Agent skill

Code Reviewer

by CaoMeiYouRen in CaoMeiYouRen/caomei-auth

审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code…

MITAuto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add CaoMeiYouRen/caomei-auth --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CaoMeiYouRen/caomei-auth code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CaoMeiYouRen/caomei-auth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
220
Token cost
~1.5k tokens
SKILL.md length
397 words
Files
7 (incl. references)
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code…

  • Tasks that involve Code review
  • SKILL.md covers 核心概念, 工作流, 最低验证矩阵 and 分级审计协议(audit-depth), plus 6 more sections
  • Calls git
  • Tasks that involve Pull requests

What it does

Code Reviewer is an agent skill from CaoMeiYouRen/caomei-auth. 审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code review、PR 审查、deep review、review gate、merge ready、blocker、evidence、pass、reject、SOLID、架构审查时都应触发。

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/agent.yaml`, `references/code-quality-checklist.md` and `references/evidence-template.md`).

It sits in Development, covering Code review, Pull requests and Human-in-the-loop approvals. It works with Git. The repository describes itself as: 草梅 Auth 是一个基于 Nuxt 全栈框架的统一登录平台。支持 OAuth2.0 协议,集成邮箱、用户名、手机号、验证码、社交媒体等多种登录注册方式。 The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Pull requests
  • Tasks that involve Human-in-the-loop approvals

Example prompts

  • “/code-reviewer”

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd3bae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 1.5k tokens when it runs, and up to ~8.4k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CaoMeiYouRen/caomei-auth at commit 7bd3bae, republished under its MIT licence (© CaoMeiYouRen). 397 words, ~1,525 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
code-reviewer
description
审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code review、PR 审查、deep review、review gate、merge ready、blocker、evidence、pass、reject、SOLID、架构审查时都应触发。
metadata.internal
true

Code Reviewer

铁律:先给 Review Gate 结论、阻塞原因和复查基线,再给摘要。不要因为测试通过、代码能跑或改动量小,就跳过正确性、安全和架构审查。没有最低验证证据,不得给 Pass。

核心概念

  • Pass / Reject 是 Gate 结论;blocker / warning / suggest 是问题分级,二者不能混用。
  • 文档、规划、配置、脚本与测试代码同样属于正式审查对象,不能因为"不是业务代码"而跳过。

