State-management review your Flutter code from your own scripts
Send Dart — a widget, a screen, a State class, a ChangeNotifier, or a whole grab-bag
— and get back one JSON object: an honest sound / refactor / rework verdict, a health
check across five state-management areas, findings ranked by severity each with corrected
Dart, a twelve-item checklist scored against the paste, and a complete refactor of what you
pasted. Everything this app does goes through the SkillSafe App API — plain JSON over
HTTPS — so you can wire review into a CI gate, a pull-request bot, or a pre-merge
check that refuses a widget mutating shared state with
no notifyListeners().
Every code step below is shown in cURL, Python, JavaScript, Go, Java, Ruby, PHP and C#;
pick a language once and the whole page follows.
Basics
Base URL: https://api.skillsafe.ai/v1/app-api, app slug
state-lens. Every request sends
Authorization: Bearer <token> and JSON bodies with
Content-Type: application/json. Responses are wrapped in an envelope:
{"data": …} on success, {"error": {"code", "message"}} on failure.
The review itself is produced by the gpt-terra model. Estimates are free;
runs are metered against your credit balance. There is a single run task — one paste
in, one review out, no follow-up calls and no session state to carry.
| Status | Meaning |
|---|---|
401 | Missing or expired token — create a new session. |
402 | Not enough credits — top up at skillsafe.ai/account/credits. |
403 | The token isn't allowed to do this (e.g. a guest reviewing a very large paste). |
404 | Unknown job or record id. |
5xx | Transient platform error — retry with backoff. |
Browsers enforce CORS for this API, so run these examples from a server, script or terminal — not from another website's frontend.
Step 0 — A tiny client
Every task below is a single HTTP call, so start with a short helper that adds the auth
header, sends JSON and unwraps the data envelope. The later steps reuse it.
export API="https://api.skillsafe.ai/v1/app-api"
export TOKEN="YOUR_TOKEN" # see step 1
# every call looks like:
# curl -s "$API/..." -H "Authorization: Bearer $TOKEN" [-d '{json}']
# jq is used below to pull fields out of the {"data": ...} envelope
import json, requests
API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = "YOUR_TOKEN" # see step 1 — read it from your shell environment in real code
def api(method, path, body=None, **headers):
res = requests.request(method, API + path, json=body,
headers={"Authorization": f"Bearer {TOKEN}", **headers})
payload = res.json()
if not res.ok:
raise RuntimeError(payload.get("error", {}).get("message", res.reason))
return payload["data"]
// Node 18+ (built-in fetch)
const API = "https://api.skillsafe.ai/v1/app-api";
const TOKEN = "YOUR_TOKEN"; // see step 1 — read it from your shell environment in real code
async function api(method, path, body, extraHeaders = {}) {
const res = await fetch(API + path, {
method,
headers: { Authorization: `Bearer ${TOKEN}`, "Content-Type": "application/json", ...extraHeaders },
body: body === undefined ? undefined : JSON.stringify(body),
});
const json = await res.json();
if (!res.ok) throw new Error(json.error?.message ?? res.statusText);
return json.data;
}
package main
import (
"bytes"
"encoding/json"
"fmt"
"net/http"
"os"
)
const API = "https://api.skillsafe.ai/v1/app-api"
var token = os.Getenv("SKILLSAFE_TOKEN") // see step 1
func call(method, path string, body, out any) error {
var buf bytes.Buffer
if body != nil {
json.NewEncoder(&buf).Encode(body)
}
req, _ := http.NewRequest(method, API+path, &buf)
req.Header.Set("Authorization", "Bearer "+token)
req.Header.Set("Content-Type", "application/json")
res, err := http.DefaultClient.Do(req)
if err != nil {
return err
}
defer res.Body.Close()
var env struct {
Data json.RawMessage `json:"data"`
Error *struct{ Message string `json:"message"` } `json:"error"`
}
json.NewDecoder(res.Body).Decode(&env)
if res.StatusCode >= 400 {
return fmt.Errorf("api %s %s: %s", method, path, env.Error.Message)
}
if out == nil {
return nil
}
return json.Unmarshal(env.Data, out)
}
// Java 17+, no dependencies. Pair with your JSON library (Jackson, Gson…)
// to read fields out of the returned envelope.
