GitHub Code Review Skill
Comprehensive GitHub code review with AI-powered swarm coordination
by ruvnet·MIT license·★ 94,702 Stars on the repo·GitHub ↗
npx degit ruvnet/RuView/.claude/skills/github-code-review#main ~/.claude/skills/github-code-reviewChecked ·commit main
Files of GitHub Code Review Skill
Show the full text1141 lines
GitHub Code Review Skill
AI-Powered Code Review: Deploy specialized review agents to perform comprehensive, intelligent code reviews that go beyond traditional static analysis.
🎯 Quick Start
Simple Review
# Initialize review swarm for PR
gh pr view 123 --json files,diff | npx ruv-swarm github review-init --pr 123
# Post review status
gh pr comment 123 --body "🔍 Multi-agent code review initiated"
Complete Review Workflow
# Get PR context with gh CLI
PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body)
PR_DIFF=$(gh pr diff 123)
# Initialize comprehensive review
npx ruv-swarm github review-init \
--pr 123 \
--pr-data "$PR_DATA" \
--diff "$PR_DIFF" \
--agents "security,performance,style,architecture,accessibility" \
--depth comprehensive
📚 Table of Contents
Core Features
Review Agents
Advanced Features
Integration & Automation
🚀 Core Features
Multi-Agent Review System
Deploy specialized AI agents for comprehensive code review:
# Initialize review swarm with GitHub CLI integration
PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body)
PR_DIFF=$(gh pr diff 123)
# Start multi-agent review
npx ruv-swarm github review-init \
--pr 123 \
--pr-data "$PR_DATA" \
--diff "$PR_DIFF" \
--agents "security,performance,style,architecture,accessibility" \
--depth comprehensive
# Post initial review status
gh pr comment 123 --body "🔍 Multi-agent code review initiated"
Benefits:
- ✅ Parallel review by specialized agents
- ✅ Comprehensive coverage across multiple domains
- ✅ Faster review cycles with coordinated analysis
- ✅ Consistent quality standards enforcement
🤖 Specialized Review Agents
Security Review Agent
Focus: Identify security vulnerabilities and suggest fixes
# Get changed files from PR
CHANGED_FILES=$(gh pr view 123 --json files --jq '.files[].path')
# Run security-focused review
SECURITY_RESULTS=$(npx ruv-swarm github review-security \
--pr 123 \
--files "$CHANGED_FILES" \
--check "owasp,cve,secrets,permissions" \
--suggest-fixes)
# Post findings based on severity
if echo "$SECURITY_RESULTS" | grep -q "critical"; then
# Request changes for critical issues
gh pr review 123 --request-changes --body "$SECURITY_RESULTS"
gh pr edit 123 --add-label "security-review-required"
else
# Post as comment for non-critical issues
gh pr comment 123 --body "$SECURITY_RESULTS"
fi
Security Checks Performed
{
"checks": [
"SQL injection vulnerabilities",
"XSS attack vectors",
"Authentication bypasses",
"Authorization flaws",
"Cryptographic weaknesses",
"Dependency vulnerabilities",
"Secret exposure",
"CORS misconfigurations"
],
"actions": [
"Block PR on critical issues",
"Suggest secure alternatives",
"Add security test cases",
"Update security documentation"
]
}
Comment Template: Security Issue
🔒 **Security Issue: [Type]**
**Severity**: 🔴 Critical / 🟡 High / 🟢 Low
**Description**:
[Clear explanation of the security issue]
**Impact**:
[Potential consequences if not addressed]
**Suggested Fix**:
```language
[Code example of the fix]
References:
</details>
---
### Performance Review Agent
**Focus:** Analyze performance impact and optimization opportunities
```bash
# Run performance analysis
npx ruv-swarm github review-performance \
--pr 123 \
--profile "cpu,memory,io" \
--benchmark-against main \
--suggest-optimizations
Performance Metrics Analyzed
{
"metrics": [
"Algorithm complexity (Big O analysis)",
"Database query efficiency",
"Memory allocation patterns",
"Cache utilization",
"Network request optimization",
"Bundle size impact",
"Render performance"
],
"benchmarks": [
"Compare with baseline",
"Load test simulations",
"Memory leak detection",
"Bottleneck identification"
]
}
Architecture Review Agent
Focus: Evaluate design patterns and architectural decisions
# Architecture review
npx ruv-swarm github review-architecture \
--pr 123 \
--check "patterns,coupling,cohesion,solid" \
--visualize-impact \
--suggest-refactoring
Architecture Analysis
{
"patterns": [
"Design pattern adherence",
"SOLID principles",
"DRY violations",
"Separation of concerns",
"Dependency injection",
"Layer violations",
"Circular dependencies"
],
"metrics": [
"Coupling metrics",
"Cohesion scores",
"Complexity measures",
"Maintainability index"
]
}
Style & Convention Agent
Focus: Enforce coding standards and best practices
# Style enforcement with auto-fix
npx ruv-swarm github review-style \
--pr 123 \
--check "formatting,naming,docs,tests" \
--auto-fix "formatting,imports,whitespace"
Style Checks
{
"checks": [
"Code formatting",
"Naming conventions",
"Documentation standards",
"Comment quality",
"Test coverage",
"Error handling patterns",
"Logging standards"
],
"auto-fix": [
"Formatting issues",
"Import organization",
"Trailing whitespace",
"Simple naming issues"
]
}
🔄 PR-Based Swarm Management
Create Swarm from PR
# Create swarm from PR description using gh CLI
gh pr view 123 --json body,title,labels,files | npx ruv-swarm swarm create-from-pr
# Auto-spawn agents based on PR labels
gh pr view 123 --json labels | npx ruv-swarm swarm auto-spawn
# Create swarm with full PR context
gh pr view 123 --json body,labels,author,assignees | \
npx ruv-swarm swarm init --from-pr-data
Label-Based Agent Assignment
Map PR labels to specialized agents:
{
"label-mapping": {
"bug": ["debugger", "tester"],
"feature": ["architect", "coder", "tester"],
"refactor": ["analyst", "coder"],
"docs": ["researcher", "writer"],
"performance": ["analyst", "optimizer"],
"security": ["security", "authentication", "audit"]
}
}
Topology Selection by PR Size
# Automatic topology selection based on PR complexity
# Small PR (< 100 lines): ring topology
# Medium PR (100-500 lines): mesh topology
# Large PR (> 500 lines): hierarchical topology
npx ruv-swarm github pr-topology --pr 123
🎬 PR Comment Commands
Execute swarm commands directly from PR comments:
<!-- In PR comment -->
/swarm init mesh 6
/swarm spawn coder "Implement authentication"
/swarm spawn tester "Write unit tests"
/swarm status
/swarm review --agents security,performance
Webhook Handler for Comment Commands
// webhook-handler.js
const { createServer } = require('http');
const { execSync } = require('child_process');
createServer((req, res) => {
if (req.url === '/github-webhook') {
const event = JSON.parse(body);
if (event.action === 'opened' && event.pull_request) {
execSync(`npx ruv-swarm github pr-init ${event.pull_request.number}`);
}
if (event.comment && event.comment.body.startsWith('/swarm')) {
const command = event.comment.body;
execSync(`npx ruv-swarm github handle-comment --pr ${event.issue.number} --command "${command}"`);
}
res.writeHead(200);
res.end('OK');
}
}).listen(3000);
⚙️ Review Configuration
