Best for
- Use when reviewing code changes, PRs, or implementations.
gmickel/flow-next/plugins/flow-next/skills/flow-next-impl-review/SKILL.md
John Carmack-level implementation review via RepoPrompt or Codex. Use when reviewing code changes, PRs, or implementations. Triggers on /flow-next:impl-review.
Decision brief
Workflow is backend-split. Read workflow-common.md for Phase 0 (backend detection + philosophy + trivial-diff triage + phase-ordering matrix), then read ONLY the file matching your active backend. The opt-in --deep/--validate/--interactive phase detail lives in optional-phases.m…
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Declared | Source record | Install path and trigger |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/gmickel/flow-next --skill "plugins/flow-next/skills/flow-next-impl-review"Inspect the Agent Skill "flow-next-impl-review" from https://github.com/gmickel/flow-next/blob/1300e43304f9ecda78250d935847998ae4bee84e/plugins/flow-next/skills/flow-next-impl-review/SKILL.md at commit 1300e43304f9ecda78250d935847998ae4bee84e. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
The executable Phase 0 lives in workflow-common.md §"Phase 0: Backend Detection" — Read it and execute it ONCE, before any other bash in this skill. It defines $FLOWCTL (bundled — NOT installed globally; which flowctl fails, expected), probes RPELIGIBLE, resolves $BACKEND via th…
No --review flag → $BACKEND comes from workflow-common.md Phase 0 (executed once per the Preamble): the single flowctl review-backend "$REVIEWID" call with ASK handling included. Do not re-resolve here.
Parse $ARGUMENTS for: - --base → BASECOMMIT (if provided, use for scoped diff) - --no-triage → set TRIAGEDISABLED=1 (skip trivial-diff pre-check) - --validate → set VALIDATE=true (fn-32.1 validator pass on NEEDSWORK) - --deep / --deep= → set DEEP=true + optional DEEPPASSES CSV (…
Parse $ARGUMENTS for: - --base → BASECOMMIT (if provided, use for scoped diff) - --no-triage → set TRIAGEDISABLED=1 (skip trivial-diff pre-check) - --validate → set VALIDATE=true (fn-32.1 validator pass on NEEDSWORK) - --deep / --deep= → set DEEP=true + optional DEEPPASSES CSV (…
if [[ -n "$DEEPPASSES" ]]; then SELECTEDPASSES="${DEEPPASSES//,/ }" else Determine changed files for auto-enable heuristic if [[ -n "$BASECOMMIT" ]]; then CHANGED="$(git diff --name-only "$BASECOMMIT"..HEAD)" else DIFFBASE=main; git rev-parse main /dev/null 2&1 || DIFFBASE=maste…
Permission review
The documentation asks the agent to read local files, directories, or repositories.
*Workflow is backend-split. Read [workflow-common.md](workflow-common.md) for Phase 0 (backend detection + philosophy + trivial-diff triage + phase-ordering matrix), then read ONLY the file matching your active backend. The opt-in `--deep`/The documentation asks the agent to read local files, directories, or repositories.
Read **only** the file for that backend:Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 672 | Source | Repository attention, not individual Skill quality |
| Compatibility | 1 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Workflow is backend-split. Read workflow-common.md for Phase 0 (backend detection + philosophy + trivial-diff triage + phase-ordering matrix), then read ONLY the file matching your active backend. The opt-in --deep/--validate/--interactive phase detail lives in optional-phases.md, loaded only when a flag fires:
BACKEND=codex → workflow-codex.mdBACKEND=copilot → workflow-copilot.mdBACKEND=cursor → workflow-cursor.mdBACKEND=host → workflow-host.mdBACKEND=rp → workflow-rp.mdDo not load the others — only the active backend's file is needed.
Conduct a John Carmack-level review of implementation changes on the current branch.
Role: Code Review Coordinator (NOT the reviewer)
Backends (branch on the Phase 0 RP_ELIGIBLE probe):
RP_ELIGIBLE=1: RepoPrompt (rp), Codex CLI (codex), GitHub Copilot CLI (copilot), Cursor CLI (cursor), or host-native (host)RP_ELIGIBLE=0: Codex CLI (codex), GitHub Copilot CLI (copilot), Cursor CLI (cursor), or host-native (host) — rp is macOS-only; never list it in guidance you surface (--review=rp stays accepted)The executable Phase 0 lives in workflow-common.md §"Phase 0: Backend Detection" — Read it and execute it ONCE, before any other bash in this skill. It defines $FLOWCTL (bundled — NOT installed globally; which flowctl fails, expected), probes RP_ELIGIBLE, resolves $BACKEND via the single flowctl review-backend call, and handles the ASK / none cases. Every later bash block here (triage, deep-pass selection) uses the $FLOWCTL it defines. Never invoke flowctl review-backend a second time in the same run.