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class SkillSafe {
static final String API = "https://api.skillsafe.ai/v1/app-api";
static final String TOKEN = System.getenv("SKILLSAFE_TOKEN"); // see step 1
static final HttpClient HTTP = HttpClient.newHttpClient();
static String api(String method, String path, String jsonBody) throws Exception {
var req = HttpRequest.newBuilder(URI.create(API + path))
.header("Authorization", "Bearer " + TOKEN)
.header("Content-Type", "application/json")
.method(method, jsonBody == null
? HttpRequest.BodyPublishers.noBody()
: HttpRequest.BodyPublishers.ofString(jsonBody))
.build();
var res = HTTP.send(req, HttpResponse.BodyHandlers.ofString());
if (res.statusCode() >= 400) throw new RuntimeException(res.body());
return res.body(); // envelope: {"data": …}
}
}
require "net/http"
require "json"
API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = ENV.fetch("SKILLSAFE_TOKEN") # see step 1
def api(method, path, body = nil)
uri = URI(API + path)
req = Net::HTTP.const_get(method.capitalize).new(uri)
req["Authorization"] = "Bearer #{TOKEN}"
req["Content-Type"] = "application/json"
req.body = body.to_json if body
res = Net::HTTP.start(uri.host, uri.port, use_ssl: true) { |h| h.request(req) }
payload = JSON.parse(res.body)
raise (payload.dig("error", "message") || res.message) unless res.is_a?(Net::HTTPSuccess)
payload["data"]
end
<?php
const API = "https://api.skillsafe.ai/v1/app-api";
$TOKEN = getenv("SKILLSAFE_TOKEN"); // see step 1
function api(string $method, string $path, ?array $body = null): mixed {
global $TOKEN;
$ch = curl_init(API . $path);
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => $method,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer $TOKEN",
"Content-Type: application/json",
],
CURLOPT_POSTFIELDS => $body === null ? null : json_encode($body),
]);
$payload = json_decode(curl_exec($ch), true);
$status = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
curl_close($ch);
if ($status >= 400) {
throw new Exception($payload["error"]["message"] ?? "HTTP $status");
}
return $payload["data"];
}
// .NET 8+
using System.Net.Http.Json;
using System.Text.Json;
static class SkillSafe
{
const string Api = "https://api.skillsafe.ai/v1/app-api";
static readonly HttpClient Http = new();
static SkillSafe() =>
Http.DefaultRequestHeaders.Authorization =
new("Bearer", Environment.GetEnvironmentVariable("SKILLSAFE_TOKEN")); // see step 1
public static async Task<JsonElement> ApiAsync(HttpMethod method, string path, object? body = null)
{
var req = new HttpRequestMessage(method, Api + path);
if (body != null) req.Content = JsonContent.Create(body);
var res = await Http.SendAsync(req);
var json = await res.Content.ReadFromJsonAsync<JsonElement>();
if (!res.IsSuccessStatusCode)
throw new Exception(json.GetProperty("error").GetProperty("message").GetString());
return json.GetProperty("data");
}
}
Step 1 — Get a token
A guest token lets you check balances and estimate costs for free. For metered review runs
billed to your own account, use your personal token: open the
token page, sign in with SkillSafe, and press
Copy shell export — it puts export SKILLSAFE_TOKEN="…" on your
clipboard, which every example below reads. Treat the token like a password: it can spend
your credits. For fully headless scripts, POST /guest mints a guest token with
no browser involved.
curl -s -X POST "$API/guest" \
-H "Content-Type: application/json" \
-d '{"slug":"state-lens"}' | jq -r '.data.token'
token = api("POST", "/guest", {"slug": "state-lens"})["token"]
const { token } = await api("POST", "/guest", { slug: "state-lens" });
var guest struct{ Token string `json:"token"` }
err := call("POST", "/guest", map[string]string{"slug": "state-lens"}, &guest)
String envelope = api("POST", "/guest", """
{"slug":"state-lens"}""");
// token is at data.token in the returned JSON
token = api("POST", "/guest", { slug: "state-lens" })["token"]
$token = api("POST", "/guest", ["slug" => "state-lens"])["token"];
var guest = await SkillSafe.ApiAsync(HttpMethod.Post, "/guest",
new { slug = "state-lens" });
var token = guest.GetProperty("token").GetString();
The app stores this browser's token under the localStorage key
skillsafe_app_token:state-lens, on the app's own origin. The
token page reads and manages it for you — you never need
to open developer tools.
Step 2 — Check who you are and your balance
Returns subject_type ("user" or "guest"),
subject_id and your credits balance. Check this before reviewing
a large paste.
curl -s "$API/me" -H "Authorization: Bearer $TOKEN" | jq '.data'
me = api("GET", "/me")
print(me["subject_type"], me["credits"])
const me = await api("GET", "/me");
console.log(me.subject_type, me.credits);
var me struct {
SubjectType string `json:"subject_type"`
Credits int64 `json:"credits"`
}
err := call("GET", "/me", nil, &me)
String envelope = api("GET", "/me", null);
// data.subject_type, data.credits
me = api("GET", "/me")
puts "#{me["subject_type"]}: #{me["credits"]} credits"
$me = api("GET", "/me");
echo "{$me['subject_type']}: {$me['credits']} credits\n";
var me = await SkillSafe.ApiAsync(HttpMethod.Get, "/me");
Console.WriteLine($"{me.GetProperty("subject_type")}: {me.GetProperty("credits")} credits");
Step 3 — Estimate the cost
Send exactly the input you would send to /run; the response's
hold_credits is the worst-case cost. Nothing is charged and no job is created,
so estimating is free — useful when you are feeding in a whole diff or a directory of
route handlers and want a ceiling before spending credits.
