- Home
- Skills
- Code Quality & Review
- Production Code Review Gate
More screenshots
Works with the AI tools you already use
Production Code Review Gate
Most AI code reviews produce long lists of generic warnings.
$9
Production Code Review Gate
Example session with this skill installed
Review this PR diff for a Node.js service adding a new Redis-backed rate limiter. Check for concurrency issues and production readiness.
- Read your context and instructions
- Compiled the production code review
- Generated the document
I have completed a production readiness review of the Redis rate limiter implementation. The review identified a critical atomicity issue in the increment logic that could lead to limit bypass under high concurrency.
Production Readiness Report: Rate Limiter PR
| ID | File | Severity | Confidence | Finding | Release Impact |
|---|---|---|---|---|---|
| CODE-01 | src/middleware/rateLimiter.ts | HIGH | 0.95 (Verified) | Non-atomic GET/SET sequence allows race condition. | BLOCK |
| OPS-01 | docker-compose.yml | MEDIUM | 0.85 (Partial) | Missing Redis resource limits in container config. | REVISE |
| TEST-01 | tests/limiter.test.ts | LOW | 0.90 (Verified) | Missing test case for Redis connection timeout. | REVISE |
Findings & Evidence
CODE-01: Race Condition in Increment Logic
The implementation fetches the current count, increments in-memory, and then sets the value back to Redis. Under concurrent requests, multiple workers will read the same initial value, causing the counter to under-count.
- Evidence: Verified via inspection of
lines 42-45. NoINCRor Lua script usage found. - Remediation: Use the Redis
INCRcommand or a Lua script to ensure atomicity.
OPS-01: Resource Constraints
The Redis service definition lacks deploy.resources.limits. In a production environment, an unconstrained Redis instance could exhaust host memory during a spike.
- Evidence: Observed missing keys in
services.redis.
Gate Decision: BLOCK
Next steps
- Replace the manual GET/SET flow in
rateLimiter.tswith an atomicINCRoperation. - Add memory limits to the Redis container definition.
- Add a concurrency test to verify the rate limit holds under parallel execution.
production-code-review-gate.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most AI code reviews produce long lists of generic warnings. Production Code Review Gate is built for the harder question: can this change safely ship?
AG-1 reviews repositories, pull requests, diffs, file sets, and pasted code using a repeatable evidence gate. It maps the changed surface, follows reachable callers and failure paths, checks counter-evidence, and publishes a finding only when it can identify the cause, trigger, mechanism, and production impact. Unverified concerns are separated into a Watchlist instead of being presented as bugs.
Each finding is organized by file and includes CRITICAL, HIGH, MEDIUM, or LOW severity; a calibrated confidence score; code-grounded evidence; a concrete remediation; an optional safe patch proposal; and focused tests that prove the correction.
The final production-readiness report covers functional correctness, security, reliability, concurrency and data integrity, performance, compatibility and rollout, tests and observability, dependencies and configuration, and maintainability.
AG-1 supports application code, APIs, databases, queues, infrastructure, containers, CI/CD, and polyglot repositories. Its dedicated SQL protocol covers injection boundaries, NULL logic, join cardinality, pagination, transactions, isolation, deadlocks, query plans, indexes, connection pools, and safe migrations.
It understands partial context, avoids fake CVEs and invented test results, redacts exposed secrets, and never treats formatting preferences as release defects.
Every review ends with one decision:
PASS — no required remediation remains in the reviewed scope. REVISE — changes or additional evidence are required before release. BLOCK — a sufficiently evidenced critical production risk must stop the release.
Ideal for senior developers, tech leads, consultants, agencies, startup teams, and engineering managers who need a serious pre-merge or pre-release quality gate.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 26 days ago
- Passed all security checks, Safe to install