feat: add review and using-entire skills (#28) · Entire
feat: add review and using-entire skills (#28)
9cea55c→main·
SnowingFox·1mo ago·4 files·+476 added/-0 removed
* feat: add review, dispatch, and using-entire skills
- review: intent-aware code review that reads checkpoint transcripts
before auditing the diff. Findings use Critical/High/Medium/Low
severity prefixes compatible with entire review --fix. Audit rules
are separated into references/review-rules.md for independent
customization.
- dispatch: generates a weekly engineering dispatch (default 7 days)
and writes DISPATCH.md. Prefers entire dispatch --local when the
CLI is available; falls back to manual git-log + checkpoint explain.
- using-entire: orchestrator skill that routes user intent to the right sub-skill or runs a general exploration flow backed by checkpoint history. Inspired by the using-superpowers pattern.
- README: add review, dispatch, and using-entire to included skills, example prompts, and the goals table.
* fix(dispatch): use basic commands instead of entire dispatch CLI
Rewrite the dispatch skill to use git log + entire explain for
checkpoint enumeration and metadata reading, instead of delegating
to entire dispatch --local. This aligns with the skill design
principle: skills orchestrate basic CLI primitives, they don't wrap
high-level commands.
* fix(using-entire): remove Chinese phrases, add reference docs
Remove Chinese trigger phrases from the routing table to keep the
skill language-neutral. Add references section pointing to
entire help and docs.entire.io/llms.txt for deeper exploration.
* fix(using-entire): describe llms.txt as AI-friendly docs index
* remove dispatch skill per reviewer feedback
The entire CLI already has a dispatch command, so a separate skill
is redundant. Updated using-entire routing table to point users to
entire dispatch directly. Removed dispatch references from README.
Changes
4
MREADME.md+20
skills
review
ASKILL.md+220
references
Areview-rules.md+87
using-entire
ASKILL.md+149
# Example command for intent awareness and checkpoints
entire review <branch>
| Find prior work before making changes | search past work for the migration |
| Understand the intent behind a function, file, or line | explain parseConfig |
| Investigate the latest change to a specific block | what happened at src/auth.ts:42 |
| Review branch changes with intent context | review this branch before merging |
| Pick up another agent's work | hand off the codex session |
| Convert repeated work into a reusable workflow | make a skill from this session |
review
Reviews code changes on the current branch by reading checkpoint transcripts to
understand developer intent, then auditing the diff for issues. Produces
intent-aware findings with severity levels (Critical / High / Medium /
Low) compatible with entire review --fix. Includes a separate
references/review-rules.md for the audit checklist.
using-entire
Orchestrator skill for codebase exploration. Routes user intent to the right sub-skill (search, explain, what-happened, review, session-handoff, session-to-skill, session-crosslink) or runs a general exploration flow that reads checkpoint history before inferring from code.
session-crosslink
Links an agent session that ran outside the repo whose commits should record it
Review Rules
This file defines the severity levels, audit dimensions, and output format for the
review skill. The SKILL.md workflow reads this file at review time.
Severity Levels
Every finding must begin with one of these severity prefixes. These prefixes are parsed
by entire review --fix to extract individual findings for automated remediation.
| Severity | Prefix | Meaning | Examples |
|---|---|---|---|
| Critical | Critical: |
Likely bug, data loss, or security vulnerability that must be fixed before merge | Null dereference, SQL injection, race condition, auth bypass, unvalidated redirect, use-after-free |
| High | High: |
Serious issue that strongly warrants fixing | Missing error handling on I/O, N+1 queries in hot path, resource leak (fd/connection/goroutine), unsafe deserialization, hardcoded secret |
| Medium | Medium: |
Improvement that reduces risk or improves maintainability | Unclear naming, duplicated logic, missing type constraints, excessive coupling, missing input validation on internal API |
| Low | Low: |
Observation worth noting but not blocking | Style inconsistency, potential future tech debt, optional micro-optimization, missing logging |
Audit Dimensions
With checkpoint context (intent-aware review)
When checkpoint transcripts are available for a file, also check:
- Intent match — Does the implementation do what the user/agent described in the session?
- Constraint adherence — Were explicitly discussed constraints (performance, backward compatibility, API contracts) respected in the final code?
- Edge case coverage — Were edge cases mentioned in the transcript actually handled?
- Leftover artifacts — Are there debugging
console.log,TODO/FIXMEcomments, commented-out code, or temporary workarounds that should have been cleaned up? - Scope creep — Did the change introduce unrelated modifications not discussed in the session that could have side effects?
Always check (with or without context)
These checks apply to every file in the diff regardless of checkpoint availability:
- Logic errors — Off-by-one, incorrect boolean logic, wrong comparison operator, infinite loops, unreachable branches, incorrect short-circuit evaluation
- Null safety — Unguarded nullable access, missing nil/undefined checks before dereference, optional chaining gaps
- Security — SQL/NoSQL injection, command injection, path traversal, XSS, CSRF, auth bypass, insecure direct object reference, data exposure in logs/errors, hardcoded credentials or secrets
- Performance — N+1 queries, unnecessary allocations in loops, missing pagination, unbounded collection growth, synchronous I/O in async context, missing indexes
- Error handling — Swallowed errors, missing catch/recover, error messages that leak internals, panic in library code, missing cleanup on error path
- API contracts — Return type mismatches, missing required fields, breaking changes to public interfaces, incorrect HTTP status codes, missing content-type headers
- Concurrency — Unprotected shared state, missing locks, goroutine/promise leaks, deadlock potential, race conditions on read-modify-write
- Resource management — Unclosed handles (files, connections, streams), missing
defer/finally/using, leaked timers or intervals - Dead code — Unreachable branches after early returns, unused imports/variables/functions, redundant conditions that are always true/false
- Test quality — Tests that never fail, assertions on implementation details rather than behavior, missing edge case coverage for new code paths
References
For a deeper understanding of Entire's capabilities beyond what the sub-skills cover, consult these resources:
- CLI help: run
entire helpto see all available commands and flags - Documentation: https://docs.entire.io/llms.txt — AI-friendly documentation index following the llms.txt standard, designed to be consumed directly by LLMs and coding agents