by joetawil7
Rules and checks that make Claude Code look around a change, not just at the lines it writes: ten questions before code, a reviewer that didn't write it, proof before done, bugs fixed as a class.
# Add to your Claude Code skills
git clone https://github.com/joetawil7/first-passSee how first-pass compares with popular alternatives.
first-pass is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by joetawil7. Rules and checks that make Claude Code look around a change, not just at the lines it writes: ten questions before code, a reviewer that didn't write it, proof before done, bugs fixed as a class. It has 76 GitHub stars.
first-pass's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/joetawil7/first-pass" and add it to your Claude Code skills directory (see the Installation section above).
first-pass is primarily written in JavaScript. It is open-source under joetawil7 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh first-pass against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
first-pass makes a coding agent check the code around a change, not only the lines it writes, and prove its work before it calls anything done. It's a Claude Code plugin; Cursor, Codex and other agents get the same rules and skills (the hooks are Claude Code only). You set it up once, in the folder that holds your repos.
What it does
file:line, a test, or a gap you decide to accept./first-pass:review checks your own branch before you ask for
review, or a teammate's PRs across several repos. Every finding comes with its proof or
is marked unproven, and it never posts to GitHub.What it helps with
/plugin marketplace add joetawil7/first-pass
/plugin install first-pass@first-pass
Then, in the folder where you start your sessions: /first-pass:setup-first-pass.
I built a product feature by feature with Claude Code. Every feature request ended with some version of "make sure the code is correct and bug free, cover all gaps, be 100% sure." Then I ran a full audit. It found 318 issues, 25 of them high severity.
When I sorted them, only 45 were mistakes in the lines being written. The rest were in the code around those lines:
| What went wrong | Issues |
|---|---|
| Another code path using the same data was not updated | 54 |
| Runs twice, runs at the same time, or stops halfway | 54 |
| An outside service fails or is slow, and the error is hidden | 45 |
| A plain mistake in the code itself | 45 |
| Time, units, rounding | 26 |
| Scale: no limit, no index, lists that stop at one page | 25 |
| Endings: cancel, delete, expire, reconnect, downgrade | 19 |
| UI, help, legal or pricing text that says what the code doesn't do | 18 |
| Pipeline: CI red, no tests against a real database | 17 |
| Hostile user or uncapped cost | 15 |
(One private codebase, sorted by hand with one cause per issue. Your mix will differ.)
Several of these had been found by earlier audits and fixed. Each fix patched one spot, and nothing carried the lesson into the next session.
"Be 100% sure" changed how sure the answers sounded. It never made the agent open the other file that writes the same field, or ask what happens when the webhook arrives twice. So first-pass names those checks, and asks for proof before anything is called done:
file:line, a test, or "Not handled, because ___" for you to accept.breaker agent reviews each change in a fresh context, starting from the other
code paths that touch the same data.| Piece | What it does | When |
|---|---|---|
premortem |
The ten questions, answered against the code | Before code |
breaker (agent) |
Fresh-context review of the diff and of every other path touching the same data; concrete findings only | Before done |
ship-check |
The definition of done, ending in a report where every "Verified" line says what was run and its result | Before done |
fix-the-class |
Reproduce, name the class, search for it everywhere, run the ten questions on the fix, fix or record each hit, make it hard to repeat | On any bug |
setup-first-pass |
Writes the rules once, a map of your repos, and a section per repo with its real commands, test limits and a drafted INVARIANTS.md |
Once, then to update |
habit-words |
Reads what you typed in your recent sessions and maps words like "be 100% sure" to the checks they should mean | At setup, then when due |
sharpen |
Rewrites the prompt you type after it: numbered asks, habit words turned into checks, names and numbers kept exactly. Shows you the rewrite, then works from it | Only when you type it |
review |
Reviews your own branch before you ask for review (type nothing after it), or a teammate's PRs, several repos at once. Checks the change against its ticket, judges the failed checks and every Bugbot comment, runs the breaker, traces the other code that uses what changed, proves each finding or marks it unproven, and says what the merge needs and how to check the deploy. Reads GitHub and never posts; pushes a fix only on your yes | Only when you type it |
| Hooks | Run each repo's own hooks from the main folder, send back a "done" with no evidence, say what drifted at session start, and hold sharpen's work until its rewrite is shown |
Every session |
A lot of us open one folder with every repo in it and start each session there. Claude Code
then finds agents, skills and hooks only in that folder and above it: a repo's own
.claude/agents, its .claude/settings.json hooks and its .cursor/rules/*.mdc imports
never load, and its CLAUDE.md loads only once a file in it is read. first-pass is built for
that:
AGENTS.md (imported by CLAUDE.md), loaded from
the first message and updated in one place.Most of us have words we type out of habit: "be 100% sure", "don't assume", "full review", "all fine, right?". They name no place to look, so the answer sounds more certain without anything more being checked.
habit-words reads what you typed in your last 20 Claude Code sessions, shows how often you
use each phrase, what went wrong after it, and what to say instead. Then it writes a short
block that maps each phrase to the checks it should trigger. You never have to type them
again, and if you do, they mean the checks, not a more confident tone.
What it reads and keeps:
~/.claude/projects, and only what you typed, plus the end
of the agent's reply before each prompt that pushes back on it. Tool output, pasted t