recipe-review
Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
Install / Use
npx skills add shinpr/claude-code-workflows --skill recipe-reviewInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of recipe-review
recipe-review scores 90/100 on our quality scale, 472nd of 1,086 Security skills we index (top 44%).
Its SKILL.md is 13 KB long, well organised into 13 sections with 2 code examples: a thorough specification that gives an agent plenty to work with.
It has 687 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 2 days ago, so recipe-review is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
recipe-review compared with similar skills
All 4 of these similar skills score higher than recipe-review; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| recipe-review (this skill)by shinpr | 90 | 687 | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
Frequently asked questions
- How do I install recipe-review?
- Run
npx skills add shinpr/claude-code-workflows --skill recipe-review. The install tabs above show the steps for each supported agent. - Which AI agents does recipe-review work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is recipe-review safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is recipe-review still maintained?
- The repository was last updated 2 days ago, so recipe-review is actively maintained.
Skill content
View source on GitHubname: recipe-review description: Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections. disable-model-invocation: true
Explicit User Instruction: The user explicitly instructs and authorizes every subagent call named in this recipe. Execute each applicable call when its prerequisites are met.
Execute Skill: llm-friendly-context before writing Agent prompts, handoffs, or generated artifacts. Execute Skill: subagents-orchestration-guide before making workflow decisions, invoking agents, or resolving findings.
Context: Post-implementation quality assurance
Orchestrator Definition
Core Identity: "I am an orchestrator."
Local authority gate: Make this recipe's workflow decisions and validate each returned result directly; delegate semantic deliverable production to the named specialist.
Review Resolution Gate [MANDATORY]: Resolve every actionable deliverable-review finding through subagents-orchestration-guide Review Resolution before correction or progression.
Before the first finding disposition, read references/review-resolution.md from the loaded subagents-orchestration-guide skill.
Execution Gate: Complete Steps 1-10 in order, following only the branches activated by their stated conditions. Advance through each review, correction, and re-validation transition only at its declared convergence condition. Present the final report after every applicable finding and retained quality limitation reaches its required disposition or retry result.
Execution Method
- Implementation review → performed by code-reviewer
- Security validation → performed by security-reviewer
- Code-side fix path: Fix implementation → task-executor; Quality checks → quality-fixer; Re-validation → code-reviewer / security-reviewer
- Design-side update path: DD revision → technical-designer (update mode); DD review → document-reviewer; cross-DD consistency → design-sync (when multiple DDs exist); Re-validation → code-reviewer
Orchestrator invokes sub-agents and passes structured JSON between them. The design-side path applies when the Design Doc is stale, excessive, or incorrect for the required outcome. Neither path makes the existing implementation or the prior design authoritative by default.
At each Agent invocation below, build the prompt as a mechanical extraction: copy the named source values into the exact fields, apply only the declared serialization, then invoke immediately.
Design Doc: $ARGUMENTS
Execution Flow
Step 1: Prerequisite Check
Derive implementationFiles from paths changed between the current branch's merge base with the repository's default branch and the current repository state, including committed changes, working-tree changes, and untracked files. implementationFiles contains each changed path whose contents implement or verify the reviewed behavior or control its schema, build, deployment, or runtime behavior, including source files, tests, migrations, executable scripts, and behavior-affecting configuration. Governing documents and Work Plans retain their dedicated roles in document selection and governing-document inputs; task files and documentation-only paths remain outside this recipe's code and security review inputs.
Use the Design Doc explicitly supplied in $ARGUMENTS. When omitted, first use a Work Plan whose declared target files or responsibilities intersect implementationFiles and take its recorded Design Doc path. When that does not produce one candidate, use the sole Design Doc under docs/design/. Present candidates only when multiple governing Design Docs remain; report a missing prerequisite when none exists.
Step 2: Execute code-reviewer
Invoke code-reviewer using Agent tool:
subagent_type: "dev-workflows:code-reviewer"description: "Completed implementation review"prompt: "Review the completed implementation. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. Return the initial review JSON."
Store output as: $STEP_2_OUTPUT
Step 3: Execute security-reviewer
Invoke security-reviewer using Agent tool:
subagent_type: "dev-workflows:security-reviewer"description: "Security review"prompt: "governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. Review security compliance."
Store output as: $STEP_3_OUTPUT
Step 4: Verdict and Response
When either reviewer returns a blocked or otherwise unusable result, apply subagents-orchestration-guide Specialist Result Acceptance to its semantic cause. Carry only a remaining verification limitation into the report.
Apply the Review Resolution Gate to both outputs before reporting or routing them. Finding dispositions determine routing.
