MCP-powered multi-dimensional code review for .NET projects.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add codewithmukesh/dotnet-claude-kit --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewithmukesh/dotnet-claude-kit code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
751
Token cost
~1.7k tokens
SKILL.md length
482 words
Files
1
Skills in repo
47
Repo updated
First seen
Licence
MIT

At a glance

MCP-powered multi-dimensional code review for .NET projects.

  • Works in 6 steps: Scope and Score Blast Radius → MCP Analysis (before reading any file) → Blast Radius Verification → …
  • Check code quality
  • SKILL.md covers What, When, How and Example, plus 1 more section
  • Calls git

What it does

Code Review is an agent skill from codewithmukesh/dotnet-claude-kit. MCP-powered multi-dimensional code review for .NET projects. Uses Roslyn analysis tools for antipatterns, diagnostics, references, and dependency graphs combined with structured manual review. Prioritizes effort with blast-radius scoring — data access, security, concurrency, and integration boundaries before style — and produces severity-categorized findings with actionable fixes. Use when: "review", "code review", "PR review", "review this", "review my code", "check code quality", "review changes", "what should…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Pull requests. It works with Model Context Protocol and .NET. The repository describes itself as: Make Claude Code a .NET 10 Expert. The licence is MIT.

When your agent uses it

  • Check code quality
  • What should I review
  • Review priorities

Example prompts

  • “review”
  • “code review”
  • “PR review”
  • “/code-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scope and Score Blast Radius
  2. MCP Analysis (before reading any file)
  3. Blast Radius Verification
  4. Architecture Compliance
  5. Manual Review — Priority Order
  6. Produce the Review

What it can do on your machine

Read from SKILL.md and the folder at commit 2330089. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 1.7k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewithmukesh/dotnet-claude-kit at commit 2330089, republished under its MIT licence (© codewithmukesh). 482 words, ~1,690 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
MCP-powered multi-dimensional code review for .NET projects. Uses Roslyn analysis tools for antipatterns, diagnostics, references, and dependency graphs combined with structured manual review. Prioritizes effort with blast-radius scoring — data access, security, concurrency, and integration boundaries before style — and produces severity-categorized findings with actionable fixes. Use when: "review", "code review", "PR review", "review this", "review my code", "check code quality", "review changes", "what should I review", "review priorities", "blast radius", "critical path".

/code-review — MCP-Powered Code Review

What

Performs a multi-dimensional code review combining Roslyn MCP analysis with structured manual review. Effort follows the 80/20 rule: the 20% of code that causes 80% of incidents (data access, security, concurrency, integration boundaries) gets thorough review; style and formatting are left to tooling.

Review dimensions: Correctness (logic, edge cases, null handling, async pitfalls), Security (auth gaps, injection, secrets, CORS), Performance (N+1, allocations, missing cancellation), Architecture compliance (layer violations, boundary breaches), Test coverage (behavior tests for changed types).

When

  • "Review this", "code review", "PR review", before merging a pull request
  • After a major refactor to verify no regressions or design drift
  • "What should I review?" — deciding where review effort goes on a large change
  • Onboarding to unfamiliar code and wanting a quality assessment

How

Step 1: Scope and Score Blast Radius

Identify changed files (git diff main...HEAD, specified files, or module). Score each change to set review depth — blast radius determines depth, not line count. A one-line middleware change outranks a 300-line rename.

Blast RadiusExamplesDepth
CriticalMiddleware, auth, DB migrations, shared kernel, CI/CDThorough — every code path
HighPublic API changes, message consumers, EF configuration, new moduleFocused — consumers + behavior
MediumNew feature following existing patterns, bug fix, new endpointStandard — checklist pass
LowDocs, formatting, renames, logging statementsGlance — build + tests pass
Step 2: MCP Analysis (before reading any file)
detect_antipatterns(projectFilter: "affected-project")   → async void, DateTime.Now, new HttpClient(), broad catch
get_diagnostics(scope: "project", path: "affected-project") → new warnings, nullability issues

Distinguish newly introduced findings from pre-existing ones — focus on new.

Step 3: Blast Radius Verification

For each modified public API:

find_references(symbolName: "ModifiedType")              → count consumers; high count = high risk
get_dependency_graph(symbolName: "ModifiedMethod", depth: 2) → ripple effects

Check whether callers handle changed return types and new error cases.

Step 4: Architecture Compliance

Verify dependency direction (Domain → nothing; Infrastructure → Application → Domain) via get_project_graph and detect_circular_dependencies. Per architecture: VSA features don't cross-reference; Clean Architecture domain has zero project references; Modular Monolith modules communicate only via integration events — find_references on a module's DbContext should resolve only inside that module.

