code-review-bugsnag — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited code-review-bugsnag (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Perform code review for a fix linked to a Bugsnag error by analyzing the related pull request and publishing results to:
@skills/pr-summary/SKILL.md and the mirrored linked-GitHub-issue summary follow the language of the source assignment. Never mix languages inside the same comment.git add, git commit, git push, git reset, git checkout -- …, etc.). Checking out the relevant branch and git pull to read the latest code are required (the mandatory Branch checkout gate below); mutating the working tree or pushing to the remote is not. Publishing is limited to PR / linked-issue comments via gh and to the Bugsnag error comment via skills/code-review-bugsnag/scripts/upsert-comment.sh.skills/code-review-bugsnag/scripts/load-issue.sh <URL|TRIPLE> — the single deterministic entry point. Requires BUGSNAG_TOKEN (a Data Access API token). Never call api.bugsnag.com directly. Read the error class, message, context, status, severity, latestEvent.stacktrace (the in-project frames are the reproduction entry point), comments[], and linkedIssues[] off the resulting JSON document.skills/code-review-bugsnag/scripts/gather-issue-context.sh <URL|TRIPLE> instead of hand-assembling the JSON. To read only the comments as a structured array, use skills/code-review-bugsnag/scripts/parse-comments.sh <URL|TRIPLE>. Both build on load-issue.sh, so the same exit codes, BUGSNAG_TOKEN requirement, and MCP fallback apply. linkedIssues point at GitHub — load that linked issue with skills/code-review-github/scripts/gather-issue-context.sh <URL> when you need its full context.app.bugsnag.com/<org>/<project>/errors/<id> URL or an <org>/<project>/<error-id> triple.linkedIssues[] (the mirrored GitHub issue/PR). Load that PR with skills/code-review-github/scripts/load-issue.sh <URL> to get the diff, commits[], and closingIssues[].headRefName from the loaded PR JSON) and pull the latest commits — git fetch origin, git checkout <headRefName>, git pull — so the review always runs against the actual current codebase on disk (the checked-out working tree), never against the remote diff in isolation. Confirm local HEAD equals the PR head SHA. If the checkout fails (missing ref, detached HEAD, or local changes that would be overwritten), stop and report it instead of reviewing from the diff. Every sub-review then reads the checked-out files.#### Issue Context Analysis Before reviewing code, treat the Bugsnag error as the assignment:
message + context describe the failure; the in-project latestEvent.stacktrace frames pinpoint the code path that must be fixed.comments[] for human-authored context (e.g. "Fixed in db", reproduction notes), plus any acceptance criteria on the linked GitHub issue.#### Reviewer Comment Fulfillment Gate (mandatory)
Run the Reviewer Comment Fulfillment Gate defined canonically in @skills/code-review-github/SKILL.md against the GitHub PR linked to this Bugsnag error — that is where this skill publishes technical CR findings and where reviewer comments and line-anchored review threads live. After loading all PR comments, verify each actionable reviewer instruction is satisfied by the current checked-out diff (the applied change corresponds to what the reviewer asked for), raise one Critical finding per not-fulfilled instruction on the GitHub PR comment with the four reproducer fields, and record the reviewer comments: M/N fulfilled verdict on the GitHub PR comment summary line. The Bugsnag non-technical comment never carries this gate's findings.
statusCheckRollup[] from the GitHub PR JSON loaded in step 1 (via skills/code-review-github/scripts/load-issue.sh). Identify which checks ran on the PR head commit (headRefOid) and their result. Pass this CI check map to the Coverage gate decision in @skills/code-review/SKILL.md (Validation → Coverage gate; the Reuse-CI-results detail now lives in @rules/code-review/general.mdc Validation & Coverage Gate) so only missing or non-green checks are run locally.Inline dispatch. Each sub-review runs inline in this wrapper's context — invoke each skill directly (@skills/<name>/SKILL.mdwith anyMODE=crflag), passing the PR URL / number and the branch already checked out, and declare the publishing contract for this CR run (quiet vs publish; see step 4). Run the sub-reviews one at a time — do not dispatch them as parallel subagents.
## Assignment Compliance markdown block (only when at least one Critical gap exists) or a skip status. The wrapper passes a returned block to @skills/pr-summary/SKILL.md as an embedded block so each tracker receives one consolidated comment per CR run (per issue #498). Do not embed the block into the GitHub PR comment.@skills/code-review/SKILL.md Specialized Reviews → Always run; it is distinct from the per-Critical-finding verification (issue #537) and must not duplicate gaps already raised by assignment-compliance-check.@skills/code-review-jira/SKILL.md): refactoring diff → @skills/refactor-entry-point-to-action/SKILL.md with MODE=cr; database operations → @skills/mysql-problem-solver/SKILL.md (surface under ## Database Analysis); shared state → @skills/race-condition-review/SKILL.md; third-party API changes → the Third-Party API & Service Analysis step from @skills/code-review/SKILL.md.Quiet mode (loop iterations from `@skills/process-code-review/SKILL.md`): when the caller requests "do not publish; return findings as in-memory markdown", skip all publishing below and return the assembled review markdown. Only the final (publishing) call after convergence runs Publish Results in full.
#### GitHub (technical findings only — always-new comment per CR run)
skills/code-review-github/scripts/upsert-comment.sh <PR-NUMBER|URL> - (body on stdin) on the linked PR. Every CR run posts a fresh PR comment; the helper appends the marker <!-- cr-comment:actor=<gh-login> --> for traceability and never edits a prior comment in place. On exit code 2/3, fall back to the GitHub MCP server's addIssueComment as a fresh post.file:line and an actionable fix. Use the template defined in templates/github-output.md. Omit empty sections entirely per @skills/code-review/SKILL.md Output Rules.#### Bugsnag (consolidated non-technical comment)
@skills/pr-summary/SKILL.md. This CR skill must not author its own summary — the goal is the uniform "Authors / Available behind / Summary of changes / How to test" output that non-developers understand.pr-summary exactly once for the Bugsnag error. When @skills/assignment-compliance-check/SKILL.md returned a markdown block, pass it as an embedded block so the Bugsnag audience sees one consolidated comment. pr-summary posts the comment via skills/code-review-bugsnag/scripts/upsert-comment.sh <URL|TRIPLE> - (Bugsnag MCP server fallback on exit code 2/3). Each CR run posts a fresh comment (Bugsnag renders plain text — no hidden per-actor marker; the token identifies the author).author.login + commits[].author.login set and the git %an <%ae> log so the published comment credits the real change author(s), never the agent / CR identity. Also pass through any test-parameter gating detected in the diff so the comment carries the Available behind line.pr-summary enforces this by design.#### Linked GitHub issues (consolidated mirror — always-new comment per CR run)
closingIssues[] non-empty), delegate the linked-GitHub-issue comment to @skills/pr-summary/SKILL.md (GitHub tracker target) and post via skills/code-review-github/scripts/upsert-comment.sh on each entry — one fresh comment per linked issue per CR run. Pass the same author + test-parameter context. If closingIssues[] is empty, note "no linked GitHub issue — mirror skipped" in the PR comment summary line.@skills/process-code-review/SKILL.md can convert each finding into a reproducer test and apply the fix. Omit empty sections and the coverage surfaces per @skills/code-review/SKILL.md Output Rules.@skills/test-like-human/SKILL.md. It runs on demand only; CR-track skills must never chain into it.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.