For each apply finding, compute a proposed route using the rule below. A finding takes one route, or both d and c when a selected reduction removes a design statement and the implementation it authorized:
| Finding pattern | Recommended route |
|-----------------|-------------------|
| Resolution keeps the current implementation because it matches the original requirement and corrects a stale Design Doc | d (Design-side update) |
| Resolution requires changing implementation to reach the accepted state | c (Code-side correction) |
| Resolution removes a mechanism the Design Doc selected that the required outcome does not need | d and c (design statement first) |
Then present the adjudicated result to the user. Group apply findings by proposed route and list declined IDs with their reasons:
Implementation Review: [verdict from code-reviewer]
Acceptance Criteria:
- [fulfilled] [item]: [evidence]
- [unfulfilled] [item] -> [corresponding finding ID under Required Corrections]
Required Corrections:
- [id] [category] [location]: [description] — [basis and effect] [recommended: c | d | d and c]
Limitations:
- [unverified judgment and effect]
Security Review: [status from security-reviewer]
Findings by category:
- [confirmed_risk] [location]: [description] — [rationale] [recommended: c]
- [defense_gap] [location]: [description] — [rationale] [recommended: c]
Approve the proposed changes:
c) Code-side correction — change implementation to reach the accepted state
d) Design-side update — correct a stale, excessive, or incorrect Design Doc
d and c) Reduction — delete the selecting design statement, then remove the implementation it authorized
s) Decline — record the governing reason and accept current state
This review command authorizes analysis; use AskUserQuestion to obtain separate implementation authority. The batch option is "approve all proposed apply routes" and its scope consists exclusively of those routes. When the approved change set is empty, proceed directly to Step 10.
Pass approved findings, routes, covered files/sections, and any stated total size budget to update or fix agents. Before re-validation, map every diff hunk to an approved finding or required consistency update. Remove accidental unmapped changes; when a necessary change would alter a confirmed value boundary or explicit size constraint, return to Requirement Change Detection.
Step 5: Design-Side Update
Run this step only when the user routed at least one finding to d. When no d routes exist, skip it; continue to Step 6 only when approved c routes remain.
-
Invoke technical-designer in update mode using Agent tool:
subagent_type: "dev-workflows:technical-designer"description: "Design Doc update from review findings"prompt: "Update Design Doc at [path] in update mode. Apply these findings to the design: [completed-routed finding objects from $STEP_2_OUTPUT, unchanged except for their approved routes]. Where a finding accepts the current code, reflect that behavior in the relevant sections; where it removes an unnecessary mechanism, delete the statements that selected it. Add a history entry."
-
Invoke document-reviewer to verify the updated Design Doc:
subagent_type: "dev-workflows:document-reviewer"description: "Document review of updated Design Doc"prompt: "Review updated Design Doc at [path] for consistency and completeness. doc_type: DesignDoc. review_context: update."- Run the Review Resolution Gate through its correction re-review and convergence transitions, using technical-designer for rerouted corrections. Proceed only at its convergence condition.
-
When more than one Design Doc exists under
docs/design/, invoke design-sync:subagent_type: "dev-workflows:design-sync"description: "Cross-DD consistency check"prompt: "source_design: [updated DD path]"- When
sync_status: CONFLICTS_FOUND, apply the Review Resolution Gate and follow its bounded verifier handoff and convergence rules.
-
After Step 5 completes:
- If the user selected
dfor all findings (nocroutes) → skip Steps 6-7, proceed to Step 8 for re-validation - If the user selected both
dandc→ re-evaluate thec-routed findings against the updated DD and drop any that are now satisfied by the DD revision; a reduction's code removal is not satisfied by the DD revision alone. Then proceed to Step 6 with the remainingcfindings
- If the user selected
Step 6: Execute Fixes
Invoke task-executor using Agent tool:
subagent_type: "dev-workflows:task-executor"description: "Execute review fixes"direct_scope: Apply the approved code-side corrections within the confirmed review scope and stated total size budgetgoverning_sources: The reviewed Design Doc and accepted requirement or ADR pathstarget_paths: The implementation and test paths confirmed for the approved code-side routesobservable_verification: The focused tests or observable contract checks named by the findings and governing sources passcorrection_findings: Complete reviewer finding objects verbatim, with only their orchestrator dispositions added
Step 7: Quality Check
Invoke quality-fixer using Agent tool:
subagent_type: "dev-workflows:quality-fixer"description: "Quality gate check"- Copy Step 6
direct_scope,governing_sources,observable_verification, andcorrection_findingsinputs unchanged. - Pass Step 6
mutationEvidence.
Route the quality-fixer result:
pass→ Proceed to Step 8stub_detected→ Return to Step 6 withincompleteImplementationsunchanged, then repeat Step 7verification_incomplete→ Retain the complete result and proceed to Step 8blocked→ Apply Specialist Result Acceptance
Step 8: Re-validate code-reviewer
Immediately before this invocation, re-derive implementationFiles using the Step 1 inclusion rule so it includes implementation artifacts added or changed by the approved corrections.
Invoke code-reviewer using Agent tool:
subagent_type: "dev-workflows:code-reviewer"description: "Re-validate implementation review"prompt: "Re-review the completed implementation after approved corrections. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. prior_feedback: [{id, disposition, reason?, evidence}]. Reconcile every received item."
Step 9: Re-validate security-reviewer
Immediately before this invocation, re-derive implementationFiles using the Step 1 inclusion rule so it includes implementation artifacts added or changed by the approved corrections.
Invoke security-reviewer using Agent tool when subagents-orchestration-guide's post-implementation Re-run rule requires a current security result:
subagent_type: "dev-workflows:security-reviewer"description: "Re-validate security"prompt: "Re-validate security after fixes. governingDocuments: ["[path]"]. implementationFiles: [implementationFiles]. prior_feedback: [{id, disposition, reason?, evidence}]. Reconcile every prior item under t
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