| Input field | Type | Notes |
|---|---|---|
code | string, required | The Dart to review: a widget, a screen, a State class, a ChangeNotifier, or several files concatenated with file-name comment headers. Very long pastes may be clipped middle-out, with a [... clipped ...] marker showing where. |
approach | string | setState | provider | riverpod | bloc | mixed | unknown — your current or intended approach. Fixes are written in its idiom (Consumer/context.watch for provider, ref.watch for riverpod, BlocBuilder for bloc). On unknown the review recommends the reference baseline: setState for ephemeral state, MVVM with provider for app state. |
notes | string, optional | Extra context: what the screen does, which state is shared with the rest of the app, what already lives in a repository or view model outside the paste. |
prescan_facts | object, optional | What a client-side prescan mechanically detected in the code: {"antipatterns": [], "widgets": [], "signals": []}. Each entry is {id, label} — keyword-matched state-management smells (ap:global-mutable-state, ap:controller-not-disposed), widget and notifier classes found (w:CartScreen) and counted state signals (sig:setstate, sig:notify, sig:consumer). Every id you send comes back in coverage_check. The web UI fills this from its own scan; API callers may omit the field or send the three empty arrays. |
retry_note | string, optional | Only set by the app's automatic reformat retry when a first reply was not valid JSON. Leave it out. |
cat > cart_screen.dart <<'DART'
List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}
DART
jq -n --rawfile c cart_screen.dart \
'{code: $c, approach: "setState", notes: "",
prescan_facts: {antipatterns: [], widgets: [], signals: []}}' > input.json
curl -s -X POST "$API/estimate" \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-d @input.json | jq '.data.hold_credits'
CODE = """List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}"""
payload = {
"code": CODE,
"approach": "setState",
"notes": "",
"prescan_facts": {"antipatterns": [], "widgets": [], "signals": []},
}
est = api("POST", "/estimate", payload)
print("worst case:", est.get("hold_credits", est.get("credits")), "credits")
const code = `List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}`;
const payload = {
code,
approach: "setState",
notes: "",
prescan_facts: { antipatterns: [], widgets: [], signals: [] },
};
const est = await api("POST", "/estimate", payload);
console.log("worst case:", est.hold_credits ?? est.credits, "credits");
const code = `List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}`
payload := map[string]any{
"code": code,
"approach": "setState",
"notes": "",
"prescan_facts": map[string]any{
"antipatterns": []any{}, "widgets": []any{}, "signals": []any{},
},
}
var est struct{ HoldCredits int64 `json:"hold_credits"` }
err := call("POST", "/estimate", payload, &est)
String code = """
List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}""";
String jsonPayload = """
{"code": %s, "approach": "setState",
"notes": "",
"prescan_facts": {"antipatterns": [], "widgets": [], "signals": []}}
""".formatted(toJsonString(code));
String envelope = api("POST", "/estimate", jsonPayload);
// worst-case cost is at data.hold_credits
CODE_TEXT = <<~'DART'
List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}
DART
payload = { code: CODE_TEXT, approach: "setState",
notes: "",
prescan_facts: { antipatterns: [], widgets: [], signals: [] } }
est = api("POST", "/estimate", payload)
puts "worst case: #{est["hold_credits"] || est["credits"]} credits"
$code = <<<'DART'
List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}
DART;
$payload = [
"code" => $code,
"approach" => "setState",
"notes" => "",
"prescan_facts" => ["antipatterns" => [], "widgets" => [], "signals" => []],
];
$est = api("POST", "/estimate", $payload);
echo "worst case: " . ($est["hold_credits"] ?? $est["credits"]) . " credits\n";
var code = """
List<Item> cartItems = [];
class CartScreen extends StatefulWidget {
const CartScreen({super.key});
@override
State<CartScreen> createState() => _CartScreenState();
}
class _CartScreenState extends State<CartScreen> {
final controller = TextEditingController();
void addItem(Item item) {
cartItems.add(item);
}
@override
Widget build(BuildContext context) {
double total = 0;
for (final i in cartItems) {
total += i.price;
}
return Text(total.toStringAsFixed(2));
}
}
""";
var payload = new {
code,
approach = "setState",
notes = "",
prescan_facts = new {
antipatterns = Array.Empty<object>(), widgets = Array.Empty<object>(),
signals = Array.Empty<object>(),
},
};
var est = await SkillSafe.ApiAsync(HttpMethod.Post, "/estimate", payload);
Console.WriteLine($"worst case: {est.GetProperty("hold_credits")} credits");
prescan_facts is how you make the review answer for things you already know
about. Send {"antipatterns": [{"id": "ap:global-mutable-state", "label": "top-level
mutable state"}], "widgets": [{"id": "w:CartScreen", "label": "CartScreen
(StatefulWidget)"}], "signals": [{"id": "sig:setstate", "label": "2 setState calls"}]}
and every one of those ids comes back in coverage_check — addressed, or
explained away as a false positive. Nothing you flag is silently dropped.
Step 4 — Run the review and wait for the result
/run takes the same input as /estimate, places a credit hold and
returns a job_id. Poll /jobs/{job_id} every 1–2 seconds
until status is succeeded or failed (a run typically
takes 30–90 s, since the refactor is written out in full). Always send an
Idempotency-Key header so a network retry can't start a second,
double-charged run. The review is in output — usually nested as
output.output, and as a JSON string, so parse defensively. The samples
below print the review name and verdict, the five health areas and the findings, then write
rewrite.code to refactored.dart.
JOB_ID=$(curl -s -X POST "$API/run" \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-H "Idempotency-Key: review-$(date +%s)" \
-d @input.json | jq -r '.data.job_id')
