avoiding-false-positives
Use this skill to validate findings during a code review. For each finding, run the rejection criteria and verification checks. If a finding fails any check, drop it.
What this skill does
# Validating Findings ## Rejection Criteria A finding is a false positive — **drop it** — if ANY of the following are true: - **Pre-existing** — code existed before this PR and was not modified by this change - **Not actually buggy** — appears wrong but is correct (e.g., variable IS defined, logic DOES produce correct results) - **Pedantic nitpick** — a senior engineer would not flag this in a real review - **Linter-catchable** — a linter or type checker will catch this; do not duplicate their work - **Generic concern** — "lacks test coverage", "general security issue" without a specific, traceable problem - **Explicitly silenced** — lint ignore comments, pragma suppressions, or documented exceptions - **Handled elsewhere** — error boundaries, middleware, validators, or framework guarantees make the issue moot ## Verification Checks For each finding that passes rejection criteria, verify ALL three: 1. Can you trace the execution path showing incorrect behavior? 2. Is this handled elsewhere (error boundaries, middleware, validators)? 3. Are you certain about framework behavior, API contracts, and language semantics? **If you cannot confidently answer all three, drop the finding.** ## Patterns to Recognize (DO NOT flag) 1. **Intentional simplicity** - Not every function needs error handling if caller handles it 2. **Framework conventions** - React hooks, dependency injection, ORM patterns have specific rules 3. **Test code** - Different standards apply (hardcoded values, no error handling often OK) 4. **Generated code** - Migrations, API clients, proto files (only review if hand-edited) 5. **Copied patterns** - If code matches existing patterns in codebase, consistency > "better" approach 6. **Automated dependency updates** - Renovate/Dependabot minor/patch updates to existing dependencies with passing CI are routine Stage 5 monitoring 7. **Lock file regeneration** - A single manifest change can produce thousands of lock file diff lines; this is normal and not a review concern **When uncertain about a pattern, search the codebase for similar examples before flagging.** ## Codebase Conventions 1. **Check existing patterns** - How does this codebase handle similar cases? 2. **Respect established conventions** - Even if non-standard, consistency > perfection 3. **Don't flag convention violations** unless they cause bugs or security issues **Examples:** - Codebase uses `any` types extensively → Don't flag individual uses - Codebase has no error handling in services → Don't flag one missing try-catch - Consistency matters more than isolated improvements ## Common False Positives **Do NOT flag when handled elsewhere or guaranteed by framework:** - **Null checks**: Language/framework ensures non-null, or prior validation occurred - **Error handling**: Error boundaries exist, function designed to throw, or caller handles - **Race conditions**: Framework synchronizes (React state, DB transactions), or operations idempotent - **Performance**: Data bounded (<100 items), runs once at startup, no profiling evidence - **Security**: Framework sanitizes (parameterized queries, JSX escaping), or API layer validates - **Lock file churn**: Large lock file diffs from a single manifest change are expected behavior, not a review concern **When uncertain, assume the developer knows something you don't.**
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.