Agent skill

Java Code Review

by decebals in decebals/claude-code-java

Checklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity.

MITAuto-check passedDevelopment

Install Java Code Review

skills CLI
$ npx skills add decebals/claude-code-java --skill java-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install decebals/claude-code-java java-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/java-code-review .claude/skills/java-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
java-code-review
GitHub stars
750
Token cost
~2.5k tokens
SKILL.md length
514 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Checklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity.

  • Works in 9 steps: Null Safety → Exception Handling → Collections & Streams → …
  • Reviewing a Java pull request before it is merged
  • SKILL.md covers When to Use, Review Strategy, Output Format and Review Checklist, plus 3 more sections
  • Calls git

What it does

The skill makes the agent review Java changes in three steps: a quick scan to understand intent and scope, a pass through a category checklist, and a summary that lists findings from critical down to minor. Findings follow a fixed markdown output format that starts with a Critical section.

Each checklist category gives a bad-code example, things to flag and fixes to suggest. Null safety flags chained calls, Optional.get() without a check and null returns where an empty collection fits. Exception handling flags empty catch blocks, broad catches and lost causes. Collections and streams cover modifying during iteration and immutable factories, and concurrency flags unsynchronized shared state and check-then-act races. The description also lists performance checks.

When your agent uses it

  • Reviewing a Java pull request before it is merged
  • Checking a newly implemented Java feature for common defects
  • Auditing Java code for null-pointer and exception-handling problems
  • Spotting thread-safety problems in shared Java state

Example prompts

  • “Review the changes in this PR for null safety and exception handling.”
  • “Do a code review of OrderService.java and list findings by severity.”
  • “Check this cache class for thread-safety problems before we merge.”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Null Safety
  2. Exception Handling
  3. Collections & Streams
  4. Concurrency
  5. Java Idioms
  6. Resource Management
  7. API Design
  8. Performance Considerations
  9. Testing Hints

What it can do on your machine

Read from SKILL.md and the folder at commit 0d98fe9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Java Code Review loads about 2.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 514 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from decebals/claude-code-java at commit 0d98fe9, republished under its MIT licence (© decebals). 514 words, ~2,484 tokens.

Download SKILL.mdSave it as .claude/skills/java-code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
java-code-review
description
Systematic code review for Java with null safety, exception handling, concurrency, and performance checks. Use when user says "review code", "check this PR", "code review", or before merging changes.
license
MIT

Java Code Review Skill

Systematic code review checklist for Java projects.

When to Use

  • User says "review this code" / "check this PR" / "code review"
  • Before merging a PR
  • After implementing a feature

Review Strategy

  1. Quick scan - Understand intent, identify scope
  2. Checklist pass - Go through each category below
  3. Summary - List findings by severity (Critical → Minor)

Output Format

markdown
## Code Review: [file/feature name]

### Critical
- [Issue description + line reference + suggestion]

### Improvements
- [Suggestion + rationale]

### Minor/Style
- [Nitpicks, optional improvements]

### Good Practices Observed
- [Positive feedback - important for morale]

Review Checklist

1. Null Safety

Check for:

java
// ❌ NPE risk
String name = user.getName().toUpperCase();

// ✅ Safe
String name = Optional.ofNullable(user.getName())
    .map(String::toUpperCase)
    .orElse("");

// ✅ Also safe (early return)
if (user.getName() == null) {
    return "";
}
return user.getName().toUpperCase();

Flags:

  • Chained method calls without null checks
  • Missing @Nullable / @NonNull annotations on public APIs
  • Optional.get() without isPresent() check
  • Returning null from methods that could return Optional or empty collection

Suggest:

  • Use Optional for return types that may be absent
  • Use Objects.requireNonNull() for constructor/method params
  • Return empty collections instead of null: Collections.emptyList()
2. Exception Handling

Check for:

java
// ❌ Swallowing exceptions
try {
    process();
} catch (Exception e) {
    // silently ignored
}

// ❌ Catching too broad
catch (Exception e) { }
catch (Throwable t) { }

// ❌ Losing stack trace
catch (IOException e) {
    throw new RuntimeException(e.getMessage());
}

// ✅ Proper handling
catch (IOException e) {
    log.error("Failed to process file: {}", filename, e);
    throw new ProcessingException("File processing failed", e);
}

Flags:

  • Empty catch blocks
  • Catching Exception or Throwable broadly
  • Losing original exception (not chaining)
  • Using exceptions for flow control
  • Checked exceptions leaking through API boundaries

Suggest:

  • Log with context AND stack trace
  • Use specific exception types
  • Chain exceptions with cause
  • Consider custom exceptions for domain errors
3. Collections & Streams

Check for:

java
// ❌ Modifying while iterating
for (Item item : items) {
    if (item.isExpired()) {
        items.remove(item);  // ConcurrentModificationException
    }
}

// ✅ Use removeIf
items.removeIf(Item::isExpired);

// ❌ Stream for simple operations
list.stream().forEach(System.out::println);

// ✅ Simple loop is cleaner
for (Item item : list) {
    System.out.println(item);
}

// ❌ Collecting to modify
List<String> names = users.stream()
    .map(User::getName)
    .collect(Collectors.toList());
names.add("extra");  // Might be immutable!

