Official agent skill

Review Areas

by Azure in Azure/azqr

In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development.

OfficialMITAuto-check passedDevelopment

Install Review Areas

skills CLI
$ npx skills add Azure/azqr --skill review-areas -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/azqr review-areas --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/azqr.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-areas .claude/skills/review-areas && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-areas
GitHub stars
796
Token cost
~1.6k tokens
SKILL.md length
676 words
Files
5
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development.

  • Works in 6 steps: Scope → Build a Change Summary → Fan Out → …
  • : in-depth review of a pull request
  • SKILL.md covers Review Areas, Workflow, Signal Filter and Area Prompt, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review Areas is an agent skill from Azure/azqr, published by the product's own GitHub organization. In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development. USE FOR: "in-depth review of a pull request", "code quality check or bug hunt", "review correctness, tests, security, performance and product areas", "review after any non-trivial development phase". DO NOT USE FOR: "plan a new implementation", "explain how existing code works".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `evals/eval.yaml`, `evals/tasks/basic-review.yaml` and `evals/tasks/should-not-trigger.yaml`).

It sits in Development, covering Subagents, Pull requests and Code quality. It works with Microsoft Azure. The licence is MIT.

When your agent uses it

  • : in-depth review of a pull request
  • Code quality check
  • Review correctness
  • Performance and product areas

Example prompts

  • “in-depth review of a pull request”
  • “code quality check or bug hunt”
  • “review correctness, tests, security, performance and product areas”
  • “/review-areas”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scope
  2. Build a Change Summary
  3. Fan Out
  4. Synthesize
  5. Save Findings
  6. Fix or Report

What it can do on your machine

Read from SKILL.md and the folder at commit 3ccbd65. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Areas loads about 1.6k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 676 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/azqr at commit 3ccbd65, republished under its MIT licence (© Azure). 676 words, ~1,593 tokens.

Download SKILL.mdSave it as .claude/skills/review-areas/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
review-areas
description
In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development. USE FOR: "in-depth review of a pull request", "code quality check or bug hunt", "review correctness, tests, security, performance and product areas", "review after any non-trivial development phase". DO NOT USE FOR: "plan a new implementation", "explain how existing code works".

Skill: Review Areas

Fan out parallel read-only subagents, each assigned a different review area, then synthesize the highest-signal findings. This surfaces issues that a single-pass review misses because each subagent goes deep on its area instead of skimming everything.

Review Areas

Pick 2–4 areas based on the nature of the change. Not every review needs all areas — match the areas to the risk profile.

AreaWhen to includeFocus
CorrectnessAlwaysLogic errors, type safety, race conditions, null/undefined paths, unsafe casts, wrong behavior
TestsWhen tests exist or should existRun tests, check failing/missing coverage, validate assertions match intent
SecurityAuth, input handling, data flow changesInput validation, auth checks, injection, data exposure
PerformanceHot paths, data structures, async changesAlgorithm complexity, unnecessary allocations, blocking async patterns
ProductUI, UX, or user-facing behavior changesUX implications, feature completeness, accessibility gaps

Workflow

1 — Scope
  • Prefer the active pull request, current git diff, or an explicit file list from the user.
  • If there is nothing to review, ask the user to point at a branch, PR, diff, or file set.
2 — Build a Change Summary

Before fanning out, build a concise change summary. Do not paste raw diffs into the subagent prompts — each subagent has tools to read files and inspect changes itself.

The summary should include:

  1. Intent — what the change is trying to accomplish (from PR description, commit messages, or conversation context).
  2. Changed files — list each file path with a one-line description of what changed (e.g., "added input validation", "refactored into helper").
  3. Risk areas — anything risky: new dependencies, auth changes, hot-path modifications, API surface changes.
  4. How to inspect — branch/PR/commit info so subagents can use their tools.

Keep the summary under ~50 lines. Subagents get better results reading code in context than scanning a wall of diff.

3 — Fan Out

Launch 2–4 parallel subagents using the area prompts below. Each subagent works in isolation — do not share one area's findings with another before synthesis.

Use unnamed subagents (no custom agent needed). Each gets a self-contained prompt with its area, the change summary, and the return format.

4 — Synthesize

When all subagents return:

  1. Deduplicate findings that overlap across areas (e.g., a correctness bug that also shows up as a missing test).
  2. Order by severity: breaking > wrong behavior > security > missing coverage > performance > product.
  3. Apply the signal filter — drop anything that wouldn't block a PR.
  4. If no blocking issues survive, say so and mention any meaningful testing gaps.
Show full SKILL.md (265 more words)Show less
5 — Save Findings

Always save the synthesized findings to session memory at /memories/session/review.md. This makes them available for follow-up turns, fix planning, and cross-referencing with future reviews.

6 — Fix or Report
  • Review-only: if the user said "only review", "just review", or "read-only", stop after reporting.
  • Default (review-and-fix):
    1. For each fixable finding, launch one or more parallel Explore subagents to investigate the fix — this is faster and deeper than reading files inline. Give each Explore agent the finding, the relevant file paths, and ask it to return the specific change needed (what to replace, where).
    2. Apply fixes in severity order based on the Explore agents' recommendations.
    3. After applying, re-check the changed lines and diagnostics to validate.
    4. Report what was fixed and any remaining items that need the user's input.

