Cross-model note. v3.0 defaults to Opus 4.7 for the primary review (best reasoning for the adversarial protocol + severity calibration). Sonnet 4.6 is a first-class fallback — set --model sonnet for cost-sensitive PR scans. Haiku 4.5 only for narrow blame-aware diffs with --local-only. Cross-engine (--engine both) runs primary on Opus and adversarial on whatever the config specifies, defaulting to Opus.
Branding note. Finding IDs (UCR-NNN), config (.ucrconfig.yml), and history dir (.ucr/history/) retain the UCR prefix from the plugin's v1.0 heritage ("Universal Code Review"). The plugin itself is rad-code-review. Migration would be breaking; the aliasing is intentional and stable.
v3.0 differentiators (new):
- Opus 4.7 as the default primary-review model with explicit
--model override
- Parallel tool calls across Steps 1–5 — deep reviews complete ~3–5× faster on Opus/Sonnet
- JSON-first subagent output — more robust across model variance than markdown parsing
- Checkpoint /
--resume — compaction-safe state writes after Steps 5, 7, 9
--non-interactive — agent/CI callers skip the findings menu and get structured return
- Externalized subagent prompts — primary/adversarial/self-adversarial templates in
references/subagent-prompts/
.ucrconfig.yml accepted-risk expiry enforcement — stale entries re-evaluated, not silently suppressed
v2.x differentiators (retained):
- Blame-aware scoping:
diff and commit scopes only flag issues on changed lines by default
- Incremental review:
--since <commit> reviews all changes since a specific commit
- Framework-specific IDOR detection: concrete mutation ownership patterns for 6 frameworks
- Performance profiling heuristics: grep-able patterns for N+1, re-renders, bundle bloat
- Dynamic ARIA state detection: catches hardcoded aria-expanded, aria-selected, etc.
Orchestrator role: Parse arguments, compute diff scope, gather user choices, detect
project context, spawn review subagents with annotated diff context, handle checkpoints
and adversarial passes, offer fixes, assemble final report.
Three report roles:
- Bug finder — functional correctness, edge cases, race conditions, state corruption
- Architecture reviewer — coupling, boundaries, extensibility, patterns, maintainability
- Release gate — security, secrets, dependencies, ops readiness, public defensibility
Review dimensions: Functional correctness, security, AI slop detection, architecture,
tests, performance, UI/UX, accessibility, release readiness, documentation, dependencies,
privacy/secrets handling.
Scope options: repo | diff | commit | tree
repo — review all files in the repository (full scan, no blame filtering)
diff — review staged + unstaged changes only (blame-aware by default)
commit — review files changed in HEAD commit only (blame-aware by default)
tree — review uncommitted working tree changes only (full scan of changed files)
Incremental review: --since
- Reviews all changes between and HEAD
- Blame-aware: only flags issues introduced in those changes
- Useful for: PR review, sprint review, post-release delta
Scan mode:
- Default for diff/commit/--since: blame-aware (only flag issues on changed lines)
- Default for repo/tree: full scan (flag all issues found)
--full-scan — override blame-aware default, flag all issues regardless of authorship
- Blame-aware mode still flags pre-existing issues when a new change depends on broken existing code
Strictness: mvp | production | public (default: production)
mvp — focus on functional correctness, critical security, and stated goals
production — full review across all dimensions
public — production + open-source readiness, public scrutiny resilience, trust signals
Engine: claude | codex | both (default: claude)
claude — Claude performs all review phases
codex — Codex performs all review phases
both — Claude does primary review (Phase 3), Codex does adversarial pass (Phase 4)
Connectivity: --local-only (default: internet-enabled)
Fix mode: --fix blockers | --fix critical-major | --fix id1,id2,...
Model selection (v3.0):
--model opus (default) — Opus 4.7 primary review
--model sonnet — Sonnet 4.6 for cost-sensitive reviews
--model haiku — Haiku 4.5 only for narrow blame-aware + --local-only scopes
--adversarial-model <name> — override adversarial-pass model separately
Non-interactive mode (v3.0):
--non-interactive — skip the findings menu, return findings + verdict + report path. Used by the code-reviewer agent, /loop sessions, and CI.
Resume (v3.0):
--resume <run-id> — rehydrate mid-review state from .ucr/state/<run-id>.json after compaction or interruption. Run IDs are logged at the start of each run.