工作流

  • Step 1: 建立审查上下文 ⚠️ REQUIRED
    • 1.1 读取 git 状态、diff 范围和受影响文件。
    • 1.2 确认入口、关键路径和高风险区域,如鉴权、数据写入、外部调用、配置变更。
    • 1.3 如果没有 diff,明确告诉用户并询问是否改看 staged changes 或指定范围。
    • 1.4 diff 规模核验:统计变更文件数与新增行数(git diff --stat)。超过阈值(默认 10 文件或 800 行新增,项目可调整)时,要求调用方说明批次拆分依据;未拆分且无正当理由 → Reject。
  • Step 2: 判定改动类型与最低验证要求 ⚠️ REQUIRED
    • 2.1 先确定变更类型,再映射到最低验证矩阵(见下方"最低验证矩阵")。
    • 2.2 代码改动默认至少包含 lint 和 typecheck;文档改动补链接和路径检查。
    • 2.3 测试按风险选择定向/全量/coverage/E2E,不一刀切。
    • 2.4 若实际证据低于最低层级,直接判定为 Reject,而不是"暂时通过"。
  • Step 2.5: 按 audit-depth 分配审查深度 ⚠️ REQUIRED(控制用时)
    • 2.5.1 审查投入与改动风险匹配,按下方"分级审计协议"选择 quick / standard / deep;调用方未声明时按 deep 防御执行。
    • 2.5.2 证据优先采信:调用方提供的已查证事实(实验证据、测试结果、源码行号引用)直接采用,翻源码仅限需要最终实锤且无外部参考的场景。
    • 2.5.3 收敛策略(不依赖时间感知):审查输出固定为"audit-depth 审查范围内可交付的结论 + 未覆盖边界",宁可给 Reject(附待补证据清单)也不无限深挖。
    • 2.5.4 复审只审修复点:第 2+ 轮只复查上轮问题编号对应的修复点 diff 与受影响断言,不得重读全量 diff。
    • 2.5.5 并发分区(仅大改动):diff 文件数 > 8 或涉及 ≥ 2 个独立模块时,按模块分区并行发起多个审查任务,主审汇总合并去重、取最严结论;小改动不得并发。
    • 2.5.6 用时反馈由调用方事后实测:审计方不自报时长、不检查时间。
  • Step 3: 加载约束与相关资料 ⚠️ REQUIRED
    • 3.1 优先读取与改动直接相关的根目录文档、配置文件和模块实现,而不是假设存在 docs/。
    • 3.2 如果改动涉及 skills//SKILL.md、agents/.agent.md 或 AGENTS.md,额外加载 skill-creator,按技能设计规范审查触发面、工作流和资源布局。
  • Step 4: 收集并延续审查证据
    • 4.1 默认把临时审查记录写入 artifacts/review-gate/(纳入 .gitignore),文件名 <date>-<scope>.md。
    • 4.2 按 evidence-template.md 预填与延续:首轮创建,多轮 review 复用同一份记录,按"第 1 轮"、"第 2 轮"追加,保留未关闭问题编号(RG-B/W/S 系列)与复查结论。
  • Step 5: 进行结构化审查
    • 5.1 使用本目录 references/solid-checklist.md 检查职责边界、扩展点和耦合度。
    • 5.2 使用本目录 references/security-checklist.md 检查鉴权、注入、密钥泄露、日志和资源滥用风险。
    • 5.3 使用本目录 references/code-quality-checklist.md 检查错误处理、边界条件、性能与可维护性。
    • 5.4 使用本目录 references/removal-plan.md 判断冗余代码是可立即删除,还是需要后续迭代计划。
    • 5.5 当用户要求 deep review、SOLID review 或 senior review 时,必须同时覆盖性能热点、异常处理、边界条件和删除计划,而不是只做浅层意见汇总。
    • 5.6 必查项(所有深度均适用):规范单点声明(审查治理定义时检查是否重复抄写权威文档完整条款,应一行链接引用);供应链信任边界(新依赖/MCP/外部 skill 引入时检查来源验证与版本钉定);流程编号标记(新增注释与测试名不得含规划/任务/审计编号如 T405、P1-1,例外仅真实常量与带文档路径的导航指针)。
    • 5.7 优先寻找会阻塞放行的问题,而不是按文件顺序复述 diff。
  • Step 6: 判定严重级别 ⚠️ REQUIRED
    • 6.1 blocker:明显 correctness bug、安全漏洞、关键验证缺失、与规范冲突、会阻塞提交。
    • 6.2 warning:较高回归风险、测试覆盖不足、结构边界模糊或证据不完整。
    • 6.3 suggest:非阻塞的可维护性、可读性、删除计划或后续优化建议。
    • 6.4 兼容映射:blocker ≈ P0/P1、warning ≈ P2、suggest ≈ P3。
  • Step 7: 输出审查结果 ⚠️ REQUIRED
    • 7.1 只有所有 blocker 关闭且最低验证矩阵满足时,才允许给 Pass。
    • 7.2 Reject 必须明确写出失败原因、缺失证据、待修问题和复查基线。
    • 7.3 对多轮 review,必须说明"本轮新增问题""本轮已关闭问题""仍待复查问题"。
    • 7.4 如果无问题,也要说明检查范围与残余风险。
  • Step 8: 确认后续动作
    • 8.1 默认停在 review,不直接改代码。
    • 8.2 只有用户明确要求修复时,才进入实现阶段。

最低验证矩阵

任何变更都必须按"验证层级 + Review Gate"判断是否可以放行:

改动类型最低验证
文档 / 规划lint:md(或链接路径检查)+ RG
纯逻辑 / 工具函数 / 服务层lint + typecheck + 定向测试 + RG
API / 鉴权 / 数据模型lint + typecheck + 定向测试 + RG(关键写路径升级到流程验证)
UI 组件 / 页面交互lint + typecheck + 测试 + 浏览器验证 + RG
修复型 Hotfixlint + typecheck + 复现与修复后结果 + RG
配置 / 依赖 / CI / 技能与 agent 定义lint + typecheck + 定向验证 + RG

本矩阵为通用默认值,项目可在 AGENTS.md 中按自身需要调整。没有 RG 结论的变更只能视为"进行中",不能视为已完成。

Show full SKILL.md (137 more words)Show less

分级审计协议(audit-depth)

