Atlas / Skills / ruvnet / Github Code Review

Github Code ReviewBLOCK

skills/ruvnet/github-code-review

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Verdict
BLOCK
Grade
D
Trust score
63 /100
Version
—
Hosts
1 documented
License
MIT
Stars
74,015
01

Overview

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Read from source at commit 2074b0fad146OBSERVED Ā· 2026-10-07
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: github-code-review
description: Comprehensive GitHub code review with AI-powered swarm coordination
---

# GitHub Code Review Skill

> **AI-Powered Code Review**: Deploy specialized review agents to perform comprehensive, intelligent code reviews that go beyond traditional static analysis.

## šŸŽÆ Quick Start

### Simple Review
```bash
# Initialize review swarm for PR
gh pr view 123 --json files,diff | npx ruv-swarm github review-init --pr 123

# Post review status
gh pr comment 123 --body "šŸ” Multi-agent code review initiated"
```

### Complete Review Workflow
```bash
# Get PR context with gh CLI
PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body)
PR_DIFF=$(gh pr diff 123)

# Initialize comprehensive review
npx ruv-swarm github review-init \
  --pr 123 \
  --pr-data "$PR_DATA" \
  --diff "$PR_DIFF" \
  --agents "security,performance,style,architecture,accessibility" \
  --depth comprehensive
```

---

## šŸ“š Table of Contents

<details>
<summary><strong>Core Features</strong></summary>

- [Multi-Agent Review System](#multi-agent-review-system)
- [Specialized Review Agents](#specialized-review-agents)
- [PR-Based Swarm Management](#pr-based-swarm-management)
- [Automated Workflows](#automated-workflows)
- [Quality Gates & Checks](#quality-gates--checks)

</details>

<details>
<summary><strong>Review Agents</strong></summary>

- [Security Review Agent](#security-review-agent)
- [Performance Review Agent](#performance-review-agent)
- [Architecture Review Agent](#architecture-review-agent)
- [Style & Convention Agent](#style--convention-agent)
- [Accessibility Agent](#accessibility-agent)

</details>

<details>
<summary><strong>Advanced Features</strong></summary>

- [Context-Aware Reviews](#context-aware-reviews)
- [Learning from History](#learning-from-history)
- [Cross-PR Analysis](#cross-pr-analysis)
- [Custom Review Agents](#custom-review-agents)

</details>

<details>
<summary><strong>Integration & Automation</strong></summary>

- [CI/CD Integration](#cicd-integration)
- [Webhook Handlers](#webhook-handlers)
- [PR Comment Commands](#pr-comment-commands)
- [Automated Fixes](#automated-fixes)

</details>

---

## šŸš€ Core Features

### Multi-Agent Review System

Deploy specialized AI agents for comprehensive code review:

```bash
# Initialize review swarm with GitHub CLI integration
PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body)
PR_DIFF=$(gh pr diff 123)

# Start multi-agent review
npx ruv-swarm github review-init \
  --pr 123 \
  --pr-data "$PR_DATA" \
  --diff "$PR_DIFF" \
  --agents "security,performance,style,architecture,accessibility" \
  --depth comprehensive

# Post initial review status
gh pr comment 123 --body "šŸ” Multi-agent code review initiated"
```

**Benefits:**
- āœ… Parallel review by specialized agents
- āœ… Comprehensive coverage across multiple domains
- āœ… Faster review cycles with coordinated analysis
- āœ… Consistent quality standards enforcement

---

## šŸ¤– Specialized Review Agents

### Security Review Agent

**Focus:** Identify security vulnerabilities and suggest fixes

```bash
# Get changed files from PR
CHANGED_FILES=$(gh pr view 123 --json files --jq '.files[].path')

# Run security-focused review
SECURITY_RESULTS=$(npx ruv-swarm github review-security \
  --pr 123 \
  --files "$CHANGED_FILES" \
  --check "owasp,cve,secrets,permissions" \
  --suggest-fixes)

# Post findings based on severity
if echo "$SECURITY_RESULTS" | grep -q "critical"; then
  # Request changes for critical issues
  gh pr review 123 --request-changes --body "$SECURITY_RESULTS"
  gh pr edit 123 --add-label "security-review-required"
else
  # Post as comment for non-critical issues
  gh pr comment 123 --body "$SECURITY_RESULTS"
fi
```

<details>
<summary><strong>Security Checks Performed</strong></summary>

```javascript
{
  "checks": [
    "SQL injection vulnerabilities",
    "XSS attack vectors",
    "Authentication bypasses",
    "Authorization flaws",
    "Cryptographic weaknesses",
    "Dependency vulnerabilities",
    "Secret exposure",
    "CORS misconfigurations"
  ],
  "actions": [
    "Block PR on critical issues",
    "Suggest secure alternatives",
    "Add security test cases",
    "Update security documentation"
  ]
}
```

