Ask an AI agent to review your branch and you usually get a mixed list: a naming nit, a missing test, a question about whether the feature is what was asked for, all in one ranking. Matt Pocock's code review skill splits that into two separate reviews. One checks the code against your repo's standards. The other checks it against the issue or spec it was meant to implement. You get both reports side by side.
What it does
You give it a starting point (a branch, a commit, main), and it:
- Pins the diff. Runs
git diff <start>...HEADand lists the commits, and stops early if the ref is wrong or the diff is empty. - Finds the spec. Issue numbers in the commit messages first, then a path
you pass, then a matching file under
docs/,specs/or.scratch/. If there isn't one, it asks. - Finds the standards. Files like
CONTRIBUTING.mdorCODING_STANDARDS.md, plus a fixed list of twelve code smells from Martin Fowler's Refactoring (Duplicated Code, Feature Envy, Shotgun Surgery and so on). Your repo's rules override the smells. - Runs two sub-agents in parallel, one per axis, each limited to about 400 words.
- Reports them separately under Standards and Spec, without merging or re-ranking.
It explains the split this way:
Code that follows every standard but implements the wrong thing → Standards pass, Spec fail.
From SKILL.md by Matt Pocock, MIT.
An example
You say: "Review since main." The branch's commits mention #42, which asked
for CSV export with a date filter. The Spec review reports that the date
filter is missing and that a JSON export was added that nobody asked for. The
Standards review separately flags a possible Data Clump (from, to and
timezone passed together through three functions) as a judgement call, and
notes the new file breaks the repo's documented naming rule.
When to use it, and when not to
Use it before you open a pull request, or when reviewing someone else's, and especially when there's a written issue to check against. It's a good way to learn the classic code smells too, because each finding names one.
It's not a security review and doesn't run your tests. For a one-line change, reading the diff yourself is quicker.
What we checked
We read every file in the folder at the commit linked above: SKILL.md and
agents/openai.yaml (a display name for Codex). There are no scripts and no
allowed-tools. It runs git commands in your repo and reads files in it.
If you've set up an issue tracker file with Matt Pocock's setup skill, it
follows that file to fetch the issue, which can go over the network with your
tracker's own command-line tool; without it, nothing leaves your machine. The
repo is MIT licensed. Our full checklist is in the
guide to checking a skill before you install it.
To settle the plan before you build, and have a spec to review against, try the grill me skill.