Code Review Skill
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
Checklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity.
$ npx skills add decebals/claude-code-java --skill java-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install decebals/claude-code-java java-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/java-code-review .claude/skills/java-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .claude/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/decebals/claude-code-java/tree/main/skills/java-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add decebals/claude-code-java --skill java-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install decebals/claude-code-java java-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/java-code-review .agents/skills/java-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .agents/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add decebals/claude-code-java --skill java-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install decebals/claude-code-java java-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/java-code-review .cursor/skills/java-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .cursor/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/decebals/claude-code-java.git --path skills/java-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add decebals/claude-code-java --skill java-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install decebals/claude-code-java java-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/java-code-review .gemini/skills/java-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .gemini/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install decebals/claude-code-java java-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add decebals/claude-code-java --skill java-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/java-code-review .github/skills/java-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .github/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add decebals/claude-code-java --skill java-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install decebals/claude-code-java java-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/java-code-review .opencode/skills/java-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "java-code-review" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/java-code-review into .opencode/skills/java-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "java-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
java-code-reviewChecklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity.
The skill makes the agent review Java changes in three steps: a quick scan to understand intent and scope, a pass through a category checklist, and a summary that lists findings from critical down to minor. Findings follow a fixed markdown output format that starts with a Critical section.
Each checklist category gives a bad-code example, things to flag and fixes to suggest. Null safety flags chained calls, Optional.get() without a check and null returns where an empty collection fits. Exception handling flags empty catch blocks, broad catches and lost causes. Collections and streams cover modifying during iteration and immutable factories, and concurrency flags unsynchronized shared state and check-then-act races. The description also lists performance checks.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0d98fe9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Java Code Review loads about 2.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 514 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from decebals/claude-code-java at commit 0d98fe9, republished under its MIT licence (© decebals). 514 words, ~2,484 tokens.
.claude/skills/java-code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Systematic code review checklist for Java projects.
## Code Review: [file/feature name]
### Critical
- [Issue description + line reference + suggestion]
### Improvements
- [Suggestion + rationale]
### Minor/Style
- [Nitpicks, optional improvements]
### Good Practices Observed
- [Positive feedback - important for morale]Check for:
// ❌ NPE risk
String name = user.getName().toUpperCase();
// ✅ Safe
String name = Optional.ofNullable(user.getName())
.map(String::toUpperCase)
.orElse("");
// ✅ Also safe (early return)
if (user.getName() == null) {
return "";
}
return user.getName().toUpperCase();Flags:
@Nullable / @NonNull annotations on public APIsOptional.get() without isPresent() checknull from methods that could return Optional or empty collectionSuggest:
Optional for return types that may be absentObjects.requireNonNull() for constructor/method paramsCollections.emptyList()Check for:
// ❌ Swallowing exceptions
try {
process();
} catch (Exception e) {
// silently ignored
}
// ❌ Catching too broad
catch (Exception e) { }
catch (Throwable t) { }
// ❌ Losing stack trace
catch (IOException e) {
throw new RuntimeException(e.getMessage());
}
// ✅ Proper handling
catch (IOException e) {
log.error("Failed to process file: {}", filename, e);
throw new ProcessingException("File processing failed", e);
}Flags:
Exception or Throwable broadlySuggest:
causeCheck for:
// ❌ Modifying while iterating
for (Item item : items) {
if (item.isExpired()) {
items.remove(item); // ConcurrentModificationException
}
}
// ✅ Use removeIf
items.removeIf(Item::isExpired);
// ❌ Stream for simple operations
list.stream().forEach(System.out::println);
// ✅ Simple loop is cleaner
for (Item item : list) {
System.out.println(item);
}
// ❌ Collecting to modify
List<String> names = users.stream()
.map(User::getName)
.collect(Collectors.toList());
names.add("extra"); // Might be immutable!
