Code Review Skill
Rain-kl/OpenFlare
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awesome-skills/code-review-skill code-review-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .claude/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awesome-skills/code-review-skill code-review-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .agents/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awesome-skills/code-review-skill code-review-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .cursor/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awesome-skills/code-review-skill code-review-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .gemini/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awesome-skills/code-review-skill code-review-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .github/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awesome-skills/code-review-skill --skill code-review-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awesome-skills/code-review-skill code-review-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-skill" agent skill from https://github.com/awesome-skills/code-review-skill/tree/main into .opencode/skills/code-review-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-skillProvides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
Code Review Skill is an agent skill from awesome-skills/code-review-skill. Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart, Flutter, NestJS, C/C++, Zig, CSS/Less/Sass, Qt, and more. Covers architecture review, performance review, security audit, code quality anti-patterns, and common bugs across all ecosystems. Use when: reviewing pull requests, conducting PR reviews, code review, reviewing code changes, establishing review standards…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 54 other files, including scripts and assets (for example `.hive/PROTOCOL.md`, `.hive/memory.md` and `.hive/tasks.md`).
It sits in Development, covering Backend development, Code review and Software architecture. It works with Java, Python, Angular and Django. The repository describes itself as: A comprehensive code review skill for Claude Code, covering React 19, Vue 3, Rust, TypeScript, TanStack Query v5, and more. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4850184. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashWebFetchFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
gitpythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Skill loads about 2.8k tokens when it runs. Until then it costs about 168 tokens; SKILL.md has 1,000 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, WebFetchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from awesome-skills/code-review-skill at commit 4850184, republished under its MIT licence (© awesome-skills). 1,000 words, ~2,828 tokens.
.claude/skills/code-review-skill/SKILL.md (or your agent's skills folder). This skill also uses 51 other files; get the full folder from GitHub.Transform code reviews from gatekeeping to knowledge sharing through constructive feedback, systematic analysis, and collaborative improvement.
Goals of Code Review:
Not the Goals:
Good Feedback is:
❌ Bad: "This is wrong."
✅ Good: "This could cause a race condition when multiple users
access simultaneously. Consider using a mutex here."
❌ Bad: "Why didn't you use X pattern?"
✅ Good: "Have you considered the Repository pattern? It would
make this easier to test. Here's an example: [link]"
❌ Bad: "Rename this variable."
✅ Good: "[nit] Consider `userCount` instead of `uc` for
clarity. Not blocking if you prefer to keep it."What to Review:
What Not to Review Manually:
Before diving into code, understand:
For large diffs, pipe the diff through
scripts/pr-analyzer.py(git diff main...HEAD | python scripts/pr-analyzer.py) to triage complexity and get a suggested review approach before reading.
For each file, check:
Use checklists for consistent reviews. See Security Review Guide for comprehensive security checklist.
Instead of stating problems, ask questions:
❌ "This will fail if the list is empty."
✅ "What happens if `items` is an empty array?"
❌ "You need error handling here."
✅ "How should this behave if the API call fails?"Use collaborative language:
❌ "You must change this to use async/await"
✅ "Suggestion: async/await might make this more readable. What do you think?"
❌ "Extract this into a function"
✅ "This logic appears in 3 places. Would it make sense to extract it?"Use labels to indicate priority:
[blocking] - Must fix before merge[important] - Should fix, discuss if disagree[nit] - Nice to have, not blocking[suggestion] - Alternative approach to consider[learning] - Educational comment, no action needed[praise] - Good work, keep it up!Severity levels: 🔴 / 🟡 / 🟢 are the three severity tiers used as the standard across all guides in this skill — 🔴 blocks the merge, 🟡 should be addressed, 🟢 is optional. The remaining markers (💡 / 📚 / 🎉) are non-blocking annotations.
根据审查的代码语言,查阅对应的详细指南:
| Language/Framework | Reference File | Key Topics |
|---|---|---|
| React | React Guide | Hooks, useEffect, React 19 Actions, RSC, Suspense, TanStack Query v5 |
| Vue 3 | Vue Guide | Composition API, 响应性系统, Props/Emits, Watchers, Composables |
| Angular 17+ | Angular Guide | Signals, Standalone, RxJS, Zoneless, 模板优化, 测试, 路由守卫, HttpInterceptor |
| Rust | Rust Guide | 所有权/借用, Unsafe 审查, 异步代码, 取消安全性, 错误处理 |
| TypeScript | TypeScript Guide | 类型安全, async/await, 不可变性, 测试, 模块解析, TS 5.x |
| Python | Python Guide | 可变默认参数, 异常处理, 类属性 |
| Django / DRF | Django Guide | 安全审查, N+1 查询, Serializer 反模式, ViewSet, 异步视图 |
| FastAPI | FastAPI Guide | Depends, Pydantic v2 validation, async correctness, sessions/N+1, auth vs authorization, test-driven verification |
| Java | Java Guide | Java 17/21 新特性, Spring Boot 3, 虚拟线程, Stream/Optional |
| Java 8 / Legacy | Java 8 Guide | Java 8, Spring Boot 2, javax.*, Stream/Optional, java.time, CompletableFuture |
| PHP | PHP Guide | PHP 8.x type system, PDO, security review, Composer, PHPUnit/PHPStan |