Exception: a --review=<backend> argument (see Backend Selection below) wins — when present, set BACKEND from the flag and skip Phase 0's review-backend call + ASK handling (still run its $FLOWCTL / RP_ELIGIBLE setup lines).
When RP_ELIGIBLE=0 (not macOS, no supported RepoPrompt CLI), never steer the user toward rp: every backend summary, recommendation, or override hint you surface presents only the runnable configured backends codex, copilot, cursor, host (plus none). export is an explicit one-off review MODE (--review=export), not a configured backend — never present it as one. Suppression is not a ban: an explicit --review=rp, FLOW_REVIEW_BACKEND=rp, or review.backend=rp still resolves to rp and errors at runtime via require_rp_cli().
Priority (first match wins):
--review=rp|codex|copilot|cursor|host|export|none argumentFLOW_REVIEW_BACKEND env var — bare backend (rp, codex, copilot, cursor, host, none) OR spec form (codex:gpt-5.4:xhigh, copilot:claude-opus-4.5, cursor:gpt-5.5-high); host is bare-only (host:<model> is rejected).flow/config.json → review.backend (same bare / spec forms)Check $ARGUMENTS for:
--review=rp or --review rp → use rp--review=codex or --review codex → use codex--review=copilot or --review copilot → use copilot--review=cursor or --review cursor → use cursor--review=host or --review host → use host--review=export or --review export → use export--review=none or --review none → skip reviewIf found, use that backend and skip all other detection.
No --review flag → $BACKEND comes from workflow-common.md Phase 0 (executed once per the Preamble): the single flowctl review-backend "$REVIEW_ID" call with ASK handling included. Do not re-resolve here.
When RP_ELIGIBLE=0, omit the rp line below from any guidance you surface (explicit --review=rp still honored):
gpt-5.5). FLOW_CODEX_MODEL / FLOW_CODEX_EFFORT env vars, or --spec codex:gpt-5.4:xhigh.FLOW_COPILOT_MODEL / FLOW_COPILOT_EFFORT env vars, or --spec copilot:claude-opus-4.5:xhigh.cursor-agent, cross-platform); reaches gpt-5.5-high (1M-ctx default), the gpt-5.3-codex family, composer-2.5, and Claude tiers (claude-opus-5-thinking-high, claude-opus-4-8-thinking-high) via a Cursor subscription. FLOW_CURSOR_MODEL env var, or --spec cursor:gpt-5.5-high. Cursor folds reasoning effort into the model name — no effort field.Spec grammar: backend[:model[:effort]] — FLOW_REVIEW_BACKEND and .flow/config.json review.backend both accept this. Examples: codex, codex:gpt-5.2, copilot:claude-opus-4.5:xhigh, cursor:gpt-5.5-high (cursor takes model only — no :effort), host (bare only). Per-task review (set via flowctl task set-backend) overrides env.
For rp backend:
setup-review - handles window selection + builder atomically--new-chat after first reviewFor codex backend:
$FLOWCTL codex impl-review exclusively--receipt for session continuity on re-reviewsFor copilot backend:
$FLOWCTL copilot impl-review exclusively--receipt for session continuity on re-reviews (session only resumes when prior receipt has mode == "copilot")--spec backend:model:effort flag, per-task review, FLOW_REVIEW_BACKEND spec, FLOW_COPILOT_MODEL / FLOW_COPILOT_EFFORT env vars, registry defaultsFor cursor backend:
$FLOWCTL cursor impl-review exclusively--receipt for session continuity on re-reviews (session only resumes when prior receipt has mode == "cursor")--spec cursor:<model> flag, per-task review, FLOW_REVIEW_BACKEND spec, FLOW_CURSOR_MODEL env var, registry default (gpt-5.5-high). No effort — Cursor bakes effort into the model name; cursor:<model>:<effort> is rejectedFor host backend (fn-123 R5 / fn-126):
host is bare-only. After selection, read workflow-host.md.
The review must use a fresh, tool-enforced read-only reviewer from a different
model family and fail closed when no cross-family pin is available.
