Agent skill

Code Reviewer

by aiskillstore in aiskillstore/marketplace

Automated code review with security scanning, quality metrics, and best practices analysis.

No licenceAuto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add aiskillstore/marketplace --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/autumnsgrove/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
430
Token cost
~2.9k tokens
SKILL.md length
1,107 words
Files
7 (incl. scripts, references)
Skills in repo
1,108
Repo updated
First seen
Licence
None found

At a glance

Automated code review with security scanning, quality metrics, and best practices analysis.

  • Works in 6 steps: Initial Analysis → Security Review → Code Quality Analysis → …
  • Reviewing code for:
  • SKILL.md covers Purpose, When to Use This Skill, Core Review Workflow and Review Checklist, plus 5 more sections
  • Runs Python scripts from its folder; calls python, npm and yarn

What it does

Code Reviewer is an agent skill from aiskillstore/marketplace. Automated code review with security scanning, quality metrics, and best practices analysis. Use when reviewing code for: (1) Security vulnerabilities and common attack vectors, (2) Code quality issues and maintainability concerns, (3) Performance bottlenecks and optimization opportunities, (4) Best practices and design patterns, (5) Test coverage and testing strategies, (6) Documentation quality and completeness

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `README.md`, `examples/review_checklist.md` and `examples/security_patterns.md`).

It sits in Development, covering Code review, Code quality and Test coverage. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Reviewing code for:
  • Security vulnerabilities and common attack vectors
  • Code quality issues and maintainability concerns
  • Performance bottlenecks and optimization opportunities

Example prompts

  • “/code-reviewer”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Initial Analysis
  2. Security Review
  3. Code Quality Analysis
  4. Performance Review
  5. Testing Assessment
  6. Documentation Review

What it can do on your machine

Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • npm
    • yarn
    • eslint

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 2.9k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,107 words (~2,942 tokens).

“Comprehensive automated code review skill that systematically analyzes code for security issues, quality metrics, performance problems, and adherence to best practices.”

— opening of SKILL.md by aiskillstore
name
code-reviewer

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (scripts, references) in skills/autumnsgrove/code-reviewer of aiskillstore/marketplace.

  • SKILL.md
  • README.md
  • examples/review_checklist.md
  • examples/security_patterns.md
  • references/performance_guide.md
  • scripts/review_helper.py
  • skill-report.json

Open the folder on GitHubat commit ad8daf7

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillaiskillstore/marketplace430—~2.9kAutomated safety check: PassNone
Reviewing Changesbitwarden/ios695—~1.1kAutomated safety check: PassGPL-3.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Architectural Code ReviewDonchitos/Claude-Code-Game-Studios26k—~3.5kAutomated safety check: PassMIT
Brooks Reviewhyhmrright/brooks-lint1.5k1 repos~430Automated safety check: PassMIT
Code Quality ReviewStudentWeis/ropy194—~2.2kAutomated safety check: PassMIT

Similar skills

  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    695 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Architectural Code Review

    Donchitos/Claude-Code-Game-Studios

    Performs an architectural review of code against coding standards, SOLID, testability and performance, and reports no verdict when the inputs are missing.

    26k GitHub stars~3.5k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Brooks Review

    hyhmrright/brooks-lint

    PR code review that surfaces decay risks, design smells, and maintainability issues with concrete Symptom → Source → Consequence → Remedy findings, drawing on twelve classic engineering books.

    1.5k GitHub starsUsed in 1 repo~430 tokens
    DevelopmentAuto-check passed
  • Code Quality Review

    StudentWeis/ropy

    Review a code change, diff, pull request, module, or test suite for code quality, comment and documentation quality, and test quality.

    194 GitHub stars~2.2k tokensUpdated 29 days ago
    DevelopmentAuto-check passed
  • Uncle Bob Craft

    sickn33/agentic-awesome-skills

    A skill your agent uses when performing code review, writing or refactoring code, or discussing architecture; complements clean-code and does not replace project linter/formatter.

    47k GitHub starsUsed in 2 repos~2.6k tokens
    DevelopmentAuto-check passed

More from aiskillstore/marketplace

All 1,108 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 2 repos~598 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Automated code review with security scanning, quality metrics, and best practices analysis. Code Reviewer is an agent skill from aiskillstore/marketplace. Automated code review with security scanning, quality metrics, and best practices analysis.

When should I use Code Reviewer?

Code Reviewer fits situations like: reviewing code for:; security vulnerabilities and common attack vectors; code quality issues and maintainability concerns; performance bottlenecks and optimization opportunities.

How do I install Code Reviewer in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill code-reviewer -a claude-code`. Or copy the skill folder (skills/autumnsgrove/code-reviewer in aiskillstore/marketplace) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add aiskillstore/marketplace --skill code-reviewer -a codex`. Or copy the skill folder (skills/autumnsgrove/code-reviewer in aiskillstore/marketplace) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

Going by SKILL.md and its folder, Code Reviewer needs Python for the scripts in its folder and the command-line tools its instructions call (python, npm, yarn and eslint). Our summary lists: Python 3; Node.js.

Does Code Reviewer access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Reviewer use?

No licence was found for Code Reviewer or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Code Reviewer use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Reviewing Changes (bitwarden/ios, 695 stars), Code Reviewer (Yikai-Liao/symusic, 189 stars), Architectural Code Review (Donchitos/Claude-Code-Game-Studios, 26k stars) and Brooks Review (hyhmrright/brooks-lint, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.