while :; do
JOB=$(curl -s "$API/jobs/$JOB_ID" -H "Authorization: Bearer $TOKEN")
STATUS=$(echo "$JOB" | jq -r '.data.status')
[ "$STATUS" = "succeeded" ] || [ "$STATUS" = "failed" ] && break
sleep 2
done
# unwrap the review once, then read it
echo "$JOB" | jq -r '.data.output.output' > review.json
jq -r '
"\(.review_name) [\(.verdict_level)]: \(.verdict)",
"",
"HEALTH",
(.health[] | " [\(.status)] \(.area) - \(.note)"),
"",
"FINDINGS",
(.findings[] | " (\(.severity)) \(.category): \(.title)"),
"",
"CHECKLIST",
(.checklist[] | " [\(.status)] \(.item) - \(.note)")' review.json
# and drop the refactored code straight into the repo
jq -r '.rewrite.code' review.json > "$(jq -r '.rewrite.filename' review.json)" # refactored.dart
import time
job_id = api("POST", "/run", payload,
**{"Idempotency-Key": "review-001"})["job_id"]
while True:
job = api("GET", f"/jobs/{job_id}")
if job["status"] in ("succeeded", "failed"):
break
time.sleep(1.5)
if job["status"] == "failed":
raise RuntimeError(job.get("error", "run failed"))
raw = job["output"]
if isinstance(raw, dict) and "output" in raw:
raw = raw["output"]
review = json.loads(raw) if isinstance(raw, str) else raw
print(f'{review["review_name"]} [{review["verdict_level"]}]: {review["verdict"]}')
for area in review["health"]:
print(f' [{area["status"]:>4}] {area["area"]:<32} {area["note"]}')
for f in review["findings"]:
print(f' ({f["severity"]}) {f["category"]}: {f["title"]}')
if f["fix_code"]:
print(f' {f["fix_code"]}')
for item in review["checklist"]:
print(f' [{item["status"]:>4}] {item["item"]:<18} {item["note"]}')
for c in review["coverage_check"]:
print(f' {c["id"]}: {"ok" if c["addressed"] else "SET ASIDE"} - {c["note"]}')
with open(review["rewrite"]["filename"], "w", encoding="utf-8") as fh: # refactored.dart
fh.write(review["rewrite"]["code"])
import { writeFileSync } from "node:fs";
const { job_id } = await api("POST", "/run", payload,
{ "Idempotency-Key": crypto.randomUUID() });
let job;
do {
await new Promise((r) => setTimeout(r, 1500));
job = await api("GET", `/jobs/${job_id}`);
} while (job.status !== "succeeded" && job.status !== "failed");
if (job.status === "failed") throw new Error(job.error ?? "run failed");
const raw = job.output?.output ?? job.output;
const review = typeof raw === "string" ? JSON.parse(raw) : raw;
console.log(`${review.review_name} [${review.verdict_level}]: ${review.verdict}`);
for (const area of review.health) {
console.log(` [${area.status}] ${area.area}: ${area.note}`);
}
for (const f of review.findings) {
console.log(` (${f.severity}) ${f.category}: ${f.title}`);
if (f.fix_code) console.log(` ${f.fix_code}`);
}
for (const item of review.checklist) console.log(` [${item.status}] ${item.item}: ${item.note}`);
for (const c of review.coverage_check) {
console.log(` ${c.id}: ${c.addressed ? "ok" : "SET ASIDE"} - ${c.note}`);
}
writeFileSync(review.rewrite.filename, review.rewrite.code); // refactored.dart
var started struct{ JobID string `json:"job_id"` }
if err := call("POST", "/run", payload, &started); err != nil {
log.Fatal(err)
}
var job struct {
Status string `json:"status"`
Error string `json:"error"`
Output json.RawMessage `json:"output"`
}
for {
if err := call("GET", "/jobs/"+started.JobID, nil, &job); err != nil {
log.Fatal(err)
}
if job.Status == "succeeded" || job.Status == "failed" {
break
}
time.Sleep(1500 * time.Millisecond)
}
// job.Output is {"output": "<json string>"} — unwrap, unquote, then unmarshal:
type Review struct {
ReviewName string `json:"review_name"`
VerdictLevel string `json:"verdict_level"`
Verdict string `json:"verdict"`
Health []struct {
Area, Status, Note string
} `json:"health"`
Findings []struct {
Severity, Category, Title, Detail string
FixCode string `json:"fix_code"`
} `json:"findings"`
Checklist []struct {
Item, Status, Note string
} `json:"checklist"`
Rewrite struct {
Filename, Code string
} `json:"rewrite"`
}
var wrapper struct{ Output string `json:"output"` }
json.Unmarshal(job.Output, &wrapper)
var review Review
json.Unmarshal([]byte(wrapper.Output), &review)
fmt.Printf("%s [%s]: %s\n", review.ReviewName, review.VerdictLevel, review.Verdict)
for _, a := range review.Health {
fmt.Printf(" [%s] %s: %s\n", a.Status, a.Area, a.Note)
}
for _, f := range review.Findings {
fmt.Printf(" (%s) %s: %s\n", f.Severity, f.Category, f.Title)
}
for _, c := range review.Checklist {
fmt.Printf(" [%s] %s: %s\n", c.Status, c.Item, c.Note)
}
os.WriteFile(review.Rewrite.Filename, []byte(review.Rewrite.Code), 0o644) // refactored.dart
String envelope = api("POST", "/run", jsonPayload);
String jobId = /* data.job_id via your JSON library */;
while (true) {
String job = api("GET", "/jobs/" + jobId, null);
String status = /* data.status */;
if (status.equals("succeeded") || status.equals("failed")) break;
Thread.sleep(1500);
}
// The review is at data.output.output as a JSON string — parse it again, then read
// review_name, verdict_level, verdict, overview, health[] (five areas with area/status/note),
// findings[] (severity/category/title/detail/fix_code), checklist[] (item/status/note),
// coverage_check[] (id/addressed/note), rewrite{filename, code}, next_steps[] and summary.
// Finally write the refactored code to disk:
// Files.writeString(Path.of(rewriteFilename), rewriteCode); // refactored.dart
started = api("POST", "/run", payload)
job = nil
loop do
job = api("GET", "/jobs/#{started["job_id"]}")
break if %w[succeeded failed].include?(job["status"])
sleep 1.5
end
raise (job["error"] || "run failed") if job["status"] == "failed"
raw = job["output"].is_a?(Hash) ? job["output"].fetch("output", job["output"]) : job["output"]
review = raw.is_a?(String) ? JSON.parse(raw) : raw
puts "#{review["review_name"]} [#{review["verdict_level"]}]: #{review["verdict"]}"
review["health"].each { |a| puts " [#{a["status"]}] #{a["area"]}: #{a["note"]}" }
review["findings"].each do |f|
puts " (#{f["severity"]}) #{f["category"]}: #{f["title"]}"
puts " #{f["fix_code"]}" unless f["fix_code"].to_s.empty?
