By acaprino
Multi-agent code review orchestration with unified code auditing (architecture, failure flow, pattern analysis, scoring), security auditing, UI race condition detection, React performance review, distributed flow analysis (cross-service contracts, timeout chains, saga validation), platform engineering review (auto-detected fullstack apps), automated lint-based dead code and unused parameter detection (ruff, vulture, knip), and multi-language dead code cleanup. Backed by a comprehensive defect taxonomy knowledge base (140+ defect patterns, CWE/OWASP mappings).
Uses power tools
Uses Bash, Write, or Edit tools
npx claudepluginhub acaprino/alfio-claude-plugins --plugin senior-review"Find and remove dead code -- auto-detects language: Knip for TypeScript/JavaScript, vulture + ruff for Python" argument-hint: "[path] [--dry-run] [--dependencies-only] [--exports-only] [--production]". TRIGGER WHEN: the user requires assistance with tasks related to this domain. DO NOT TRIGGER WHEN: the task is outside the specific scope of this component.
"Unified code review -- auto-detects scope and runs architecture, security, and pattern analysis agents in parallel. Automatically uses deep-dive context if available." argument-hint: "[PR number | --branch <name> | --commits N] [--auto-comment] [--strict] [--security-focus]". TRIGGER WHEN: the user requires assistance with tasks related to this domain. DO NOT TRIGGER WHEN: the task is outside the specific scope of this component.
"Orchestrate comprehensive multi-dimensional code review using specialized review agents. Includes deep-dive structural and semantic analysis by default for deeper context. Supports multi-service distributed flow analysis with cross-boundary contract verification, timeout chain validation, and resilience pattern auditing." argument-hint: "<target path(s) or description> [--skip-deep-dive] [--distributed] [--security-focus] [--performance-critical] [--strict-mode] [--framework react|spring|django|rails]". TRIGGER WHEN: the user requires assistance with tasks related to this domain. DO NOT TRIGGER WHEN: the task is outside the specific scope of this component.
"Analyze current branch changes, generate a comprehensive PR description with risk assessment and review checklist, and optionally create the PR via gh CLI" argument-hint: "[--base main] [--create] [--split-check] [--strict-mode]". TRIGGER WHEN: the user requires assistance with tasks related to this domain. DO NOT TRIGGER WHEN: the task is outside the specific scope of this component.
Adversarial code quality auditor combining architecture review, failure flow tracing, pattern consistency analysis, and quantitative scoring into a single comprehensive agent. Hunts for coupling violations, broken abstractions, failure-path bugs, resource leaks, stale caches, pattern deviations, and anti-patterns. Produces a calibrated Code Quality Score. Replaces architect-review + failure-flow-tracer + pattern-quality-scorer. TRIGGER WHEN: the user requires assistance with tasks related to this domain, or specifically asks for a code review, architecture audit, quality scoring, failure analysis, or pattern consistency check. DO NOT TRIGGER WHEN: the task involves writing tests, simple code formatting, or security-specific auditing (use security-auditor instead).
Adversarial cross-service flow analyst for microservices, agent-based, and multi-module distributed systems. Traces request flows, API/message contracts, saga orchestration, timeout chains, and integration boundaries across multiple services or modules. Hunts for contract mismatches, cascading timeout violations, missing idempotency, broken saga compensation, message ordering bugs, and split-brain risks. TRIGGER WHEN: the user requires assistance with cross-service analysis, distributed flow tracing, contract verification, or multi-service code review. DO NOT TRIGGER WHEN: the task involves a single monolithic module with no cross-boundary interactions.
Adversarial security reviewer with attacker mindset. Hunts for injection vectors, auth bypasses, secret leaks, crypto mistakes, missing headers, and dependency vulnerabilities. Assumes code is exploitable and proves it. Use in senior-review pipeline. TRIGGER WHEN: the user requires assistance with tasks related to this domain. DO NOT TRIGGER WHEN: the task is outside the specific scope of this component.
Adversarial UI race condition analyst. Detects timing bugs between async data loading, DOM/widget layout, event handlers, and programmatic UI manipulation (scroll, focus, resize). Framework-agnostic: works with React, Angular, Vue, Qt, GTK, Flutter, SwiftUI, Electron, Tauri. Hunts for layout-dependent reads racing against incomplete renders, scroll position corruption, sticky/auto-scroll breakage, focus theft, and stale measurement closures. TRIGGER WHEN: the user requires assistance with UI race conditions, scroll bugs, layout shift issues, focus timing problems, or async rendering bugs. DO NOT TRIGGER WHEN: the task involves pure backend logic, API design, or database operations with no UI component.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, rules, and legacy command shims evolved over 10+ months of intensive daily use
Complete collection of battle-tested Claude Code configs agents, skills, hooks, rules, and legacy command shims evolved over 10+ months of intensive daily use
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
v9.29.0 — Model defaults refreshed: Opus 4.7 for planning/strategy/security-review, GPT-5.4 for code-review/implementation. New GPT-5.4 prompting guide. Set OCTOPUS_LEGACY_ROLES=1 to opt out. Run /octo:setup.