All skills
jeffallan avatar

/code-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/code-reviewer

This session only. Nothing lands on disk.

referencesreport-template.md

≈769 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Report Template

Full Review Report Template

# Code Review: [PR Title]

## Summary
[1-2 sentence overview of the changes and overall assessment]

**Verdict**: [ ] Approve | [x] Request Changes | [ ] Comment

## Critical Issues (Must Fix)

### 1. [File:Line] Security: SQL Injection Risk
- **Current**: String interpolation in query
- **Suggested**: Use parameterized query
- **Impact**: Potential data breach

```typescript
// Current (vulnerable)
const query = `SELECT * FROM users WHERE id = ${id}`;

// Suggested (secure)
const query = 'SELECT * FROM users WHERE id = $1';
db.query(query, [id]);

Major Issues (Should Fix)

1. [File:Line] Performance: N+1 Query

  • Current: Fetching users in loop
  • Suggested: Use eager loading with include
  • Impact: ~100 extra DB queries per request

2. [File:Line] Logic: Missing edge case

  • Current: No handling for empty array
  • Suggested: Add guard clause
  • Impact: Potential runtime error

Minor Issues (Nice to Have)

1. [File:Line] Naming: Unclear variable name

  • Current: d
  • Suggested: createdDate

2. [File:Line] Style: Inconsistent formatting

  • Current: Mixed quotes
  • Suggested: Use single quotes consistently

Positive Feedback

  • Clean separation of concerns in service layer
  • Comprehensive input validation on DTOs
  • Good test coverage for edge cases
  • Excellent error messages

Questions for Author

  • What's the expected behavior when X happens?
  • Should this support pagination for large datasets?
  • Is the retry logic intentional or accidental?

Test Coverage Assessment

  • Happy path tested
  • Error cases tested
  • Edge cases tested (missing empty array test)
  • Integration tests present

Checklist

  • No security vulnerabilities
  • Performance is acceptable (N+1 issue)
  • Code is readable
  • Tests are adequate
  • Documentation is present

## Verdict Guidelines

| Verdict | When to Use |
|---------|-------------|
| **Approve** | No blocking issues, minor suggestions only |
| **Request Changes** | Critical or major issues must be fixed |
| **Comment** | Questions need answers, no blocking issues |

## Severity Definitions

| Severity | Definition | Examples |
|----------|------------|----------|
| **Critical** | Security risk, data loss, crashes | SQL injection, auth bypass |
| **Major** | Significant performance, maintainability | N+1 queries, god functions |
| **Minor** | Style, naming, small improvements | Variable names, formatting |

## Time Boxing

| Section | Suggested Time |
|---------|----------------|
| Context & understanding | 5 minutes |
| Critical/security review | 10 minutes |
| Logic & performance | 15 minutes |
| Tests review | 10 minutes |
| Writing report | 10 minutes |
| **Total** | ~50 minutes |

## Quick Checks Before Submitting

- [ ] All critical issues have clear remediation
- [ ] Major issues explain the impact
- [ ] At least one positive comment included
- [ ] Questions are specific and answerable
- [ ] Verdict matches the issues found

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The code-reviewer skill is a specialized tool for performing deep code analysis. It is assessed as low risk primarily due to its inherent function of processing untrusted source code, which creates a surface for indirect prompt injection. Automated scanner alerts for the skill file and documentation URL were evaluated and determined to be likely false positives triggered by educational security examples and standard author-owned resources on GitHub Pages.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files
All 3 allowed tools
ReadGrepGlob
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "quality",
  "triggers": "code review, PR review, pull request, review code, code quality",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "security-reviewer, test-master, architecture-designer"
}

README badge

README badge for jeffallan/claude-skills/code-reviewer

Analyzes code diffs and files to identify bugs, security vulnerabilities, N+1 queries, code smells, and architectural issues, then produces a prioritized review report. Use when reviewing pull requests, auditing code quality, or checking for SQL injection, XSS, and other OWASP risks before merge.

Generated from the current SKILL.md.

What types of security vulnerabilities does this skill check for?
The skill checks for SQL injection, XSS, insecure deserialization, and applies OWASP Top 10 as a baseline. It is not a replacement for specialized security tools.
Does this skill review test coverage?
Yes. The skill validates test coverage and quality as part of the review, checking whether edge cases are covered and tests assert behavior rather than implementation.
Can I use this alongside other code review skills?
Yes. The skill complements specialized skills like security-reviewer and test-master by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
Does this skill check for N+1 query problems?
Yes. The skill specifically identifies N+1 queries as part of its performance analysis, with guidance on prefetching patterns.
What does the final output look like?
A structured report with summary, critical and major issues separated by priority, minor issues, positive feedback, questions for the author, and a final verdict (Approve / Request Changes / Comment).

Generated from the current SKILL.md. These answers refresh after source changes.