For all backends:
REVIEW_RECEIPT_PATH set: write receipt after review (any verdict)<promise>RETRY</promise> and stopFORBIDDEN:
Arguments: $ARGUMENTS
Format: [task ID] [--base <commit>] [--validate] [--deep[=passes]] [--interactive] [focus areas]
--base <commit> - Compare against this commit instead of main/master (for task-scoped reviews)--validate - After NEEDS_WORK verdict, run a validator pass that drops false-positive findings (fn-32.1, opt-in)--deep / --deep=<passes> - Run additional specialized passes (adversarial / security / performance) after primary review (fn-32.2, opt-in)--interactive - On NEEDS_WORK, walk through each finding with the user (Apply/Defer/Skip/Acknowledge) (fn-32.3, opt-in, Ralph-incompatible)Scope behavior:
--base: Reviews only changes since that commit (task-scoped)--base: Reviews entire branch vs main/master (full branch review)Opt-in flags (fn-32):
--validate — adds a validator pass on NEEDS_WORK that re-checks each finding
for false positives. All findings dropping upgrades verdict to SHIP.FLOW_VALIDATE_REVIEW=1 env var — enables --validate session-wide (works in Ralph).--deep — adds adversarial pass always + security/performance auto-enabled
per diff paths. --deep=adversarial,security restricts to listed passes.FLOW_REVIEW_DEEP=1 env var — enables --deep session-wide (works in Ralph).--interactive — per-finding walkthrough on NEEDS_WORK. No env var form —
per-invocation only, always hard-errors in Ralph mode (REVIEW_RECEIPT_PATH or
FLOW_RALPH=1) to prevent accidental autonomous engagement.REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null || pwd)"
Parse $ARGUMENTS for:
--base <commit> → BASE_COMMIT (if provided, use for scoped diff)--no-triage → set TRIAGE_DISABLED=1 (skip trivial-diff pre-check)--validate → set VALIDATE=true (fn-32.1 validator pass on NEEDS_WORK)--deep / --deep=<passes> → set DEEP=true + optional DEEP_PASSES CSV (fn-32.2)--interactive → set INTERACTIVE=true (fn-32.3 per-finding walkthrough on NEEDS_WORK; Ralph-blocked)fn-* → TASK_IDIf --base not provided, BASE_COMMIT stays empty (will fall back to main/master).
Opt-in flags + env vars — ONE parse fence (fn-110) for --validate / --deep / --interactive:
VALIDATE=false
DEEP=false
DEEP_PASSES="" # optional CSV: "adversarial,security"
INTERACTIVE=false
for arg in $ARGUMENTS; do
case "$arg" in
--validate) VALIDATE=true ;;
--deep) DEEP=true ;;
--deep=*) DEEP=true; DEEP_PASSES="${arg#--deep=}" ;;
--interactive) INTERACTIVE=true ;;
esac
done
# Env opt-ins (Ralph-friendly). --interactive has NO env var form — per-invocation only.
if [[ "${FLOW_VALIDATE_REVIEW:-}" == "1" ]]; then
VALIDATE=true
fi
if [[ "${FLOW_REVIEW_DEEP:-}" == "1" ]]; then
DEEP=true
fi
# Ralph-block (fn-32.3): Ralph must never engage interactive.
if [[ "$INTERACTIVE" == "true" ]]; then
if [[ -n "${REVIEW_RECEIPT_PATH:-}" || "${FLOW_RALPH:-}" == "1" ]]; then
echo "Error: --interactive requires a user at the terminal; not compatible with Ralph mode (REVIEW_RECEIPT_PATH or FLOW_RALPH detected)." >&2
exit 2
fi
fi
VALIDATE gates the validator pass in workflow-common.md. When false (default),
behavior is unchanged.
DEEP gates the deep-pass phase in workflow-common.md. When false (default),
behavior is unchanged.
Pass selection (when DEEP=true):
# If explicit CSV provided, use those passes verbatim.
# Otherwise: adversarial always + security/performance auto-enabled by
# changed-file globs via `flowctl review-deep-auto`.
if [[ -n "$DEEP_PASSES" ]]; then
SELECTED_PASSES="${DEEP_PASSES//,/ }"
else
# Determine changed files for auto-enable heuristic
if [[ -n "$BASE_COMMIT" ]]; then
CHANGED="$(git diff --name-only "$BASE_COMMIT"..HEAD)"
else
DIFF_BASE=main; git rev-parse main >/dev/null 2>&1 || DIFF_BASE=master
CHANGED="$(git diff --name-only "$DIFF_BASE"..HEAD)"
fi
SELECTED_PASSES="$(printf '%s\n' "$CHANGED" | $FLOWCTL review-deep-auto)"
fi
echo "Deep passes selected: $SELECTED_PASSES"
See deep-passes.md for the pass prompt templates, the auto-enable globs, and merge/promotion rules.
