ce-code-review
Structured code review for bugs, regressions, tests, and standards. Use before PRs or when asked for review; interactive mode can fix locally, while mode:agent reports only for pipeline callers.
Security Assessment
About ce-code-review
A structured code-review skill that evaluates code changes using dynamically selected reviewer personas. It spawns parallel sub-agents that return structured JSON, then merges and deduplicates their findings into a single report. It is meant to run before creating a pull request, after finishing a task during iterative implementation, or whenever feedback on a change is needed, and it can be invoked standalone or embedded inside a larger workflow.
Two operating modes share the same review pipeline. In default interactive mode it produces a Markdown report with pipe-delimited finding tables and an actionable-findings summary, and it applies safe, verified fixes and commits them when the pre-review working tree was clean. In mode:agent (with mode:headless as a deprecated alias) it is report-only: it returns one JSON object as a deterministic contract for programmatic and cross-harness callers and never mutates the working tree, leaving the caller to apply. A core operating principle is 'apply locally; never push' — it never pushes, opens PRs, or files tickets in any mode. It also avoids blocking prompts and never switches branches; passing a PR number, URL, or branch name selects review scope only, not permission to mutate the tree. Arguments are parsed for tokens such as base:<sha-or-ref>, plan:<path>, and grouping:auto/off/always, with explicit conflict rules that stop the run before dispatching reviewers.
Findings use a P0-P3 severity scale answering urgency, while autofix_class (gated_auto, manual, advisory) and owner describe the shape of follow-up rather than granting apply permission. Synthesis owns the final route, chooses the more conservative route on disagreement, and rejects unsafe classes such as safe_auto. A quick-review short-circuit can defer to the harness's built-in review for fast, light reviews, but mode:agent always runs the full multi-agent pipeline and returns JSON.
FAQ
What is the difference between default mode and mode:agent?
Default interactive mode returns a Markdown report and applies safe, verified fixes (committing them when the tree was clean). mode:agent is report-only: it returns a single JSON object and never mutates the working tree, leaving the caller to apply.
Does the skill ever push my changes or open a pull request?
No. A core principle is 'apply locally; never push' — it never pushes, opens PRs, or files tickets in any mode, because push is the outward step the user owns.
If I pass a PR number or branch name, will it check that branch out?
No. Passing a PR number, URL, or branch name selects review scope only. It never runs gh pr checkout, git checkout, or git switch; to review local work on a branch you must check it out yourself.
What does the severity scale mean and how does it relate to auto-fixing?
Severities run P0 (critical, must fix before merge) through P3 (minor, user's discretion) and answer urgency. The autofix_class and owner fields describe follow-up shape, not apply permission — the apply decision is judgment made during synthesis.
Can I get a quick review instead of the full multi-agent pipeline?
Yes, when arguments indicate a quick, fast, or light review and mode:agent is not active, it runs the harness's built-in code review and stops. mode:agent always bypasses this short-circuit and runs the full pipeline.
All Files
24 filesInstall ce-code-review
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
everyinc/compound-engineering-plugin