审查投入与改动风险匹配,不应对所有改动一视同仁长时间分析:

audit-depth适用改动审查范围时间盒
quick文档措辞、简单配置、重命名、测试补强只核验证声明(lint/typecheck/定向测试结果)+ diff 概要一致性 + 明显错误;禁止跑实验、定向测试或翻全量源码≤ 5 分钟
standard常规业务逻辑、模块内改动正确性 + 边界 + 测试覆盖;定向抽查 ≤ 3 个关键文件≤ 10 分钟
deep发布流程、安全/鉴权、外部调用、数据写入、配置与依赖变更、agent/skill 定义全量 checklist + 针对性实证(临时仓库/本地实验/验证命令按需执行)≤ 20 分钟
  • 时间盒由调用方用宿主系统时钟事后实测回填,审计方不自报时长、不检查时间;实测超时仅作分级校准信号,不回溯要求补动作。
  • 调用方发起审计时必须显式声明 audit-depth(quick / standard / deep + 理由)、变更文件清单、已验证证据摘要与复审问题编号;未声明按 deep 防御执行。

输出格式

markdown
## Review Gate
- 结论: Pass | Reject
- 改动类型:
- 最低验证要求:
- 审查轮次:
- audit-depth:(调用方声明 + 本轮实际执行档位)
- 失败原因或通过条件:
- 复查基线:

## Findings
### blocker
1. [path/to/file.ext] 标题
    - 风险
    - 修复方向

### warning

### suggest

## 验证证据
- 已执行验证:
- 结果摘要:
- 未覆盖边界:
- 后续补跑计划:

技能文件专项审查

当改动涉及技能体系时,额外检查:

  • description 是否真的能触发技能,而不是抽象介绍。
  • 正文是否具备铁律、工作流、确认门、反模式和交付前检查。
  • references/、scripts/、assets/ 是否职责清晰,是否存在跨目录重复定义。
  • 是否保留了兼容别名,以及 canonical skill 是否唯一明确。
  • 如果技能刚经历模板化重构,是否通过 git diff 或提交历史保留了旧版中的项目特化规则。
  • skill / agent 改动是否保持唯一事实源,无重复抄写权威文档完整条款。

深度审查模式

当用户要求 deep review、code review expert 或 senior review 时:

  • 使用 references/solid-checklist.md 审查职责边界、扩展性与耦合。
  • 使用 references/security-checklist.md 审查鉴权、注入、密钥、SSRF、路径问题和竞态。
  • 使用 references/code-quality-checklist.md 审查 swallowed exceptions、async error、N+1、缓存和边界条件。
  • 使用 references/removal-plan.md 判断死代码是立即可删还是需要迁移计划。
  • 解释为什么这是结构性风险,而不是只给表面建议。

确认门

  • 没有用户确认时,不直接实现审查意见。
  • 审查范围过大时,先和用户确认是全量 review 还是重点 review。

反模式

  • 只给笼统评价,如"看起来不错""代码质量还行"。
  • 按文件顺序复述 diff,而不是提炼真正的问题。
  • 用"可能"掩盖已经足够明确的风险。
  • 审查技能文件时,继续沿用旧模板标准而忽略 skill-creator。
  • 只写"已审查通过"而不说明依据。
  • 只跑 lint / typecheck 就给所有改动 Pass。
  • 把问题分级当成最终 Gate 结论,或把 warning 写成"已通过"。
  • 审查文档、脚本、配置、技能文件时不补充对应的最小验证。
  • 没有复查基线,导致多轮 review 无法对账。
  • 超限 diff 未核对拆分依据就放行。

交付前检查

  • Review Gate 结论(Pass/Reject)与问题分级(blocker/warning/suggest)分离清晰。
  • 最低验证矩阵已核对,证据缺失已导致 Reject 而非"暂时通过"。
  • audit-depth 已声明,审查范围与深度匹配。
  • 多轮 review 已按问题编号给出"本轮新增/已关闭/仍待复查"。
  • 证据记录已写入 artifacts/review-gate/(如适用)。
  • Findings 排在总结前面。
  • 每个阻塞问题都说明了风险和修复方向。
  • 已覆盖正确性、安全、架构、性能和测试风险。
  • 如果审查了技能文件,已按 skill-creator 规范补充设计审查。
  • 未经用户确认,不包含自动实施修改。

© CaoMeiYouRen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .github/skills/code-reviewer of CaoMeiYouRen/caomei-auth.

