Agent skill

Engineering Code Review

by agentara in agentara/skills

A skill your agent uses when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability…

MITAuto-check passedDevelopment

Install Engineering Code Review

skills CLI
$ npx skills add agentara/skills --skill engineering-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentara/skills engineering-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentara/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/engineering/engineering-code-review .claude/skills/engineering-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
engineering-code-review
GitHub stars
600
Token cost
~2k tokens
SKILL.md length
958 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability…

  • Works in 8 steps: Establish scope. → Gather review material. → Take the broad view first. → …
  • Proposed implementations for engineering quality
  • SKILL.md covers Review Standard, Review Workflow, Review Checklist and Comment Severity, plus 2 more sections
  • Calls git

What it does

Engineering Code Review is an agent skill from agentara/skills. Use when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability, specialist risk, or approval risk. TRIGGER on "review this PR", "code review", "LGTM?", "approve?", "is this code/diff/change safe to merge/deploy?", and local diff reviews. DO NOT TRIGGER for PR descriptions, PR splitting, author review-feedback responses, or non-code safety questions unless code review is requested.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, Code review and Code quality. The repository describes itself as: Original and practical skills for AI builders. The licence is MIT.

When your agent uses it

  • Proposed implementations for engineering quality
  • Maintainability
  • Specialist risk
  • Is this code/diff/change safe to merge/deploy?

Example prompts

  • “review this PR”
  • “code review”
  • “approve?”
  • “/engineering-code-review”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Establish scope.
  2. Gather review material.
  3. Take the broad view first.
  4. Review the main design before details.
  5. Review every human-written line in your assigned scope.
  6. Check the change against the review checklist below.
  7. Check verification evidence.
  8. Make a verdict.

What it can do on your machine

Read from SKILL.md and the folder at commit 950e1bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • google.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Engineering Code Review loads about 2k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 958 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentara/skills at commit 950e1bf, republished under its MIT licence (© agentara). 958 words, ~2,048 tokens.

Download SKILL.mdSave it as .claude/skills/engineering-code-review/SKILL.md (or your agent's skills folder).
name
engineering-code-review
description
Use when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability, specialist risk, or approval risk. TRIGGER on "review this PR", "code review", "LGTM?", "approve?", "is this code/diff/change safe to merge/deploy?", and local diff reviews. DO NOT TRIGGER for PR descriptions, PR splitting, author review-feedback responses, or non-code safety questions unless code review is requested.

Engineering Code Review

Use code review to protect and improve long-term code health while still allowing useful changes to land. The standard is not perfection; the standard is that the change improves the system overall and does not introduce unacceptable risk.

Adapted from Google Engineering Practices Documentation, especially the code review overview, reviewer guide, standard of review, navigation, speed, small changes, and emergency guidance. Sources: https://google.github.io/eng-practices/, https://google.github.io/eng-practices/review/reviewer/standard.html, https://google.github.io/eng-practices/review/reviewer/navigate.html, https://google.github.io/eng-practices/review/reviewer/speed.html, https://google.github.io/eng-practices/review/developer/small-cls.html, and https://google.github.io/eng-practices/review/emergencies.html. License: CC-BY 3.0.

Review Standard

  • Favor approval when the change definitely improves the code health of the touched system, even if it is not perfect.
  • Do not approve changes that make the system worse unless this is a true emergency and the follow-up cleanup is explicit.
  • Prefer technical facts, data, existing project standards, and durable design principles over taste.
  • Treat style guides and automated formatters as authorities. Personal style preferences are nits.
  • If several designs are defensible, accept the author's preference unless it harms code health.
  • Ask for another qualified reviewer when the change touches specialized areas such as security, privacy, concurrency, accessibility, internationalization, infrastructure, data migration, or domain logic you cannot validate.

Review Workflow

  1. Establish scope.

    • Identify the diff, requested review scope, target branch, and whether you are doing a full or partial review.
    • If partial, state exactly which files, behaviors, or concerns you reviewed.
  2. Gather review material.

    • For a GitHub PR, inspect the PR description, linked issue/design docs, changed files, existing review comments, CI status, and relevant commit history before commenting.
    • For a local review, inspect git status --short, the target branch or base SHA when known, and the local diff.
    • If there is no visible diff or PR context, ask for it instead of inventing a review.
  3. Take the broad view first.

