Agent skill

Code Review Assistant

by ArabelaTso in ArabelaTso/Skills-4-SE

Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations.

Apache-2.0Auto-check passedDevelopment

Install Code Review Assistant

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill code-review-assistant -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE code-review-assistant --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review-assistant .claude/skills/code-review-assistant && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-assistant
GitHub stars
253
Token cost
~3k tokens
SKILL.md length
682 words
Files
1
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations.

  • Works in 10 steps: 🐛 Correctness & Bugs → 🔒 Security → ⚡ Performance → …
  • Reviewing pull requests
  • SKILL.md covers Overview, Review Categories, Review Workflow and Review Template, plus 11 more sections
  • Calls gh and git

What it does

Code Review Assistant is an agent skill from ArabelaTso/Skills-4-SE. Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations. Use when reviewing pull requests, examining code changes, evaluating new code, assessing code quality, or providing feedback on implementations. Analyzes code for correctness, security vulnerabilities, performance bottlenecks, maintainability issues, test coverage, documentation quality, and adherence to coding standards. Produces structured markdown reviews with…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Code quality and Pull requests. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Reviewing pull requests
  • Examining code changes
  • Evaluating new code
  • Assessing code quality

Example prompts

  • “/code-review-assistant”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. 🐛 Correctness & Bugs
  2. 🔒 Security
  3. ⚡ Performance
  4. 🏗️ Code Quality
  5. ✅ Testing
  6. 📚 Documentation
  7. Understand Context
  8. Read the Code
  9. Identify Issues
  10. Provide Feedback

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Assistant loads about 3k tokens when it runs. Until then it costs about 186 tokens; SKILL.md has 682 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~186
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 682 words, ~2,953 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-assistant/SKILL.md (or your agent's skills folder).
name
code-review-assistant
description
Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations. Use when reviewing pull requests, examining code changes, evaluating new code, assessing code quality, or providing feedback on implementations. Analyzes code for correctness, security vulnerabilities, performance bottlenecks, maintainability issues, test coverage, documentation quality, and adherence to coding standards. Produces structured markdown reviews with categorized findings, severity ratings, specific examples, and actionable recommendations. Triggers when users ask to review code, check pull requests, evaluate implementations, find bugs, or assess code quality.

Code Review Assistant

Overview

Perform thorough, constructive code reviews that identify issues, suggest improvements, and ensure code quality, security, and maintainability.

Review Categories

Examine code across these dimensions:

1. 🐛 Correctness & Bugs
  • Logic errors
  • Edge case handling
  • Null/undefined checks
  • Type mismatches
  • Off-by-one errors
  • Race conditions
2. 🔒 Security
  • Input validation
  • SQL injection risks
  • XSS vulnerabilities
  • Authentication/authorization flaws
  • Sensitive data exposure
  • Insecure dependencies
3. ⚡ Performance
  • Algorithm efficiency (O(n) complexity)
  • Memory leaks
  • Unnecessary computations
  • Database query optimization
  • Caching opportunities
4. 🏗️ Code Quality
  • Readability and clarity
  • Naming conventions
  • Code duplication (DRY principle)
  • Function/method length
  • Complexity (cyclomatic)
  • SOLID principles
5. ✅ Testing
  • Test coverage
  • Edge case testing
  • Unit vs integration tests
  • Test quality and clarity
  • Mock usage appropriateness
6. 📚 Documentation
  • Code comments quality
  • API documentation
  • Function/method docstrings
  • Complex logic explanation
  • README updates

Review Workflow

Step 1: Understand Context

Gather information:

  • What's the purpose of this code?
  • What problem does it solve?
  • What's the scope of changes?
  • Are there related files to consider?

