Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Quality Review

ASecurity

Deep code review with web research. Use when double-checking code

19 stars
0 votes
0 copies
1 views
Added 10/4/2026
code-qualityreacttestingapici/cdsecurityperformancedocumentation

Works with

api

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add TheMostlyGreat/mythos --skill quality-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quality Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Quality Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/themostlygreat-quality-review/badge)](https://www.skillsdirectory.com/skills/themostlygreat-quality-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: quality-review
description: Deep code review with web research. Use when double-checking code
  against latest docs, verifying dependency versions, or reviewing security
  concerns. Complements automatic quality hook with ecosystem verification.
allowed-tools: "*"
---

# Quality Reviewing

Deep review with web research to verify against current ecosystem. Complements automatic hook.

**When to use this skill (not automatic hook):**

- **Explicit web research**: "double check against latest docs", "verify versions", "check security"
- **Deep dive needed**: Performance, architecture, trade-offs beyond automatic hook
- **Pre-change review**: Review before making changes (hook only triggers after)

**Relationship:** Automatic hook does fast check with existing knowledge. This skill does deep dive with web research (2-3 min).

## 1. Detect Phase

If in BDD workflow, read current ticket from `.safeword-project/tickets/` and apply phase-appropriate research:

| Phase           | Research Focus                                  |
| --------------- | ----------------------------------------------- |
| intake          | Similar features in ecosystem, scope patterns   |
| define-behavior | Testing patterns, BDD research and patterns     |
| scenario-gate   | Architecture patterns, test layer strategy      |
| implement       | **Library versions, deprecated APIs, security** |
| done            | CI/CD patterns, release checklists              |

## 2. Verify Versions (Primary Value)

**CRITICAL**: This is your main differentiator from automatic hook.

Search for: "[library name] latest stable version 2025"
Search for: "[library name] security vulnerabilities"

**Flag if outdated:**

- Major versions behind -> WARN (e.g., React 17 when 19 is stable)
- Minor versions behind -> NOTE
- Security vulnerabilities -> CRITICAL (must upgrade)
- Using latest -> Confirm

## 3. Verify Documentation (Primary Value)

Fetch official documentation for libraries in use.

**Look for:**

- Deprecated APIs being used?
- Newer, better patterns available?
- Recent recommendation changes?

## Output Format

```markdown
## Quality Review

**Versions:** [✓/⚠️/❌] [Latest version check]
**Documentation:** [✓/⚠️/❌] [Current docs check]
**Security:** [✓/⚠️/❌] [Vulnerability check]

**Verdict:** [APPROVE / REQUEST CHANGES / NEEDS DISCUSSION]

**Critical issues:** [List or "None"]
**Suggested improvements:** [List or "None"]
**Provenance:** For version/API claims:

- (verified: [source URL or doc title]) — fetched this session
- (training data: may be outdated) — not verified
- (uncertain) — could not verify

**Next:** [concrete action — upgrade X from a.b.c to x.y.z, refactor {file}:{line}, ask team about Z, or proceed to implementation if APPROVE]
```

The `**Next:**` line is required. On APPROVE, name what to do now (proceed, commit, run /verify). On REQUEST CHANGES, name the specific edit and re-review trigger. On NEEDS DISCUSSION, name the question to ask. A verdict that doesn't tell the reader what to do next is incomplete.

## Reminders

1. **Primary value: Web research** - Verify versions, docs, security
2. **Complement automatic hook** - Hook prompts for the decision-brief verdict and per-phase evidence; you verify versions, primary-literature claims, and ecosystem context the hook can't see
3. **Phase matters** - Adapt research focus to current BDD phase
4. **Be concise** - Hook already prompts for general quality, focus on what it can't do

**Voice:** plainspoken and concise — write to be scanned.

Attribution

TheMostlyGreatTheMostlyGreat
View sourceSee grades on GitHubMore from TheMostlyGreat →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman Commit

Ultra-compressed commit message generator. Cuts noise from commit messages while preserving intent and reasoning. Conventional Commits format. Subject ≤50 chars, body only when "why" isn't obvious. Use when user says "write a commit", "commit message", "generate commit", "/commit", or invokes /caveman-commit. Auto-triggers when staging changes.

1100021 votes

Caveman Review

Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", "/review", or invokes /caveman-review. Auto-triggers when reviewing pull requests.

1100021 votes

Verification Loop

一个全面的 Claude Code 会话验证系统。

2456590 votes

Django Verification

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

2456590 votes

Springboot Verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

2456590 votes
View all in code-quality →