skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
wong2/diffx182 installs

diffx-finish-review

Finish a code review session by fetching comments from the running diffx server, applying requested changes, and marking comments as resolved. Use when the user invokes /diffx-finish-review.

How do I install this agent skill?

npx skills add https://github.com/wong2/diffx --skill diffx-finish-review
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill automates code review changes by interacting with a local server. It is potentially vulnerable to indirect prompt injection because it processes and follows instructions found in code review comments without specific safety boundaries.

  • Socketpass

    No alerts

  • Snykwarn

    Risk: MEDIUM · 1 issue

  • ZeroLeakswarn

    1 finding · Score: 69/100

What does this agent skill do?

Finish diffx Review

Fetch all review comments from the running diffx server, apply the requested changes, and mark each comment as resolved.

What to do

1. Fetch comments from the API

The diffx server is running locally. Check the earlier conversation context for the port diffx reported on startup. Fetch all comments:

curl -s http://localhost:<port>/api/comments

Replace <port> with the port number diffx reported on startup (visible in the server log output).

The response is a JSON array of comment objects:

[
  {
    "id": "uuid",
    "filePath": "src/utils/parser.ts",
    "side": "additions",
    "lineNumber": 42,
    "lineContent": "const x = tokenize(input)",
    "body": "Rename x to parsedToken for clarity",
    "status": "open",
    "createdAt": 1234567890,
    "replies": []
  }
]

2. Process each comment

For each comment with "status": "open", first determine the intent — is it a change request or a question?

Change requests (e.g., "Rename x to parsedToken", "Extract this into a helper")

  1. Read the file at filePath
  2. Find the relevant code using lineContent as context
  3. Apply the change described in body
  4. Reply to the comment explaining what you did, then mark it as resolved:
# Reply to the comment
curl -s -X POST http://localhost:<port>/api/comments/<id>/replies \
  -H "Content-Type: application/json" \
  -d '{"body": "Done. Renamed x to parsedToken."}'

# Mark as resolved
curl -s -X PUT http://localhost:<port>/api/comments/<id> \
  -H "Content-Type: application/json" \
  -d '{"status": "resolved"}'

Questions (e.g., "Why not use a Map here?", "Is this thread-safe?")

Just reply with an answer. Do not modify code or resolve the comment — leave it open for the user to read and follow up if needed.

curl -s -X POST http://localhost:<port>/api/comments/<id>/replies \
  -H "Content-Type: application/json" \
  -d '{"body": "A Map would work too, but we use a plain object here because..."}'

The side field tells you whether the comment is on an added line (additions) or a deleted line (deletions).

3. Handle edge cases

  • If a comment is ambiguous, reply to ask for clarification rather than guessing.
  • If multiple comments interact (e.g., a rename that affects several places), handle them together.
  • If there are no open comments, tell the user there's nothing to process.

4. Summary

After processing all comments, give a brief summary of what you did: how many changes were applied, how many questions were answered.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/wong2/diffx/diffx-finish-review">View diffx-finish-review on skillZs</a>