end
review["checklist"].each { |c| puts " [#{c["status"]}] #{c["item"]}: #{c["note"]}" }
review["coverage_check"].each { |c| puts " #{c["id"]}: #{c["addressed"] ? "ok" : "SET ASIDE"}" }
File.write(review["rewrite"]["filename"], review["rewrite"]["code"]) # refactored.dart
$started = api("POST", "/run", $payload);
do {
sleep(2);
$job = api("GET", "/jobs/" . $started["job_id"]);
} while (!in_array($job["status"], ["succeeded", "failed"]));
if ($job["status"] === "failed") {
throw new Exception($job["error"] ?? "run failed");
}
$raw = is_array($job["output"]) ? ($job["output"]["output"] ?? $job["output"]) : $job["output"];
$review = is_string($raw) ? json_decode($raw, true) : $raw;
echo "{$review['review_name']} [{$review['verdict_level']}]: {$review['verdict']}\n";
foreach ($review["health"] as $a) {
echo " [{$a['status']}] {$a['area']}: {$a['note']}\n";
}
foreach ($review["findings"] as $f) {
echo " ({$f['severity']}) {$f['category']}: {$f['title']}\n";
if ($f["fix_code"] !== "") { echo " {$f['fix_code']}\n"; }
}
foreach ($review["checklist"] as $item) {
echo " [{$item['status']}] {$item['item']}: {$item['note']}\n";
}
foreach ($review["coverage_check"] as $c) {
echo " {$c['id']}: " . ($c["addressed"] ? "ok" : "SET ASIDE") . "\n";
}
file_put_contents($review["rewrite"]["filename"], $review["rewrite"]["code"]); // refactored.dart
var started = await SkillSafe.ApiAsync(HttpMethod.Post, "/run", payload);
var jobId = started.GetProperty("job_id").GetString();
JsonElement job;
while (true)
{
job = await SkillSafe.ApiAsync(HttpMethod.Get, $"/jobs/{jobId}");
var status = job.GetProperty("status").GetString();
if (status is "succeeded" or "failed") break;
await Task.Delay(1500);
}
var rawText = job.GetProperty("output").GetProperty("output").GetString();
using var doc = JsonDocument.Parse(rawText!);
var review = doc.RootElement;
Console.WriteLine($"{review.GetProperty("review_name")} " +
$"[{review.GetProperty("verdict_level")}]: {review.GetProperty("verdict")}");
foreach (var a in review.GetProperty("health").EnumerateArray())
{
Console.WriteLine($" [{a.GetProperty("status")}] {a.GetProperty("area")}: {a.GetProperty("note")}");
}
foreach (var f in review.GetProperty("findings").EnumerateArray())
{
Console.WriteLine($" ({f.GetProperty("severity")}) {f.GetProperty("category")}: " +
$"{f.GetProperty("title")}");
}
foreach (var c in review.GetProperty("checklist").EnumerateArray())
{
Console.WriteLine($" [{c.GetProperty("status")}] {c.GetProperty("item")}: {c.GetProperty("note")}");
}
var rewrite = review.GetProperty("rewrite");
await File.WriteAllTextAsync(rewrite.GetProperty("filename").GetString()!, // refactored.dart
rewrite.GetProperty("code").GetString()!);
The model is asked for one JSON object and nothing else, but a stray code fence or preamble
is always possible. Strip a leading ```json fence, take the text between the
first { and the last }, and only then parse — that is what
the app does before it falls back to a retry_note reformat run.
The review object — output schema
One JSON object, always the same shape. Every array is present (findings is
empty only if genuinely nothing applies); health always has exactly the five
areas, checklist always has exactly the twelve items, and
rewrite.code is never empty. If the paste was too thin to review responsibly,
you still get this object: what is there gets reviewed, the verdict says the
paste is thin, and what you would need to show lands in next_steps. If the
paste is not Dart at all, you still get the object — one high-severity finding
explaining what arrived, every health area at risk, every checklist item at
na, and a rewrite.code comment block saying what to paste instead.
| Field | Type | Meaning |
|---|---|---|
review_name | string | A short name for the review, taken from the code's own widget, screen or class naming. |
verdict_level | string | sound (nothing material found), refactor (findings exist but are medium/low or only bite at scale) or rework (a high finding means the code is broken or leaking as pasted). |
verdict | string | One or two sentences: the overall state and the single most important change. |
overview | string | One or two paragraphs: what this code does, and the pattern behind what was found. |
health | array of 5 | {area, status, note} — the five areas listed below, each exactly once. status is good (nothing material), risk (works, with caveats) or bad (a high-severity finding lives here). Each note references something concrete in the pasted code; an area with no evidence in the paste is risk, never good. |
findings | array | {severity, category, title, detail, fix_code}. severity is high (a real bug or broken pattern now — state mutated with no rebuild scheduled, a controller leak, shared mutable globals) | medium (works today but scales badly) | low (hygiene); category is classification, data-flow, rebuild, lifecycle, provider, architecture or correctness. detail quotes the class, method or expression it concerns; fix_code is corrected Dart in your own naming, or an empty string when the finding is a question or trade-off rather than a mechanical fix. |
checklist | array of 12 | {item, status, note} — the twelve state-management items listed below, each exactly once and in order. status is pass (the paste shows it handled), fail (the paste shows it mishandled — a finding backs this) or na (the paste gives no evidence either way). The note says what was seen or what is missing. |
coverage_check | array | {id, addressed, note} — one entry per prescan_facts item you sent (ap:global-mutable-state, w:CartScreen, sig:setstate, …), saying where the review covers it or why it was set aside (a keyword hit can be a false positive; the note says so). Nothing you flagged is silently dropped. |
rewrite | object | {filename, code} — filename is normally refactored.dart, and code is your own code refactored: same screens, same intent, findings fixed — ephemeral state kept in setState, shared state lifted into a ChangeNotifier view model behind a repository, notifyListeners() on every mutation, the provider scoped low, Consumer narrowed, context.read in callbacks, controllers disposed. Your naming, style and comments are preserved, and it is a complete replacement for what you pasted, not a fragment. |
next_steps | string[] | Ordered and concrete: lift the cart into a view model, dispose the controller, move the fetch out of build(), and so on. |
summary | string | 3–5 sentences a tech lead could paste into a code review. |
The five health areas, in order, spelled exactly like this:
| area | What its note covers |
|---|---|
State classification | Ephemeral state (one widget's own concern) kept in a StatefulWidget and mutated inside setState; app state (shared across widgets or sessions) lifted out of the widget into a view model. |
Data flow & source of truth | State flows down from the data layer through the view model to the view, events flow up; one class owns each piece of data and nobody else keeps a second copy. |
