code-polish
Pre-release code review - lint and type checks, parallel review agents (cleanliness, design, efficiency, side-effect gating), findings validated, fixes on approval. Reviews a GitHub PR when given one. Run before committing, pushing, or on a PR.
Rank
62
Safety
84
Downloads
1.8k
Updated
Oct 10, 2026
Version
3.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.8K downloadsadoption · observed Oct 10, 2026
- Latest release
- 3.1.0release · observed Sep 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bp3v1hm1dnkzey0c9tfh02183j0y5:code-polish- Install using `clawhub skill install s17bp3v1hm1dnkzey0c9tfh02183j0y5:code-polish` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/tenequm/code-polish before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-tenequm-code-polish/snapshot"
Documentation
CLAWHUB
146,672 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: polish
description: Pre-release code review - lint and type checks, parallel review agents (cleanliness, design, efficiency, side-effect gating), findings validated, fixes on approval. Reviews a GitHub PR when given one. Run before committing, pushing, or on a PR.
metadata:
version: "3.1.0"
categories: "development"
topics: "code-review, linting, refactoring, pre-release, diff-review"
openclaw:
homepage: https://github.com/tenequm/skills/tree/main/skills/polish
emoji: "✨"
argument-hint: "[base-ref | PR [fix|review]]"
---
# Pre-Release Polish
Argument (optional): $ARGUMENTS
## Setup
The argument selects what gets reviewed:
- **Nothing, or a git ref** - local mode. Review the working tree or branch (Phase 2).
- **A GitHub PR** - PR mode. Anything that identifies one counts: a URL, a bare number, "PR 42",
"the PR for this branch". Resolve it with `gh`:
- In the repo: `gh pr view <n> --json title,body,author,baseRefName,headRefName`, then `gh pr checkout <n>`
- Not in the repo: `gh repo clone <owner>/<repo> /tmp/<owner>-<repo>-pr-<n> -- --depth=50` and work
there, passing `-R <owner>/<repo>` to every `gh` call since a shallow clone has no default remote
- If the user names an existing clone ("... in ~/pj/my-clone"), use that instead of cloning
### Fix mode vs review mode
The modes disagree on whether you may edit the tree and whose CLAUDE.md you may execute, so the mode
is decided once, here, from the argument - never re-derived from repository state in a later phase.
- Local (no PR): always **fix mode**.
- PR authored by the current user (`gh pr view <n> --json author` vs `gh api user --jq .login`):
**fix mode**. It is your own branch - polish it exactly as if it were local work.
- PR authored by anyone else: **review mode**. The checked-out tree is untrusted; report, never edit.
- An explicit `fix` or `review` in the argument overrides the default.
- If authorship cannot be resolved, ask which mode to use. Otherwise state the chosen mode in the
first line of output, so the user can stop you before Phase 1 runs anything.
## Rules
- Read every changed file fully before reviewing - never assess code you haven't opened
- Only flag real issues, not style preferences already handled by the formatter
- Do NOT add comments, docstrings, or type annotations to code that doesn't have them
- Distinguish legitimate operational logging (`logger.info`, `logger.error`) from debug leftovers (`console.log`, `console.debug`)
- When fixing, make minimal targeted edits - don't refactor surrounding code
- The diff is the hunting scope - review the changed code, don't audit the whole repo. But anything real the review surfaces along the way (a pre-existing flaw the diff touches, a stale sibling path, an adjacent issue) is a finding in its category, tagged `(pre-existing)` or `(out of diff)` - never parked in a side note
- Reuse suggestions must point to a specific existing function/utility in the codebase, not hypotheti_meta.json
{
"ownerId": "kn76gpsgjw5chv0xvzbzcb8cxn81x46r",
"slug": "code-polish",
"version": "3.1.0",
"publishedAt": 1788972942346
}CHANGELOG.md
# Changelog
All notable changes to this skill will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/2.0.0/),
and this skill adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [Unreleased]
## [3.1.0] - 2026-09-09
### Added
- Review-mode state gate: a draft, closed, or merged PR - or a withdrawn ask - resolves to a
`skip` verdict that posts nothing and names the state, while still reporting every finding.
