Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

MITAuto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-code-tresor code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
777
Token cost
~1.8k tokens
SKILL.md length
514 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

  • Works in 5 steps: You write code → I auto-analyze (instant feedback) → I flag: "⚠️ Potential issue on line 42" → …
  • Quality mentions
  • SKILL.md covers When I Activate, What I Check, Relationship with… and Analysis Examples, plus 10 more sections
  • Calls claude

What it does

Code Reviewer is an agent skill from alirezarezvani/claude-code-tresor. Automatic code quality and best practices analysis. Use proactively when files are modified, saved, or committed. Analyzes code style, patterns, potential bugs, and security basics. Triggers on file changes, git diff, code edits, quality mentions.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Development, covering Code review, Code quality and Subagents. It works with Git and TypeScript. The repository describes itself as: A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and prompts that supercharge your development workflow. The licence is MIT.

When your agent uses it

  • Quality mentions
  • Tasks that involve Code review
  • Tasks that involve Code quality

Example prompts

  • “/code-reviewer”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): Read, Grep, Glob

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. You write code
  2. I auto-analyze (instant feedback)
  3. I flag: "⚠️ Potential issue on line 42"
  4. You want details → Invoke @code-reviewer sub-agent
  5. Sub-agent provides comprehensive analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 4b68050. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 1.8k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 514 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-code-tresor at commit 4b68050, republished under its MIT licence (© alirezarezvani). 514 words, ~1,799 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-reviewer
description
Automatic code quality and best practices analysis. Use proactively when files are modified, saved, or committed. Analyzes code style, patterns, potential bugs, and security basics. Triggers on file changes, git diff, code edits, quality mentions.
allowed-tools
Read, Grep, Glob

Code Reviewer Skill

Lightweight automatic code quality checks while you code.

When I Activate

  • ✅ Files modified or saved
  • ✅ Git diff run
  • ✅ Code mentioned in conversation
  • ✅ User asks about code quality
  • ✅ Before commits

What I Check

Quick Wins
  • Code style and formatting issues
  • Common anti-patterns
  • Obvious bugs (null checks, undefined references)
  • Basic security patterns (hardcoded secrets)
  • Import/export issues
  • Unused variables and functions
What I Don't Do
  • Deep architectural review → Use @code-reviewer sub-agent
  • Comprehensive security audit → Use security-auditor skill
  • Performance profiling → Use @architect sub-agent
  • Full refactoring plans → Use @code-reviewer sub-agent

Relationship with @code-reviewer Sub-Agent

Me (Skill): Fast, lightweight, real-time feedback @code-reviewer (Sub-Agent): Deep analysis with examples and strategy

Workflow
  1. You write code
  2. I auto-analyze (instant feedback)
  3. I flag: "⚠️ Potential issue on line 42"
  4. You want details → Invoke @code-reviewer sub-agent
  5. Sub-agent provides comprehensive analysis

Analysis Examples

JavaScript/TypeScript
javascript
// You write this code:
function getUser(id) {
  return db.query(`SELECT * FROM users WHERE id = ${id}`);
}

// I immediately flag:
// 🚨 Line 2: SQL injection vulnerability
// 💡 Use parameterized queries
React
javascript
// You write:
function UserList({ users }) {
  return users.map(user => <User data={user} />);
}

// I flag:
// ⚠️ Missing key prop in list rendering (line 2)
// 💡 Add key={user.id} to User component
Python
python
# You write:
def process_data(data):
    return data['user']['profile']['name']

# I flag:
# ⚠️ Potential KeyError - no safety checks (line 2)
# 💡 Use .get() or add try/except

Check Categories

Code Style
  • Inconsistent naming conventions
  • Missing semicolons (JavaScript)
  • Improper indentation
  • Long functions (>50 lines)
  • Magic numbers
Potential Bugs
  • Null/undefined access without checks
  • Array access without bounds checking
  • Type mismatches (TypeScript)
  • Unreachable code
  • Infinite loops
Basic Security
  • Hardcoded API keys or secrets
  • SQL injection patterns
  • eval() or exec() usage
  • Insecure random number generation
  • Missing input validation
Best Practices
  • Missing error handling
  • Console.log in production code
  • Commented-out code blocks
  • TODO comments without context
  • Overly complex conditions

Output Format

🤖 code-reviewer skill:
  [Severity] Issue description (file:line)
  💡 Quick fix suggestion
  📖 Reference: [link to learn more]
Severity Levels
  • 🚨 CRITICAL: Must fix (security, data loss)
  • ⚠️ HIGH: Should fix (bugs, performance)
  • 📋 MEDIUM: Consider fixing (maintainability)
  • 💡 LOW: Nice to have (style, readability)

When to Invoke Sub-Agent

After I flag issues, invoke @code-reviewer sub-agent for:

  • Detailed explanation of the issue
  • Multiple fix alternatives with pros/cons
  • Architectural recommendations
  • Refactoring strategies
  • Best practice guidelines

Example:

Me: "⚠️ Potential N+1 query detected"
You: "@code-reviewer explain the N+1 issue and show optimal solution"
Sub-agent: [Provides comprehensive analysis with examples]

Sandboxing Compatibility

Works without sandboxing: ✅ Yes (default, recommended for learning) Works with sandboxing: ✅ Yes (no special configuration needed)

  • Filesystem: Read-only access to project files
  • Network: None required
  • Configuration: None required
Show full SKILL.md (220 more words)Show less

Customization

Want different checks or patterns?

