code-review-and-quality
78Review Code Across Five Quality Axes
Code reviews often miss risks when they focus only on tests or style. This skill guides a consistent review of correctness, readability, architecture, security, and performance.
Instrument Production Systems with Clear Telemetry
Production teams need reliable evidence when services fail, slow down, or behave unexpectedly. This skill helps design useful logs, metrics, traces, alerts, and verification steps.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "observability-and-instrumentation" from https://skillstore.io/skills/addyosmani-observability-and-instrumentation.md and its manifest at https://skillstore.io/api/skills/addyosmani-observability-and-instrumentation/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "observability-and-instrumentation". A payment retry feature needs telemetry for success rate, permanent failures, and provider latency.
Expected outcome:
Using "observability-and-instrumentation". A team wants to page on CPU usage and label metrics with customer IDs.
Expected outcome:
Use user-facing error rate or latency for paging, and move customer identifiers to logs or traces. Keep metric labels bounded.
Using "observability-and-instrumentation". A service has alerts but no runbooks or staging verification.
Expected outcome:
All 41 static findings are false positives caused by Markdown backticks, documentation syntax, benign example code, or a relative reference. The reviewed skill contains no executable commands, credential exfiltration, unsafe file access, or prompt injection.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/addyosmani-observability-and-instrumentation/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/addyosmani-observability-and-instrumentation?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/addyosmani-observability-and-instrumentation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/addyosmani-observability-and-instrumentation/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/addyosmani-observability-and-instrumentation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>addyosmani. (2026). observability-and-instrumentation security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/addyosmani-observability-and-instrumentation/audits/2@techreport{addyosmani-addyosmani-observability-and-instrumentation-2026,
author = {addyosmani},
title = {observability-and-instrumentation security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/addyosmani-observability-and-instrumentation/audits/2},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "observability-and-instrumentation security audit report (audit version 2)"
version: "unspecified"
type: report
authors:
- name: "addyosmani"
date-released: "2026-09-19"
url: "https://skillstore.io/skills/addyosmani-observability-and-instrumentation/audits/2"
identifiers:
- type: other
value: "skillstore:addyosmani-observability-and-instrumentation:audit:2"
description: "Skillstore immutable audit report identifier"
Define the endpoint questions, add structured logs, and select RED metrics with bounded labels.
Add correlation IDs, distributed tracing, and actionable alerts so on-call engineers can follow a failing request.
Use the verification checklist to assess telemetry coverage, secret handling, alert quality, and staging validation.
Review this feature description and list two to four questions an on-call engineer must answer. Map each question to a log, metric, or trace.
Design structured log events for this endpoint. Include stable event names, safe fields, log levels, correlation IDs, and entry-point attribution.
Create an observability plan for this service and its dependencies. Cover RED metrics, bounded labels, OpenTelemetry traces, sampling, and symptom-based alerts.
Review this instrumentation diff against the observability checklist. Identify missing signals, cardinality risks, sensitive data exposure, alert weaknesses, and staging tests.
Author
addyosmaniLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
5d5054f8a23586f9b500fece1cb613a9dffc787b
Maintenance freshness
9/19/2026
Usage
1 downloads ยท 0 views
File structure
๐ SKILL.md
Review Code Across Five Quality Axes
Code reviews often miss risks when they focus only on tests or style. This skill guides a consistent review of correctness, readability, architecture, security, and performance.
Clarify User Intent Before You Build
Underspecified requests cause teams to build the wrong outcome and discover misalignment late. This skill runs a focused, one-question interview that turns ambiguity into confirmed intent.
Plan Work Into Verifiable Tasks
Large or vague software work can hide dependencies, missing acceptance criteria, and verification gaps. This skill converts a specification into ordered task slices with checkpoints, scope guidance, and clear completion conditions.
Document Decisions and Architecture Clearly
Teams lose context when important technical decisions remain in chat, code comments, or individual memory. This skill turns architectural reasoning, API guidance, project instructions, and release changes into structured documentation.
Build Accessible, Production-Ready Frontends
Frontend work can become inconsistent, inaccessible, or difficult to maintain. This skill guides component architecture, responsive layouts, state handling, and polished user experiences.
Debug Errors with a Root-Cause Workflow
Debugging failures by guesswork wastes time and can hide the real cause. This skill provides a repeatable process for reproducing, isolating, fixing, and verifying problems.
Add Python Observability Patterns
by 0xDarkMatter
Python services often lack consistent logging, metrics, and tracing patterns. This skill provides practical structlog, Prometheus, and OpenTelemetry examples for production applications.
Track MEV Latency With Span Guidance
by BarisSozen
Latency issues in MEV systems are hard to isolate across calls and transaction stages. This skill guides span hierarchy, instrumentation, aggregation, and alert thresholds.
Instrument Apps with Azure Application Insights
by microsoft
Application teams need consistent telemetry setup across languages and Azure hosting services. This skill provides targeted SDK, infrastructure, environment, and query guidance for Application Insights.
Deploy Kubernetes Workloads With Guided Steps
by sickn33
Kubernetes releases require many coordinated artifacts and checks. This skill guides container preparation, manifests, Helm charts, service mesh, security, observability, and deployment validation.
Troubleshoot DevOps Incidents Systematically
by sickn33
Complex incidents often produce scattered signals across applications, infrastructure, and cloud services. This skill organizes evidence, tests hypotheses, and recommends immediate and preventive actions.
Optimize Application Performance
by sickn33
Slow systems hurt users, reliability, and cloud costs. This skill helps diagnose bottlenecks, design tests, and plan measured optimizations.