For PRs:

bash
# View PR diff
gh pr diff <PR-NUMBER>

# View PR description
gh pr view <PR-NUMBER>

# See changed files
git diff --name-only main..HEAD
Step 2: Read the Code

First pass - high level:

  • Overall structure and organization
  • Naming consistency
  • Code patterns used
  • Separation of concerns

Second pass - detailed:

  • Line-by-line logic verification
  • Edge cases and error handling
  • Performance considerations
  • Security implications
Step 3: Identify Issues

Categorize findings by severity:

🔴 Critical: Must fix before merge

  • Security vulnerabilities
  • Data loss risks
  • System crashes
  • Breaking changes

🟡 Important: Should fix before merge

  • Logic bugs
  • Performance issues
  • Poor error handling
  • Missing tests for critical paths

🔵 Minor: Nice to have

  • Code style inconsistencies
  • Missing comments
  • Minor optimizations
  • Naming improvements

💡 Suggestion: Optional improvements

  • Refactoring opportunities
  • Alternative approaches
  • Future considerations
Step 4: Provide Feedback

Structure feedback constructively:

For each issue:

  1. Location: File and line number
  2. Issue: What's wrong
  3. Impact: Why it matters
  4. Recommendation: How to fix
  5. Example: Code suggestion if helpful

Tone guidelines:

  • Be specific and objective
  • Focus on code, not the person
  • Explain the "why" behind suggestions
  • Acknowledge good practices
  • Ask questions for clarification when unsure

Review Template

markdown
# Code Review: [PR Title / Code Description]

## Summary
- **Files Reviewed:** X files, Y lines changed
- **Overall Assessment:** [Approve/Request Changes/Comment]
- **Critical Issues:** N
- **Important Issues:** M
- **Minor Issues:** K

---

## 🔴 Critical Issues

### Issue 1: [Title]
**Location:** `path/to/file.py:42`

**Problem:**
[Clear description of the issue]

**Impact:**
[Why this is critical - security, data loss, crashes, etc.]

**Recommendation:**
[Specific fix needed]

**Example:**
```python
# Current (problematic)
user_input = request.GET['id']
query = f"SELECT * FROM users WHERE id = {user_input}"

# Suggested (fixed)
user_input = request.GET.get('id')
if user_input and user_input.isdigit():
    query = "SELECT * FROM users WHERE id = %s"
    cursor.execute(query, (user_input,))

🟡 Important Issues

Issue 2: [Title]

[Same structure as above]


🔵 Minor Issues

Issue 3: [Title]

[Shorter format acceptable for minor issues]


💡 Suggestions

  • [Optional improvement 1]
  • [Optional improvement 2]

✅ Positive Observations

  • [Good practice 1]
  • [Well-implemented feature]

Questions for Author

  • [Clarifying question about design decision]
  • [Question about intended behavior]

Recommendations

  1. Fix all critical issues before merge
  2. Address important issues or provide justification
  3. Consider minor improvements where feasible
  4. Add tests for edge cases X, Y, Z

Overall: [Approve with suggestions / Request changes / Needs discussion]


## Common Issues by Language

### Python
```python
# ❌ Mutable default argument
def append_to(element, to=[]):  # Bug: to persists across calls
    to.append(element)
    return to

# ✅ Correct
def append_to(element, to=None):
    if to is None:
        to = []
    to.append(element)
    return to

# ❌ Catching bare exceptions
try:
    risky_operation()
except:  # Too broad, masks errors
    pass

# ✅ Specific exception handling
try:
    risky_operation()
except ValueError as e:
    logger.error(f"Invalid value: {e}")
    raise

# ❌ String concatenation in loops
result = ""
for item in items:
    result += str(item)  # Creates new string each iteration

# ✅ Use join
result = "".join(str(item) for item in items)
JavaScript/TypeScript
javascript
// ❌ == instead of ===
if (value == null) {  // Loose equality
    // ...
}

// ✅ Strict equality
if (value === null || value === undefined) {
    // ...
}

// ❌ Unhandled promise rejection
fetchData().then(data => process(data));

// ✅ Error handling
fetchData()
    .then(data => process(data))
    .catch(error => console.error('Error:', error));

// ❌ Variable shadowing
const name = "Global";
function greet() {
    const name = "Local";  // Shadows outer name
    console.log(name);
}