  1. Copy this skill:

    bash
    cp -r ~/.claude/skills/development/code-reviewer ~/.claude/skills/development/my-code-reviewer
  2. Edit SKILL.md:

    • Modify description to adjust triggers
    • Customize check categories
    • Add language-specific patterns
  3. Restart Claude Code:

    bash
    claude --restart

See ../../TEMPLATES.md for customization guide.

Examples in Action

TypeScript Function
typescript
// Before:
async function fetchUsers(ids) {
  const users = [];
  for (let id of ids) {
    const user = await User.findById(id);  // N+1 query!
    users.push(user);
  }
  return users;
}

// I flag:
// ⚠️ N+1 query pattern detected (line 4)
// 💡 Use User.findByIds(ids) for batch loading

// After fix:
async function fetchUsers(ids) {
  return await User.findByIds(ids);
}
React Component
jsx
// Before:
function UserCard({ user }) {
  const [data, setData] = useState();

  useEffect(() => {
    fetch(`/api/users/${user.id}`)
      .then(res => res.json())
      .then(setData);
  }, []);  // Missing dependency!

  return <div>{data?.name}</div>;
}

// I flag:
// ⚠️ useEffect dependency array incomplete (line 6)
// 💡 Add user.id to dependencies: [user.id]

// After fix:
useEffect(() => {
  fetch(`/api/users/${user.id}`)
    .then(res => res.json())
    .then(setData);
}, [user.id]);

Integration with /review Command

The /review command aggregates my findings with deep sub-agent analysis:

bash
/review --scope staged --checks all

# Command workflow:
# 1. Collects my automatic findings
# 2. Invokes @code-reviewer sub-agent for deep analysis
# 3. Invokes @security-auditor sub-agent
# 4. Generates comprehensive report with priorities

Performance Impact

  • Activation time: < 100ms
  • Analysis time: < 1 second per file
  • Memory usage: Minimal (read-only)
  • Background operation: Non-blocking

This skill operates asynchronously and won't slow down your coding workflow.

Language Support

Fully Supported
  • JavaScript/TypeScript (ES6+, React, Node.js)
  • Python (3.8+, Django, FastAPI)
  • Java (Spring Boot patterns)
  • Go (standard patterns)
Partial Support
  • Ruby, PHP, C#, Rust
  • Framework-agnostic patterns apply

Want to add language-specific patterns? See customization guide above.

Tips for Best Results

  1. Write code first, then review - Let me catch issues as you go
  2. Don't ignore warnings - Each flagged issue is worth reviewing
  3. Use sub-agent for learning - Invoke @code-reviewer to understand "why"
  4. Customize for your stack - Add project-specific patterns
  5. Combine with /review - Use command for comprehensive pre-commit checks
  • security-auditor skill: Deeper security vulnerability scanning
  • test-generator skill: Auto-suggest tests for your code
  • @code-reviewer sub-agent: Comprehensive code review with examples
  • /review command: Full workflow with multiple agents

Learn More

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/development/code-reviewer of alirezarezvani/claude-code-tresor.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 4b68050

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillalirezarezvani/claude-code-tresor777—~1.8kAutomated safety check: PassMIT
Review And Simplify ChangesDimillian/Skills4k—~2kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Hunk Extension Authoring Mapmodem-dev/hunk9.5k—~5.8kAutomated safety check: PassMIT

Similar skills

  • Review a git diff or explicit file scope for reuse, code quality, efficiency, clarity, and standards issues, then optionally apply safe Codex-driven fixes.

    4k GitHub stars~2k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Maps the hunkdiff/extension API for building Hunk terminal diff viewer extensions: panes, file views, commands, dialogs, themes, VCS backends and lifecycle events.

    9.5k GitHub stars~5.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes

More from alirezarezvani/claude-code-tresor

  • API Documenter

    alirezarezvani/claude-code-tresor

    Auto-generate API documentation from code and comments. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check: notes
  • Git Commit Helper

    alirezarezvani/claude-code-tresor

    Generate conventional commit messages automatically. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check: notes
  • Readme Updater

    alirezarezvani/claude-code-tresor

    Keep README files current with project changes. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Test Generator

    alirezarezvani/claude-code-tresor

    Automatically suggest tests for new functions and components.

    777 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed
  • Secret Scanner

    alirezarezvani/claude-code-tresor

    Detect exposed secrets, API keys, credentials, and tokens in code.

    777 GitHub stars~1.4k tokensUpdated 3 mo ago
    Auto-check: warnings

Works with

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor. Code Reviewer is an agent skill from alirezarezvani/claude-code-tresor. Automatic code quality and best practices analysis.

When should I use Code Reviewer?

Code Reviewer fits situations like: quality mentions; tasks that involve Code review; tasks that involve Code quality.

How do I install Code Reviewer in Claude Code?

Run `npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer -a claude-code`. Or copy the skill folder (skills/development/code-reviewer in alirezarezvani/claude-code-tresor) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer -a codex`. Or copy the skill folder (skills/development/code-reviewer in alirezarezvani/claude-code-tresor) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

Going by SKILL.md and its folder, Code Reviewer needs the command-line tools its instructions call (claude). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Grep, Glob.

Does Code Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Review And Simplify Changes (Dimillian/Skills, 4k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars) and Code Reviewer (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-code-tresor, which has 777 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 3, 2026.

Source: alirezarezvani/claude-code-tresor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.