Configuration File
# .github/review-swarm.yml
version: 1
review:
auto-trigger: true
required-agents:
- security
- performance
- style
optional-agents:
- architecture
- accessibility
- i18n
thresholds:
security: block # Block merge on security issues
performance: warn # Warn on performance issues
style: suggest # Suggest style improvements
rules:
security:
- no-eval
- no-hardcoded-secrets
- proper-auth-checks
- validate-input
performance:
- no-n-plus-one
- efficient-queries
- proper-caching
- optimize-loops
architecture:
- max-coupling: 5
- min-cohesion: 0.7
- follow-patterns
- avoid-circular-deps
Custom Review Triggers
{
"triggers": {
"high-risk-files": {
"paths": ["**/auth/**", "**/payment/**", "**/admin/**"],
"agents": ["security", "architecture"],
"depth": "comprehensive",
"require-approval": true
},
"performance-critical": {
"paths": ["**/api/**", "**/database/**", "**/cache/**"],
"agents": ["performance", "database"],
"benchmarks": true,
"regression-threshold": "5%"
},
"ui-changes": {
"paths": ["**/components/**", "**/styles/**", "**/pages/**"],
"agents": ["accessibility", "style", "i18n"],
"visual-tests": true,
"responsive-check": true
}
}
}
🤖 Automated Workflows
Auto-Review on PR Creation
# .github/workflows/auto-review.yml
name: Automated Code Review
on:
pull_request:
types: [opened, synchronize]
issue_comment:
types: [created]
jobs:
swarm-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Setup GitHub CLI
run: echo "${{ secrets.GITHUB_TOKEN }}" | gh auth login --with-token
- name: Run Review Swarm
run: |
# Get PR context with gh CLI
PR_NUM=${{ github.event.pull_request.number }}
PR_DATA=$(gh pr view $PR_NUM --json files,title,body,labels)
PR_DIFF=$(gh pr diff $PR_NUM)
# Run swarm review
REVIEW_OUTPUT=$(npx ruv-swarm github review-all \
--pr $PR_NUM \
--pr-data "$PR_DATA" \
--diff "$PR_DIFF" \
--agents "security,performance,style,architecture")
# Post review results
echo "$REVIEW_OUTPUT" | gh pr review $PR_NUM --comment -F -
# Update PR status
if echo "$REVIEW_OUTPUT" | grep -q "approved"; then
gh pr review $PR_NUM --approve
elif echo "$REVIEW_OUTPUT" | grep -q "changes-requested"; then
gh pr review $PR_NUM --request-changes -b "See review comments above"
fi
- name: Update Labels
run: |
# Add labels based on review results
if echo "$REVIEW_OUTPUT" | grep -q "security"; then
gh pr edit $PR_NUM --add-label "security-review"
fi
if echo "$REVIEW_OUTPUT" | grep -q "performance"; then
gh pr edit $PR_NUM --add-label "performance-review"
fi
💬 Intelligent Comment Generation
Generate Contextual Review Comments
# Get PR diff with context
PR_DIFF=$(gh pr diff 123 --color never)
PR_FILES=$(gh pr view 123 --json files)
# Generate review comments
COMMENTS=$(npx ruv-swarm github review-comment \
--pr 123 \
--diff "$PR_DIFF" \
--files "$PR_FILES" \
--style "constructive" \
--include-examples \
--suggest-fixes)
# Post comments using gh CLI
echo "$COMMENTS" | jq -c '.[]' | while read -r comment; do
FILE=$(echo "$comment" | jq -r '.path')
LINE=$(echo "$comment" | jq -r '.line')
BODY=$(echo "$comment" | jq -r '.body')
COMMIT_ID=$(gh pr view 123 --json headRefOid -q .headRefOid)
# Create inline review comments
gh api \
--method POST \
/repos/:owner/:repo/pulls/123/comments \
-f path="$FILE" \
-f line="$LINE" \
-f body="$BODY" \
-f commit_id="$COMMIT_ID"
done
Batch Comment Management
# Manage review comments efficiently
npx ruv-swarm github review-comments \
--pr 123 \
--group-by "agent,severity" \
--summarize \
--resolve-outdated
🚪 Quality Gates & Checks
Status Checks
# Required status checks in branch protection
protection_rules:
required_status_checks:
strict: true
contexts:
- "review-swarm/security"
- "review-swarm/performance"
- "review-swarm/architecture"
- "review-swarm/tests"
Define Quality Gates
# Set quality gate thresholds
npx ruv-swarm github quality-gates \
--define '{
"security": {"threshold": "no-critical"},
"performance": {"regression": "<5%"},
"coverage": {"minimum": "80%"},
"architecture": {"complexity": "<10"},
"duplication": {"maximum": "5%"}
}'
Track Review Metrics
# Monitor review effectiveness
npx ruv-swarm github review-metrics \
--period 30d \
--metrics "issues-found,false-positives,fix-rate,time-to-review" \
--export-dashboard \
--format json
🎓 Advanced Features
Context-Aware Reviews
Analyze PRs with full project context:
# Review with comprehensive context
npx ruv-swarm github review-context \
--pr 123 \
--load-related-prs \
--analyze-impact \
--check-breaking-changes \
--dependency-analysis
Learning from History
Train review agents on your codebase patterns:
# Learn from past reviews
npx ruv-swarm github review-learn \
--analyze-past-reviews \
--identify-patterns \
--improve-suggestions \
--reduce-false-positives
# Train on your codebase
npx ruv-swarm github review-train \
--learn-patterns \
--adapt-to-style \
--improve-accuracy
Cross-PR Analysis
Coordinate reviews across related pull requests:
# Analyze related PRs together
npx ruv-swarm github review-batch \
--prs "123,124,125" \
--check-consistency \
--verify-integration \
--combined-impact
Multi-PR Swarm Coordination
# Coordinate swarms across related PRs
npx ruv-swarm github multi-pr \
--prs "123,124,125" \
--strategy "parallel" \
--share-memory
🛠️ Custom Review Agents
Create Custom Agent
// custom-review-agent.js
class CustomReviewAgent {
constructor(config) {
this.config = config;
this.rules = config.rules || [];
}
async review(pr) {
const issues = [];
// Custom logic: Check for TODO comments in production code
if (await this.checkTodoComments(pr)) {
issues.push({
severity: 'warning',
file: pr.file,
line: pr.line,
message: 'TODO comment found in production code',
suggestion: 'Resolve TODO or create issue to track it'
});
}
// Custom logic: Verify API versioning
if (await this.checkApiVersioning(pr)) {
issues.push({
severity: 'error',
file: pr.file,
line: pr.line,
message: 'API endpoint missing versioning',
suggestion: 'Add /v1/, /v2/ prefix to API routes'
});
}
return issues;
}
async checkTodoComments(pr) {
// Implementation
const todoRegex = /\/\/\s*TODO|\/\*\s*TODO/gi;
return todoRegex.test(pr.diff);
}
async checkApiVersioning(pr) {
// Implementation
const apiRegex = /app\.(get|post|put|delete)\(['"]\/api\/(?!v\d+)/;
return apiRegex.test(pr.diff);
}
}
module.exports = CustomReviewAgent;
Register Custom Agent
# Register custom review agent
npx ruv-swarm github register-agent \
--name "custom-reviewer" \
--file "./custom-review-agent.js" \
--category "standards"
🔧 CI/CD Integration
Integration with Build Pipeline
# .github/workflows/build-and-review.yml
name: Build and Review
on: [pull_request]
jobs:
build-and-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- run: npm install
- run: npm test
- run: npm run build
swarm-review:
needs: build-and-test
runs-on: ubuntu-latest
steps:
- name: Run Swarm Review
run: |
npx ruv-swarm github review-all \
--pr ${{ github.event.pull_request.number }} \
--include-build-results
Automated PR Fixes