// ✅ Explicit mutable list
List<String> names = users.stream()
.map(User::getName)
.collect(Collectors.toCollection(ArrayList::new));Flags:
Collectors.toList() returns mutable listList.of(), Set.of(), Map.of() for immutable collectionsSuggest:
List.copyOf() for defensive copiesremoveIf() instead of iterator removalCheck for:
// ❌ Not thread-safe
private Map<String, User> cache = new HashMap<>();
// ✅ Thread-safe
private Map<String, User> cache = new ConcurrentHashMap<>();
// ❌ Check-then-act race condition
if (!map.containsKey(key)) {
map.put(key, computeValue());
}
// ✅ Atomic operation
map.computeIfAbsent(key, k -> computeValue());
// ❌ Double-checked locking (broken without volatile)
if (instance == null) {
synchronized(this) {
if (instance == null) {
instance = new Instance();
}
}
}Flags:
volatile on shared variablesSuggest:
java.util.concurrent classesAtomicReference, AtomicInteger for simple cases@ThreadSafe / @NotThreadSafe annotationsequals/hashCode:
// ❌ Only equals without hashCode
@Override
public boolean equals(Object o) { ... }
// Missing hashCode!
// ❌ Mutable fields in hashCode
@Override
public int hashCode() {
return Objects.hash(id, mutableField); // Breaks HashMap
}
// ✅ Use immutable fields, implement both
@Override
public boolean equals(Object o) {
if (this == o) return true;
if (!(o instanceof User user)) return false;
return Objects.equals(id, user.id);
}
@Override
public int hashCode() {
return Objects.hash(id);
}toString:
// ❌ Missing - hard to debug
// No toString()
// ❌ Including sensitive data
return "User{password='" + password + "'}";
// ✅ Useful for debugging
@Override
public String toString() {
return "User{id=" + id + ", name='" + name + "'}";
}Builders:
// ✅ For classes with many optional parameters
User user = User.builder()
.name("John")
.email("john@example.com")
.build();Flags:
equals without hashCodehashCodetoString on domain objectsinstanceof pattern matching (Java 16+)Check for:
// ❌ Resource leak
FileInputStream fis = new FileInputStream(file);
// ... might throw before close
// ✅ Try-with-resources
try (FileInputStream fis = new FileInputStream(file)) {
// ...
}
// ❌ Multiple resources, wrong order
try (BufferedWriter writer = new BufferedWriter(new FileWriter(file))) {
// FileWriter might not be closed if BufferedWriter fails
}
// ✅ Separate declarations
try (FileWriter fw = new FileWriter(file);
BufferedWriter writer = new BufferedWriter(fw)) {
// Both properly closed
}Flags:
Closeable/AutoCloseableCheck for:
// ❌ Boolean parameters
process(data, true, false); // What do these mean?
// ✅ Use enums or builder
process(data, ProcessMode.ASYNC, ErrorHandling.STRICT);
// ❌ Returning null for "not found"
public User findById(Long id) {
return users.get(id); // null if not found
}
// ✅ Return Optional
public Optional<User> findById(Long id) {
return Optional.ofNullable(users.get(id));
}
// ❌ Accepting null collections
public void process(List<Item> items) {
if (items == null) items = Collections.emptyList();
}
// ✅ Require non-null, accept empty
public void process(List<Item> items) {
Objects.requireNonNull(items, "items must not be null");
}Flags:
Check for:
// ❌ String concatenation in loop
String result = "";
for (String s : strings) {
result += s; // Creates new String each iteration
}
// ✅ StringBuilder
StringBuilder sb = new StringBuilder();
for (String s : strings) {
sb.append(s);
}
// ❌ Regex compilation in loop
for (String line : lines) {
if (line.matches("pattern.*")) { } // Compiles regex each time
}
// ✅ Pre-compiled pattern
private static final Pattern PATTERN = Pattern.compile("pattern.*");
for (String line : lines) {
if (PATTERN.matcher(line).matches()) { }
}
// ❌ N+1 in loops
for (User user : users) {
List<Order> orders = orderRepo.findByUserId(user.getId());
}
// ✅ Batch fetch
Map<Long, List<Order>> ordersByUser = orderRepo.findByUserIds(userIds);Flags:
IntStream, LongStream)Suggest tests for:
| Severity | Criteria |
|---|---|
| Critical | Security vulnerability, data loss risk, production crash |
| High | Bug likely, significant performance issue, breaks API contract |
| Medium | Code smell, maintainability issue, missing best practice |
| Low | Style, minor optimization, suggestion |
git diff)| Category | Key Checks |
|---|---|
| Null Safety | Chained calls, Optional misuse, null returns |
| Exceptions | Empty catch, broad catch, lost stack trace |
| Collections | Modification during iteration, stream vs loop |
| Concurrency | Shared mutable state, check-then-act |
| Idioms | equals/hashCode pair, toString, builders |
| Resources | try-with-resources, connection leaks |
| API | Boolean params, null handling, validation |
| Performance | String concat, regex in loop, N+1 |
© decebals, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/java-code-review of decebals/claude-code-java.