Signal Filter

Keep only findings a senior engineer would block a PR for:

  • Will fail to compile, type-check, or produce wrong results
  • Clear, citable violation of workspace coding standards
  • Security vulnerability with a concrete exploit path
  • Missing error handling that causes silent failures

Drop: style preferences, linter-catchable issues, pre-existing problems, speculative concerns.

Area Prompt

Each subagent gets this prompt with {AREA} and {FOCUS} filled in from the Review Areas table.

text
You are a focused code review subagent. Your area is: {AREA}

## What changed
<change summary from step 2: intent, changed files with one-line descriptions, risk areas>

## How to inspect
<branch, PR number, or commit range the subagent can use with its tools>

Focus on: {FOCUS}

Use your tools to read the changed files, check diagnostics, and run focused tests. Do not rely solely on this summary — dig into the code yourself. Read functions end-to-end. Trace inputs through branches and error paths. Check callers when contracts change.

Rules:
- Stay read-only. Do not edit files.
- Only flag issues that would block a PR — things that break, regress, or expose a concrete vulnerability.
- Do not report issues outside your area.
- Do not suggest code edits — describe the problem and why it matters.
- Check loaded workspace instructions and skills before flagging standard violations.
- Keep your response short. No preamble, no style commentary.

Return format:

**Area**: {AREA}

**Findings** (0–5 items, severity order):
- [file:line] One-sentence description. Why it matters.

If nothing blocks approval: "No blocking issues found in {AREA}."

Output Shape

Changes Summary (50 words max): What changed, why, and expected impact.

What's Done Well (1–3 items): Acknowledge good patterns worth reinforcing.

Critical Issues (0–5 items, severity order): Each with file references and the area that surfaced it.

Improvements (0–5 items): High-value suggestions that didn't quite reach "blocking" but are worth addressing.

Verdict: Ready / Needs Revisions / Blocked — with a specific next step.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in .agents/skills/review-areas of Azure/azqr.

  • SKILL.md
  • evals/eval.yaml
  • evals/tasks/basic-review.yaml
  • evals/tasks/should-not-trigger.yaml
  • evals/trigger_tests.yaml

Open the folder on GitHubat commit 3ccbd65

Compare with similar skills

Review Areas next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Areas compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Areas this skillAzure/azqr796—~1.6kAutomated safety check: PassMIT
Code Reviewdotnet/maui23k—~8.2kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Cherry Studio PR ReviewCherryHQ/cherry-studio53k—~3.9kAutomated safety check: PassAGPL-3.0

Similar skills

  • Code Review

    dotnet/maui

    Official

    Deep code review of PR or materialized candidate-patch changes for correctness, safety, and MAUI conventions.

    23k GitHub stars~8.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    53k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes

More from Azure/azqr

  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    796 GitHub starsUsed in 89 repos~8.2k tokens
    Auto-check passed
  • Kql Validator

    Azure/azqr

    Official

    Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

    796 GitHub stars~703 tokensUpdated yesterday
    Auto-check passed
  • Azqr Developer

    Azure/azqr

    Official

    Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

    796 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Code Simplifier

    Azure/azqr

    Official

    Analyzes recently modified code and creates pull requests with simplifications that improve clarity, consistency, and maintainability while preserving functionality

    796 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Review Areas

What does Review Areas do?

In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development. Review Areas is an agent skill from Azure/azqr, published by the product's own GitHub organization. In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development.

When should I use Review Areas?

Review Areas fits situations like: : in-depth review of a pull request; code quality check; review correctness; performance and product areas.

How do I install Review Areas in Claude Code?

Run `npx skills add Azure/azqr --skill review-areas -a claude-code`. Or copy the skill folder (.agents/skills/review-areas in Azure/azqr) into .claude/skills/review-areas in your project. Claude Code loads it when a task matches its description.

How do I install Review Areas in Codex?

Run `npx skills add Azure/azqr --skill review-areas -a codex`. Or copy the skill folder (.agents/skills/review-areas in Azure/azqr) into .agents/skills/review-areas in your project. Codex loads it when a task matches its description.

Can I use Review Areas in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/azqr --skill review-areas -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-areas, .gemini/skills/review-areas, .github/skills/review-areas and .opencode/skills/review-areas in your project.

What does Review Areas need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Areas is instructions for the agent only.

Does Review Areas access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Areas safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Areas use?

Review Areas is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Areas use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Areas?

Skills that share tags, products or a category with Review Areas: Code Review (dotnet/maui, 23k stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), GitHub Review Iteration (prisma/orm, 48k stars) and Code Review Skill (awesome-skills/code-review-skill, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Areas?

Azure (a GitHub organization, an official publisher) maintains it in Azure/azqr, which has 796 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 9, 2026.

Source: Azure/azqr on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.