# Auto-fix common issues
npx ruv-swarm github pr-fix 123 \
--issues "lint,test-failures,formatting" \
--commit-fixes \
--push-changes
Progress Updates to PR
# Post swarm progress to PR using gh CLI
PROGRESS=$(npx ruv-swarm github pr-progress 123 --format markdown)
gh pr comment 123 --body "$PROGRESS"
# Update PR labels based on progress
if [[ $(echo "$PROGRESS" | grep -o '[0-9]\+%' | sed 's/%//') -gt 90 ]]; then
gh pr edit 123 --add-label "ready-for-review"
fi
📋 Complete Workflow Examples
Example 1: Security-Critical PR
# Review authentication system changes
npx ruv-swarm github review-init \
--pr 456 \
--agents "security,authentication,audit" \
--depth "maximum" \
--require-security-approval \
--penetration-test
Example 2: Performance-Sensitive PR
# Review database optimization
npx ruv-swarm github review-init \
--pr 789 \
--agents "performance,database,caching" \
--benchmark \
--profile \
--load-test
Example 3: UI Component PR
# Review new component library
npx ruv-swarm github review-init \
--pr 321 \
--agents "accessibility,style,i18n,docs" \
--visual-regression \
--component-tests \
--responsive-check
Example 4: Feature Development PR
# Review new feature implementation
gh pr view 456 --json body,labels,files | \
npx ruv-swarm github pr-init 456 \
--topology hierarchical \
--agents "architect,coder,tester,security" \
--auto-assign-tasks
Example 5: Bug Fix PR
# Review bug fix with debugging focus
npx ruv-swarm github pr-init 789 \
--topology mesh \
--agents "debugger,analyst,tester" \
--priority high \
--regression-test
📊 Monitoring & Analytics
Review Dashboard
# Launch real-time review dashboard
npx ruv-swarm github review-dashboard \
--real-time \
--show "agent-activity,issue-trends,fix-rates,coverage"
Generate Review Reports
# Create comprehensive review report
npx ruv-swarm github review-report \
--format "markdown" \
--include "summary,details,trends,recommendations" \
--email-stakeholders \
--export-pdf
PR Swarm Analytics
# Generate PR-specific analytics
npx ruv-swarm github pr-report 123 \
--metrics "completion-time,agent-efficiency,token-usage,issue-density" \
--format markdown \
--compare-baseline
Export to GitHub Insights
# Export metrics to GitHub Insights
npx ruv-swarm github export-metrics \
--pr 123 \
--to-insights \
--dashboard-url
🔐 Security Considerations
Best Practices
- Token Permissions: Ensure GitHub tokens have minimal required scopes
- Command Validation: Validate all PR comments before execution
- Rate Limiting: Implement rate limits for PR operations
- Audit Trail: Log all swarm operations for compliance
- Secret Management: Never expose API keys in PR comments or logs
Security Checklist
- GitHub token scoped to repository only
- Webhook signatures verified
- Command injection protection enabled
- Rate limiting configured
- Audit logging enabled
- Secrets scanning active
- Branch protection rules enforced
📚 Best Practices
1. Review Configuration
- ✅ Define clear review criteria upfront
- ✅ Set appropriate severity thresholds
- ✅ Configure agent specializations for your stack
- ✅ Establish override procedures for emergencies
2. Comment Quality
- ✅ Provide actionable, specific feedback
- ✅ Include code examples with suggestions
- ✅ Reference documentation and best practices
- ✅ Maintain respectful, constructive tone
3. Performance Optimization
- ✅ Cache analysis results to avoid redundant work
- ✅ Use incremental reviews for large PRs
- ✅ Enable parallel agent execution
- ✅ Batch comment operations efficiently
4. PR Templates
<!-- .github/pull_request_template.md -->
## Swarm Configuration
- Topology: [mesh/hierarchical/ring/star]
- Max Agents: [number]
- Auto-spawn: [yes/no]
- Priority: [high/medium/low]
## Tasks for Swarm
- [ ] Task 1 description
- [ ] Task 2 description
- [ ] Task 3 description
## Review Focus Areas
- [ ] Security review
- [ ] Performance analysis
- [ ] Architecture validation
- [ ] Accessibility check
5. Auto-Merge When Ready
# Auto-merge when swarm completes and passes checks
SWARM_STATUS=$(npx ruv-swarm github pr-status 123)
if [[ "$SWARM_STATUS" == "complete" ]]; then
# Check review requirements
REVIEWS=$(gh pr view 123 --json reviews --jq '.reviews | length')
if [[ $REVIEWS -ge 2 ]]; then
# Enable auto-merge
gh pr merge 123 --auto --squash
fi
fi
🔗 Integration with Claude Code
Workflow Pattern
- Claude Code reads PR diff and context
- Swarm coordinates review approach based on PR type
- Agents work in parallel on different review aspects
- Progress updates posted to PR automatically
- Final review performed before marking ready
Example: Complete PR Management
[Single Message - Parallel Execution]:
// Initialize coordination
mcp__claude-flow__swarm_init { topology: "hierarchical", maxAgents: 5 }
mcp__claude-flow__agent_spawn { type: "reviewer", name: "Senior Reviewer" }
mcp__claude-flow__agent_spawn { type: "tester", name: "QA Engineer" }
mcp__claude-flow__agent_spawn { type: "coordinator", name: "Merge Coordinator" }
// Create and manage PR using gh CLI
Bash("gh pr create --title 'Feature: Add authentication' --base main")
Bash("gh pr view 54 --json files,diff")
Bash("gh pr review 54 --approve --body 'LGTM after automated review'")
// Execute tests and validation
Bash("npm test")
Bash("npm run lint")
Bash("npm run build")
// Track progress
TodoWrite { todos: [
{ content: "Complete code review", status: "completed", activeForm: "Completing code review" },
{ content: "Run test suite", status: "completed", activeForm: "Running test suite" },
{ content: "Validate security", status: "completed", activeForm: "Validating security" },
{ content: "Merge when ready", status: "pending", activeForm: "Merging when ready" }
]}
🆘 Troubleshooting
Common Issues
Issue: Review agents not spawning
Solution:
# Check swarm status
npx ruv-swarm swarm-status
# Verify GitHub CLI authentication
gh auth status
# Re-initialize swarm
npx ruv-swarm github review-init --pr 123 --force
Issue: Comments not posting to PR
Solution:
# Verify GitHub token permissions
gh auth status
# Check API rate limits
gh api rate_limit
# Use batch comment posting
npx ruv-swarm github review-comments --pr 123 --batch
Issue: Review taking too long
Solution:
# Use incremental review for large PRs
npx ruv-swarm github review-init --pr 123 --incremental
# Reduce agent count
npx ruv-swarm github review-init --pr 123 --agents "security,style" --max-agents 3
# Enable parallel processing
npx ruv-swarm github review-init --pr 123 --parallel --cache-results
📖 Additional Resources
Related Skills
github-pr-manager- Comprehensive PR lifecycle managementgithub-workflow-automation- Automate GitHub workflowsswarm-coordination- Advanced swarm orchestration
Documentation
Support
- GitHub Issues: Report bugs and request features
- Community: Join discussions and share experiences
- Examples: Browse example configurations and workflows
📄 License
This skill is part of the Claude Code Flow project and is licensed under the MIT License.
