All skills
jeffallan avatar

/code-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/code-reviewer

This session only. Nothing lands on disk.

referencesfeedback-examples.md

≈865 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Feedback Examples

Good vs Bad Feedback

Be Specific, Not Vague

BAD: "This is confusing"

GOOD: "This function handles both validation and persistence. Consider
      splitting into `validateUser()` and `saveUser()` for single
      responsibility and easier testing."

Be Actionable, Not Just Critical

BAD: "Fix the query"

GOOD: "This will cause N+1 queries - one per post. Use `include: [Author]`
      to eager load authors in a single query. See: [link to docs]"

Be Constructive, Not Demanding

BAD: "Add tests"

GOOD: "Missing test for the case when `email` is already taken. Add a test
      that verifies 409 is returned with appropriate error message."

Ask Questions, Don't Assume

BAD: "This is wrong"

GOOD: "I notice this returns null instead of throwing. Is that intentional?
      The other methods throw on not-found. Should this be consistent?"

Praise Examples

Reinforce good patterns with specific praise:

"Great use of early returns here - much more readable than nested ifs!"

"Nice extraction of this validation logic into a reusable function."

"Excellent error messages - they'll help debugging in production."

"Good choice using a discriminated union here instead of optional fields."

"Appreciate the comprehensive test coverage, especially the edge cases."

Feedback by Category

Critical (Must Fix)

**[CRITICAL] Security: SQL Injection**
Location: `src/users/service.ts:45`

The query uses string interpolation:
`SELECT * FROM users WHERE id = ${id}`

This is vulnerable to SQL injection. Use parameterized query:
`db.query('SELECT * FROM users WHERE id = $1', [id])`

Major (Should Fix)

**[MAJOR] Performance: N+1 Query**
Location: `src/posts/service.ts:23`

Current code fetches users in a loop (N+1 problem):
```typescript
for (const post of posts) {
  post.author = await User.findById(post.authorId);
}

Suggestion: Use eager loading:

const posts = await Post.findAll({ include: [User] });

Impact: ~100 extra DB queries per request with current approach.


### Minor (Nice to Have)

```markdown
**[MINOR] Naming: Unclear variable**
Location: `src/utils/date.ts:12`

`d` is unclear. Consider `createdDate` or `timestamp` for better readability.

**[MINOR] Style: Prefer const**
Location: `src/config/index.ts:8`

`let config` is never reassigned. Use `const` for immutability.

Question Format

**[QUESTION]**
Location: `src/orders/service.ts:67`

What's the expected behavior when the user has an existing pending order?
Should this:
- Return the existing order?
- Create a new one anyway?
- Return an error?

Summary Format

## Summary

Overall this is a solid implementation of the user registration flow.
The validation logic is clean and the error handling is comprehensive.

**Blocking Issues**: 1 critical (SQL injection)
**Suggestions**: 2 major, 3 minor

Once the SQL injection is fixed, this is ready to merge. The major
suggestions are performance improvements worth considering.

Quick Reference

Feedback Type Tone Required Action
Critical Firm, clear Must fix before merge
Major Suggestive Should fix
Minor Optional Nice to have
Praise Positive None - reinforcement
Question Curious Response needed

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The code-reviewer skill is a specialized tool for performing deep code analysis. It is assessed as low risk primarily due to its inherent function of processing untrusted source code, which creates a surface for indirect prompt injection. Automated scanner alerts for the skill file and documentation URL were evaluated and determined to be likely false positives triggered by educational security examples and standard author-owned resources on GitHub Pages.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files
All 3 allowed tools
ReadGrepGlob
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "quality",
  "triggers": "code review, PR review, pull request, review code, code quality",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "security-reviewer, test-master, architecture-designer"
}

README badge

README badge for jeffallan/claude-skills/code-reviewer

Analyzes code diffs and files to identify bugs, security vulnerabilities, N+1 queries, code smells, and architectural issues, then produces a prioritized review report. Use when reviewing pull requests, auditing code quality, or checking for SQL injection, XSS, and other OWASP risks before merge.

Generated from the current SKILL.md.

What types of security vulnerabilities does this skill check for?
The skill checks for SQL injection, XSS, insecure deserialization, and applies OWASP Top 10 as a baseline. It is not a replacement for specialized security tools.
Does this skill review test coverage?
Yes. The skill validates test coverage and quality as part of the review, checking whether edge cases are covered and tests assert behavior rather than implementation.
Can I use this alongside other code review skills?
Yes. The skill complements specialized skills like security-reviewer and test-master by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
Does this skill check for N+1 query problems?
Yes. The skill specifically identifies N+1 queries as part of its performance analysis, with guidance on prefetching patterns.
What does the final output look like?
A structured report with summary, critical and major issues separated by priority, minor issues, positive feedback, questions for the author, and a final verdict (Approve / Request Changes / Comment).

Generated from the current SKILL.md. These answers refresh after source changes.