    • Read the description, issue, tests, and surrounding context.
    • Decide whether the change should exist in this codebase now.
    • If the direction is wrong, say so early and suggest the better path.
    • If the change is too large to review thoroughly, request a split or a reviewer-approved large-change plan before attempting a shallow full review.
  4. Review the main design before details.

    • Find the core files or APIs that define the change.
    • Review architecture, ownership boundaries, data flow, compatibility, and rollback risk before naming or formatting comments.
    • Send major design concerns immediately if they invalidate the rest of the review.
  5. Review every human-written line in your assigned scope.

    • Generated files, large data files, or mechanical output can be sampled when appropriate.
    • If code is too hard to understand, request simplification or clearer structure before approval.
  6. Check the change against the review checklist below.

  7. Check verification evidence.

    • Prefer existing CI and targeted tests when the user did not ask you to run commands.
    • Run local tests only when the environment and request make that appropriate; otherwise state which tests are missing or unverified.
    • Do not claim tests passed unless you saw the command output or CI result.
  8. Make a verdict.

    • APPROVE: code health improves and remaining comments are non-blocking.
    • APPROVE_WITH_COMMENTS: remaining comments are minor, optional, or the author can be trusted to handle them without another review round.
    • REQUEST_CHANGES: correctness, design, maintainability, test, documentation, or risk issues remain.
    • NEEDS_SPECIALIST: another reviewer must cover a domain you cannot responsibly assess.
Show full SKILL.md (417 more words)Show less

Review Checklist

  • Design: Does the change belong here? Is the abstraction appropriate for the current system?
  • Functionality: Does it do what the author intends, and is that behavior good for users and future developers?
  • Edge cases: Are failures, empty states, retries, idempotency, ordering, time, permissions, and concurrency considered?
  • Complexity: Is it understandable quickly? Is it solving today's known problem rather than a speculative future one?
  • Tests: Are unit, integration, or end-to-end tests appropriate for the risk? Would the tests fail if the code were broken?
  • Test quality: Are assertions meaningful, focused, deterministic, and maintainable?
  • Naming: Do names communicate purpose without being vague or noisy?
  • Comments: Do comments explain why, constraints, or non-obvious algorithms instead of restating the code?
  • Documentation: Are READMEs, API docs, migration notes, runbooks, or generated docs updated when behavior or usage changes?
  • Style and consistency: Does the change follow project conventions without mixing unrelated formatting churn into functional work?
  • Context: Does the change improve the system around it, or does it add another small piece of long-term complexity?
  • Operations: Are deployment, migration, observability, rollback, feature flags, and failure handling adequate for the change?
  • Security: Are authorization, authentication, secrets, injection, dependency, deserialization, and privilege-boundary risks handled?
  • Privacy: Does the change avoid unnecessary collection, logging, exposure, retention, or cross-boundary movement of sensitive data?
  • Accessibility: For user interfaces, are keyboard access, semantics, focus, contrast, labels, and assistive-technology behavior preserved?
  • Internationalization: Are locale, timezone, encoding, text expansion, pluralization, sorting, and translated strings handled where relevant?

Escalate to a specialist when you cannot confidently assess security, privacy, accessibility, internationalization, concurrency, infrastructure, data migration, or domain-specific correctness.

Comment Severity

  • BLOCKER: must be fixed before approval.
  • IMPORTANT: should be fixed before approval unless there is a written rationale.
  • QUESTION: answer needed before final verdict.
  • NIT: polish that must not block approval.
  • OPTIONAL: suggestion the author may decline.
  • FYI: learning or future consideration, not a requested change.

Output Format

Lead with findings, highest severity first. Use file and line references when available.

markdown
## Findings
- [BLOCKER] path/file.ext:123 - Problem. Why it matters. Required change.
- [IMPORTANT] path/file.ext:45 - Problem. Why it matters. Suggested fix.

## Open Questions
- ...

## Verdict
REQUEST_CHANGES | APPROVE_WITH_COMMENTS | APPROVE | NEEDS_SPECIALIST

## Notes
- Scope reviewed:
- Tests/commands checked:
- Follow-ups:

If no issues are found, say that clearly and still mention any unverified scope or residual risk.