Last Updated: 2025-10-19 Version: 1.0.0 Maintainer: Claude Code Flow Team
| 1 | |
| 2 | name github-code-review |
| 3 | version 1.0.0 |
| 4 | description Comprehensive GitHub code review with AI-powered swarm coordination |
| 5 | category github |
| 6 | tags [code-review, github, swarm, pr-management, automation] |
| 7 | author Claude Code Flow |
| 8 | requires |
| 9 | - github-cli |
| 10 | - ruv-swarm |
| 11 | - claude-flow |
| 12 | capabilities |
| 13 | - Multi-agent code review |
| 14 | - Automated PR management |
| 15 | - Security and performance analysis |
| 16 | - Swarm-based review orchestration |
| 17 | - Intelligent comment generation |
| 18 | - Quality gate enforcement |
| 19 | |
| 20 | |
| 21 | # GitHub Code Review Skill |
| 22 | |
| 23 | > **AI-Powered Code Review**: Deploy specialized review agents to perform comprehensive, intelligent code reviews that go beyond traditional static analysis. |
| 24 | |
| 25 | ## 🎯 Quick Start |
| 26 | |
| 27 | ### Simple Review |
| 28 | |
| 29 | # Initialize review swarm for PR |
| 30 | gh pr view 123 --json files,diff | npx ruv-swarm github review-init --pr 123 |
| 31 | |
| 32 | # Post review status |
| 33 | gh pr comment 123 --body "🔍 Multi-agent code review initiated" |
| 34 | |
| 35 | |
| 36 | ### Complete Review Workflow |
| 37 | |
| 38 | # Get PR context with gh CLI |
| 39 | PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body) |
| 40 | PR_DIFF=$(gh pr diff 123) |
| 41 | |
| 42 | # Initialize comprehensive review |
| 43 | npx ruv-swarm github review-init \ |
| 44 | --pr 123 \ |
| 45 | --pr-data "$PR_DATA" \ |
| 46 | --diff "$PR_DIFF" \ |
| 47 | --agents "security,performance,style,architecture,accessibility" \ |
| 48 | --depth comprehensive |
| 49 | |
| 50 | |
| 51 | |
| 52 | |
| 53 | ## 📚 Table of Contents |
| 54 | |
| 55 | <details> |
| 56 | <summary><strong>Core Features</strong></summary> |
| 57 | |
| 58 | [Multi-Agent Review System] |
| 59 | [Specialized Review Agents] |
| 60 | [PR-Based Swarm Management] |
| 61 | [Automated Workflows] |
| 62 | [Quality Gates & Checks] |
| 63 | |
| 64 | </details> |
| 65 | |
| 66 | <details> |
| 67 | <summary><strong>Review Agents</strong></summary> |
| 68 | |
| 69 | [Security Review Agent] |
| 70 | [Performance Review Agent] |
| 71 | [Architecture Review Agent] |
| 72 | [Style & Convention Agent] |
| 73 | [Accessibility Agent] |
| 74 | |
| 75 | </details> |
| 76 | |
| 77 | <details> |
| 78 | <summary><strong>Advanced Features</strong></summary> |
| 79 | |
| 80 | [Context-Aware Reviews] |
| 81 | [Learning from History] |
| 82 | [Cross-PR Analysis] |
| 83 | [Custom Review Agents] |
| 84 | |
| 85 | </details> |
| 86 | |
| 87 | <details> |
| 88 | <summary><strong>Integration & Automation</strong></summary> |
| 89 | |
| 90 | [CI/CD Integration] |
| 91 | [Webhook Handlers] |
| 92 | [PR Comment Commands] |
| 93 | [Automated Fixes] |
| 94 | |
| 95 | </details> |
| 96 | |
| 97 | |
| 98 | |
| 99 | ## 🚀 Core Features |
| 100 | |
| 101 | ### Multi-Agent Review System |
| 102 | |
| 103 | Deploy specialized AI agents for comprehensive code review: |
| 104 | |
| 105 | |
| 106 | # Initialize review swarm with GitHub CLI integration |
| 107 | PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body) |
| 108 | PR_DIFF=$(gh pr diff 123) |
| 109 | |
| 110 | # Start multi-agent review |
| 111 | npx ruv-swarm github review-init \ |
| 112 | --pr 123 \ |
| 113 | --pr-data "$PR_DATA" \ |
| 114 | --diff "$PR_DIFF" \ |
| 115 | --agents "security,performance,style,architecture,accessibility" \ |
| 116 | --depth comprehensive |
| 117 | |
| 118 | # Post initial review status |
| 119 | gh pr comment 123 --body "🔍 Multi-agent code review initiated" |
| 120 | |
| 121 | |
| 122 | **Benefits:** |
| 123 | ✅ Parallel review by specialized agents |
| 124 | ✅ Comprehensive coverage across multiple domains |
| 125 | ✅ Faster review cycles with coordinated analysis |
| 126 | ✅ Consistent quality standards enforcement |
| 127 | |
| 128 | |
| 129 | |
| 130 | ## 🤖 Specialized Review Agents |
| 131 | |
| 132 | ### Security Review Agent |
| 133 | |
| 134 | **Focus:** Identify security vulnerabilities and suggest fixes |
| 135 | |
| 136 | |
| 137 | # Get changed files from PR |
| 138 | CHANGED_FILES=$(gh pr view 123 --json files --jq '.files[].path') |
| 139 | |
| 140 | # Run security-focused review |
| 141 | SECURITY_RESULTS=$(npx ruv-swarm github review-security \ |
| 142 | --pr 123 \ |
| 143 | --files "$CHANGED_FILES" \ |
| 144 | --check "owasp,cve,secrets,permissions" \ |
| 145 | --suggest-fixes) |
| 146 | |
| 147 | # Post findings based on severity |
| 148 | if echo "$SECURITY_RESULTS" | grep -q "critical"; then |
| 149 | # Request changes for critical issues |
| 150 | gh pr review 123 --request-changes --body "$SECURITY_RESULTS" |
| 151 | gh pr edit 123 --add-label "security-review-required" |
| 152 | else |
| 153 | # Post as comment for non-critical issues |
| 154 | gh pr comment 123 --body "$SECURITY_RESULTS" |
| 155 | fi |
| 156 | |
| 157 | |
| 158 | <details> |
| 159 | <summary><strong>Security Checks Performed</strong></summary> |
| 160 | |
| 161 | |
| 162 | { |
| 163 | "checks": [ |
| 164 | "SQL injection vulnerabilities", |
| 165 | "XSS attack vectors", |
| 166 | "Authentication bypasses", |
| 167 | "Authorization flaws", |
| 168 | "Cryptographic weaknesses", |
| 169 | "Dependency vulnerabilities", |
| 170 | "Secret exposure", |
| 171 | "CORS misconfigurations" |
| 172 | ], |
| 173 | "actions": [ |
| 174 | "Block PR on critical issues", |
| 175 | "Suggest secure alternatives", |
| 176 | "Add security test cases", |
| 177 | "Update security documentation" |
| 178 | ] |
| 179 | } |
| 180 | |
| 181 | |
| 182 | </details> |
| 183 | |
| 184 | <details> |
| 185 | <summary><strong>Comment Template: Security Issue</strong></summary> |
| 186 | |
| 187 | |
| 188 | 🔒 **Security Issue: [Type]** |
| 189 | |
| 190 | **Severity**: 🔴 Critical / 🟡 High / 🟢 Low |
| 191 | |
| 192 | **Description**: |
| 193 | [Clear explanation of the security issue] |
| 194 | |
| 195 | **Impact**: |
| 196 | [Potential consequences if not addressed] |
| 197 | |
| 198 | **Suggested Fix**: |
| 199 | |
| 200 | [Code example of the fix] |
| 201 | |
| 202 | |
| 203 | **References**: |
| 204 | - [OWASP Guide](link) |
| 205 | - [Security Best Practices](link) |
| 206 | |
| 207 | |
| 208 | </details> |
| 209 | |
| 210 | |
| 211 | |
| 212 | ### Performance Review Agent |
| 213 | |
| 214 | **Focus:** Analyze performance impact and optimization opportunities |
| 215 | |
| 216 | |
| 217 | # Run performance analysis |
| 218 | npx ruv-swarm github review-performance \ |
| 219 | --pr 123 \ |
| 220 | --profile "cpu,memory,io" \ |
| 221 | --benchmark-against main \ |
| 222 | --suggest-optimizations |
| 223 | |
| 224 | |
| 225 | <details> |
| 226 | <summary><strong>Performance Metrics Analyzed</strong></summary> |