Rebuild efficiency | Rebuilds scoped to what actually depends on the state — Consumer/context.watch narrowed to the smallest subtree, context.read in callbacks, no whole-screen repaint for one row. |
Lifecycle & disposal | Controllers, subscriptions and timers disposed in dispose(); setState after an await guarded by a mounted check. |
Architecture & layering | MVVM in place: a Repository doing I/O, a ChangeNotifier view model converting data into UI state, and a lean view with no business logic in build(). |
The twelve checklist items, in order, spelled exactly like this:
| item | What its note covers |
|---|---|
Ephemeral state via setState | Widget-local state held as a private field in a State class and mutated only inside a setState callback. |
Shared state lifted out of widgets | State more than one widget reads lives outside the tree — not in a global variable, not in one screen's State. |
Single source of truth | One class owns each piece of data and is the only one that may modify it; no second copies drifting apart. |
Unidirectional data flow | State down, events up — the view calls the view model, the view model calls the repository, never the reverse. |
notifyListeners on every mutation | Every ChangeNotifier mutation ends with notifyListeners(), including the loading and error transitions. |
Provider scoped low in the tree | ChangeNotifierProvider placed directly above the subtree that needs it, not at runApp. |
Consumer/watch granularity | Consumer and context.watch narrowed to the widgets that actually display the state. |
read (not watch) in callbacks | Handlers use context.read<T>() (or listen: false) so calling a method does not rebuild the caller. |
Controllers and subscriptions disposed | Every controller, StreamSubscription and Timer created by a State is cancelled or disposed in dispose(). |
Logic kept out of build() | build() lays out widgets only — no awaits, no network calls, no accumulation loops re-run on every frame. |
State exposed immutably | Collections handed out as List.unmodifiable(...) or copies, so only the owner mutates them. |
View/ViewModel separation | Views hold routing, animation and simple UI conditionals; everything else lives in the view model. |
A small, realistic result for the CartScreen paste above, trimmed for length:
{
"review_name": "cart_screen.dart - CartScreen cart list",
"verdict_level": "rework",
"verdict": "addItem() mutates the shared cartItems list with no setState and no
notifyListeners, so the screen never updates; lift the cart into a
view model before anything else.",
"overview": "One StatefulWidget rendering a cart. The cart itself is the top-level
cartItems list, so it is app state being driven with setState. Two
problems follow: nothing schedules a rebuild when the list changes,
and the TextEditingController is never disposed. build() also runs
the totals loop on every frame.",
"health": [
{ "area": "State classification", "status": "bad",
"note": "'List<Item> cartItems = [];' is top-level shared state managed as if
it were widget-local." },
{ "area": "Data flow & source of truth", "status": "bad",
"note": "Any widget can write to cartItems; no class owns it." },
{ "area": "Rebuild efficiency", "status": "risk",
"note": "No Consumer or watch in the paste - every change would repaint the
whole screen through setState." },
{ "area": "Lifecycle & disposal", "status": "bad",
"note": "'final controller = TextEditingController();' with no dispose()
override in _CartScreenState." },
{ "area": "Architecture & layering", "status": "bad",
"note": "No repository and no view model: the widget holds the data and the
pricing arithmetic." }
],
"findings": [
{ "severity": "high", "category": "correctness",
"title": "addItem() mutates cartItems without setState or notifyListeners",
"detail": "'void addItem(Item item) { cartItems.add(item); }' changes the list
and schedules no rebuild, so the new row never appears.",
"fix_code": "void addItem(Item item) {\n repository.add(item);\n notifyListeners();\n}" },
{ "severity": "high", "category": "classification",
"title": "The cart is app state in a top-level mutable list",
"detail": "'List<Item> cartItems = [];' sits at file scope, so every screen
reads and writes the same global.",
"fix_code": "class CartRepository {\n final List<Item> _items = [];\n List<Item> get items => List.unmodifiable(_items);\n}" },
{ "severity": "high", "category": "lifecycle",
"title": "controller is never disposed",
"detail": "_CartScreenState creates a TextEditingController and has no
dispose() override at all.",
"fix_code": "@override\nvoid dispose() {\n controller.dispose();\n super.dispose();\n}" },
{ "severity": "medium", "category": "architecture",
"title": "The totals loop runs inside build()",
"detail": "'for (final i in cartItems) { total += i.price; }' re-runs on every
rebuild; it belongs on the view model as a getter.",
"fix_code": "double get total =>\n cartItems.fold(0, (sum, item) => sum + item.price);" }
],
"checklist": [
{ "item": "Ephemeral state via setState", "status": "fail",
"note": "The only state in the widget is the shared cart, and it is not
mutated inside setState at all." },
{ "item": "Shared state lifted out of widgets", "status": "fail",
"note": "cartItems is a top-level variable rather than a repository." },
{ "item": "Single source of truth", "status": "fail",
"note": "Nothing owns the cart list." },
{ "item": "Unidirectional data flow", "status": "fail",
"note": "The widget writes to the model directly." },
{ "item": "notifyListeners on every mutation", "status": "fail",
"note": "No ChangeNotifier in the paste; addItem notifies nobody." },
{ "item": "Provider scoped low in the tree", "status": "na",
"note": "No provider is used yet." },
{ "item": "Consumer/watch granularity", "status": "na",
"note": "No Consumer or watch in the paste." },
{ "item": "read (not watch) in callbacks", "status": "na",
"note": "No provider reads in the paste." },
{ "item": "Controllers and subscriptions disposed", "status": "fail",
"note": "controller has no dispose()." },
{ "item": "Logic kept out of build()", "status": "fail",
"note": "The totals loop runs in build()." },
{ "item": "State exposed immutably", "status": "fail",
"note": "cartItems is a public growable list." },
{ "item": "View/ViewModel separation", "status": "fail",
"note": "There is no view model." }
],
"coverage_check": [
{ "id": "ap:global-mutable-state", "addressed": true,
"note": "Covered by the classification finding - moved into CartRepository." },
{ "id": "w:CartScreen", "addressed": true,
"note": "The widget under review; becomes a lean view over CartViewModel." },
{ "id": "sig:setstate", "addressed": true,
"note": "Zero setState calls despite mutable shared state - that is the bug." }
],
"rewrite": { "filename": "refactored.dart",
"code": "class CartViewModel extends ChangeNotifier { … }" },
"next_steps": [
"Create CartRepository as the single owner of the cart list.",
"Add CartViewModel extends ChangeNotifier and call notifyListeners() in addItem.",
"Wrap the cart body in a ChangeNotifierProvider inside CartScreen, not at runApp.",
"Add a dispose() that disposes controller."