// ✅ Distinct names
const globalName = "Global";
function greet() {
    const userName = "User";
    console.log(userName);
}
Java
java
// ❌ Resource leak
public void readFile(String path) {
    FileInputStream fis = new FileInputStream(path);
    // ... use fis
    // Missing close(), leaks file handle
}

// ✅ Try-with-resources
public void readFile(String path) {
    try (FileInputStream fis = new FileInputStream(path)) {
        // ... use fis
    } // Automatically closed
}

// ❌ Using == for String comparison
if (str == "value") {  // Compares references
    // ...
}

// ✅ Use equals()
if ("value".equals(str)) {  // Compares content, null-safe
    // ...
}
Show full SKILL.md (278 more words)Show less

Security Checklist

Input Validation:

  • ✅ All user inputs validated?
  • ✅ Whitelist validation used?
  • ✅ Input length limits enforced?
  • ✅ Special characters escaped?

SQL Injection:

  • ✅ Prepared statements/parameterized queries used?
  • ✅ No string concatenation for SQL?
  • ✅ ORM used correctly?

XSS Prevention:

  • ✅ Output encoding applied?
  • ✅ HTML sanitization for user content?
  • ✅ Content Security Policy headers set?

Authentication/Authorization:

  • ✅ Authentication required for sensitive operations?
  • ✅ Authorization checks present?
  • ✅ Session management secure?
  • ✅ Password hashing used (not plain text)?

Data Protection:

  • ✅ Sensitive data encrypted at rest?
  • ✅ Sensitive data encrypted in transit (HTTPS)?
  • ✅ No secrets in code/logs?
  • ✅ Proper file permissions set?

Performance Review Points

Algorithm Complexity:

  • Nested loops: O(n²) or worse?
  • Can use more efficient algorithm?
  • Unnecessary iterations?

Database:

  • N+1 query problem?
  • Missing indexes?
  • Fetching unnecessary data?
  • Could use batch operations?

Caching:

  • Repeated expensive computations?
  • Could cache results?
  • Cache invalidation handled?

Memory:

  • Large objects kept in memory?
  • Memory leaks possible?
  • Could stream instead of load all?

Code Quality Standards

Function/Method Size:

  • ✅ Functions under 50 lines (guideline)
  • ✅ Single responsibility per function
  • ✅ Clear, descriptive names

Complexity:

  • ✅ Cyclomatic complexity < 10 (guideline)
  • ✅ Nesting depth reasonable (< 4 levels)
  • ✅ Complex logic well-commented

DRY (Don't Repeat Yourself):

  • ✅ No code duplication
  • ✅ Common logic extracted to functions
  • ✅ Constants defined once

Naming:

  • ✅ Variables: noun phrases (userData, itemCount)
  • ✅ Functions: verb phrases (getUserData, calculateTotal)
  • ✅ Booleans: question form (isValid, hasPermission)
  • ✅ Classes: PascalCase nouns (UserService, DataProcessor)

Testing Review

Coverage:

  • ✅ New code has tests?
  • ✅ Critical paths tested?
  • ✅ Edge cases covered?

Test Quality:

  • ✅ Tests are independent?
  • ✅ Clear test names describing what's tested?
  • ✅ Arrange-Act-Assert pattern followed?
  • ✅ No test interdependencies?

Test Types:

  • ✅ Unit tests for business logic?
  • ✅ Integration tests for API endpoints?
  • ✅ Error cases tested?

Example Reviews

Example 1: Security Issue
markdown
### 🔴 Critical: SQL Injection Vulnerability
**Location:** `api/users.py:45`

**Problem:**
User input is directly interpolated into SQL query without sanitization.

**Impact:**
Attacker could execute arbitrary SQL commands, leading to data breach or data loss.

**Code:**
```python
# Current (VULNERABLE)
def get_user(user_id):
    query = f"SELECT * FROM users WHERE id = {user_id}"
    return db.execute(query)

Recommendation: Use parameterized queries to prevent SQL injection.

Fix:

python
def get_user(user_id):
    query = "SELECT * FROM users WHERE id = %s"
    return db.execute(query, (user_id,))

### Example 2: Performance Issue

