We've distilled 10+ years of frontend and fullstack engineering into a structured AI toolkit —
a skills repository purpose-built for AI agents and LLMs.
What's Inside · Code Review · Implementation Skills · All Skills · Installation · CI Setup
Built by Enpitech | a comprehensive AI engineering toolkit for Claude Code, VS Code Copilot, Cursor, and more. Multi-pass code review, Figma-to-code implementation, and growing. Works in CI and locally. Supports React, Node.js, Python, and any language.
In Claude Code, run these one by one:
/plugin marketplace add enpitech/ai-tools
/plugin install enpitech@enpitech
Then /reload-plugins to activate. Skills will be available under /enpitech:<skill-name>.
This toolkit packages Enpitech's 10+ years of frontend and fullstack expertise into structured AI skills. Each skill gives your agent a deterministic, repeatable process — not a vague prompt, but a step-by-step system.
|
Multi-pass review system: 5–7 sequential passes per language. Bugs → Security → Architecture → Performance → Quality. CI-ready. Pixel-perfect implementation from Figma designs via MCP. Auto breakpoints, design tokens, asset export, visual verification.
|
Fullstack and general skills detect your language and framework automatically. Ships with a GitHub Actions workflow. Comment All criteria live in plain markdown files. Add passes, change thresholds, adapt to your stack. More skills coming. |
|
A developer opens a PR with React changes. A teammate comments |
Before pushing a Node.js branch, run |
|
A tech lead assesses a Python project before a refactor. |
A designer hands off a Figma section. |
|
A PR touches React frontend and Express backend. |
Before a release, |
Two scope prefixes, applied uniformly across all languages:
| Prefix | Scope | Where | Includes deps? |
|---|---|---|---|
cr- |
PR diff + affected files | CI + Local | ✗ |
cra- |
Full codebase audit | Local only | ✓ |
| Skill | Scope | What it does | CI Trigger |
|---|---|---|---|
cr-react |
Diff | 7-pass React/Next.js review | /cr-react |
cra-react |
Full | React audit + system checks + dep audit | — |
cr-node |
Diff | 7-pass Node.js review | /cr-node |
cra-node |
Full | Node.js audit + system checks + dep audit | — |
cr-python |
Diff | 7-pass Python review | /cr-python |
cra-python |
Full | Python audit + system checks + dep audit | — |
cr-general |
Diff | 5-pass language-agnostic review | /cr-general |
cra-general |
Full | General audit + system checks + dep audit | — |
cr-deps |
Deps | 6-pass dependency health audit | /cr-deps |
cr-fullstack |
Diff | Auto-detect stack + cross-layer checks | /cr-fullstack |
cra-fullstack |
Full | Full audit per layer + cross-layer + dep audit | — |
All review skills report only CRITICAL and WARNING findings at 8/10+ confidence.
| Skill | What it does | Requirements |
|---|---|---|
figma-to-code |
Pixel-perfect Figma → responsive production code. Auto breakpoints, DS tokens, asset export, visual verification loop. | Figma MCP + Playwright MCP |
React/Next.js — 7 passes
| Pass | Focus | Examples |
|---|---|---|
| 1. BUGS | Logic errors | null access, race conditions, wrong conditionals |
| 2. SECURITY | Vulnerabilities | XSS, exposed secrets, unauthenticated Server Actions |
| 3. COMPONENT ARCHITECTURE | Structure | God components, prop drilling, cross-feature imports |
| 4. HOOKS & STATE | React patterns | Derived state in useEffect, stale closures, joinable hooks |
| 5. PERFORMANCE | Speed | Sequential awaits, missing dynamic imports, barrel file imports |
| 6. CODE QUALITY | React-specific | Array mutation, missing error boundaries, duplicated logic |
| 7. INTENT CHECK | PR scope | Unrelated changes that snuck into the diff |
Context-aware: React Compiler, Next.js SSR/RSC, design systems (@radix-ui, shadcn).