Show full SKILL.md (176 more words)Show less
Step 5: Manual Review — Priority Order

Review what tools can't catch, highest-risk areas first:

PriorityAreaCheck
1Data accessN+1 (missing Include/projection), raw SQL with user input, missing CancellationToken
2SecurityEvery endpoint has explicit [Authorize]/[AllowAnonymous], input validated, no secrets in code, no PII in logs
3ConcurrencyToken propagated end-to-end, no .Result/.Wait(), thread-safe shared state
4IntegrationRetry/timeout on external calls, consumer idempotency, no swallowed exceptions
5CorrectnessBusiness logic, edge cases (empty/null/concurrent), entities mapped to DTOs at the boundary
6TestsBehavior tested (not implementation); happy path + main error case covered
—Style/namingMention only after the above; formatters and analyzers own this
Step 6: Produce the Review

Every finding states what's wrong, why it matters, and how to fix it. Never bury a security bug under naming nits.

markdown
## Code Review: [Scope]

### Summary
[1-3 sentences: scope, risk level, recommendation]

### Critical (must fix before merge)
- **[Title]** — [file:line] [What's wrong. Why it matters. How to fix.]

### Warnings (should fix, creates tech debt)
- **[Title]** — [file:line] [...]

### Suggestions (nice to have)
- **[Title]** — [file:line] [...]

### Architecture Compliance
[PASS/WARN with boundary-violation notes]

### Test Coverage
[Which changed types have tests; specific scenarios to add]

### What's Good
- [Always include — reinforce good patterns]

Quick review (1-2 files, low blast radius): run detect_antipatterns + get_diagnostics, read for correctness, output Summary + Issues + What's Good.

Example

User: /code-review the changes in this PR

Claude: 7 changed files across 3 projects. CreateOrder touches data access
and a public endpoint — High blast radius. Running MCP analysis...

## Code Review: Order Processing Feature

### Summary
Adds CreateOrder/GetOrder endpoints with EF Core persistence. Well-structured
VSA feature. Two issues need attention before merge.

### Critical (must fix before merge)
- **Missing CancellationToken propagation** — CreateOrder.cs:38
  SaveChangesAsync() called without the token. Client disconnects keep
  burning server resources. Pass `ct` from the handler parameter.

### Warnings (should fix, creates tech debt)
- **N+1 query in GetOrder** — GetOrder.cs:25
  Order loaded without `.Include(o => o.Items)`; one lazy load per item
  during serialization. Eager-load or use a projection.

### Suggestions (nice to have)
- **Seal the handler** — CreateOrderHandler.cs:10
  Not designed for inheritance; `sealed` enables devirtualization.

### Architecture Compliance
PASS — all changes within Features/Orders/, no layer violations.

### Test Coverage
Happy path covered. Add tests for validation failure and not-found.

### What's Good
- Clean command/query separation; FluentValidation covers edge cases
- Response DTOs are records, no entity leaks
  • /de-sloppify — Cleanup pass for the style/formatting issues review skips
  • /verify — Automated verification pipeline (complements manual review)
  • /health-check — Broader project health assessment beyond a single PR

© codewithmukesh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-review of codewithmukesh/dotnet-claude-kit.

Open the folder on GitHubat commit 2330089

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillcodewithmukesh/dotnet-claude-kit751—~1.7kAutomated safety check: PassMIT
Code Reviewsbroenne/mcp-windows105—~1.6kAutomated safety check: PassMIT
MAUI PR Performance Analysisdotnet/maui23k—~2.4kAutomated safety check: PassMIT
Code Reviewjonathanpeppers/dotnes780—~2.1kAutomated safety check: PassMIT
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0
Code Reviewimbenrabi/Financial-Modeling-Prep-MCP-Server150—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review

    sbroenne/mcp-windows

    Review pull requests in mcp-windows for concrete bugs in MCP and CLI contracts, Windows UI automation, element identity, snapshots, bounded searches, and service lifetime.

    105 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.

    23k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    jonathanpeppers/dotnes

    Review dotnes pull requests against established repository rules.

    780 GitHub stars~2.1k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    imbenrabi/Financial-Modeling-Prep-MCP-Server

    Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants.

    150 GitHub stars~2.6k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Official

    Lists open pull requests in dotnet/maui and dotnet/docs-maui that are worth reviewing next, ranked by priority labels, milestone and partner or community origin.

    23k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed

More from codewithmukesh/dotnet-claude-kit

All 47 skills in this repo
  • API Versioning

    codewithmukesh/dotnet-claude-kit

    API versioning strategies for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Scaffold

    codewithmukesh/dotnet-claude-kit

    Architecture-aware feature scaffolding for .NET 10 projects.

    751 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Advisor

    codewithmukesh/dotnet-claude-kit

    Architecture selection advisor for .NET applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Aspire

    codewithmukesh/dotnet-claude-kit

    .NET Aspire for cloud-native orchestration. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Caching

    codewithmukesh/dotnet-claude-kit

    Caching strategies for .NET 10 applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

MCP-powered multi-dimensional code review for .NET projects. Code Review is an agent skill from codewithmukesh/dotnet-claude-kit.NET projects.

When should I use Code Review?

Code Review fits situations like: check code quality; what should I review; review priorities.

How do I install Code Review in Claude Code?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in codewithmukesh/dotnet-claude-kit) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill code-review -a codex`. Or copy the skill folder (skills/code-review in codewithmukesh/dotnet-claude-kit) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewithmukesh/dotnet-claude-kit --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review (sbroenne/mcp-windows, 105 stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars), Code Review (jonathanpeppers/dotnes, 780 stars) and Code Review (nteract/semiotic, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

codewithmukesh (a GitHub organization) maintains it in codewithmukesh/dotnet-claude-kit, which has 751 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on August 7, 2026.

Source: codewithmukesh/dotnet-claude-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.