Project config: .ucrconfig.yml (if present in repo root)
History: .ucr/history/{YYYY-MM-DD}-{HHmmss}-{scope}-{strictness}.md (previous review reports)
State: .ucr/state/{run-id}.json (checkpoints for --resume)
Preserve all workflow gates, user checkpoints, and subagent boundaries.
1---2name: rad-code-review3description: Review my code, code review, is this ready to ship, check for bugs, security audit, review this PR, pre-merge check, is this safe to deploy, check code quality. Blame-aware diff scoping, 3-role adversarial review, AI slop detection (14 patterns), framework IDOR, WCAG 2.2, performance heuristics, severity-ranked findings, optional fix application. v3.0: Opus 4.7 optimized with parallel tool calls, JSON-first subagent output, compaction-safe checkpointing, non-interactive mode for agents/CI.4---5
6**Cross-model note.** v3.0 defaults to **Opus 4.7** for the primary review (best reasoning for the adversarial protocol + severity calibration). **Sonnet 4.6** is a first-class fallback — set `--model sonnet` for cost-sensitive PR scans. **Haiku 4.5** only for narrow blame-aware diffs with `--local-only`. Cross-engine (`--engine both`) runs primary on Opus and adversarial on whatever the config specifies, defaulting to Opus.
7
8**Branding note.** Finding IDs (`UCR-NNN`), config (`.ucrconfig.yml`), and history dir (`.ucr/history/`) retain the UCR prefix from the plugin's v1.0 heritage ("Universal Code Review"). The plugin itself is `rad-code-review`. Migration would be breaking; the aliasing is intentional and stable.
9
10<objective>
11Run a professional-grade, diff-aware code review and produce a structured report with
12severity-ranked findings, release verdict, and optional fix application.
13
14**v3.0 differentiators (new):**
15- **Opus 4.7 as the default primary-review model** with explicit `--model` override
16- **Parallel tool calls** across Steps 1–5 — deep reviews complete ~3–5× faster on Opus/Sonnet
17- **JSON-first subagent output** — more robust across model variance than markdown parsing
18- **Checkpoint / `--resume`** — compaction-safe state writes after Steps 5, 7, 9
19- **`--non-interactive`** — agent/CI callers skip the findings menu and get structured return
20- **Externalized subagent prompts** — primary/adversarial/self-adversarial templates in `references/subagent-prompts/`
21- **`.ucrconfig.yml` accepted-risk expiry enforcement** — stale entries re-evaluated, not silently suppressed
22
23**v2.x differentiators (retained):**
24- Blame-aware scoping: `diff` and `commit` scopes only flag issues on changed lines by default
25- Incremental review: `--since <commit>` reviews all changes since a specific commit
26- Framework-specific IDOR detection: concrete mutation ownership patterns for 6 frameworks
27- Performance profiling heuristics: grep-able patterns for N+1, re-renders, bundle bloat
28- Dynamic ARIA state detection: catches hardcoded aria-expanded, aria-selected, etc.
29
30**Orchestrator role:** Parse arguments, compute diff scope, gather user choices, detect
31project context, spawn review subagents with annotated diff context, handle checkpoints
32and adversarial passes, offer fixes, assemble final report.
33
34**Three report roles:**
351. Bug finder — functional correctness, edge cases, race conditions, state corruption
362. Architecture reviewer — coupling, boundaries, extensibility, patterns, maintainability
373. Release gate — security, secrets, dependencies, ops readiness, public defensibility
38
39**Review dimensions:** Functional correctness, security, AI slop detection, architecture,
40tests, performance, UI/UX, accessibility, release readiness, documentation, dependencies,
41privacy/secrets handling.