],
"summary": "The cart is app state in a global list, mutated with no rebuild scheduled. …"
}
The refactor is a starting point, not a sign-off: it is written to be complete and
self-consistent with the findings, but it is AI-generated and it only sees what you pasted.
Read it, run dart analyze and your widget tests against it, and keep the human
review in the loop before it goes anywhere near production.
Step 5 — Stream the review as it is written
/run-stream takes exactly the same body as /run but answers with
server-sent events, so you can show progress instead of a spinner — useful here
because the refactor makes for a long reply. This app's own progress panel is this
endpoint. Events are separated by a blank line; each has an event: line and a
data: line carrying JSON.
| Event | Payload | Meaning |
|---|---|---|
job | {job_id, status} | Sent once, when the job is accepted — show "starting". |
delta | {text} | A chunk of the reply, in order. Append it; the accumulated length is your only progress signal (the total is not known in advance). |
done | {job_id, status, charged_credits, output} | The final, authoritative result — read the review from output.output rather than trusting concatenated deltas, and the settled price from charged_credits. |
error | {code, message} | Replaces done when the run fails. |
# -N disables buffering so events print as they arrive
curl -N -s -X POST "$API/run-stream" \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-H "Idempotency-Key: review-$(date +%s)" \
-d @input.json
# event: job
# data: {"job_id":"job_...","status":"running"}
#
# event: delta
# data: {"text":"{\"review_name\":\"cart_screen.dart"}
# ...
# event: done
# data: {"job_id":"job_...","status":"succeeded","charged_credits":612,"output":{"output":"{...}"}}
import json, requests
result = None
with requests.post(
API + "/run-stream",
headers={"Authorization": f"Bearer {TOKEN}",
"Idempotency-Key": "review-001"},
json=payload,
stream=True,
) as r:
r.raise_for_status()
event = None
for line in r.iter_lines(decode_unicode=True):
if not line:
continue
if line.startswith("event:"):
event = line[len("event:"):].strip()
elif line.startswith("data:"):
data = json.loads(line[len("data:"):].strip())
if event == "delta":
print(".", end="", flush=True) # live progress
elif event == "done":
result = data
elif event == "error":
raise RuntimeError(data.get("message", "run failed"))
review = json.loads(result["output"]["output"]) # authoritative
print("charged:", result["charged_credits"], "-", review["review_name"])
for area in review["health"]:
print(f' [{area["status"]}] {area["area"]}')
open(review["rewrite"]["filename"], "w", encoding="utf-8").write(review["rewrite"]["code"])
const res = await fetch(API + "/run-stream", {
method: "POST",
headers: {
Authorization: `Bearer ${TOKEN}`,
"Content-Type": "application/json",
"Idempotency-Key": crypto.randomUUID(),
},
body: JSON.stringify(payload),
});
const reader = res.body.getReader();
const decoder = new TextDecoder();
let buf = "", done = null;
for (;;) {
const chunk = await reader.read();
if (chunk.done) break;
buf += decoder.decode(chunk.value, { stream: true });
const frames = buf.split("\n\n");
buf = frames.pop();
for (const frame of frames) {
const name = /^event:\s*(.+)$/m.exec(frame)?.[1];
const body = /^data:\s*(.+)$/m.exec(frame)?.[1];
if (!name || !body) continue;
const data = JSON.parse(body);
if (name === "delta") process.stdout.write("."); // live progress
if (name === "done") done = data;
if (name === "error") throw new Error(data.message ?? "run failed");
}
}
const review = JSON.parse(done.output.output);
console.log(`\n${done.charged_credits} credits - ${review.review_name}`);
for (const area of review.health) console.log(` [${area.status}] ${area.area}`);
writeFileSync(review.rewrite.filename, review.rewrite.code); // refactored.dart
body, _ := json.Marshal(payload)
req, _ := http.NewRequest("POST", API+"/run-stream", bytes.NewReader(body))
req.Header.Set("Authorization", "Bearer "+token)
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Idempotency-Key", "review-001")
res, err := http.DefaultClient.Do(req)
if err != nil {
log.Fatal(err)
}
defer res.Body.Close()
var event string
var final map[string]any
sc := bufio.NewScanner(res.Body)
sc.Buffer(make([]byte, 0, 64*1024), 4*1024*1024)
for sc.Scan() {
line := sc.Text()
switch {
case strings.HasPrefix(line, "event:"):
event = strings.TrimSpace(strings.TrimPrefix(line, "event:"))
case strings.HasPrefix(line, "data:"):
var data map[string]any
json.Unmarshal([]byte(strings.TrimPrefix(line, "data:")), &data)
switch event {
case "delta":
fmt.Print(".") // live progress
case "done":
final = data
case "error":
log.Fatal(data["message"])
}
}
}
// final["output"].(map[string]any)["output"].(string) is the review JSON —
// unmarshal it into the Review struct from step 4, then write review.Rewrite.Code to disk.