/enpitech:cr-react # PR diff review
/enpitech:cra-react # Full codebase audit + system checks + dep audit
Node.js — 7 passes (OWASP + eslint-plugin-security)
| Pass | Focus | Examples |
|---|---|---|
| 1. BUGS | Logic errors | Unhandled promise rejections, race conditions, event loop blocking |
| 2. SECURITY | Vulnerabilities | eval/exec injection, prototype pollution, ReDoS, SSRF, missing helmet/CSRF |
| 3. ASYNC PATTERNS | Event loop | Blocking calls in async, missing Promise.all, stream backpressure |
| 4. ERROR HANDLING | Resilience | Bare catch, missing error events, uncaughtException without exit |
| 5. API DESIGN | Express/Fastify | Missing request size limits, rate limiting, input validation, permissive CORS |
| 6. PERFORMANCE | Runtime | Sync fs/crypto ops, missing connection pooling, N+1 queries, memory leaks |
| 7. CODE QUALITY | Node-specific | require(variable), new Buffer(), deprecated APIs, missing graceful shutdown |
Context-aware: Express, Fastify, Koa; TypeScript; Prisma, Sequelize, TypeORM, Mongoose.
/enpitech:cr-node # PR diff review
/enpitech:cra-node # Full codebase audit + system checks + dep audit
Python — 7 passes (Bandit + Ruff + Pylint)
| Pass | Focus | Examples |
|---|---|---|
| 1. BUGS | Logic errors | Mutable default arguments, loop variable closures, unreachable code |
| 2. SECURITY | Vulnerabilities | eval/exec, pickle, subprocess shell=True, SQL injection, unsafe YAML, XML attacks |
| 3. TYPE SAFETY | Type correctness | Missing annotations, inconsistent returns, overly broad Any |
| 4. ASYNC PATTERNS | asyncio/threading | Blocking in async, missing await, sync sleep, thread safety |
| 5. API DESIGN | Django/Flask/FastAPI | Missing auth decorators, debug mode, insecure uploads, rate limiting |
| 6. PERFORMANCE | Efficiency | Generator vs list comprehension, quadratic string concat, inefficient loops |
| 7. CODE QUALITY | Pythonic | Bare except, mutable defaults, unused imports, missing context managers |
Context-aware: Django, Flask, FastAPI, SQLAlchemy, Pydantic, pytest, mypy/pyright.
/enpitech:cr-python # PR diff review
/enpitech:cra-python # Full codebase audit + system checks + dep audit
General — Any Language — 5 passes
Works with Vue.js, Angular, Svelte, Go, Rust, Ruby, PHP, Java, Kotlin, Swift, C#, and more.
| Pass | Focus | Examples |
|---|---|---|
| 1. BUGS | Logic errors | Null access, resource leaks, concurrency issues, off-by-one |
| 2. SECURITY | Vulnerabilities | Injection, hardcoded secrets, insecure crypto, SSRF, XSS, CSRF |
| 3. ERROR HANDLING | Resilience | Silent failures, bare exception catching, missing cleanup |
| 4. PERFORMANCE | Efficiency | Blocking I/O, N+1 queries, quadratic algorithms, memory issues |
| 5. CODE QUALITY | Maintainability | Dead code, duplication, overly complex functions, deprecated APIs |
Auto-detects language and framework, then applies framework-specific checks (Vue v-html XSS, Go unchecked errors, Rails mass assignment, Laravel raw queries, Spring injection, etc.).
/enpitech:cr-general # PR diff review
/enpitech:cra-general # Full codebase audit + system checks + dep audit
Dependencies — 6 audit passes
| Pass | Focus | What It Checks |
|---|---|---|
| 1. VULNERABILITIES | Security | npm audit / pip-audit — CVEs by severity |
| 2. OUTDATED | Freshness | Major version lag, security-related updates |
| 3. DEPRECATIONS | Lifecycle | Deprecated packages, suggested replacements |
| 4. LICENSE | Compliance | Copyleft in permissive projects, missing licenses |
| 5. UNUSED | Bloat | Declared but never imported dependencies |
| 6. LOCKFILE | Integrity | Missing lockfile, unpinned versions, sync issues |
Auto-detects npm, yarn, pnpm, pip, poetry, uv, pipenv.