Open the folder on GitHubat commit 0d98fe9
Java Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Java Code Review this skilldecebals/claude-code-java | 750 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Code Review Skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| SeekDB Code Reviewoceanbase/seekdb | 3.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Cross-Language Coding Standardszereight/gitlab-mcp | 2k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Code Qualitypiomin/claude-ai-spring-boot | 1.3k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review Excellenceandrew-yangy/gru-ai | 155 | — | ~1.7k | Automated safety check: Notes | MIT |
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
oceanbase/seekdb
Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.
zereight/gitlab-mcp
Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.
piomin/claude-ai-spring-boot
Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.
andrew-yangy/gru-ai
Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.
ClickHouse/clickhouse-java
Review changes in clickhouse-java for correctness, compatibility, API stability, and missing tests.
decebals/claude-code-java
Reviews REST API design for correct HTTP verbs, versioning, DTO use, consistent responses and backward compatibility before an API change ships.
decebals/claude-code-java
Reviews a Java project's architecture at the macro level: package structure, module boundaries, dependency direction and layering.
decebals/claude-code-java
A practical Java reference for Builder, Factory, Singleton, Strategy, Observer and other patterns, with a table matching problems to patterns.
decebals/claude-code-java
JPA/Hibernate patterns and common pitfalls (N+1, lazy loading, transactions, queries).
decebals/claude-code-java
Java logging best practices with SLF4J, structured logging (JSON), and MDC for request tracing.
decebals/claude-code-java
Builds changelog entries from conventional commits in a Java project, after working out whether it uses SemVer, two-part versions or calendar versions.
Works with
Categories
Checklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity. The skill makes the agent review Java changes in three steps: a quick scan to understand intent and scope, a pass through a category checklist, and a summary that lists findings from critical down to minor. Findings follow a fixed markdown output format that starts with a Critical section.
Java Code Review fits situations like: reviewing a Java pull request before it is merged; checking a newly implemented Java feature for common defects; auditing Java code for null-pointer and exception-handling problems; spotting thread-safety problems in shared Java state.
Run `npx skills add decebals/claude-code-java --skill java-code-review -a claude-code`. Or copy the skill folder (skills/java-code-review in decebals/claude-code-java) into .claude/skills/java-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add decebals/claude-code-java --skill java-code-review -a codex`. Or copy the skill folder (skills/java-code-review in decebals/claude-code-java) into .agents/skills/java-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add decebals/claude-code-java --skill java-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/java-code-review, .gemini/skills/java-code-review, .github/skills/java-code-review and .opencode/skills/java-code-review in your project.
Going by SKILL.md and its folder, Java Code Review needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Java Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Java Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), SeekDB Code Review (oceanbase/seekdb, 3.1k stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars) and Code Quality (piomin/claude-ai-spring-boot, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
decebals (a GitHub user) maintains it in decebals/claude-code-java, which has 750 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 6, 2026.
Source: decebals/claude-code-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.