| Ruby / Rails | Ruby Guide | Ruby semantics, Rails 8, Active Record, Active Job, security, testing |
| C# / .NET | C# Guide | C# 12 特性, 异步编程, EF Core 性能, ASP.NET Core, LINQ |
| Go | Go Guide | 错误处理, goroutine/channel, context, 接口设计 |
| Kotlin / Android | Kotlin Guide | 协程, Flow, Jetpack Compose, 空安全, 内存泄漏, 架构模式 |
| Swift / SwiftUI | Swift Guide | Optionals, Swift Concurrency, Sendable/actors, SwiftUI property wrappers, value vs reference types, API design |
| Dart / Flutter | Dart Guide | Widget rebuilds, const constructors, null safety, isolates, async in build, Riverpod/Bloc, platform channels, keys, disposal |
| NestJS | NestJS Guide | 依赖注入, 分层架构, DTO 验证, Guard/Interceptor, 循环依赖 |
| Svelte / SvelteKit | Svelte Guide | Runes, Load 函数, Form Actions, Store 迁移, SSR/CSR 边界 |
| C | C Guide | 指针/缓冲区, 内存安全, UB, 安全编码, 可移植性, 测试 |
| C++ | C++ Guide | RAII, 智能指针, C++20/23, constexpr, 测试 |
| Zig | Zig Guide | Allocators, error unions, defer/errdefer, comptime, C interop |
| CSS/Less/Sass | CSS Guide | 变量规范, !important, 性能优化, 响应式, 兼容性 |
| Qt | Qt Guide | 对象模型, 信号/槽, Model/View, QML, Qt6 迁移, 测试 |
Language-agnostic patterns applicable to all code reviews:
| Topic | Reference File | Key Topics |
|---|---|---|
| Architecture Review | Architecture Review Guide | SOLID, anti-patterns, coupling/cohesion, dependency direction |
| Performance Review | Performance Review Guide | Web Vitals, N+1, algorithm complexity, memory leaks, caching |
| Security Review | Security Review Guide | SQLi, XSS, CSRF, SSRF, IDOR, 命令注入, 跨语言示例 |
| Universal Quality | Universal Quality Guide | Reuse audit, parameter sprawl, leaky abstractions, nested conditionals, stringly-typed code, TOCTOU, no-op updates, redundant state |
| Common Bugs | Common Bugs Checklist | Language-specific bug patterns, common pitfalls |
| SQL Injection Prevention | SQL Injection Guide | Parameterized queries, ORM safety, 6 languages, dynamic identifiers, detection |
| XSS Prevention | XSS Prevention Guide | Output encoding, CSP, 5 frameworks, input validation vs encoding, detection |
| N+1 Queries | N+1 Queries Guide | Eager loading, batch fetching, DataLoader, 5 languages, detection |
| Error Handling | Error Handling Guide | Fail fast, error hierarchy, 7 languages, anti-patterns, logging |
| Async & Concurrency | Concurrency Guide | Goroutines, async/await, actors, structured concurrency, 7 languages |
| Review Best Practices | Code Review Best Practices | Communication, reviewer mindset, giving feedback, severity labels |
© awesome-skills, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 51 other files (scripts, assets) in the repository root of awesome-skills/code-review-skill.
Open the folder on GitHubat commit 4850184
Code Review Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Skill this skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Code Review SkillRain-kl/OpenFlare | 288 | — | ~2.3k | Automated safety check: Notes | MIT | |
| Code Review Excellenceandrew-yangy/gru-ai | 155 | — | ~1.7k | Automated safety check: Notes | MIT | |
| Code Revieweralirezarezvani/claude-skills | 28k | 1 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Senior Fullstackborghei/Claude-Skills | 886 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Code Reviewerrevfactory/harness-100 | 1.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
Rain-kl/OpenFlare
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.
andrew-yangy/gru-ai
Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.
alirezarezvani/claude-skills
Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C, .NET, Java, C, C++, Rust, Ruby, PHP, and Dart/Flutter.
borghei/Claude-Skills
Fullstack development toolkit with project scaffolding for Next.js/FastAPI/MERN/Django stacks and code quality analysis.
revfactory/harness-100
Full pipeline for automated code review. An agent skill from revfactory/harness-100.
alirezarezvani/claude-skills
A skill your agent uses when the user says 'build me an app', 'create a project from this spec', 'scaffold a new repo', 'generate a starter', 'turn this idea into code', 'bootstrap a project', 'I…
Categories
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…. Code Review Skill is an agent skill from awesome-skills/code-review-skill.NET, Kotlin, Swift, Dart, Flutter, NestJS, C/C++, Zig, CSS/Less/Sass, Qt, and more.
Code Review Skill fits situations like: : reviewing pull requests; conducting PR reviews; reviewing code changes; establishing review standards.
Run `npx skills add awesome-skills/code-review-skill --skill code-review-skill -a claude-code`. Or copy the skill folder (the awesome-skills/code-review-skill repository) into .claude/skills/code-review-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awesome-skills/code-review-skill --skill code-review-skill -a codex`. Or copy the skill folder (the awesome-skills/code-review-skill repository) into .agents/skills/code-review-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awesome-skills/code-review-skill --skill code-review-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-skill, .gemini/skills/code-review-skill, .github/skills/code-review-skill and .opencode/skills/code-review-skill in your project.
Going by SKILL.md and its folder, Code Review Skill needs the command-line tools its instructions call (git and python). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebFetch.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Code Review Skill is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Skill: Code Review Skill (Rain-kl/OpenFlare, 288 stars), Code Review Excellence (andrew-yangy/gru-ai, 155 stars), Code Reviewer (alirezarezvani/claude-skills, 28k stars) and Senior Fullstack (borghei/Claude-Skills, 886 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awesome-skills (a GitHub organization) maintains it in awesome-skills/code-review-skill, which has 2,073 GitHub stars. The repository was last updated on September 8, 2026.
Source: awesome-skills/code-review-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.