Capability
What it can do Reads files
All 3 allowed tools
ReadGrepGlob
Other metadata
- metadata
{
"author": "https://github.com/Jeffallan",
"version": "1.1.0",
"domain": "quality",
"triggers": "code review, PR review, pull request, review code, code quality",
"role": "specialist",
"scope": "review",
"output-format": "report",
"related-skills": "security-reviewer, test-master, architecture-designer"
}
What it does
Analyzes code diffs and files to identify bugs, security vulnerabilities, N+1 queries, code smells, and architectural issues, then produces a prioritized review report. Use when reviewing pull requests, auditing code quality, or checking for SQL injection, XSS, and other OWASP risks before merge.
Generated from the current SKILL.md.
Frequently asked
What types of security vulnerabilities does this skill check for?
The skill checks for SQL injection, XSS, insecure deserialization, and applies OWASP Top 10 as a baseline. It is not a replacement for specialized security tools.
Does this skill review test coverage?
Yes. The skill validates test coverage and quality as part of the review, checking whether edge cases are covered and tests assert behavior rather than implementation.
Can I use this alongside other code review skills?
Yes. The skill complements specialized skills like security-reviewer and test-master by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
Does this skill check for N+1 query problems?
Yes. The skill specifically identifies N+1 queries as part of its performance analysis, with guidance on prefetching patterns.
What does the final output look like?
A structured report with summary, critical and major issues separated by priority, minor issues, positive feedback, questions for the author, and a final verdict (Approve / Request Changes / Comment).
Generated from the current SKILL.md. These answers refresh after source changes.