review
v0.32.0Code-review toolkit: six reviewer agents, read-only over the reviewed code (code, security, architecture, doc drift, build/test/lint, CI-log audit), plus orchestration skills for the quality gate, fan-out, and enforceability audit (/review:audit-enforceability), and CI lane commands (/review:code-review, /review:security-review) for org reusable workflows.
By Melodic SoftwareLicense: MIT20 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 6 skill or MCP entries
- Source updated
- Sep 28, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install review for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install review-6@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/melodic-software/claude-code-pluginsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/review/.
Plugin files
├── .claude-plugin/plugin.json├── skills/audit-enforceability/SKILL.md├── skills/code-review/SKILL.md├── skills/fanout/SKILL.md├── skills/quality-gate/SKILL.md├── skills/security-review/SKILL.md└── skills/setup/SKILL.md
Included Skills6
Audit which review findings a deterministic check could catch instead of a model re-deriving them every run: read ONE operator-named findings file, derive a finding class per row, map it through the crosswalk to the cheapest enforcement rung (editorconfig severity, analyzer-pack rule, custom analyzer, Semgrep rule, architecture test, hook, or llm-only), and write one proposal stub per finding naming that rung and its owner. Use when: 'which of these findings could a linter or analyzer catch', 'audit enforceability', 'promote findings to a deterministic check', 'what rung catches this', 'can we stop re-finding this'. 'Enforceability' here means whether ONE finding can be caught deterministically; it is not the question of whether a convention is machine-checkable, and not the C1-C5 promotion the autonomy work classes use. Read-only on the reviewed code and on the findings file it reads; the memory-tier stubs it writes are its report. It proposes a rung and never implements one.
CI code-review lane for a GitHub pull request. High-signal correctness and maintainability findings only, scoped out of security when a security lane exists. When the bundled code-review skill resolves in your session, prefer it for a session-driven review of the current diff or a named PR; this skill for the CI lane a reusable workflow runs on one PR. Use when: 'CI code review', 'claude-review lane', '/review:code-review', or a reusable workflow invokes the org code-review plugin command.
Fan out review across many finding-producing surfaces at once, this plugin's reviewer agents, the project's own per-concern review criteria docs, and orchestrator review plugins, then normalize the heterogeneous outputs into one severity-ranked, deduplicated report persisted to disk. Use when asked for a breadth review of a change (every reviewer at once, every angle or side, one combined ranked report), or to 'fix the review findings' (the fix action applies the merged set of persisted findings).
Single-lens review checkpoint between 'code works' and 'code is ready'. Routes to self, code, architecture, security, spec, close-out, downstream, pr, criteria, slice, or restatement mode and delegates to the matching reviewer. Use when the user says 'review this', 'self-review', 'quality gate', 'code review', 'architecture review', 'security review', 'does this match the spec/issue/plan', or 'close-out review' / 'review the container' for a shipped spec container, or after implementation completes. Downstream mode covers 'what could this break', 'blast radius', 'what else does this touch', 'who calls this'. Breakage outside the diff on a change already written; assessing a plan's reach before implementation is '/planning:plan' and '/planning:devils-advocate', and a rename sweep is '/docs-hygiene:rename-references audit blast'.
CI security-review lane for a GitHub pull request. Logic, trust-boundary, and Actions security findings static analysis misses. When the plugin-backed built-in security-review command resolves in your session, prefer it for a one-off security pass over your current branch; this skill for the CI lane a reusable workflow runs on one PR. Use when: 'CI security review', 'claude-security-review lane', '/review:security-review', or a reusable workflow invokes the org security-review plugin command.
Configure the review plugin for this repository: bootstrap the consumer's standards index per the standards convention, since review criteria resolve through that index, persisting docs/standards/ and, on relocation, .claude/standards.yaml. Use when: 'set up review', 'configure the review plugin', 'review setup', 'set up standards', 'bootstrap the standards index', or a review skill reports a missing or version-skewed standards index. Actions: check (read-only verification, default) | apply (bootstrap, reconfigure, or migrate). Re-runnable.
Plugin manifests1
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "review",
"version": "0.32.0",
"description": "Code-review toolkit: six reviewer agents, read-only over the reviewed code (code, security, architecture, doc drift, build/test/lint, CI-log audit), plus orchestration skills for the quality gate, fan-out, and enforceability audit (/review:audit-enforceability), and CI lane commands (/review:code-review, /review:security-review) for org reusable workflows.",
"author": {
"name": "Melodic Software",
"email": "[email protected]"
},
"license": "MIT",
"keywords": [
"review",
"code-review",
"security",
"architecture",
"quality-gate",
"ci",
"agents",
"skill"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[review on Agent Plugins Marketplace](https://pluginsmp.com/plugins/review-6)