All skills
jeffallan avatar

/code-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/code-reviewer

This session only. Nothing lands on disk.

referencesreview-checklist.md

≈622 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Review Checklist

Comprehensive Review Checklist

Category Key Questions
Design Does it fit existing patterns? Right abstraction level?
Logic Edge cases handled? Race conditions? Null checks?
Security Input validated? Auth checked? Secrets safe?
Performance N+1 queries? Memory leaks? Caching needed?
Tests Adequate coverage? Edge cases tested? Mocks appropriate?
Naming Clear, consistent, intention-revealing?
Error Handling Errors caught? Meaningful messages? Logged?
Documentation Public APIs documented? Complex logic explained?

Review Process

1. Context (5 min)

  • Read PR description
  • Understand the problem being solved
  • Check linked issues/tickets
  • Note expected changes

2. Structure (10 min)

  • Review file organization
  • Check architectural fit
  • Verify design patterns used
  • Note any breaking changes

3. Code Details (20 min)

  • Review logic correctness
  • Check edge cases
  • Verify error handling
  • Look for security issues
  • Check performance concerns
  • Review naming clarity

4. Tests (10 min)

  • Verify test coverage
  • Check test quality
  • Look for edge case tests
  • Ensure mocks are appropriate

5. Final Pass (5 min)

  • Note positive patterns
  • Prioritize feedback
  • Write summary

Category Deep Dive

Design Questions

  • Does this change belong in this file/module?
  • Is the abstraction level appropriate?
  • Could this be simpler?
  • Does it follow existing patterns?
  • Is it extensible without modification?

Logic Questions

  • What happens with null/undefined inputs?
  • Are boundary conditions handled?
  • Could there be race conditions?
  • Is the order of operations correct?
  • Are all code paths tested?

Security Questions

  • Is all user input validated?
  • Are SQL queries parameterized?
  • Is output properly encoded?
  • Are secrets handled safely?
  • Is authentication checked?
  • Is authorization enforced?

Performance Questions

  • Are there N+1 query patterns?
  • Is data fetched efficiently?
  • Are expensive operations cached?
  • Could this cause memory leaks?
  • Is pagination implemented?

Quick Reference

Review Focus Time %
Context & PR description 10%
Architecture & design 20%
Code logic & details 40%
Tests & coverage 20%
Final review & summary 10%

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The code-reviewer skill is a specialized tool for performing deep code analysis. It is assessed as low risk primarily due to its inherent function of processing untrusted source code, which creates a surface for indirect prompt injection. Automated scanner alerts for the skill file and documentation URL were evaluated and determined to be likely false positives triggered by educational security examples and standard author-owned resources on GitHub Pages.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files
All 3 allowed tools
ReadGrepGlob
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "quality",
  "triggers": "code review, PR review, pull request, review code, code quality",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "security-reviewer, test-master, architecture-designer"
}

README badge

README badge for jeffallan/claude-skills/code-reviewer

Analyzes code diffs and files to identify bugs, security vulnerabilities, N+1 queries, code smells, and architectural issues, then produces a prioritized review report. Use when reviewing pull requests, auditing code quality, or checking for SQL injection, XSS, and other OWASP risks before merge.

Generated from the current SKILL.md.

What types of security vulnerabilities does this skill check for?
The skill checks for SQL injection, XSS, insecure deserialization, and applies OWASP Top 10 as a baseline. It is not a replacement for specialized security tools.
Does this skill review test coverage?
Yes. The skill validates test coverage and quality as part of the review, checking whether edge cases are covered and tests assert behavior rather than implementation.
Can I use this alongside other code review skills?
Yes. The skill complements specialized skills like security-reviewer and test-master by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
Does this skill check for N+1 query problems?
Yes. The skill specifically identifies N+1 queries as part of its performance analysis, with guidance on prefetching patterns.
What does the final output look like?
A structured report with summary, critical and major issues separated by priority, minor issues, positive feedback, questions for the author, and a final verdict (Approve / Request Changes / Comment).

Generated from the current SKILL.md. These answers refresh after source changes.