report. Never synthesize directly from raw reviewer artifacts. In the multi-agent path, emit only this skill's report: do not also invoke a harness-native findings or reporting tool, which belongs to the quick-review short-circuit alone.
Operating principles
- Report-only by default; never push. A bare
ce-code-reviewinvocation produces findings and does not apply them. Entering the apply stage requiresapply:local, or an explicit user request in the invoking prompt to apply or fix this review's findings; a deprecatedmode:autofixtoken is neither.mode:agentnever mutates the tree, even when nested inside a workflow that later applies findings. Never push, open PRs, or file tickets in any mode. - No blocking prompts. Never use
AskUserQuestion,request_user_input,ask_user, or other blocking question tools. Infer intent, plan, and scope from explicit tokens, git state, PR metadata, and conversation. Note uncertainty in Coverage or the verdict — do not stop to ask. - Explicit mutations only. Never run
gh pr checkout,git checkout,git switch, or similar branch-switch commands. Passing a PR number, URL, or branch name selects review scope, not permission to mutate the working tree. Uncommitted work can only be reviewed from the checkout that holds it, so to review it on a feature branch, stay on that branch (or check it out yourself) and passbase:or no target. - Report outcomes, not machinery. What you show the user is about the review: what is being examined, which coverage is included and the one-line reason for each conditional lens, the independent cross-model pass, and the findings. Name what the user would recognize — a PR number, a reviewer's concern, a peer model — rather than this skill's plumbing, whose internal labels, dispatch bookkeeping, and setup narration stay out of user-facing text. Never claim more about the peer than its receipt attests. This governs what you surface and suppress, not the wording; use your own voice.
Task Visibility
For the multi-agent path, once the review scope is resolved, use the platform's task-tracking capability when available to show a short user-facing view derived from the execution spine. Track review outcomes, not individual personas, setup mechanics, or tool calls; add conditional work only when its gate fires, and update the view at meaningful transitions. If no task-tracking capability is available, continue with the normal progress and final report without simulating a task list in chat.
All Files
0 filesInstall ce-code-review
Download and extract the skill files to your .claude/skills/ directory.
Download ZIPClone the repository and copy the skill files to your project.
git clone https://github.com/EveryInc/compound-engineering-plugin/blob/main/skills/ce-code-review/SKILL.md # Copy SKILL.md to your .claude/skills/ directory
Copy





Home