Common Mistakes

  • Blocking approval on preference rather than code health.
  • Reviewing only the changed lines when the surrounding function or module makes the change unsafe.
  • Accepting complex code because the author explained it only in the review thread.
  • Letting "clean it up later" pass when the change itself introduces the complexity.
  • Requesting large rewrites late instead of flagging design problems early.
  • Delaying the author when a quick broad response would unblock useful work.

© agentara, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/engineering/engineering-code-review of agentara/skills.

Open the folder on GitHubat commit 950e1bf

Compare with similar skills

Engineering Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Engineering Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Engineering Code Review this skillagentara/skills600—~2kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review Specialist

    lhfer/claude-howto-zh-cn

    Structured code review across security, performance, code quality and maintainability, with a checklist, a finding template and two Python scripts for complexity metrics.

    2.3k GitHub stars~267 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from agentara/skills

All 20 skills in this repo
  • World Cup Predictor

    agentara/skills

    Predict FIFA World Cup matches, full tournament paths, and champion probabilities through Codex-native subagents that analyze live news, weather, injuries, markets, Polymarket, tactics, and…

    600 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Presentation Design

    agentara/skills

    Generate a premium 6-slide presentation design board as one single composite image.

    600 GitHub stars~2.4k tokensUpdated 9 days ago
    Auto-check passed
  • Publish Research Site

    agentara/skills

    Turn a thesis, proposition, trend, question, or explainer topic into a citation-backed, image-rich, interactive website and deploy it with Vercel CLI.

    600 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Portrait Clone

    agentara/skills

    Turn any n reference images (with at least one person) into one exhaustively locked, always de-slopped, JSON-only AIGC image prompt whose every variable is pinned so each generation is nearly…

    600 GitHub starsUsed in 1 repo~5k tokens
    Auto-check passed
  • Create AI image-generation prompts and image-generation workflows for torn-paper editorial collage style posters with layered ripped paper, rough typography, stamps, tape, stickers, cutout subjects…

    600 GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Article To HTML

    agentara/skills

    Render a markdown draft / any document in the conversation context into a single-file "paper proposal" HTML — serif body, monospace meta, numbered sections, inline SVG figures, callouts, tables…

    600 GitHub stars~1.7k tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about Engineering Code Review

What does Engineering Code Review do?

A skill your agent uses when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability…. Engineering Code Review is an agent skill from agentara/skills. Use when reviewing code, pull requests, patches, CLs, diffs, or proposed implementations for engineering quality, code health, design, functionality, tests, maintainability, specialist risk, or approval risk.

When should I use Engineering Code Review?

Engineering Code Review fits situations like: proposed implementations for engineering quality; maintainability; specialist risk; is this code/diff/change safe to merge/deploy?.

How do I install Engineering Code Review in Claude Code?

Run `npx skills add agentara/skills --skill engineering-code-review -a claude-code`. Or copy the skill folder (skills/engineering/engineering-code-review in agentara/skills) into .claude/skills/engineering-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Engineering Code Review in Codex?

Run `npx skills add agentara/skills --skill engineering-code-review -a codex`. Or copy the skill folder (skills/engineering/engineering-code-review in agentara/skills) into .agents/skills/engineering-code-review in your project. Codex loads it when a task matches its description.

Can I use Engineering Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentara/skills --skill engineering-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/engineering-code-review, .gemini/skills/engineering-code-review, .github/skills/engineering-code-review and .opencode/skills/engineering-code-review in your project.

What does Engineering Code Review need to run?

Going by SKILL.md and its folder, Engineering Code Review needs the command-line tools its instructions call (git).

Does Engineering Code Review access the network?

SKILL.md names 1 domain. As links in the text: google.github.io. This is read from the text; nothing was executed.

Is Engineering Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Engineering Code Review use?

Engineering Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Engineering Code Review use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Engineering Code Review?

Skills that share tags, products or a category with Engineering Code Review: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Reviewer (jewbetcha/opentrace, 116 stars) and Code Review Skill (Rain-kl/OpenFlare, 288 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Engineering Code Review?

agentara (a GitHub organization) maintains it in agentara/skills, which has 600 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on September 29, 2026.

Source: agentara/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.