| 227 | |
| 228 | |
| 229 | { |
| 230 | "metrics": [ |
| 231 | "Algorithm complexity (Big O analysis)", |
| 232 | "Database query efficiency", |
| 233 | "Memory allocation patterns", |
| 234 | "Cache utilization", |
| 235 | "Network request optimization", |
| 236 | "Bundle size impact", |
| 237 | "Render performance" |
| 238 | ], |
| 239 | "benchmarks": [ |
| 240 | "Compare with baseline", |
| 241 | "Load test simulations", |
| 242 | "Memory leak detection", |
| 243 | "Bottleneck identification" |
| 244 | ] |
| 245 | } |
| 246 | |
| 247 | |
| 248 | </details> |
| 249 | |
| 250 | |
| 251 | |
| 252 | ### Architecture Review Agent |
| 253 | |
| 254 | **Focus:** Evaluate design patterns and architectural decisions |
| 255 | |
| 256 | |
| 257 | # Architecture review |
| 258 | npx ruv-swarm github review-architecture \ |
| 259 | --pr 123 \ |
| 260 | --check "patterns,coupling,cohesion,solid" \ |
| 261 | --visualize-impact \ |
| 262 | --suggest-refactoring |
| 263 | |
| 264 | |
| 265 | <details> |
| 266 | <summary><strong>Architecture Analysis</strong></summary> |
| 267 | |
| 268 | |
| 269 | { |
| 270 | "patterns": [ |
| 271 | "Design pattern adherence", |
| 272 | "SOLID principles", |
| 273 | "DRY violations", |
| 274 | "Separation of concerns", |
| 275 | "Dependency injection", |
| 276 | "Layer violations", |
| 277 | "Circular dependencies" |
| 278 | ], |
| 279 | "metrics": [ |
| 280 | "Coupling metrics", |
| 281 | "Cohesion scores", |
| 282 | "Complexity measures", |
| 283 | "Maintainability index" |
| 284 | ] |
| 285 | } |
| 286 | |
| 287 | |
| 288 | </details> |
| 289 | |
| 290 | |
| 291 | |
| 292 | ### Style & Convention Agent |
| 293 | |
| 294 | **Focus:** Enforce coding standards and best practices |
| 295 | |
| 296 | |
| 297 | # Style enforcement with auto-fix |
| 298 | npx ruv-swarm github review-style \ |
| 299 | --pr 123 \ |
| 300 | --check "formatting,naming,docs,tests" \ |
| 301 | --auto-fix "formatting,imports,whitespace" |
| 302 | |
| 303 | |
| 304 | <details> |
| 305 | <summary><strong>Style Checks</strong></summary> |
| 306 | |
| 307 | |
| 308 | { |
| 309 | "checks": [ |
| 310 | "Code formatting", |
| 311 | "Naming conventions", |
| 312 | "Documentation standards", |
| 313 | "Comment quality", |
| 314 | "Test coverage", |
| 315 | "Error handling patterns", |
| 316 | "Logging standards" |
| 317 | ], |
| 318 | "auto-fix": [ |
| 319 | "Formatting issues", |
| 320 | "Import organization", |
| 321 | "Trailing whitespace", |
| 322 | "Simple naming issues" |
| 323 | ] |
| 324 | } |
| 325 | |
| 326 | |
| 327 | </details> |
| 328 | |
| 329 | |
| 330 | |
| 331 | ## 🔄 PR-Based Swarm Management |
| 332 | |
| 333 | ### Create Swarm from PR |
| 334 | |
| 335 | |
| 336 | # Create swarm from PR description using gh CLI |
| 337 | gh pr view 123 --json body,title,labels,files | npx ruv-swarm swarm create-from-pr |
| 338 | |
| 339 | # Auto-spawn agents based on PR labels |
| 340 | gh pr view 123 --json labels | npx ruv-swarm swarm auto-spawn |
| 341 | |
| 342 | # Create swarm with full PR context |
| 343 | gh pr view 123 --json body,labels,author,assignees | \ |
| 344 | npx ruv-swarm swarm init --from-pr-data |
| 345 | |
| 346 | |
| 347 | ### Label-Based Agent Assignment |
| 348 | |
| 349 | Map PR labels to specialized agents: |
| 350 | |
| 351 | |
| 352 | { |
| 353 | "label-mapping": { |
| 354 | "bug": ["debugger", "tester"], |
| 355 | "feature": ["architect", "coder", "tester"], |
| 356 | "refactor": ["analyst", "coder"], |
| 357 | "docs": ["researcher", "writer"], |
| 358 | "performance": ["analyst", "optimizer"], |
| 359 | "security": ["security", "authentication", "audit"] |
| 360 | } |
| 361 | } |
| 362 | |
| 363 | |
| 364 | ### Topology Selection by PR Size |
| 365 | |
| 366 | |
| 367 | # Automatic topology selection based on PR complexity |
| 368 | # Small PR (< 100 lines): ring topology |
| 369 | # Medium PR (100-500 lines): mesh topology |
| 370 | # Large PR (> 500 lines): hierarchical topology |
| 371 | npx ruv-swarm github pr-topology --pr 123 |
| 372 | |
| 373 | |
| 374 | |
| 375 | |
| 376 | ## 🎬 PR Comment Commands |
| 377 | |
| 378 | Execute swarm commands directly from PR comments: |
| 379 | |
| 380 | |
| 381 | <!-- In PR comment --> |
| 382 | /swarm init mesh 6 |
| 383 | /swarm spawn coder "Implement authentication" |
| 384 | /swarm spawn tester "Write unit tests" |
| 385 | /swarm status |
| 386 | /swarm review --agents security,performance |
| 387 | |
| 388 | |
| 389 | <details> |
| 390 | <summary><strong>Webhook Handler for Comment Commands</strong></summary> |
| 391 | |
| 392 | |
| 393 | // webhook-handler.js |
| 394 | const { createServer } = require('http'); |
| 395 | const { execSync } = require('child_process'); |
| 396 | |
| 397 | createServer((req, res) => { |
| 398 | if (req.url === '/github-webhook') { |
| 399 | const event = JSON.parse(body); |
| 400 | |
| 401 | if (event.action === 'opened' && event.pull_request) { |
| 402 | execSync(`npx ruv-swarm github pr-init ${event.pull_request.number}`); |
| 403 | } |
| 404 | |
| 405 | if (event.comment && event.comment.body.startsWith('/swarm')) { |
| 406 | const command = event.comment.body; |
| 407 | execSync(`npx ruv-swarm github handle-comment --pr ${event.issue.number} --command "${command}"`); |
| 408 | } |
| 409 | |
| 410 | res.writeHead(200); |
| 411 | res.end('OK'); |
| 412 | } |
| 413 | }).listen(3000); |
| 414 | |
| 415 | |
| 416 | </details> |
| 417 | |
| 418 | |
| 419 | |
| 420 | ## ⚙️ Review Configuration |
| 421 | |
| 422 | ### Configuration File |
| 423 | |
| 424 | |
| 425 | # .github/review-swarm.yml |
| 426 | version: 1 |
| 427 | review: |
| 428 | auto-trigger: true |
| 429 | required-agents: |
| 430 | - security |
| 431 | - performance |
| 432 | - style |
| 433 | optional-agents: |
| 434 | - architecture |
| 435 | - accessibility |
| 436 | - i18n |
| 437 | |
| 438 | thresholds: |
| 439 | security: block # Block merge on security issues |
| 440 | performance: warn # Warn on performance issues |
| 441 | style: suggest # Suggest style improvements |
| 442 | |
| 443 | rules: |
| 444 | security: |
| 445 | - no-eval |
| 446 | - no-hardcoded-secrets |
| 447 | - proper-auth-checks |
| 448 | - validate-input |
| 449 | performance: |
| 450 | - no-n-plus-one |
| 451 | - efficient-queries |
| 452 | - proper-caching |
| 453 | - optimize-loops |
| 454 | architecture: |
| 455 | - max-coupling: 5 |
| 456 | - min-cohesion: 0.7 |
| 457 | - follow-patterns |
| 458 | - avoid-circular-deps |
| 459 | |
| 460 | |
| 461 | ### Custom Review Triggers |
| 462 | |
| 463 | |
| 464 | { |
| 465 | "triggers": { |
| 466 | "high-risk-files": { |
| 467 | "paths": ["**/auth/**", "**/payment/**", "**/admin/**"], |
| 468 | "agents": ["security", "architecture"], |
| 469 | "depth": "comprehensive", |
| 470 | "require-approval": true |
| 471 | }, |
| 472 | "performance-critical": { |
