ring:reviewing-code

A code-review workflow that sends several reviewers to inspect a change at the same time, then combines their findings into a severity-ranked report. Some extra reviewers are added when the changed code touches certain systems.

In plain words
What is it for?
Use it after major implementation work, complex bug fixes, or before merging to the main branch. It is intended for the code-review stage of a larger development process.
Why use it?
It helps catch problems before a large feature or bug fix is merged. It also separates finding issues from fixing them, so the review result stays clear.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/lerianstudio/ring/reviewing-code
Any agent
npx skills add LerianStudio/ring --skill reviewing-code
Clone the repo
git clone --depth 1 https://github.com/LerianStudio/ring

Made for: Claude Code, Codex.

Per session 97 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,016 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00097 $0.02016
Opus 5 $0.00048 $0.01008
Sonnet 5 $0.00019 $0.00403
Haiku 4.5 $0.00010 $0.00202

Measured 2d ago against content hash a2b73d812fbe, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ring:reviewing-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

default/skills/reviewing-code/SKILL.md · 196 lines

How it starts

The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Review (Gate 8)

When to use

  • Gate 8 of development cycle
  • After completing major feature implementation
  • Before merge to main branch
  • After completing complex bug work

Skip when

  • Task is purely conversational or informational with no code changes
  • Changes are limited to documentation or comments with zero logic modifications
  • Code has not been modified since the last completed review cycle

Sequence

Runs after: ring:implementing-tasks Runs before: ring:validating-acceptance-criteria

Complementary: ring:running-dev-cycle, ring:implementing-tasks

Dispatch the 9 default reviewer subagents in parallel, plus any triggered conditional specialists. Dispatch count is dynamic: 9 + triggered specialists, max 12. Do not say or imply all 12 always dispatch.

Announce at start: "Using ring:reviewing-code to dispatch 9 default reviewers plus triggered conditional specialists."

Report-only boundary: This skill does not remediate findings, dispatch implementation work, write comments into source files, generate external artifacts, invoke secondary review tools, or re-run reviewers automatically. It only dispatches the selected reviewers once and reports their findings in the current session.

Default Reviewers (Hard Gate)

# Agent Focus
1 ring:code-reviewer Architecture, design patterns, code quality
2 ring:logic-reviewer Domain correctness, business rules, edge cases
3 ring:security-reviewer Vulnerabilities, authentication, OWASP risks
4 ring:test-reviewer Test quality, coverage, edge cases, anti-patterns
5 ring:nil-reviewer Nil/null pointer safety for Go and TypeScript
6 ring:dead-code-reviewer Orphaned code detection, reachability analysis
7 ring:perf-reviewer Performance hotspots, allocations, goroutine leaks, N+1
8 ring:tenancy-reviewer Multi-tenant patterns, tenantId propagation, DB isolation
9 ring:commons-reviewer lib-commons package usage and reinvented-wheel opportunities

Read the full file on GitHub · 196 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 196 lines · 97 tokens per session scan A a2b73d812fbe

Subscribe to this mod's changes

ring:reviewing-code is a skill published in the GitHub repository LerianStudio/ring (210 stars, last pushed 13d ago), licensed Apache-2.0. It adds 97 tokens to every session and 2,016 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

brainstorm

Explores a codebase, researches the problem space, and produces an approved design specification before any code is written. Use when the user wants to create a new feature, add significant functionality, redesign a subsystem, or build something that touches multiple parts of the project.

greglas75/zuvo · 56 tokens

pentest

Hybrid white-box + black-box penetration testing across 7 dimensions (PT1-PT7). Stack-aware source-to-sink tracing, exploit verification, CMS overlay, and deterministic finding aggregation. Uses explicit candidate schemas, canonical-key deduplication, score caps, and MUST-GATE enforcement. Flags: zuvo:pentest [path] |…

greglas75/zuvo · 124 tokens

a11y-audit

Dedicated WCAG 2.2 AA/AAA accessibility audit across 10 dimensions (A1-A10) covering semantic HTML, keyboard navigation, ARIA patterns, color contrast, forms, images/media, responsive/zoom, motion/animation, reading/content, and legal compliance. Goes far beyond surface-level design-review checks with deep…

greglas75/zuvo · 147 tokens

debug

Systematic bug investigation with a five-phase framework: reproduce, narrow, diagnose, fix, verify. Supports automated regression bisect via --regression flag. Produces a structured debug report with root cause analysis, regression test, and CQ/Q self-evaluations.

greglas75/zuvo · 55 tokens

init

Write or refresh the ## Tech debt operations section in CLAUDE.md so a team shares one source of truth for debt-ops disciplines and cached quality commands. Idempotent. Only the managed section changes; other sections are untouched. Invoked explicitly via /debt-ops:init (solo users get the same content from the…

bcanfield/agentic-tech-debt · 74 tokens

debt-ops-init

Write or refresh a "Tech debt operations" section in the project's AGENTS.md so the team shares one source of truth for debt-ops disciplines. Run ONLY when the user explicitly asks to set up, install, or initialize debt-ops disciplines — never auto-invoke. Idempotent; only the managed section changes, other sections…

bcanfield/agentic-tech-debt · 76 tokens