All skills
flutter avatar

/code-review

@7712f53 official
by flutterflutter/skills3k stars
182

Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback. Use when you need to review code changes thoroughly.

Use this Skill: https://skilld.dev/gh/flutter/skills/code-review

This session only. Nothing lands on disk.

referencesreview_criteria.md

≈703 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Review Criteria

This reference document outlines the criteria to prioritize when performing a code review, as well as guidelines for severity and constraints to ensure high-quality feedback.

Prioritized Criteria

1. Correctness

Verify code functionality, handle edge cases, and ensure alignment between function descriptions and implementations.

  • Logic errors: Check for flawed logic or incorrect algorithms.
  • Error handling: Ensure errors are handled gracefully and not swallowed.
  • Race conditions: Look for potential concurrency issues.
  • Data validation: Verify that inputs are validated correctly.
  • API usage: Ensure APIs are used correctly and efficiently.

2. Efficiency

Identify performance bottlenecks and optimize for efficiency.

  • Avoid unnecessary loops, iterations, or calculations.
  • Watch for memory leaks or inefficient data structures.
  • Avoid excessive logging in performance-critical paths.

3. Maintainability

Assess code readability, modularity, and adherence to language idioms.

  • Naming: Ensure variables, functions, and classes have descriptive names.
  • Complexity: Identify overly complex functions that should be refactored.
  • Code duplication: Look for opportunities to reuse code.
  • Style: Adhere to specified style guides. Violations should be noted.
  • Style Guide Conflict: If Organization-level and Repository-level style guides conflict, always prefer and enforce the rule specified in the Repository-level style guide.

4. Security

Identify potential vulnerabilities.

  • Insecure storage of sensitive data.
  • Injection attacks (SQL, command, etc.).
  • Insufficient access controls or validation.

Severity Levels

Use these severity levels to categorize your findings:

  • critical: Must be addressed immediately. Could lead to serious consequences for correctness, security, or performance.
  • high: Should be addressed soon. Likely to cause problems in the future.
  • medium: Should be considered for future improvement. Not critical or urgent.
  • low: Minor or stylistic issues. Can be addressed at the author's discretion.

Critical Constraints

  • Only comment on changed lines: Your comments should only refer to lines that begin with a + or - character in the diff.
  • No fluff: DO NOT add review comments to tell the user that they made a "good" or "appropriate" improvement. Only comment when there is an improvement opportunity.
  • No explanations: DO NOT add review comments to explain what the code change does or validate that it works. The author knows what they wrote.
  • Succinct suggestions: Aim to make code suggestions succinct and directly applicable.
  • Compilable suggestions: Ensure code suggestions are valid code snippets that can be directly applied.

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    The skill performs multi-step code reviews using Git and GitHub CLI. It includes a Python script for managing large diffs. While functionally safe, it processes untrusted code changes which presents a potential surface for indirect prompt injection.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 7712f53. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago

README badge

README badge for flutter/skills/code-review

Performs a comprehensive, multi-step code review of pull requests or local code changes using an iterative workflow—generation, critique, and synthesis—to produce actionable feedback on correctness, efficiency, maintainability, and security. Targets the review process itself, avoiding generic praise and focusing only on issues found in modified lines.

Generated from the current SKILL.md.

Does this skill work with GitHub pull requests and local git changes?
Yes. It supports reviewing GitHub PRs using `gh pr view` and `gh pr diff`, and local changes using `git status`, `git diff`, and `git log -p`.
What does this skill focus on when reviewing code?
It checks correctness, efficiency, maintainability, and security. It only adds comments for actual issues or improvement opportunities, not validation or explanation of unchanged code.
Does this skill integrate with other skills?
Yes. It references specialized skills like `api-review` for API design feedback, `code-documentation` for documentation standards, and language/framework-specific skills to align with project best practices.
What format does the final review output use?
Reviews are written as Markdown files with a high-level summary, file summaries, comments ordered by severity (critical, high, medium, low), and a recommendations section with actionable feedback.

Generated from the current SKILL.md. These answers refresh after source changes.