| 473 | "paths": ["**/api/**", "**/database/**", "**/cache/**"], |
| 474 | "agents": ["performance", "database"], |
| 475 | "benchmarks": true, |
| 476 | "regression-threshold": "5%" |
| 477 | }, |
| 478 | "ui-changes": { |
| 479 | "paths": ["**/components/**", "**/styles/**", "**/pages/**"], |
| 480 | "agents": ["accessibility", "style", "i18n"], |
| 481 | "visual-tests": true, |
| 482 | "responsive-check": true |
| 483 | } |
| 484 | } |
| 485 | } |
| 486 | |
| 487 | |
| 488 | |
| 489 | |
| 490 | ## 🤖 Automated Workflows |
| 491 | |
| 492 | ### Auto-Review on PR Creation |
| 493 | |
| 494 | |
| 495 | # .github/workflows/auto-review.yml |
| 496 | name: Automated Code Review |
| 497 | on: |
| 498 | pull_request: |
| 499 | types: [opened, synchronize] |
| 500 | issue_comment: |
| 501 | types: [created] |
| 502 | |
| 503 | jobs: |
| 504 | swarm-review: |
| 505 | runs-on: ubuntu-latest |
| 506 | steps: |
| 507 | - uses: actions/checkout@v3 |
| 508 | with: |
| 509 | fetch-depth: 0 |
| 510 | |
| 511 | - name: Setup GitHub CLI |
| 512 | run: echo "${{ secrets.GITHUB_TOKEN }}" | gh auth login --with-token |
| 513 | |
| 514 | - name: Run Review Swarm |
| 515 | run: | |
| 516 | # Get PR context with gh CLI |
| 517 | PR_NUM=${{ github.event.pull_request.number }} |
| 518 | PR_DATA=$(gh pr view $PR_NUM --json files,title,body,labels) |
| 519 | PR_DIFF=$(gh pr diff $PR_NUM) |
| 520 | |
| 521 | # Run swarm review |
| 522 | REVIEW_OUTPUT=$(npx ruv-swarm github review-all \ |
| 523 | --pr $PR_NUM \ |
| 524 | --pr-data "$PR_DATA" \ |
| 525 | --diff "$PR_DIFF" \ |
| 526 | --agents "security,performance,style,architecture") |
| 527 | |
| 528 | # Post review results |
| 529 | echo "$REVIEW_OUTPUT" | gh pr review $PR_NUM --comment -F - |
| 530 | |
| 531 | # Update PR status |
| 532 | if echo "$REVIEW_OUTPUT" | grep -q "approved"; then |
| 533 | gh pr review $PR_NUM --approve |
| 534 | elif echo "$REVIEW_OUTPUT" | grep -q "changes-requested"; then |
| 535 | gh pr review $PR_NUM --request-changes -b "See review comments above" |
| 536 | fi |
| 537 | |
| 538 | - name: Update Labels |
| 539 | run: | |
| 540 | # Add labels based on review results |
| 541 | if echo "$REVIEW_OUTPUT" | grep -q "security"; then |
| 542 | gh pr edit $PR_NUM --add-label "security-review" |
| 543 | fi |
| 544 | if echo "$REVIEW_OUTPUT" | grep -q "performance"; then |
| 545 | gh pr edit $PR_NUM --add-label "performance-review" |
| 546 | fi |
| 547 | |
| 548 | |
| 549 | |
| 550 | |
| 551 | ## 💬 Intelligent Comment Generation |
| 552 | |
| 553 | ### Generate Contextual Review Comments |
| 554 | |
| 555 | |
| 556 | # Get PR diff with context |
| 557 | PR_DIFF=$(gh pr diff 123 --color never) |
| 558 | PR_FILES=$(gh pr view 123 --json files) |
| 559 | |
| 560 | # Generate review comments |
| 561 | COMMENTS=$(npx ruv-swarm github review-comment \ |
| 562 | --pr 123 \ |
| 563 | --diff "$PR_DIFF" \ |
| 564 | --files "$PR_FILES" \ |
| 565 | --style "constructive" \ |
| 566 | --include-examples \ |
| 567 | --suggest-fixes) |
| 568 | |
| 569 | # Post comments using gh CLI |
| 570 | echo "$COMMENTS" | jq -c '.[]' | while read -r comment; do |
| 571 | FILE=$(echo "$comment" | jq -r '.path') |
| 572 | LINE=$(echo "$comment" | jq -r '.line') |
| 573 | BODY=$(echo "$comment" | jq -r '.body') |
| 574 | COMMIT_ID=$(gh pr view 123 --json headRefOid -q .headRefOid) |
| 575 | |
| 576 | # Create inline review comments |
| 577 | gh api \ |
| 578 | --method POST \ |
| 579 | /repos/:owner/:repo/pulls/123/comments \ |
| 580 | -f path="$FILE" \ |
| 581 | -f line="$LINE" \ |
| 582 | -f body="$BODY" \ |
| 583 | -f commit_id="$COMMIT_ID" |
| 584 | done |
| 585 | |
| 586 | |
| 587 | ### Batch Comment Management |
| 588 | |
| 589 | |
| 590 | # Manage review comments efficiently |
| 591 | npx ruv-swarm github review-comments \ |
| 592 | --pr 123 \ |
| 593 | --group-by "agent,severity" \ |
| 594 | --summarize \ |
| 595 | --resolve-outdated |
| 596 | |
| 597 | |
| 598 | |
| 599 | |
| 600 | ## 🚪 Quality Gates & Checks |
| 601 | |
| 602 | ### Status Checks |
| 603 | |
| 604 | |
| 605 | # Required status checks in branch protection |
| 606 | protection_rules: |
| 607 | required_status_checks: |
| 608 | strict: true |
| 609 | contexts: |
| 610 | - "review-swarm/security" |
| 611 | - "review-swarm/performance" |
| 612 | - "review-swarm/architecture" |
| 613 | - "review-swarm/tests" |
| 614 | |
| 615 | |
| 616 | ### Define Quality Gates |
| 617 | |
| 618 | |
| 619 | # Set quality gate thresholds |
| 620 | npx ruv-swarm github quality-gates \ |
| 621 | --define '{ |
| 622 | "security": {"threshold": "no-critical"}, |
| 623 | "performance": {"regression": "<5%"}, |
| 624 | "coverage": {"minimum": "80%"}, |
| 625 | "architecture": {"complexity": "<10"}, |
| 626 | "duplication": {"maximum": "5%"} |
| 627 | }' |
| 628 | |
| 629 | |
| 630 | ### Track Review Metrics |
| 631 | |
| 632 | |
| 633 | # Monitor review effectiveness |
| 634 | npx ruv-swarm github review-metrics \ |
| 635 | --period 30d \ |
| 636 | --metrics "issues-found,false-positives,fix-rate,time-to-review" \ |
| 637 | --export-dashboard \ |
| 638 | --format json |
| 639 | |
| 640 | |
| 641 | |
| 642 | |
| 643 | ## 🎓 Advanced Features |
| 644 | |
| 645 | ### Context-Aware Reviews |
| 646 | |
| 647 | Analyze PRs with full project context: |
| 648 | |
| 649 | |
| 650 | # Review with comprehensive context |
| 651 | npx ruv-swarm github review-context \ |
| 652 | --pr 123 \ |
| 653 | --load-related-prs \ |
| 654 | --analyze-impact \ |
| 655 | --check-breaking-changes \ |
| 656 | --dependency-analysis |
| 657 | |
| 658 | |
| 659 | ### Learning from History |
| 660 | |
| 661 | Train review agents on your codebase patterns: |
| 662 | |
| 663 | |
| 664 | # Learn from past reviews |
| 665 | npx ruv-swarm github review-learn \ |
| 666 | --analyze-past-reviews \ |
| 667 | --identify-patterns \ |
| 668 | --improve-suggestions \ |
| 669 | --reduce-false-positives |
| 670 | |
| 671 | # Train on your codebase |
| 672 | npx ruv-swarm github review-train \ |
| 673 | --learn-patterns \ |
| 674 | --adapt-to-style \ |
| 675 | --improve-accuracy |
| 676 | |
| 677 | |
| 678 | ### Cross-PR Analysis |
| 679 | |
| 680 | Coordinate reviews across related pull requests: |
| 681 | |
| 682 | |
| 683 | # Analyze related PRs together |
| 684 | npx ruv-swarm github review-batch \ |
| 685 | --prs "123,124,125" \ |
| 686 | --check-consistency \ |
| 687 | --verify-integration \ |
| 688 | --combined-impact |
| 689 | |
| 690 | |
| 691 | ### Multi-PR Swarm Coordination |
| 692 | |
| 693 | |
| 694 | # Coordinate swarms across related PRs |
| 695 | npx ruv-swarm github multi-pr \ |
| 696 | --prs "123,124,125" \ |
| 697 | --strategy "parallel" \ |
| 698 | --share-memory |
| 699 | |
| 700 | |
| 701 | |
| 702 | |
| 703 | ## 🛠️ Custom Review Agents |
| 704 | |
| 705 | ### Create Custom Agent |