```markdown
### 🟡 Important: N+1 Query Problem
**Location:** `services/order_service.py:78-82`

**Problem:**
Loading users in a loop creates N+1 database queries.

**Impact:**
For 100 orders, this creates 101 queries (1 + 100), severely impacting performance.

**Code:**
```python
# Current (inefficient)
orders = Order.query.all()
for order in orders:
    order.user = User.query.get(order.user_id)  # N queries

Recommendation: Use eager loading or a single query with join.

Fix:

python
# Option 1: Eager loading
orders = Order.query.options(joinedload(Order.user)).all()

# Option 2: Separate query
orders = Order.query.all()
user_ids = [o.user_id for o in orders]
users = {u.id: u for u in User.query.filter(User.id.in_(user_ids)).all()}
for order in orders:
    order.user = users[order.user_id]

## Tips for Effective Reviews

**Be constructive:**
- Explain why, not just what
- Suggest solutions, don't just criticize
- Acknowledge good code

**Be specific:**
- Point to exact lines
- Provide code examples
- Quantify impact when possible

**Prioritize:**
- Fix critical issues first
- Don't nitpick minor style issues
- Focus on what matters

**Ask questions:**
- "Could you explain the reasoning behind...?"
- "Have you considered...?"
- "What happens if...?"

**Provide context:**
- Link to documentation
- Reference coding standards
- Cite security best practices

**Be timely:**
- Review promptly
- Don't block unnecessarily
- Iterate in conversations

This skill provides comprehensive code review guidance. Save it to the current path when ready to package.

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-review-assistant of ArabelaTso/Skills-4-SE.

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Code Review Assistant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Assistant compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Assistant this skillArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Quality ReviewStudentWeis/ropy194—~2.2kAutomated safety check: PassMIT
Reviewing Changesbitwarden/ios695—~1.1kAutomated safety check: PassGPL-3.0
Aidd Reviewparalleldrive/aidd384—~945Automated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Quality Review

    StudentWeis/ropy

    Review a code change, diff, pull request, module, or test suite for code quality, comment and documentation quality, and test quality.

    194 GitHub stars~2.2k tokensUpdated 29 days ago
    DevelopmentAuto-check passed
  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    695 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Aidd Review

    paralleldrive/aidd

    Conduct a thorough code review focusing on code quality, best practices, security, test coverage, and adherence to project standards and functional requirements.

    384 GitHub stars~945 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Code Review Assistant

What does Code Review Assistant do?

Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations. Code Review Assistant is an agent skill from ArabelaTso/Skills-4-SE. Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations.

When should I use Code Review Assistant?

Code Review Assistant fits situations like: reviewing pull requests; examining code changes; evaluating new code; assessing code quality.

How do I install Code Review Assistant in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill code-review-assistant -a claude-code`. Or copy the skill folder (skills/code-review-assistant in ArabelaTso/Skills-4-SE) into .claude/skills/code-review-assistant in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Assistant in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill code-review-assistant -a codex`. Or copy the skill folder (skills/code-review-assistant in ArabelaTso/Skills-4-SE) into .agents/skills/code-review-assistant in your project. Codex loads it when a task matches its description.

Can I use Code Review Assistant in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill code-review-assistant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-assistant, .gemini/skills/code-review-assistant, .github/skills/code-review-assistant and .opencode/skills/code-review-assistant in your project.

What does Code Review Assistant need to run?

Going by SKILL.md and its folder, Code Review Assistant needs the command-line tools its instructions call (gh and git). Our summary lists: Python 3.

Does Code Review Assistant access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review Assistant safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Assistant use?

Code Review Assistant is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Assistant use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Assistant?

Skills that share tags, products or a category with Code Review Assistant: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Quality Review (StudentWeis/ropy, 194 stars), Reviewing Changes (bitwarden/ios, 695 stars) and Aidd Review (paralleldrive/aidd, 384 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Assistant?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.