All skills
jeffallan avatar

/code-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/code-reviewer

This session only. Nothing lands on disk.

referencescommon-issues.md

≈750 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Common Issues

N+1 Query Problem

// N+1 queries - BAD
const posts = await Post.findAll();
for (const post of posts) {
  post.author = await User.findById(post.authorId); // N queries!
}

// Single query with join - GOOD
const posts = await Post.findAll({ include: [User] });

// Or batch load
const posts = await Post.findAll();
const authorIds = posts.map(p => p.authorId);
const authors = await User.findByIds(authorIds);

Missing Error Handling

// Unhandled rejection - BAD
const data = await fetch('/api/data').then(r => r.json());

// Proper error handling - GOOD
try {
  const response = await fetch('/api/data');
  if (!response.ok) {
    throw new Error(`HTTP ${response.status}`);
  }
  const data = await response.json();
} catch (error) {
  logger.error('Failed to fetch data', { error });
  throw new DataFetchError('Could not load data');
}

Magic Numbers/Strings

// Magic number - BAD
if (user.age >= 18) { ... }
setTimeout(fn, 86400000);

// Named constant - GOOD
const MINIMUM_AGE = 18;
const ONE_DAY_MS = 24 * 60 * 60 * 1000;

if (user.age >= MINIMUM_AGE) { ... }
setTimeout(fn, ONE_DAY_MS);

Deep Nesting

// Deep nesting - BAD
if (user) {
  if (user.isActive) {
    if (user.hasPermission) {
      doSomething();
    }
  }
}

// Early returns - GOOD
if (!user || !user.isActive || !user.hasPermission) {
  return;
}
doSomething();

God Functions

// Does too much - BAD
async function processOrder(order) {
  // validate
  // check inventory
  // process payment
  // send email
  // update database
  // log analytics
}

// Single responsibility - GOOD
async function processOrder(order) {
  await validateOrder(order);
  await reserveInventory(order);
  await chargePayment(order);
  await sendConfirmation(order);
}

Mutable Shared State

// Shared mutable - BAD
const config = { debug: false };
function enableDebug() {
  config.debug = true;
}

// Immutable pattern - GOOD
function createConfig(overrides = {}) {
  return Object.freeze({ debug: false, ...overrides });
}

Missing Null Checks

// Unsafe access - BAD
const name = user.profile.name;

// Safe access - GOOD
const name = user?.profile?.name ?? 'Unknown';

Synchronous File Operations

// Blocks event loop - BAD
const data = fs.readFileSync('file.txt');

// Non-blocking - GOOD
const data = await fs.promises.readFile('file.txt');

Quick Reference

Issue Impact Fix
N+1 queries Performance Eager load or batch
Missing error handling Reliability Try/catch + logging
Magic numbers Maintainability Named constants
Deep nesting Readability Early returns
God functions Testability Single responsibility
Mutable shared state Bugs Immutable patterns
Missing null checks Crashes Optional chaining
Sync file operations Performance Async operations

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The code-reviewer skill is a specialized tool for performing deep code analysis. It is assessed as low risk primarily due to its inherent function of processing untrusted source code, which creates a surface for indirect prompt injection. Automated scanner alerts for the skill file and documentation URL were evaluated and determined to be likely false positives triggered by educational security examples and standard author-owned resources on GitHub Pages.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files
All 3 allowed tools
ReadGrepGlob
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "quality",
  "triggers": "code review, PR review, pull request, review code, code quality",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "security-reviewer, test-master, architecture-designer"
}

README badge

README badge for jeffallan/claude-skills/code-reviewer

Analyzes code diffs and files to identify bugs, security vulnerabilities, N+1 queries, code smells, and architectural issues, then produces a prioritized review report. Use when reviewing pull requests, auditing code quality, or checking for SQL injection, XSS, and other OWASP risks before merge.

Generated from the current SKILL.md.

What types of security vulnerabilities does this skill check for?
The skill checks for SQL injection, XSS, insecure deserialization, and applies OWASP Top 10 as a baseline. It is not a replacement for specialized security tools.
Does this skill review test coverage?
Yes. The skill validates test coverage and quality as part of the review, checking whether edge cases are covered and tests assert behavior rather than implementation.
Can I use this alongside other code review skills?
Yes. The skill complements specialized skills like security-reviewer and test-master by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
Does this skill check for N+1 query problems?
Yes. The skill specifically identifies N+1 queries as part of its performance analysis, with guidance on prefetching patterns.
What does the final output look like?
A structured report with summary, critical and major issues separated by priority, minor issues, positive feedback, questions for the author, and a final verdict (Approve / Request Changes / Comment).

Generated from the current SKILL.md. These answers refresh after source changes.