| 706 | |
| 707 | |
| 708 | // custom-review-agent.js |
| 709 | class CustomReviewAgent { |
| 710 | constructor(config) { |
| 711 | this.config = config; |
| 712 | this.rules = config.rules || []; |
| 713 | } |
| 714 | |
| 715 | async review(pr) { |
| 716 | const issues = []; |
| 717 | |
| 718 | // Custom logic: Check for TODO comments in production code |
| 719 | if (await this.checkTodoComments(pr)) { |
| 720 | issues.push({ |
| 721 | severity: 'warning', |
| 722 | file: pr.file, |
| 723 | line: pr.line, |
| 724 | message: 'TODO comment found in production code', |
| 725 | suggestion: 'Resolve TODO or create issue to track it' |
| 726 | }); |
| 727 | } |
| 728 | |
| 729 | // Custom logic: Verify API versioning |
| 730 | if (await this.checkApiVersioning(pr)) { |
| 731 | issues.push({ |
| 732 | severity: 'error', |
| 733 | file: pr.file, |
| 734 | line: pr.line, |
| 735 | message: 'API endpoint missing versioning', |
| 736 | suggestion: 'Add /v1/, /v2/ prefix to API routes' |
| 737 | }); |
| 738 | } |
| 739 | |
| 740 | return issues; |
| 741 | } |
| 742 | |
| 743 | async checkTodoComments(pr) { |
| 744 | // Implementation |
| 745 | const todoRegex = /\/\/\s*TODO|\/\*\s*TODO/gi; |
| 746 | return todoRegex.test(pr.diff); |
| 747 | } |
| 748 | |
| 749 | async checkApiVersioning(pr) { |
| 750 | // Implementation |
| 751 | const apiRegex = /app\.(get|post|put|delete)\(['"]\/api\/(?!v\d+)/; |
| 752 | return apiRegex.test(pr.diff); |
| 753 | } |
| 754 | } |
| 755 | |
| 756 | module.exports = CustomReviewAgent; |
| 757 | |
| 758 | |
| 759 | ### Register Custom Agent |
| 760 | |
| 761 | |
| 762 | # Register custom review agent |
| 763 | npx ruv-swarm github register-agent \ |
| 764 | --name "custom-reviewer" \ |
| 765 | --file "./custom-review-agent.js" \ |
| 766 | --category "standards" |
| 767 | |
| 768 | |
| 769 | |
| 770 | |
| 771 | ## 🔧 CI/CD Integration |
| 772 | |
| 773 | ### Integration with Build Pipeline |
| 774 | |
| 775 | |
| 776 | # .github/workflows/build-and-review.yml |
| 777 | name: Build and Review |
| 778 | on: [pull_request] |
| 779 | |
| 780 | jobs: |
| 781 | build-and-test: |
| 782 | runs-on: ubuntu-latest |
| 783 | steps: |
| 784 | - uses: actions/checkout@v3 |
| 785 | - run: npm install |
| 786 | - run: npm test |
| 787 | - run: npm run build |
| 788 | |
| 789 | swarm-review: |
| 790 | needs: build-and-test |
| 791 | runs-on: ubuntu-latest |
| 792 | steps: |
| 793 | - name: Run Swarm Review |
| 794 | run: | |
| 795 | npx ruv-swarm github review-all \ |
| 796 | --pr ${{ github.event.pull_request.number }} \ |
| 797 | --include-build-results |
| 798 | |
| 799 | |
| 800 | ### Automated PR Fixes |
| 801 | |
| 802 | |
| 803 | # Auto-fix common issues |
| 804 | npx ruv-swarm github pr-fix 123 \ |
| 805 | --issues "lint,test-failures,formatting" \ |
| 806 | --commit-fixes \ |
| 807 | --push-changes |
| 808 | |
| 809 | |
| 810 | ### Progress Updates to PR |
| 811 | |
| 812 | |
| 813 | # Post swarm progress to PR using gh CLI |
| 814 | PROGRESS=$(npx ruv-swarm github pr-progress 123 --format markdown) |
| 815 | |
| 816 | gh pr comment 123 --body "$PROGRESS" |
| 817 | |
| 818 | # Update PR labels based on progress |
| 819 | if [[ $(echo "$PROGRESS" | grep -o '[0-9]\+%' | sed 's/%//') -gt 90 ]]; then |
| 820 | gh pr edit 123 --add-label "ready-for-review" |
| 821 | fi |
| 822 | |
| 823 | |
| 824 | |
| 825 | |
| 826 | ## 📋 Complete Workflow Examples |
| 827 | |
| 828 | ### Example 1: Security-Critical PR |
| 829 | |
| 830 | |
| 831 | # Review authentication system changes |
| 832 | npx ruv-swarm github review-init \ |
| 833 | --pr 456 \ |
| 834 | --agents "security,authentication,audit" \ |
| 835 | --depth "maximum" \ |
| 836 | --require-security-approval \ |
| 837 | --penetration-test |
| 838 | |
| 839 | |
| 840 | ### Example 2: Performance-Sensitive PR |
| 841 | |
| 842 | |
| 843 | # Review database optimization |
| 844 | npx ruv-swarm github review-init \ |
| 845 | --pr 789 \ |
| 846 | --agents "performance,database,caching" \ |
| 847 | --benchmark \ |
| 848 | --profile \ |
| 849 | --load-test |
| 850 | |
| 851 | |
| 852 | ### Example 3: UI Component PR |
| 853 | |
| 854 | |
| 855 | # Review new component library |
| 856 | npx ruv-swarm github review-init \ |
| 857 | --pr 321 \ |
| 858 | --agents "accessibility,style,i18n,docs" \ |
| 859 | --visual-regression \ |
| 860 | --component-tests \ |
| 861 | --responsive-check |
| 862 | |
| 863 | |
| 864 | ### Example 4: Feature Development PR |
| 865 | |
| 866 | |
| 867 | # Review new feature implementation |
| 868 | gh pr view 456 --json body,labels,files | \ |
| 869 | npx ruv-swarm github pr-init 456 \ |
| 870 | --topology hierarchical \ |
| 871 | --agents "architect,coder,tester,security" \ |
| 872 | --auto-assign-tasks |
| 873 | |
| 874 | |
| 875 | ### Example 5: Bug Fix PR |
| 876 | |
| 877 | |
| 878 | # Review bug fix with debugging focus |
| 879 | npx ruv-swarm github pr-init 789 \ |
| 880 | --topology mesh \ |
| 881 | --agents "debugger,analyst,tester" \ |
| 882 | --priority high \ |
| 883 | --regression-test |
| 884 | |
| 885 | |
| 886 | |
| 887 | |
| 888 | ## 📊 Monitoring & Analytics |
| 889 | |
| 890 | ### Review Dashboard |
| 891 | |
| 892 | |
| 893 | # Launch real-time review dashboard |
| 894 | npx ruv-swarm github review-dashboard \ |
| 895 | --real-time \ |
| 896 | --show "agent-activity,issue-trends,fix-rates,coverage" |
| 897 | |
| 898 | |
| 899 | ### Generate Review Reports |
| 900 | |
| 901 | |
| 902 | # Create comprehensive review report |
| 903 | npx ruv-swarm github review-report \ |
| 904 | --format "markdown" \ |
| 905 | --include "summary,details,trends,recommendations" \ |
| 906 | --email-stakeholders \ |
| 907 | --export-pdf |
| 908 | |
| 909 | |
| 910 | ### PR Swarm Analytics |
| 911 | |
| 912 | |
| 913 | # Generate PR-specific analytics |
| 914 | npx ruv-swarm github pr-report 123 \ |
| 915 | --metrics "completion-time,agent-efficiency,token-usage,issue-density" \ |
| 916 | --format markdown \ |
| 917 | --compare-baseline |
| 918 | |
| 919 | |
| 920 | ### Export to GitHub Insights |
| 921 | |
| 922 | |
| 923 | # Export metrics to GitHub Insights |
| 924 | npx ruv-swarm github export-metrics \ |
| 925 | --pr 123 \ |
| 926 | --to-insights \ |
| 927 | --dashboard-url |
| 928 | |
| 929 | |
| 930 | |
| 931 | |
| 932 | ## 🔐 Security Considerations |
| 933 | |
| 934 | ### Best Practices |
| 935 | |
| 936 | **Token Permissions**: Ensure GitHub tokens have minimal required scopes |
| 937 | **Command Validation**: Validate all PR comments before execution |
| 938 | **Rate Limiting**: Implement rate limits for PR operations |
| 939 | **Audit Trail**: Log all swarm operations for compliance |
| 940 | **Secret Management**: Never expose API keys in PR comments or logs |
| 941 | |
| 942 | ### Security Checklist |
| 943 | |
| 944 | [ ] GitHub token scoped to repository only |