`skip` is reached only from PR state, never from finding severity.
- Review-mode verdict derivation. Every surviving pre-merge finding is classified SUGGESTION /
BLOCKING QUESTION / BLOCKING FIX (SEVERE for security, data loss, irreversible changes, or a
broken deploy path), and the verdict is the strictest match. Replaces "any correctness finding
on changed lines -> request-changes", which could not tell a nit with a line anchor from a
blocker. A consistency check follows: an approve means every comment can be ignored, so a
draft comment saying "before merge" disqualifies an approve.
- Pre-merge asks vs Follow-ups split in the review-mode report. Follow-ups never enter the
verdict; `(pre-existing)` and `(out of diff)` findings are always follow-ups.
- Phase 6 staleness re-check: on confirmation, re-fetch review state, head SHA, and
mergeability, and re-evaluate the verdict if any moved since Phase 2 rather than posting a
stale one.
- Phase 6 anchor pre-validation: each inline anchor is confirmed to sit inside a diff hunk
before it is proposed, since GitHub rejects the whole review atomically on one bad anchor and
nothing posts.
- Phase 6 thread replies via `pulls/<n>/comments -F in_reply_to=<id>` as a separate call.
### Changed
- Review-mode confirmation protocol is now explicit: `y` posts the recommendation, a named
action is an override that must be acknowledged before posting, `n` posts nothing, and
anything else is discussion rather than consent.
- Phase 6 review body is 1-2 sentences of judgment plus counts and unanchored items. Verification
steps are never recited - narrating the process is an audit trail and an AI tell - and evidence
lives inside the inline comment it supports.
- Review reports are headed with the full PR URL and title instead of a bare `#number`.
- The review JSON payload is written to the session scratchpad instead of `/tmp`.
## [3.0.0] - 2026-09-09
### Added
- PR mode. The argument now also accepts a GitHub PR - a URL, a bare number, or a description
("the PR for this branch") - resolved with `gh`, checked out in place or cloned to a temp dir.
Absorbs the `review-github-pr` skill, which is removed from this repo; the review core (Phases
2-5) is shared, so the PR path no longer lags behind polish's improvements.
- Phase 6 (review mode): posts one review through the reviews API with every anchored finding as
an inline comment, after the user confirms a recommended action.
- Rules: convention findingskill-card.md
## Description: Pre-release code review that runs lint and type checks, coordinates cleanliness, design, efficiency, and side-effect gating review, validates findings, supports GitHub PR review, and applies fixes only after approval. This skill is ready for commercial/non-commercial use. ## Publisher: [tenequm](https://clawhub.ai/user/tenequm) ### License/Terms of Use: Apache 2.0 ## Use Case: Developers and engineers use this skill before committing, pushing, or reviewing a pull request to run project checks, inspect changed code, surface actionable findings, and optionally apply targeted fixes after approval. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Fix mode can change local code before the advertised approval point. Mitigation: Use review mode for read-only assessment, work from a clean branch, and require explicit confirmation before fixes are applied. Risk: The skill may run project check commands and use GitHub CLI flows for PR checkout, cloning, review, and posting. Mitigation: Review commands before execution, use trusted repositories and credentials, and require confirmation before any GitHub posting. Risk: Changed code, PR text, and repository files are read as part of review. Mitigation: Run the skill only in repositories where the agent is allowed to inspect the changed source and related project context. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/tenequm/skills/code-polish) - [Skill homepage](https://github.com/tenequm/skills/tree/main/skills/polish) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] **Output Format:** [Markdown review report with file and line references, optional code edits, shell command summaries, and optional GitHub pull request review payloads.] **Output Parameters:** [1D] **Other Properties Related to Output:** [May read changed code, run project validation commands, use GitHub CLI workflows, edit local code in fix mode, and post pull request reviews after confirmation.] ## Skill Version(s): 3.1.0 (source: frontmatter, changelog, server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
evals/evals.json