/enpitech:cr-deps
Runs standalone, or automatically as part of any
cra-*full audit. Not included incr-*diff reviews.
Fullstack — Cross-Layer (Auto-Detect)
Dynamically detects which languages are in the project and applies the right criteria per layer:
| Detected | Criteria applied |
|---|---|
| React/Next.js | rules/react.md |
| Express/Fastify/Koa | rules/node.md |
| Django/Flask/FastAPI | rules/python.md |
| Vue, Angular, Svelte, Go, Rust, Ruby, PHP, Java, etc. | rules/general.md |
| Monorepo | Reads each workspace's config to classify |
Stack examples:
- React + Express → React passes on frontend, Node passes on backend
- Vue + Go → General passes on both (auto-adapted)
- React + FastAPI → React passes on frontend, Python passes on backend
Cross-layer checks (always applied):
- API contract validation
- Shared type drift
- Environment variable hygiene
- Authentication flow consistency
- Error contract matching
- Data flow security
- API versioning & deprecation
/enpitech:cr-fullstack # PR diff + cross-layer checks
/enpitech:cra-fullstack # Full audit per layer + cross-layer + system checks + dep audit
Figma → Code — Implementation Skill
Converts Figma designs into pixel-perfect, responsive, production-ready code using MCP tools.
| Step | What it does |
|---|---|
| 1. Variables | Collects section name, Figma URL, node IDs, route, selector from user |
| 2. Baselines | Pulls mobile/tablet/desktop images via Figma MCP |
| 3. Token mapping | Auto-discovers breakpoints, maps design values to existing DS tokens |
| 4. Asset classification | Classifies each node as ASSET (export as-is) or UI ELEMENT (build with code) |
| 5. Scaffold | Generates responsive code using DS primitives and tokens |
| 6. Visual verification | Screenshots via Playwright MCP, compares to Figma baseline, iterates |
Requires: Figma MCP server + Playwright MCP server running.
Policies: No invented content/styles. No new breakpoints. No custom sizes outside token scale. Assets used as-is (never recreated with CSS).
/enpitech:figma-to-code # Interactive — asks for Figma URL and section details
The skills and rules are structured markdown files. They work natively as a Claude Code plugin, but can also be used with any AI coding assistant that reads instructions from your repo — including VS Code with GitHub Copilot, Cursor, Windsurf, and others.
From a marketplace search for "Enpitech" and install the "AI Tools" plugin. or in claude code, run:
/plugins install enpitech
From a local directory:
git clone https://github.com/enpitech/ai-tools.git
claude --plugin-dir ./ai-toolsOr add it permanently to your project's .claude/plugins.json.
Skills become /enpitech:cr-react, /enpitech:cra-react, /enpitech:cr-node, etc.
Note: Plugins don't install workflow files. Copy the CI workflow manually:
cp -r ai-tools/.github your-project/
# Clone this repo
git clone https://github.com/enpitech/ai-tools.git
# Copy into your project
cp -r ai-tools/rules your-project/rules
cp -r ai-tools/skills your-project/skills
cp -r ai-tools/.github your-project/ # CI workflow (optional)Once the files are in your repo, any AI coding assistant can use them:
| Tool | How it picks up the skills |
|---|---|
| Claude Code | Reads skills/ and rules/ automatically. Invoke with /cr-react, /cra-node, etc. |
| GitHub Copilot (VS Code) | Reference the rules files as context in chat, or add them to .github/copilot-instructions.md |
| Cursor | Add rules files to .cursor/rules/ or reference them in chat context |
| Windsurf | Reference the criteria markdown files as project context |
| Other AI assistants | Point the agent to the relevant rules/*.md file — they're self-contained review criteria |
The
rules/*.mdfiles are the core value — they contain all the review criteria and work with any LLM. Theskills/*/SKILL.mdfiles add agent-specific automation (diff collection, file scanning, output formatting, MCP orchestration).