// Java 17+ — read the stream line by line instead of buffering the body.
var req = HttpRequest.newBuilder(URI.create(API + "/run-stream"))
.header("Authorization", "Bearer " + TOKEN)
.header("Content-Type", "application/json")
.header("Idempotency-Key", "review-001")
.POST(HttpRequest.BodyPublishers.ofString(jsonPayload))
.build();
var res = HTTP.send(req, HttpResponse.BodyHandlers.ofLines());
String event = null, done = null;
for (String line : (Iterable<String>) res.body()::iterator) {
if (line.startsWith("event:")) {
event = line.substring(6).trim();
} else if (line.startsWith("data:")) {
String data = line.substring(5).trim();
if ("delta".equals(event)) System.out.print("."); // live progress
else if ("done".equals(event)) done = data;
else if ("error".equals(event)) throw new RuntimeException(data);
}
}
// parse `done`, then parse data.output.output again — it is a JSON string holding
// review_name, verdict_level, health[], findings[], checklist[], rewrite{filename, code} and the rest.
require "net/http"
require "json"
uri = URI(API + "/run-stream")
req = Net::HTTP::Post.new(uri)
req["Authorization"] = "Bearer #{TOKEN}"
req["Content-Type"] = "application/json"
req["Idempotency-Key"] = "review-001"
req.body = payload.to_json
event = nil
done = nil
Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
http.request(req) do |res|
res.read_body do |chunk|
chunk.each_line do |line|
line = line.strip
if line.start_with?("event:")
event = line.delete_prefix("event:").strip
elsif line.start_with?("data:")
data = JSON.parse(line.delete_prefix("data:").strip)
case event
when "delta" then print "." # live progress
when "done" then done = data
when "error" then raise (data["message"] || "run failed")
end
end
end
end
end
end
review = JSON.parse(done["output"]["output"])
puts "\n#{done["charged_credits"]} credits - #{review["review_name"]}"
review["health"].each { |a| puts " [#{a["status"]}] #{a["area"]}" }
File.write(review["rewrite"]["filename"], review["rewrite"]["code"]) # refactored.dart
$event = null;
$done = null;
$ch = curl_init(API . "/run-stream");
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer $TOKEN",
"Content-Type: application/json",
"Idempotency-Key: review-001",
],
CURLOPT_POSTFIELDS => json_encode($payload),
CURLOPT_WRITEFUNCTION => function ($ch, $chunk) use (&$event, &$done) {
foreach (explode("\n", $chunk) as $line) {
$line = trim($line);
if (str_starts_with($line, "event:")) {
$event = trim(substr($line, 6));
} elseif (str_starts_with($line, "data:")) {
$data = json_decode(trim(substr($line, 5)), true);
if ($event === "delta") { echo "."; } // live progress
elseif ($event === "done") { $done = $data; }
elseif ($event === "error") { throw new Exception($data["message"] ?? "run failed"); }
}
}
return strlen($chunk);
},
]);
curl_exec($ch);
curl_close($ch);
$review = json_decode($done["output"]["output"], true);
echo "\n{$done['charged_credits']} credits - {$review['review_name']}\n";
foreach ($review["health"] as $a) { echo " [{$a['status']}] {$a['area']}\n"; }
file_put_contents($review["rewrite"]["filename"], $review["rewrite"]["code"]); // refactored.dart
var req = new HttpRequestMessage(HttpMethod.Post, Api + "/run-stream") {
Content = JsonContent.Create(payload),
};
req.Headers.Add("Idempotency-Key", "review-001");
using var res = await Http.SendAsync(req, HttpCompletionOption.ResponseHeadersRead);
using var reader = new StreamReader(await res.Content.ReadAsStreamAsync());
string? evt = null, done = null;
while (await reader.ReadLineAsync() is { } line)
{
if (line.StartsWith("event:")) evt = line[6..].Trim();
else if (line.StartsWith("data:"))
{
var data = line[5..].Trim();
if (evt == "delta") Console.Write("."); // live progress
else if (evt == "done") done = data;
else if (evt == "error") throw new Exception(data);
}
}
using var final = JsonDocument.Parse(done!);
var text = final.RootElement.GetProperty("output").GetProperty("output").GetString();
using var reviewDoc = JsonDocument.Parse(text!);
var review = reviewDoc.RootElement;
Console.WriteLine(review.GetProperty("review_name"));
foreach (var a in review.GetProperty("health").EnumerateArray())
Console.WriteLine($" [{a.GetProperty("status")}] {a.GetProperty("area")}");
var rewrite = review.GetProperty("rewrite");
await File.WriteAllTextAsync(rewrite.GetProperty("filename").GetString()!, // refactored.dart
rewrite.GetProperty("code").GetString()!);
In a browser, the native EventSource only speaks GET, and this endpoint is a
POST — read the fetch response body incrementally, as the JavaScript
sample above does. On an idempotent replay the server may answer with a plain JSON
envelope instead of an event stream; check the Content-Type before you start
parsing frames.