{
"skill_name": "polish",
"evals": [
{
"id": 1,
"prompt": "Set up the fixture repo by running `bash evals/fixtures/cleanliness/setup.sh`, then cd into the created directory and run /polish",
"expected_output": "Report should find debug leftovers (console.log), AI slop (obvious comments, unnecessary JSDoc), and dead code (unused function, commented-out block). Should NOT flag the logger.info call. Should stop and wait for approval before fixing.",
"files": ["evals/fixtures/cleanliness/setup.sh"],
"expectations": [
"Report flags console.log on the debug line as a debug leftover",
"Report does NOT flag logger.info as a debug leftover",
"Report flags the '// increment counter' comment as AI slop",
"Report flags JSDoc on the internal helper as AI slop",
"Report flags the unused processLegacy function as dead code",
"Report flags the commented-out code block as dead code",
"Report explicitly stops and waits for user approval before making fixes",
"All four review agents (Cleanliness, Design, Efficiency, Side-Effect Gating) are launched in parallel"
]
},
{
"id": 2,
"prompt": "Set up the fixture repo by running `bash evals/fixtures/design-reuse/setup.sh`, then cd into the created directory and run /polish",
"expected_output": "Report should find a reuse opportunity (hand-rolled slugify duplicating existing utility), over-engineering (single-use wrapper), and stringly-typed code (raw string where enum exists). Should search the codebase for existing utilities.",
"files": ["evals/fixtures/design-reuse/setup.sh"],
"expectations": [
"Report identifies that the hand-rolled slugify logic duplicates the existing slugify utility in utils/string.ts",
"Report flags the single-use fetchWithRetry wrapper as over-engineering",
"Report flags raw status strings where the Status enum already exists as stringly-typed code",
"Agent 2 (Design) searches beyond the changed files to find existing utilities",
"Report explicitly stops and waits for user approval before making fixes"
]
},
{
"id": 3,
"prompt": "Set up the fixture repo by running `bash evals/fixtures/efficiency/setup.sh`, then cd into the created directory and run /polish",
"expected_output": "Report should find sequential awaits that could be parallel, an N+1 query pattern, and a TOCTOU anti-pattern. Should NOT flag the one-time setup function.",
"files": ["evals/fixtures/efficiency/setup.sh"],
"expectations": [
"Report flags the sequential awaits on independent API calls and suggests Promise.all or similar",
"Report flags the N+1 pattern (querying details inside a loop)",
"Report flags the TOCTOU pattern (checking file existence before reading)",
"Report does NOT flag the one-time initConfig setup function for efficiency",
"Report explicitly stopsAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/tenequm/skills/code-polish",
"sourceUrl": "https://clawhub.ai/tenequm/skills/code-polish",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:35:58.952Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-tenequm-code-polish/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tenequm-code-polish/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T01:35:58.952Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.8K downloads",
"href": "https://clawhub.ai/tenequm/code-polish",
"sourceUrl": "https://clawhub.ai/tenequm/code-polish",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:35:58.952Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "3.1.0",
"href": "https://clawhub.ai/tenequm/code-polish",
"sourceUrl": "https://clawhub.ai/tenequm/code-polish",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-09T16:55:42.346Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-tenequm-code-polish/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tenequm-code-polish/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 3.1.0",
"description": "Updated code-polish from 3.0.0 to 3.1.0. Changes: - modified `CHANGELOG.md` - modified `SKILL.md`",
"href": "https://clawhub.ai/tenequm/code-polish",
"sourceUrl": "https://clawhub.ai/tenequm/code-polish",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-09T16:55:42.346Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