| 945 | [ ] Webhook signatures verified |
| 946 | [ ] Command injection protection enabled |
| 947 | [ ] Rate limiting configured |
| 948 | [ ] Audit logging enabled |
| 949 | [ ] Secrets scanning active |
| 950 | [ ] Branch protection rules enforced |
| 951 | |
| 952 | |
| 953 | |
| 954 | ## 📚 Best Practices |
| 955 | |
| 956 | ### 1. Review Configuration |
| 957 | ✅ Define clear review criteria upfront |
| 958 | ✅ Set appropriate severity thresholds |
| 959 | ✅ Configure agent specializations for your stack |
| 960 | ✅ Establish override procedures for emergencies |
| 961 | |
| 962 | ### 2. Comment Quality |
| 963 | ✅ Provide actionable, specific feedback |
| 964 | ✅ Include code examples with suggestions |
| 965 | ✅ Reference documentation and best practices |
| 966 | ✅ Maintain respectful, constructive tone |
| 967 | |
| 968 | ### 3. Performance Optimization |
| 969 | ✅ Cache analysis results to avoid redundant work |
| 970 | ✅ Use incremental reviews for large PRs |
| 971 | ✅ Enable parallel agent execution |
| 972 | ✅ Batch comment operations efficiently |
| 973 | |
| 974 | ### 4. PR Templates |
| 975 | |
| 976 | |
| 977 | <!-- .github/pull_request_template.md --> |
| 978 | ## Swarm Configuration |
| 979 | - Topology: [mesh/hierarchical/ring/star] |
| 980 | - Max Agents: [number] |
| 981 | - Auto-spawn: [yes/no] |
| 982 | - Priority: [high/medium/low] |
| 983 | |
| 984 | ## Tasks for Swarm |
| 985 | - [ ] Task 1 description |
| 986 | - [ ] Task 2 description |
| 987 | - [ ] Task 3 description |
| 988 | |
| 989 | ## Review Focus Areas |
| 990 | - [ ] Security review |
| 991 | - [ ] Performance analysis |
| 992 | - [ ] Architecture validation |
| 993 | - [ ] Accessibility check |
| 994 | |
| 995 | |
| 996 | ### 5. Auto-Merge When Ready |
| 997 | |
| 998 | |
| 999 | # Auto-merge when swarm completes and passes checks |
| 1000 | SWARM_STATUS=$(npx ruv-swarm github pr-status 123) |
| 1001 | |
| 1002 | if [[ "$SWARM_STATUS" == "complete" ]]; then |
| 1003 | # Check review requirements |
| 1004 | REVIEWS=$(gh pr view 123 --json reviews --jq '.reviews | length') |
| 1005 | |
| 1006 | if [[ $REVIEWS -ge 2 ]]; then |
| 1007 | # Enable auto-merge |
| 1008 | gh pr merge 123 --auto --squash |
| 1009 | fi |
| 1010 | fi |
| 1011 | |
| 1012 | |
| 1013 | |
| 1014 | |
| 1015 | ## 🔗 Integration with Claude Code |
| 1016 | |
| 1017 | ### Workflow Pattern |
| 1018 | |
| 1019 | **Claude Code** reads PR diff and context |
| 1020 | **Swarm** coordinates review approach based on PR type |
| 1021 | **Agents** work in parallel on different review aspects |
| 1022 | **Progress** updates posted to PR automatically |
| 1023 | **Final review** performed before marking ready |
| 1024 | |
| 1025 | ### Example: Complete PR Management |
| 1026 | |
| 1027 | |
| 1028 | [Single Message - Parallel Execution]: |
| 1029 | // Initialize coordination |
| 1030 | mcp__claude-flow__swarm_init { topology: "hierarchical", maxAgents: 5 } |
| 1031 | mcp__claude-flow__agent_spawn { type: "reviewer", name: "Senior Reviewer" } |
| 1032 | mcp__claude-flow__agent_spawn { type: "tester", name: "QA Engineer" } |
| 1033 | mcp__claude-flow__agent_spawn { type: "coordinator", name: "Merge Coordinator" } |
| 1034 | |
| 1035 | // Create and manage PR using gh CLI |
| 1036 | Bash("gh pr create --title 'Feature: Add authentication' --base main") |
| 1037 | Bash("gh pr view 54 --json files,diff") |
| 1038 | Bash("gh pr review 54 --approve --body 'LGTM after automated review'") |
| 1039 | |
| 1040 | // Execute tests and validation |
| 1041 | Bash("npm test") |
| 1042 | Bash("npm run lint") |
| 1043 | Bash("npm run build") |
| 1044 | |
| 1045 | // Track progress |
| 1046 | TodoWrite { todos: [ |
| 1047 | { content: "Complete code review", status: "completed", activeForm: "Completing code review" }, |
| 1048 | { content: "Run test suite", status: "completed", activeForm: "Running test suite" }, |
| 1049 | { content: "Validate security", status: "completed", activeForm: "Validating security" }, |
| 1050 | { content: "Merge when ready", status: "pending", activeForm: "Merging when ready" } |
| 1051 | ]} |
| 1052 | |
| 1053 | |
| 1054 | |
| 1055 | |
| 1056 | ## 🆘 Troubleshooting |
| 1057 | |
| 1058 | ### Common Issues |
| 1059 | |
| 1060 | <details> |
| 1061 | <summary><strong>Issue: Review agents not spawning</strong></summary> |
| 1062 | |
| 1063 | **Solution:** |
| 1064 | |
| 1065 | # Check swarm status |
| 1066 | npx ruv-swarm swarm-status |
| 1067 | |
| 1068 | # Verify GitHub CLI authentication |
| 1069 | gh auth status |
| 1070 | |
| 1071 | # Re-initialize swarm |
| 1072 | npx ruv-swarm github review-init --pr 123 --force |
| 1073 | |
| 1074 | |
| 1075 | </details> |
| 1076 | |
| 1077 | <details> |
| 1078 | <summary><strong>Issue: Comments not posting to PR</strong></summary> |
| 1079 | |
| 1080 | **Solution:** |
| 1081 | |
| 1082 | # Verify GitHub token permissions |
| 1083 | gh auth status |
| 1084 | |
| 1085 | # Check API rate limits |
| 1086 | gh api rate_limit |
| 1087 | |
| 1088 | # Use batch comment posting |
| 1089 | npx ruv-swarm github review-comments --pr 123 --batch |
| 1090 | |
| 1091 | |
| 1092 | </details> |
| 1093 | |
| 1094 | <details> |
| 1095 | <summary><strong>Issue: Review taking too long</strong></summary> |
| 1096 | |
| 1097 | **Solution:** |
| 1098 | |
| 1099 | # Use incremental review for large PRs |
| 1100 | npx ruv-swarm github review-init --pr 123 --incremental |
| 1101 | |
| 1102 | # Reduce agent count |
| 1103 | npx ruv-swarm github review-init --pr 123 --agents "security,style" --max-agents 3 |
| 1104 | |
| 1105 | # Enable parallel processing |
| 1106 | npx ruv-swarm github review-init --pr 123 --parallel --cache-results |
| 1107 | |
| 1108 | |
| 1109 | </details> |
| 1110 | |
| 1111 | |
| 1112 | |
| 1113 | ## 📖 Additional Resources |
| 1114 | |
| 1115 | ### Related Skills |
| 1116 | `github-pr-manager` - Comprehensive PR lifecycle management |
| 1117 | `github-workflow-automation` - Automate GitHub workflows |
| 1118 | `swarm-coordination` - Advanced swarm orchestration |
| 1119 | |
| 1120 | ### Documentation |
| 1121 | [GitHub CLI Documentation] |
| 1122 | [RUV Swarm Guide] |
| 1123 | [Claude Flow Integration] |
| 1124 | |
| 1125 | ### Support |
| 1126 | GitHub Issues: Report bugs and request features |
| 1127 | Community: Join discussions and share experiences |
| 1128 | Examples: Browse example configurations and workflows |
| 1129 | |
| 1130 | |
| 1131 | |
| 1132 | ## 📄 License |
| 1133 | |
| 1134 | This skill is part of the Claude Code Flow project and is licensed under the MIT License. |
| 1135 | |
| 1136 | |
| 1137 | |
| 1138 | **Last Updated:** 2025-10-19 |
| 1139 | **Version:** 1.0.0 |
| 1140 | **Maintainer:** Claude Code Flow Team |
| 1141 |
Discussion
Alternatives
Browse more free Claude skills or everything in Development.