Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
bitwarden avatar

Avoiding False Positives

  • 86 installs
  • 129 repo stars
  • Updated August 4, 2026
  • bitwarden/ai-plugins

Avoiding False Positives is a Claude skill that validates code review findings by running rejection and verification checks, dropping any finding that fails.

About

This skill validates code review findings and drops false positives. For each finding it runs rejection criteria (pre-existing, pedantic, linter-catchable, generic, handled elsewhere) and three verification checks, dropping any finding that fails. It also lists patterns not to flag, like framework conventions, test code, and lock-file churn. A developer uses it to keep automated or AI-assisted code reviews from surfacing noise.

  • Rejection criteria that drop pre-existing, pedantic, or linter-catchable findings
  • Three verification checks each finding must pass
  • Catalog of common false positives (null checks, race conditions, performance)

Avoiding False Positives by the numbers

  • 86 all-time installs (skills.sh)
  • Ranked #476 of 1,352 Code Review & Quality skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

avoiding-false-positives capabilities & compatibility

Capabilities
code review · finding validation
Use cases
code review
From the docs

What avoiding-false-positives says it does

For each finding, run the rejection criteria and verification checks. If a finding fails any check, drop it.
SKILL.md
When uncertain, assume the developer knows something you don't.
SKILL.md
npx skills add https://github.com/bitwarden/ai-plugins --skill avoiding-false-positives

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs86
repo stars129
Last updatedAugust 4, 2026
Repositorybitwarden/ai-plugins

What it does

Validate code review findings and drop false positives before reporting them.

Who is it for?

Filtering noise out of code review findings so only real, traceable issues are reported.

Skip if: Generating the findings themselves or classifying their severity.

When should I use this skill?

You are validating findings during a code review and want to drop false positives.

What you get

Each finding is checked against rejection criteria and verification checks, and false positives are dropped.

  • Validated set of code review findings with false positives removed

By the numbers

  • 7 rejection criteria
  • 3 verification checks
  • 7 patterns not to flag

Files

SKILL.mdMarkdownGitHub ↗

Validating Findings

Rejection Criteria

A finding is a false positive — drop it — if ANY of the following are true:

  • Pre-existing — code existed before this PR and was not modified by this change
  • Not actually buggy — appears wrong but is correct (e.g., variable IS defined, logic DOES produce correct results)
  • Pedantic nitpick — a senior engineer would not flag this in a real review
  • Linter-catchable — a linter or type checker will catch this; do not duplicate their work
  • Generic concern — "lacks test coverage", "general security issue" without a specific, traceable problem
  • Explicitly silenced — lint ignore comments, pragma suppressions, or documented exceptions
  • Handled elsewhere — error boundaries, middleware, validators, or framework guarantees make the issue moot

Verification Checks

For each finding that passes rejection criteria, verify ALL three:

1. Can you trace the execution path showing incorrect behavior? 2. Is this handled elsewhere (error boundaries, middleware, validators)? 3. Are you certain about framework behavior, API contracts, and language semantics?

If you cannot confidently answer all three, drop the finding.

Patterns to Recognize (DO NOT flag)

1. Intentional simplicity - Not every function needs error handling if caller handles it 2. Framework conventions - React hooks, dependency injection, ORM patterns have specific rules 3. Test code - Different standards apply (hardcoded values, no error handling often OK) 4. Generated code - Migrations, API clients, proto files (only review if hand-edited) 5. Copied patterns - If code matches existing patterns in codebase, consistency > "better" approach 6. Automated dependency updates - Renovate/Dependabot minor/patch updates to existing dependencies with passing CI are routine Stage 5 monitoring 7. Lock file regeneration - A single manifest change can produce thousands of lock file diff lines; this is normal and not a review concern

When uncertain about a pattern, search the codebase for similar examples before flagging.

Codebase Conventions

1. Check existing patterns - How does this codebase handle similar cases? 2. Respect established conventions - Even if non-standard, consistency > perfection 3. Don't flag convention violations unless they cause bugs or security issues

Examples:

  • Codebase uses any types extensively → Don't flag individual uses
  • Codebase has no error handling in services → Don't flag one missing try-catch
  • Consistency matters more than isolated improvements

Common False Positives

Do NOT flag when handled elsewhere or guaranteed by framework:

  • Null checks: Language/framework ensures non-null, or prior validation occurred
  • Error handling: Error boundaries exist, function designed to throw, or caller handles
  • Race conditions: Framework synchronizes (React state, DB transactions), or operations idempotent
  • Performance: Data bounded (<100 items), runs once at startup, no profiling evidence
  • Security: Framework sanitizes (parameterized queries, JSX escaping), or API layer validates
  • Lock file churn: Large lock file diffs from a single manifest change are expected behavior, not a review concern

When uncertain, assume the developer knows something you don't.

Related skills

FAQ

When should a finding be dropped?

If it is pre-existing, not actually buggy, a pedantic nitpick, linter-catchable, a generic concern, explicitly silenced, or handled elsewhere.

What are the verification checks?

Whether you can trace the execution path, whether it is handled elsewhere, and whether you are certain about framework and language semantics.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.