42</objective>
43
44<execution_context>
45**Load these files NOW before proceeding:**
46- ${CLAUDE_SKILL_DIR}/workflows/orchestrate-review.md (main workflow)
47- ${CLAUDE_SKILL_DIR}/references/severity-model.md (severity classification)
48- ${CLAUDE_SKILL_DIR}/references/trust-model.md (trust boundaries)
49</execution_context>
50
51<context>
52Arguments: $ARGUMENTS
53
54**Scope options:** repo | diff | commit | tree
55- `repo` — review all files in the repository (full scan, no blame filtering)
56- `diff` — review staged + unstaged changes only (blame-aware by default)
57- `commit` — review files changed in HEAD commit only (blame-aware by default)
58- `tree` — review uncommitted working tree changes only (full scan of changed files)
59
60**Incremental review:** --since <commit>
61- Reviews all changes between <commit> and HEAD
62- Blame-aware: only flags issues introduced in those changes
63- Useful for: PR review, sprint review, post-release delta
64
65**Scan mode:**
66- Default for diff/commit/--since: blame-aware (only flag issues on changed lines)
67- Default for repo/tree: full scan (flag all issues found)
68- `--full-scan` — override blame-aware default, flag all issues regardless of authorship
69- Blame-aware mode still flags pre-existing issues when a new change depends on broken existing code
70
71**Strictness:** mvp | production | public (default: production)
72- `mvp` — focus on functional correctness, critical security, and stated goals
73- `production` — full review across all dimensions
74- `public` — production + open-source readiness, public scrutiny resilience, trust signals
75
76**Engine:** claude | codex | both (default: claude)
77- `claude` — Claude performs all review phases
78- `codex` — Codex performs all review phases
79- `both` — Claude does primary review (Phase 3), Codex does adversarial pass (Phase 4)
80
81**Connectivity:** --local-only (default: internet-enabled)
82**Fix mode:** --fix blockers | --fix critical-major | --fix id1,id2,...
83
84**Model selection (v3.0):**
85- `--model opus` (default) — Opus 4.7 primary review
86- `--model sonnet` — Sonnet 4.6 for cost-sensitive reviews
87- `--model haiku` — Haiku 4.5 only for narrow blame-aware + --local-only scopes
88- `--adversarial-model <name>` — override adversarial-pass model separately
89
90**Non-interactive mode (v3.0):**
91- `--non-interactive` — skip the findings menu, return findings + verdict + report path. Used by the `code-reviewer` agent, `/loop` sessions, and CI.
92
93**Resume (v3.0):**
94- `--resume <run-id>` — rehydrate mid-review state from `.ucr/state/<run-id>.json` after compaction or interruption. Run IDs are logged at the start of each run.
95
96**Project config:** .ucrconfig.yml (if present in repo root)
97**History:** .ucr/history/{YYYY-MM-DD}-{HHmmss}-{scope}-{strictness}.md (previous review reports)
98**State:** .ucr/state/{run-id}.json (checkpoints for --resume)
99</context>
100
101<process>
102Execute the orchestrate-review workflow from
103${CLAUDE_SKILL_DIR}/workflows/orchestrate-review.md end-to-end.
104
105Preserve all workflow gates, user checkpoints, and subagent boundaries.
106</process>
107
108<critical_rules>
1091. **Always ask for scope** if not provided in arguments
1102. **Blame-aware by default** for diff/commit/--since scopes — only flag issues on changed lines unless the change depends on pre-existing broken code
1113. **Disclose internet usage** before proceeding if not --local-only — state what will be accessed and why
1124. **Never include secret values** in reports — show file, line, key name, and type only. Mask values completely in code snippets.
1135. **Triage-first mode:** If project appears fundamentally broken (50+ critical findings or unsalvageable architecture), switch to triage report — verdict, systemic diagnosis, top 5-10 blockers, remediation roadmap. Say plainly if rebuild is warranted.
1146. **Load .ucrconfig.yml** exclusions and accepted-risk rules if present. Surface all exclusions and accepted risks in the report for auditability.
1157. **Save report** to .ucr/history/{timestamp}-{scope}-{strictness}.md after completion
1168. **Compare against history** — if previous reports exist for this repo, summarize resolved, remaining, and newly introduced findings
1179. **Secrets in config** — if .ucrconfig.yml contains accepted risks, validate they are still acknowledged, not stale
11810. **Do not fabricate findings** — if you cannot verify something, mark confidence as "possible" and say what verification is needed
11911. **Do not suppress findings** because they seem minor — rank them accurately and let severity speak. But do suppress findings that fail the evidence threshold for their severity level.
120</critical_rules>
121
122<success_criteria>
123- [ ] User confirmed scope, strictness, engine, and connectivity
124- [ ] Diff context computed and annotated (if blame-aware mode)
125- [ ] Project type(s) detected and relevant modules loaded
126- [ ] Primary review completed with findings scoped to changed lines (if blame-aware)
127- [ ] Adversarial pass completed (if dual-engine or self-adversarial)
128- [ ] Review-of-review pass completed (de-duplication, calibration)
129- [ ] Findings presented to user with severity ranking
130- [ ] Fix option offered (if findings exist)
131- [ ] Report generated and saved
132- [ ] History comparison included (if previous reports exist)
133</success_criteria>