classifying-review-findings

Use this skill when categorizing code review findings into severity levels. Apply when determining which emoji and label to use for PR comments, deciding if an…

npx skills add https://github.com/bitwarden/ai-plugins --skill classifying-review-findings

Classifying Review Findings

Severity Categories

EmojiCategoryCriteria
❌CRITICALWill break, crash, expose data, or violate requirements
⚠️IMPORTANTMissing error handling, unhandled edge cases, could cause bugs
♻️DEBTDuplicates patterns, violates conventions, needs rework within 6 months
🎨SUGGESTEDMeasurably improves security, reduces complexity by 3+, eliminates bug classes
❓QUESTIONRequires human knowledge - unclear requirements, intent, or system conflicts

ALWAYS use hybrid emoji + text format for each finding (if multiple severities apply, use the most severe: ❌ > ⚠️ > ♻️ > 🎨 > ❓):

Before Classifying

Verify ALL three:

  1. Can you trace the execution path showing incorrect behavior?
  2. Is this handled elsewhere (error boundaries, middleware, validators)?
  3. Are you certain about framework behavior and language semantics?

If any answer is "no" or "unsure" → DO NOT classify as a finding.

Not Valid Findings (Reject)

  • Praise ("great implementation")
  • Vague suggestions ("could be simpler")
  • Style preferences without enforced standard
  • Naming nitpicks unless actively misleading
  • PR metadata issues (title, description, test plan) - handled by summary skill, not classified here
  • Renovate/Dependabot minor/patch updates to existing dependencies with passing CI — these are routine Stage 5 monitoring, not reviewable findings

Suggested Improvements (🎨) Criteria

Only suggest improvements that provide measurable value:

  1. Security gain - Eliminates entire vulnerability class (SQL injection, XSS, etc.)
  2. Complexity reduction - Reduces cyclomatic complexity by 3+, eliminates nesting level
  3. Bug prevention - Makes entire category of bugs impossible (type safety, null safety)
  4. Performance gain - Reduces O(n²) to O(n), eliminates N+1 queries (provide evidence)

Provide concrete metrics:

  • ❌ "This could be simpler"
  • ✅ "This has cyclomatic complexity of 12; extracting validation logic would reduce to 6"

If you can't measure the improvement, don't suggest it.

More skills from bitwarden

figma-to-angular
bitwarden
This skill turns a Figma design spec into a fully implemented Angular component with Storybook stories in the Bitwarden Clients monorepo. The output should match the design visually while following all codebase conventions.
force-multiplier
bitwarden
Apply one intent across many targets at once — a fleet of repositories across the Bitwarden ecosystem, or many projects inside a monorepo — as N consistent,…
analyzing-git-sessions
bitwarden
Analyzes git commits and changes within a timeframe or commit range, providing structured summaries for code review, retrospectives, work logs, or session…
coordinating-cross-team-breakdown
bitwarden
Coordinate cross-team review and signoff for a Bitwarden Tech Breakdown. Use when identifying affected teams, building the Part 3 signoff table, chasing…
assessing-jira-issue-relevance
bitwarden
Use when the user provides a single Jira issue key and asks whether it is still relevant, still applicable, still pending, still a bug, has been fixed, or can…
assessing-test-coverage
bitwarden
Use when determining what test coverage ALREADY exists for a specific change (a PR, Jira key, Tech Breakdown doc, Testmo CSV, changed paths, or named…
retrospecting
bitwarden
Performs comprehensive analysis of Claude Code sessions, examining git history, conversation logs, code changes, and gathering user feedback to generate…
reviewing-incremental-changes
bitwarden
Use this skill when re-reviewing a PR that already has comments or when responding to developer changes after initial review. Apply when PR threads exist or…