Interactive flag + Ralph-block (fn-32.3): parsed and Ralph-blocked in the single fence above (no env var form — per-invocation only).
INTERACTIVE gates the walkthrough phase in walkthrough.md.
When false (default), behavior is unchanged. When true + verdict is
NEEDS_WORK, the skill walks each finding with the user via the platform's
blocking question tool (Apply / Defer / Skip / Acknowledge / LFG-rest).
See walkthrough.md for the full per-finding flow and deferred-findings sink contract.
Before invoking the configured backend, run a fast pre-check that short-circuits
lockfile-only, docs-only, release-chore, and generated-file diffs. On SKIP, the
receipt is written with mode: "triage_skip" / verdict: "SHIP" and the
expensive backend call is skipped entirely.
Opt-out: --no-triage argument or FLOW_RALPH_NO_TRIAGE=1 env var.
if [[ -z "${TRIAGE_DISABLED:-}" && -z "${FLOW_RALPH_NO_TRIAGE:-}" ]]; then
RECEIPT_PATH="${REVIEW_RECEIPT_PATH:-/tmp/impl-review-receipt${TASK_ID:+-${TASK_ID}}.json}" # fn-90 R5: task-scoped default (concurrent tasks no longer collide); explicit REVIEW_RECEIPT_PATH still wins
# Subcommand + one literal flag stay on the command line (the Ralph guard
# blocks a variable in either of the two tokens after the launcher).
TRIAGE_ARGS=(--receipt "$RECEIPT_PATH")
[[ -n "$BASE_COMMIT" ]] && TRIAGE_ARGS+=(--base "$BASE_COMMIT")
[[ -n "$TASK_ID" ]] && TRIAGE_ARGS+=(--task "$TASK_ID")
# Deterministic-only by default; set FLOW_TRIAGE_LLM=1 to enable LLM judge
# for ambiguous diffs. Deterministic is conservative — ambiguous → REVIEW.
[[ -z "${FLOW_TRIAGE_LLM:-}" ]] && TRIAGE_ARGS+=(--no-llm)
if TRIAGE_OUT=$($FLOWCTL triage-skip --json "${TRIAGE_ARGS[@]}" 2>/dev/null); then
# Exit 0 = SKIP. Receipt already written by flowctl.
SKIP_REASON=$(echo "$TRIAGE_OUT" | jq -r '.reason // "trivial diff"' 2>/dev/null || echo "trivial diff")
echo "Triage-skip: $SKIP_REASON"
echo "VERDICT=SHIP"
exit 0
fi
# Exit 1 = proceed to full review (normal path). Exit >=2 = error, also falls
# through so impl-review proceeds safely rather than failing on triage.
fi
Opt-out note: Pass --no-triage to force the full backend review (useful
when explicitly validating a suspicious chore diff, or when the deterministic
whitelist misclassifies). FLOW_RALPH_NO_TRIAGE=1 has the same effect for
Ralph runs.
$BACKEND was already resolved by workflow-common.md Phase 0 (Preamble) — do NOT re-run it.$BACKEND | File to read |
|---|---|
codex | workflow-codex.md |
copilot | workflow-copilot.md |
cursor | workflow-cursor.md |
host | workflow-host.md |
rp | workflow-rp.md |
Do not read the other backend files. Each is self-contained for its backend; loading the others wastes context.
Follow the phases in the per-backend file end-to-end. Each file owns its own Identify → Execute → Verdict → Receipt steps (and, for RP, the full Phase 1-4 setup-review / chat-send / receipt build + Fix Loop). Cross-backend gated phases (Deep-Pass, Validator, Interactive Walkthrough) live in workflow-common.md — the backend files reference them.
CRITICAL: Do NOT ask user for confirmation. Automatically fix ALL valid issues and re-review — our goal is production-grade world-class software and architecture. Never use AskUserQuestion in this loop.