</details>

<details>
<summary><strong>Comment Template: Security Issue</strong></summary>

```markdown
šŸ”’ **Security Issue: [Type]**

**Severity**: šŸ”“ Critical / 🟔 High / 🟢 Low

**Description**:
[Clear explanation of the security issue]

**Impact**:
[Potential consequences if not addressed]

**Suggested Fix**:
```language
[Code example of the fix]
```

**References**:
- [OWASP Guide](link)
- [Security Best Practices](link)
```

</details>

---

### Performance Review Agent

**Focus:** Analyze performance impact and optimization opportunities

```bash
# Run performance analysis
npx ruv-swarm github review-performance \
  --pr 123 \
  --profile "cpu,memory,io" \
  --benchmark-against main \
  --suggest-optimizations
```

<details>
<summary><strong>Performance Metrics Analyzed</strong></summary>

```javascript
{
  "metrics": [
    "Algorithm complexity (Big O analysis)",
    "Database query efficiency",
    "Memory allocation patterns",
    "Cache utilization",
    "Network request optimization",
    "Bundle size impact",
    "Render performance"
  ],
  "benchmarks": [
    "Compare with baseline",
    "Load test simulations",
    "Memory leak detection",
    "Bottleneck identification"
  ]
}
```

</details>

---

### Architecture Review Agent

**Focus:** Evaluate design patterns and architectural decisions

```bash
# Architecture review
npx ruv-swarm github review-architecture \
  --pr 123 \
  --check "patterns,coupling,cohesion,solid" \
  --visualize-impact \
  --suggest-refactoring
```

<details>
<summary><strong>Architecture Analysis</strong></summary>

```javascript
{
  "patterns": [
    "Design pattern adherence",
    "SOLID principles",
    "DRY violations",
    "Separation of concerns",
    "Dependency injection",
    "
04

Trust audit

BLOCKgrade D Ā· trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (9)

HIGHPrivilege escalation / persistence Ā· review.unsafe_action Ā· CWE-269, CWE-250
SKILL.md
if echo "$REVIEW_OUTPUT" | grep -q "approved"; then
  gh pr review $PR_NUM --approve
Why it matters. The skill instructs the agent to automatically approve pull requests based on automated review output without human oversight, bypassing required human code review.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
HIGHPrivilege escalation / persistence Ā· review.unsafe_action Ā· CWE-269, CWE-250
SKILL.md
gh pr merge 123 --auto --squash
Why it matters. The skill instructs the agent to automatically merge pull requests without explicit user approval, performing a privileged deployment action based solely on automated review output.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
HIGHPrivilege escalation / persistence Ā· review.unsafe_action Ā· CWE-269, CWE-250
SKILL.md
--commit-fixes \
--push-changes
Why it matters. The skill instructs the agent to automatically commit and push code fixes to the repository without user approval, modifying source code and updating the remote branch autonomously.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
HIGHPrivilege escalation / persistence Ā· review.unsafe_action Ā· CWE-269, CWE-250
SKILL.md
execSync(`npx ruv-swarm github handle-comment --pr ${event.issue.number} --command "${command}"`);
Why it matters. The skill's webhook handler example executes untrusted PR comment content as shell commands via execSync, creating a command injection vulnerability where any PR comment starting with /swarm is run as a system command.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
MEDIUMInventory / provenance Ā· inv.symlink Ā· CWE-1104
crates
crates
Why it matters. link not followed
MEDIUMInventory / provenance Ā· inv.symlink Ā· CWE-1104
plugin/agents
plugin/agents
Why it matters. link not followed
MEDIUMInventory / provenance Ā· inv.symlink Ā· CWE-1104
plugin/commands
plugin/commands
Why it matters. link not followed
MEDIUMInventory / provenance Ā· inv.symlink Ā· CWE-1104
plugin/skills
plugin/skills
Why it matters. link not followed
MEDIUMPrivilege escalation / persistence Ā· review.unsafe_action Ā· CWE-269, CWE-250
SKILL.md
--email-stakeholders \
Why it matters. The skill instructs the agent to send emails to stakeholders without explicit user consent, performing external communications on the user's behalf.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-07 Ā· audit v0.4.1 Ā· source sha 2074b0fad146full audit observations/trust-audit/skill/ruvnet__github-code-review.json Ā· Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-072074b0fad146BLOCKD63first audit
06

Questions

What does the Github Code Review skill do?

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Is Github Code Review safe to install?

No — not without reading the findings first. The audit graded it D (63/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Github Code Review access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Github Code Review work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (2074b0fad146), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement