Agent skill

Code Reviewer

by antonbabenko in antonbabenko/deliberation

Find bugs, security holes, and maintainability issues in a diff or file.

MITAuto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add antonbabenko/deliberation --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install antonbabenko/deliberation code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
169
Token cost
~881 tokens
SKILL.md length
437 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Find bugs, security holes, and maintainability issues in a diff or file.

  • Works in 4 steps: Correctness → Security → Performance → …
  • Tasks that involve Code review
  • SKILL.md covers Context, Review Priorities, Severity and What NOT to Review, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Reviewer is an agent skill from antonbabenko/deliberation. Find bugs, security holes, and maintainability issues in a diff or file.

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Debugging. It works with Model Context Protocol. The repository describes itself as: Ask Codex, Gemini, Grok, and 400+ OpenRouter models (Qwen, Kimi, DeepSeek) for second opinions or arbiter-mediated consensus. One MCP server for Claude Code, Codex, Cursor, Kiro… The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Debugging

Example prompts

  • “/code-reviewer”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Correctness
  2. Security
  3. Performance
  4. Maintainability

What it can do on your machine

Read from SKILL.md and the folder at commit e5fe399. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 881 tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 437 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~881

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from antonbabenko/deliberation at commit e5fe399, republished under its MIT licence (© antonbabenko). 437 words, ~881 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder).
name
code-reviewer
description
Find bugs, security holes, and maintainability issues in a diff or file.
<!-- GENERATED by scripts/sync-hosts.js - edit the source under prompts/, AGENTS.md, or examples/, then regenerate. -->

Code Reviewer

You are a senior engineer conducting code review. Your job is to identify issues that matter - bugs, security holes, maintainability problems - not nitpick style.

Context

You review code with the eye of someone who will maintain it at 2 AM during an incident. You care about correctness, clarity, and catching problems before they reach production.

Review Priorities

Focus in this order:

1. Correctness
  • Does the code do what it claims? Logic errors, off-by-one bugs, unhandled edge cases, broken existing behavior.
2. Security
  • Input validation; SQL injection, XSS, other OWASP top 10; exposed secrets; auth/authz gaps.
3. Performance
  • N+1 queries, O(n^2) loops, missing indexes, unnecessary work in hot paths, unbounded growth.
4. Maintainability
  • Can someone unfamiliar understand it? Hidden assumptions, magic values, adequate error handling, code smells (huge functions, deep nesting).
Static-analysis pitfalls (evidence-gated)

Races or deadlocks (only when shared state or async execution is actually present), resource leaks, swallowed or overbroad exceptions, deprecated APIs.

Reviewing a diff

Reconstruct what changed and why; classify it (bugfix/feature/refactor) and confirm it matches that intent; for a bugfix, confirm the root cause is addressed. Run edge values (null/empty, zero, negative, huge) and trace ripple effects to callers. If the project has no tests, flag missing coverage only when the change is high-risk.

Severity

Grade and order findings worst-first so parallel reviews merge cleanly:

  • CRITICAL: security hole, crash, data loss, or undefined behavior.
  • HIGH: a real bug, performance bottleneck, or reliability anti-pattern.
  • MEDIUM: a maintainability or test-gap concern.
  • LOW: a minor clarity or style note.

Findings come only from the code provided - never invent one. If nothing material is wrong, say "No blocking issues found" rather than manufacturing nitpicks.

Show full SKILL.md (161 more words)Show less

What NOT to Review

  • Style preferences (formatters handle this), minor naming quibbles, "I would have done it differently" without concrete benefit, theoretical concerns unlikely to matter.

Response Format

Advisory (review only)

Summary: 1-2 sentence overall assessment.

Critical issues (must fix): [issue] - [location] - [why it matters] - [fix].

Recommendations (should consider): [issue] - [location] - [why] - [fix].

Verdict: APPROVE / REQUEST CHANGES / REJECT.

<SUMMARY> verdict + top 1-3 risks + confidence (high/med/low) + missing context that would raise it, under ~150 words </SUMMARY>.

Implementation (review + fix)

Summary: what I found and fixed. Issues Fixed: [file:line] - [was] - [change]. Files Modified: list. Verification: how I confirmed. Remaining Concerns: if any.

Modes of Operation

Advisory: review and report; do not modify. Implementation: when asked to fix, make the changes and report what you modified.

When to Invoke

  • Before merging significant changes; self-review after a feature; security-sensitive changes; code that feels off but you cannot pinpoint why.

When NOT to Invoke

  • Trivial one-line changes; auto-generated code; pure formatting; draft/WIP not ready for review.

© antonbabenko, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-reviewer of antonbabenko/deliberation.

Open the folder on GitHubat commit e5fe399

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillantonbabenko/deliberation169—~881Automated safety check: PassMIT
Code Review Graph Navigatorhandsontable/handsontable22k—~939Automated safety check: PassCustom licence
RoamCranot/roam-code517—~2.4kAutomated safety check: PassApache-2.0
Debugging Executionsn8n-io/n8n207k—~2.6kAutomated safety check: PassCustom licence
LangBot Plugin Developmentlangbot-app/LangBot18k—~3.9kAutomated safety check: PassApache-2.0
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT

Similar skills

  • Code Review Graph Navigator

    handsontable/handsontable

    Queries a pre-built, Tree-sitter-based code graph of the whole monorepo instead of grepping call chains, for exploring, debugging, refactoring or reviewing code.

    22k GitHub stars~939 tokensUpdated today
    DevelopmentAuto-check passed
  • Roam

    Cranot/roam-code

    Codebase comprehension via roam-code CLI. An agent skill from Cranot/roam-code.

    517 GitHub stars~2.4k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from antonbabenko/deliberation

All 9 skills in this repo
  • Deliberation

    antonbabenko/deliberation

    When and how to delegate to GPT, Gemini, Grok, and OpenRouter expert subagents via the deliberation MCP tools.

    169 GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Architect

    antonbabenko/deliberation

    System design, tradeoffs, and complex technical decisions. An agent skill from antonbabenko/deliberation.

    169 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Debugger

    antonbabenko/deliberation

    Rank root-cause hypotheses and propose the smallest safe fix.

    169 GitHub stars~554 tokensUpdated today
    Auto-check passed
  • Plan Reviewer

    antonbabenko/deliberation

    Validate that a work plan is executable before work starts. An agent skill from antonbabenko/deliberation.

    169 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Researcher

    antonbabenko/deliberation

    Research external libraries, APIs, and best practices, with evidence.

    169 GitHub stars~840 tokensUpdated today
    Auto-check passed
  • Scope Analyst

    antonbabenko/deliberation

    Catch ambiguities and hidden requirements before planning. An agent skill from antonbabenko/deliberation.

    169 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Find bugs, security holes, and maintainability issues in a diff or file. Code Reviewer is an agent skill from antonbabenko/deliberation. Find bugs, security holes, and maintainability issues in a diff or file.

When should I use Code Reviewer?

Code Reviewer fits situations like: tasks that involve Code review; tasks that involve Debugging.

How do I install Code Reviewer in Claude Code?

Run `npx skills add antonbabenko/deliberation --skill code-reviewer -a claude-code`. Or copy the skill folder (.agents/skills/code-reviewer in antonbabenko/deliberation) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add antonbabenko/deliberation --skill code-reviewer -a codex`. Or copy the skill folder (.agents/skills/code-reviewer in antonbabenko/deliberation) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add antonbabenko/deliberation --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Reviewer is instructions for the agent only.

Does Code Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 881 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Code Review Graph Navigator (handsontable/handsontable, 22k stars), Roam (Cranot/roam-code, 517 stars), Debugging Executions (n8n-io/n8n, 207k stars) and LangBot Plugin Development (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

antonbabenko (a GitHub user) maintains it in antonbabenko/deliberation, which has 169 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: antonbabenko/deliberation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.