Cherry-pick what you need
Rules (review criteria — pick by language):
| File | Purpose |
|---|---|
rules/react.md |
React/Next.js 7-pass review criteria |
rules/node.md |
Node.js 7-pass review criteria |
rules/python.md |
Python 7-pass review criteria |
rules/general.md |
Language-agnostic 5-pass review criteria |
rules/deps.md |
Dependency audit criteria |
rules/fullstack.md |
Cross-layer check criteria |
rules/autofix.md |
Autofix workflow (local options + CI comment format) |
Skills (pick by language + scope):
| File | Skill |
|---|---|
skills/cr-react/SKILL.md |
PR diff React review |
skills/cra-react/SKILL.md |
Full codebase React audit |
skills/cr-node/SKILL.md |
PR diff Node.js review |
skills/cra-node/SKILL.md |
Full codebase Node.js audit |
skills/cr-python/SKILL.md |
PR diff Python review |
skills/cra-python/SKILL.md |
Full codebase Python audit |
skills/cr-general/SKILL.md |
PR diff general review |
skills/cra-general/SKILL.md |
Full codebase general audit |
skills/cr-deps/SKILL.md |
Dependency health audit |
skills/cr-fullstack/SKILL.md |
PR diff fullstack review |
skills/cra-fullstack/SKILL.md |
Full codebase fullstack audit |
skills/figma-to-code/SKILL.md |
Figma → pixel-perfect production code |
- Copy
.github/workflows/claude-code-review.ymlinto your repo - Add
ANTHROPIC_API_KEYto your repo secrets (Settings → Secrets → Actions) - Comment one of these on any PR:
| Trigger | Review Type |
|---|---|
/cr-react |
React/Next.js code review |
/cr-node |
Node.js code review |
/cr-python |
Python code review |
/cr-general |
Language-agnostic code review |
/cr-deps |
Dependency health audit |
/cr-fullstack |
Fullstack auto-detect + cross-layer |
cra-*skills (full audits) are local-only and not triggered in CI.
After a review posts findings, reply to apply fixes:
| Command | What it does | Reply to |
|---|---|---|
/fix |
Apply the fix for a single finding | An individual finding comment |
/fix-all |
Apply all suggested fixes at once | The main review summary comment |
The autofix job checks out the PR branch, applies the fix(es), commits, and pushes automatically.
The workflow:
- Detects the trigger keyword and selects the appropriate review criteria
- Only runs for repo collaborators (OWNER/MEMBER/COLLABORATOR)
- Posts a summary comment with all findings, each linking to
/fix - Posts individual finding replies with full details and suggested code changes
/fixand/fix-allreplies trigger a separate job that applies fixes and pushes
Optional: Auto-trigger on PR
Uncomment the pull_request trigger in the workflow:
on:
pull_request:
types: [opened, synchronize]
issue_comment:
types: [created]- Trigger restricted to repo OWNER/MEMBER/COLLABORATOR only
- Autofix only applies changes suggested in review findings — no arbitrary modifications
- Fix job requires explicit
/fixor/fix-allreply from an authorized collaborator - All commits are attributed to
github-actions[bot]
Edit the criteria files in rules/ to add/remove review passes, adjust confidence thresholds, change severity levels, or add framework-specific checks.
| File | Controls |
|---|---|
rules/react.md |
React/Next.js review rules |
rules/node.md |
Node.js review rules |
rules/python.md |
Python review rules |
rules/general.md |
Language-agnostic review rules |
rules/deps.md |
Dependency audit rules |
rules/fullstack.md |
Cross-layer check rules |
rules/autofix.md |
Autofix workflow (local + CI) |
All review skills reference these files — single source of truth per concern.
Implementation skills like figma-to-code are self-contained in their SKILL.md — no separate rules file needed.
Built with ❤️ by Enpitech
MIT License
MIT