Review code and test evidence
Read collaboration, artifacts, and safety before reviewing.
Review is read-only. Do not implement fixes unless the user separately requests changes.
Establish the contract
- Resolve the scope from an explicit file list, diff range, active Flow state, or working-tree diff.
- Read applicable
AGENTS.md, the relevant acceptance criteria, quality rules, and prohibitions.
- If scope is ambiguous, inspect safely and state the bounded scope used.
Correctness lens
- Read the complete diff, not only a summary.
- Check behavior, error paths, boundary cases, security, concurrency, data integrity, compatibility, conventions, and unnecessary complexity.
- Report only actionable findings with severity, file, tight line range, consequence, and concrete remediation.
- Use inline code comments when the runtime supports them.
QA lens
- Map each acceptance criterion and changed behavior to existing tests.
- Run the relevant test commands when safe and non-mutating beyond normal local build artifacts.
- Identify untested failure paths and explain the smallest valuable missing test.
- Distinguish environmental failures from product failures.
Run the two lenses sequentially by default. Use separate collaborating workers only when the user explicitly requests delegation or parallel agent work, following collaboration.
Verdict
Use the worst applicable result:
APPROVED: no critical or major finding and evidence is adequate;
CHANGES_REQUESTED: at least one major finding or material test gap;
BLOCKED: scope, evidence, or environment prevents a responsible review.
Return findings first, ordered by severity, followed by assumptions, test evidence, and verdict. Persist a report only when the user requested it or this is an active Flow phase with artifact persistence already authorized.
1---2name: flow-review3description: Reviews code diffs or explicit file sets through independent correctness and QA lenses, producing a severity-ordered verdict for pre-merge audits or review gates.4---56# Review code and test evidence78Read [collaboration](../../references/collaboration.md), [artifacts](../../references/artifacts.md), and [safety](../../references/safety.md) before reviewing.910Review is read-only. Do not implement fixes unless the user separately requests changes.1112## Establish the contract13141. Resolve the scope from an explicit file list, diff range, active Flow state, or working-tree diff.152. Read applicable `AGENTS.md`, the relevant acceptance criteria, quality rules, and prohibitions.163. If scope is ambiguous, inspect safely and state the bounded scope used.1718## Correctness lens1920- Read the complete diff, not only a summary.21- Check behavior, error paths, boundary cases, security, concurrency, data integrity, compatibility, conventions, and unnecessary complexity.22- Report only actionable findings with severity, file, tight line range, consequence, and concrete remediation.23- Use inline code comments when the runtime supports them.2425## QA lens2627- Map each acceptance criterion and changed behavior to existing tests.28- Run the relevant test commands when safe and non-mutating beyond normal local build artifacts.29- Identify untested failure paths and explain the smallest valuable missing test.30- Distinguish environmental failures from product failures.3132Run the two lenses sequentially by default. Use separate collaborating workers only when the user explicitly requests delegation or parallel agent work, following [collaboration](../../references/collaboration.md).3334## Verdict3536Use the worst applicable result:3738- `APPROVED`: no critical or major finding and evidence is adequate;39- `CHANGES_REQUESTED`: at least one major finding or material test gap;40- `BLOCKED`: scope, evidence, or environment prevents a responsible review.4142Return findings first, ordered by severity, followed by assumptions, test evidence, and verdict. Persist a report only when the user requested it or this is an active Flow phase with artifact persistence already authorized.