MAJOR_RETHINK is NOT a fix-loop input. Every backend can emit MAJOR_RETHINK (a valid verdict tag), but it means the design/approach is wrong — not something to patch finding-by-finding. Do NOT enter the fix loop on it. Escalate immediately: surface the reviewer's rationale to the caller and stop with a typed BLOCKED: DESIGN_CONFLICT (Ralph mode: output <promise>RETRY</promise>). A re-approach is a human/worker decision, never an ad-hoc patch. Only NEEDS_WORK drives the loop below.
MAX ITERATIONS (backend-agnostic — rp, codex, copilot, cursor, host):
flowctl reserves a per-task round before every task-scoped dispatch. A delivered
SHIP / NEEDS_WORK / MAJOR_RETHINK / NEEDS_HUMAN consumes it; a no-verdict transport failure
is durably recorded and refunded. At ${MAX_REVIEW_ITERATIONS:-8} verdict
rounds it refuses with ESCALATE: + exit 4. More than
${MAX_REVIEW_TRANSPORT_FAILURES:-2} consecutive no-verdict failures stop
separately with TRANSPORT_UNHEALTHY + exit 5: repair the backend, never reset
the verdict counter. This loop is internal; callers invoke impl-review once.
The counter resets only on SHIP or explicit re-plan, never on an edit, fresh
invocation, or transport failure.**
Unchanged-artifact terminal: NOT_RETRYABLE: artifact unchanged since last verdict exits 1 before a review is sent. It is a human-action terminal:
autonomous loops must stop without refunding, resetting, adding --force, or
redispatching. The human may edit the artifact, explicitly reset, or choose a
deliberate --force dispatch.
ANTI-PATTERN (never do either):
VERDICT=SHIP|NEEDS_WORK|MAJOR_RETHINK|NEEDS_HUMAN, the round is consumed and the
attempt is recorded; transport classification is unreachable past that
point. Do not re-dispatch, re-frame a NEEDS_WORK as a backend/sandbox
problem, or claim a refund for it. NEEDS_WORK is fix-loop input, full
stop.read-only). A sandbox-blocked reviewer means something
asked it to mutate the workspace: fix that, do not pass
--sandbox workspace-write / danger-full-access or set CODEX_SANDBOX.
The one exception is Windows, where auto already resolves for you.If verdict is NEEDS_WORK, loop internally until SHIP or the iteration cap:
DEEP=true) — see optional-phases.md § Deep-Pass Phase.
$FLOWCTL <backend> deep-pass --pass <name> --receipt ... --primary-findings ....SHIP → NEEDS_WORK if it surfaces new blocking findings;
it never downgrades NEEDS_WORK → SHIP.VALIDATE=true) — see optional-phases.md § Validator Pass.
$FLOWCTL <backend> validate --findings-file ... --receipt ...INTERACTIVE=true AND verdict still NEEDS_WORK) — see walkthrough.md.
.flow/review-deferred/<branch-slug>.md.walkthrough: {applied, deferred, skipped, acknowledged}.git add --all)flowctl codex impl-review (receipt enables context)flowctl copilot impl-review (receipt enables context; must be mode == "copilot" to resume)flowctl cursor impl-review (receipt enables context; must be mode == "cursor" to resume)$FLOWCTL rp chat-send --window "$W" --tab "$T" --message-file <literal re-review path from workflow-rp.md's fix loop> (NO --new-chat; stdout redirected to the same literal response file, Read once)$FLOWCTL rp chat-send --window "$W" --context-id "$T" --chat-id "$CHAT_ID" --mode review --message-file <literal re-review path> (T is the canonical context binding, not visible-tab projection; NO --tab; same response-file rule)<verdict>SHIP</verdict> — or the MAX ITERATIONS cap above breaks the loop (escalate with surviving findings)CRITICAL: For RP, re-reviews must stay in the SAME chat so reviewer has context. Only use --new-chat on the FIRST review.
Alternatives
gmickel/flow-next
Carmack-level implementation review of changes via the configured backend. Use when asked to review code or a diff in a flow-next repo.
PramodDutta/qaskills
Gate RAG pipelines in CI with versioned golden eval sets, per-metric thresholds, baseline drift detection, and a build that fails when retrieval or answer quality regresses.
PramodDutta/qaskills
Generate comprehensive test cases from state machine models covering all states, transitions, guard conditions, and invalid transition attempts for workflow-heavy features
Borda/AI-Rig
Codex-native code-remediation loop: triage/apply code-review findings, rerun checks, publish unresolved gaps with measurable gates; `$code-remediate #123 +review` remediates a PR from latest matching code-review artifact.