  • SKILL.md
  • agents/agent.yaml
  • references/code-quality-checklist.md
  • references/evidence-template.md
  • references/removal-plan.md
  • references/security-checklist.md
  • references/solid-checklist.md

Open the folder on GitHubat commit 7bd3bae

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillCaoMeiYouRen/caomei-auth220—~1.5kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Code Reviewflutter/flutter179k—~1.4kAutomated safety check: PassBSD-3-Clause
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Knowledge Graph PR Reviewtirth8205/code-review-graph32k—~452Automated safety check: PassMIT

Similar skills

  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Knowledge Graph PR Review

    tirth8205/code-review-graph

    Reviews a pull request or branch diff with a code knowledge graph and produces a structured review that includes blast-radius analysis.

    32k GitHub stars~452 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed

More from CaoMeiYouRen/caomei-auth

All 14 skills in this repo
  • Full Stack Master

    CaoMeiYouRen/caomei-auth

    需要统筹需求澄清、上下文扫描、技术方案、前后端实现、UI 验证、测试、质量审查、文档同步和提交节奏时使用。它负责编排多技能协作,而不是亲自替代所有专业技能。用户提到 end-to-end workflow、全流程开发、从需求到提交、PDTFC+、多技能编排时都应触发。

    220 GitHub stars~1k tokensUpdated 7 days ago
    Auto-check passed
  • Quality Guardian

    CaoMeiYouRen/caomei-auth

    运行并解读 lint、类型检查、测试等质量门时使用。它不只是执行命令,还要根据变更范围选择最小充分检查、分析失败原因,并给出是否允许继续提交或发布的判断。用户提到 lint、typecheck、tests、quality gate、验证改动时都应触发。

    220 GitHub stars~358 tokensUpdated 7 days ago
    Auto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 7 days ago
    Auto-check: notes
  • Gh CLI

    CaoMeiYouRen/caomei-auth

    使用 GitHub CLI(gh)处理仓库、issue、pull request、workflow、project、release、codespace、gist、search、api、auth、config、alias、secret、variable、extension、ruleset 和 status 等命令行操作时使用。用户提到 gh、gh cli、GitHub CLI、gh…

    220 GitHub stars~460 tokensUpdated 7 days ago
    Auto-check passed
  • Backend Expert

    CaoMeiYouRen/caomei-auth

    设计或实现后端 API、服务层、数据库读写、鉴权权限控制、输入校验、事务处理与错误处理时使用。用户提到 API、route、handler、server、auth、permission、drizzle、database、zod、Hono、Nuxt server routes、backend bug 修复时都应触发。

    220 GitHub stars~329 tokensUpdated 7 days ago
    Auto-check passed
  • Context Analyzer

    CaoMeiYouRen/caomei-auth

    在动手规划、修改、调试或回答复杂项目问题前使用。用于快速扫描项目结构、依赖、约束文档、关键文件和调用链,输出任务相关上下文,而不是直接改代码。用户提到 analyze context、scan repo、understand project、定位实现、找规范、排查调用链时都应触发。

    220 GitHub stars~296 tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Code Reviewer

What does Code Reviewer do?

审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code…. Code Reviewer is an agent skill from CaoMeiYouRen/caomei-auth.

When should I use Code Reviewer?

Code Reviewer fits situations like: tasks that involve Code review; tasks that involve Pull requests; tasks that involve Human-in-the-loop approvals.

How do I install Code Reviewer in Claude Code?

Run `npx skills add CaoMeiYouRen/caomei-auth --skill code-reviewer -a claude-code`. Or copy the skill folder (.github/skills/code-reviewer in CaoMeiYouRen/caomei-auth) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add CaoMeiYouRen/caomei-auth --skill code-reviewer -a codex`. Or copy the skill folder (.github/skills/code-reviewer in CaoMeiYouRen/caomei-auth) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CaoMeiYouRen/caomei-auth --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

Going by SKILL.md and its folder, Code Reviewer needs the command-line tools its instructions call (git).

Does Code Reviewer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.9k tokens, read only when the agent opens those files.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars), Code Review (flutter/flutter, 179k stars) and PR Review State Fetch (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

CaoMeiYouRen (a GitHub user) maintains it in CaoMeiYouRen/caomei-auth, which has 220 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 1, 2026.

Source: CaoMeiYouRen/caomei-auth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.