PluginBench
Skill
Pass
Audit score 90

flows-code-review

cognitedata/builder-skills

Run technical code review for Flows app certification in your local git repository.

What is flows-code-review?

This skill executes the code review step of Flows app certification by pulling the latest review checks from cognitedata/builder-skills and running them against your app. Use it when you need a technical review, pre-submit review, or app certification code review—re-run until all Must Fix items are resolved before moving to design review.

  • Validates git repository and app structure (package.json, git dir, App-Brief.md)
  • Pulls latest flows-review-checks and code-quality from cognitedata/builder-skills
  • Runs comprehensive code quality checks including hunt, packages, and coverage analysis
  • Generates scored review report with must-fix, should-fix, and nice-to-fix categorizations
  • Writes artifacts to reviews/code-review/feedback-round-<N>/ with file inventory, findings, package audit, and final report
  • Tracks review rounds and requires re-runs until Must Fix count reaches zero

How to install flows-code-review

npx skills add https://github.com/cognitedata/builder-skills --skill flows-code-review
Prerequisites
  • Git repository initialized in your app directory
  • package.json file present at repository root
  • Node.js and npm installed to run npx commands
  • Optional: Cognite CLI for pulling skills (fallback to curl if unavailable)
Claude Code
Cursor
Windsurf
Cline

How to use flows-code-review

  1. 1.Ensure your working directory is the app root (git repository)
  2. 2.Run the skill; it will check for package.json, git setup, and App-Brief.md
  3. 3.The skill pulls flows-review-checks and code-quality from cognitedata/builder-skills
  4. 4.Review artifacts are written to reviews/code-review/feedback-round-<N>/
  5. 5.Check the code-review-report.md for must-fix, should-fix, and nice-to-fix items
  6. 6.Address all must-fix items in your code
  7. 7.Re-run the skill to verify fixes and generate a new feedback round
  8. 8.Repeat until Must Fix open: 0 appears in the report

Use cases

Good for
  • Conduct initial technical code review before Flows app certification submission
  • Re-run code review after addressing must-fix items to verify improvements
  • Audit code quality, dependencies, and test coverage as part of app certification workflow
  • Generate formal review documentation for app certification process
  • Track review progress across multiple feedback rounds
Who it's for
  • Flows app developers preparing for certification
  • Technical reviewers conducting app certification reviews
  • DevOps or platform teams managing app quality gates

flows-code-review FAQ

What if the Cognite CLI pull fails?

The skill falls back to fetching flows-review-checks and code-quality directly from the cognitedata/builder-skills GitHub repository using curl.

Can I use review checks already in my app's skills/ folder?

No. The skill always pulls the latest checks from cognitedata/builder-skills to ensure you're using the current review bar, not stale local copies.

What does each artifact file contain?

review-files.md lists the file inventory, review-findings.md contains hunt results and categorized issues, review-packages.md shows package audit results, and code-review-report.md is the scored final report with approval path and summary counts.

When should I stop re-running this skill?

Stop when Must Fix open: 0 appears in the latest feedback round's code-review-report.md. Then proceed to flows-design-review.

What if App-Brief.md is missing?

The skill warns that flows-app-brief should be run first but continues with the code review anyway.

Full instructions (SKILL.md)

Source of truth, from cognitedata/builder-skills.


name: flows-code-review description: >- Run the technical (code) review step of Flows app certification in a local git app. Loads flows-review-checks for the actual bar, then writes artifacts under reviews/code-review/feedback-round-<N>/. Use when the user asks for a Flows code review, technical review, pre-submit review, app certification code review, or "run flows-code-review". Re-run until 0 open Must Fix items remain before moving on to flows-design-review. allowed-tools: Read, Glob, Grep, Bash, Write

Flows Code Review

This skill is the local runner for the technical review step:

flows-app-brief  →  build  →  flows-code-review (this skill, repeat until clean)  →  flows-design-review  →  flows-external-app-submit

Checks and scoring live in flows-review-checks. Do not copy them here. Do not score from memory. Do not substitute test-coverage or other fix skills for the review bar.

This file only decides: git/app-brief pre-checks, feedback-round folder, that the working directory is the app root, where to write files, and the submitter Summary block.

Pre-checks

  • package.json exists
  • We are inside a git repository (git rev-parse --git-dir)
  • If App-Brief.md is missing at repo root, warn that flows-app-brief should be run first, but continue

Feedback round: look at reviews/code-review/. If it doesn't exist, use feedback-round-1/. Otherwise the next missing round number.

Working directory for all review commands: repo root (the app).

Step 1 — Pull latest checks from cognitedata/builder-skills, then run them

Every review run must start by taking flows-review-checks and code-quality from cognitedata/builder-skills. Do not score from whatever is already in the app’s skills/ folder.

If this workspace already is builder-skills (git remote contains cognitedata/builder-skills): you are in that repo — Read local skills/flows-review-checks/SKILL.md (it loads local code-quality).

Otherwise (reviewing an app): pull those two skills from this repo, then read them:

npx @cognite/cli@latest apps skills pull --skill flows-review-checks
npx @cognite/cli@latest apps skills pull --skill code-quality

If the CLI pull fails, get the same two files from main:

curl -fsSL https://raw.githubusercontent.com/cognitedata/builder-skills/main/skills/flows-review-checks/SKILL.md
curl -fsSL https://raw.githubusercontent.com/cognitedata/builder-skills/main/skills/code-quality/SKILL.md

Then Glob '**/skills/flows-review-checks/SKILL.md' and Read the first match (after a successful pull, that is the copy you just fetched). Follow it completely: hunt (including code-quality searches — do not apply its fixes), packages, coverage, scores, categorization, shared verify.

Step 2 — Write artifacts here

Round dir: reviews/code-review/feedback-round-<N>/

Shared outputFilename here
File inventoryreview-files.md
Hunt + must/should/nicereview-findings.md
Package auditreview-packages.md
Scored reportcode-review-report.md

code-review-report.md must include everything flows-review-checks requires (checks performed, coverage scope, scores 1.1 and 1.3–1.6, 2.1–2.6, 3.1, must/should/nice with _Impact:_ on Must Fix), plus:

# [App name] — Flows code review

This document is the platform review for [App name], conducted as part of the Cognite Flows app certification process.

## Path to approval

This review found **[N] must-fix item(s)** that block approval. Once the must-fix items are addressed, re-run `flows-code-review`.

### Reviewed commit
`<full SHA>`

End code-review-report.md with this block (required by flows-external-app-submit):

## Summary

- Must Fix open: <integer>
- Should Fix open: <integer>
- Nice Fix open: <integer>

Use exactly those labels. When all Must Fix items are resolved: Must Fix open: 0.

Step 3 — Runner verify

After flows-review-checks Step 6:

  1. The four files above exist in this round’s folder.
  2. This run pulled (or, in builder-skills, already had) current flows-review-checks and code-quality from cognitedata/builder-skills before scoring.
  3. Print:
Must Fix open: <n>
Should Fix open: <n>
Nice Fix open: <n>

When to stop

Re-run this skill until Must Fix open: 0 in the latest round’s code-review-report.md. Only then proceed to flows-design-review.