// ✅ Explicit mutable list
List<String> names = users.stream()
    .map(User::getName)
    .collect(Collectors.toCollection(ArrayList::new));

Flags:

  • Modifying collections during iteration
  • Overusing streams for simple operations
  • Assuming Collectors.toList() returns mutable list
  • Not using List.of(), Set.of(), Map.of() for immutable collections
  • Parallel streams without understanding implications

Suggest:

  • List.copyOf() for defensive copies
  • removeIf() instead of iterator removal
  • Streams for transformations, loops for side effects
4. Concurrency

Check for:

java
// ❌ Not thread-safe
private Map<String, User> cache = new HashMap<>();

// ✅ Thread-safe
private Map<String, User> cache = new ConcurrentHashMap<>();

// ❌ Check-then-act race condition
if (!map.containsKey(key)) {
    map.put(key, computeValue());
}

// ✅ Atomic operation
map.computeIfAbsent(key, k -> computeValue());

// ❌ Double-checked locking (broken without volatile)
if (instance == null) {
    synchronized(this) {
        if (instance == null) {
            instance = new Instance();
        }
    }
}

Flags:

  • Shared mutable state without synchronization
  • Check-then-act patterns without atomicity
  • Missing volatile on shared variables
  • Synchronized on non-final objects
  • Thread-unsafe lazy initialization

Suggest:

  • Prefer immutable objects
  • Use java.util.concurrent classes
  • AtomicReference, AtomicInteger for simple cases
  • Consider @ThreadSafe / @NotThreadSafe annotations
5. Java Idioms

equals/hashCode:

java
// ❌ Only equals without hashCode
@Override
public boolean equals(Object o) { ... }
// Missing hashCode!

// ❌ Mutable fields in hashCode
@Override
public int hashCode() {
    return Objects.hash(id, mutableField);  // Breaks HashMap
}

// ✅ Use immutable fields, implement both
@Override
public boolean equals(Object o) {
    if (this == o) return true;
    if (!(o instanceof User user)) return false;
    return Objects.equals(id, user.id);
}

@Override
public int hashCode() {
    return Objects.hash(id);
}

toString:

java
// ❌ Missing - hard to debug
// No toString()

// ❌ Including sensitive data
return "User{password='" + password + "'}";

// ✅ Useful for debugging
@Override
public String toString() {
    return "User{id=" + id + ", name='" + name + "'}";
}

Builders:

java
// ✅ For classes with many optional parameters
User user = User.builder()
    .name("John")
    .email("john@example.com")
    .build();

Flags:

  • equals without hashCode
  • Mutable fields in hashCode
  • Missing toString on domain objects
  • Constructors with > 3-4 parameters (suggest builder)
  • Not using instanceof pattern matching (Java 16+)
6. Resource Management

Check for:

java
// ❌ Resource leak
FileInputStream fis = new FileInputStream(file);
// ... might throw before close

// ✅ Try-with-resources
try (FileInputStream fis = new FileInputStream(file)) {
    // ...
}

// ❌ Multiple resources, wrong order
try (BufferedWriter writer = new BufferedWriter(new FileWriter(file))) {
    // FileWriter might not be closed if BufferedWriter fails
}

// ✅ Separate declarations
try (FileWriter fw = new FileWriter(file);
     BufferedWriter writer = new BufferedWriter(fw)) {
    // Both properly closed
}

Flags:

  • Not using try-with-resources for Closeable/AutoCloseable
  • Resources opened but not in try-with-resources
  • Database connections/statements not properly closed
Show full SKILL.md (200 more words)Show less
7. API Design

Check for:

java
// ❌ Boolean parameters
process(data, true, false);  // What do these mean?

// ✅ Use enums or builder
process(data, ProcessMode.ASYNC, ErrorHandling.STRICT);

// ❌ Returning null for "not found"
public User findById(Long id) {
    return users.get(id);  // null if not found
}

// ✅ Return Optional
public Optional<User> findById(Long id) {
    return Optional.ofNullable(users.get(id));
}

// ❌ Accepting null collections
public void process(List<Item> items) {
    if (items == null) items = Collections.emptyList();
}

// ✅ Require non-null, accept empty
public void process(List<Item> items) {
    Objects.requireNonNull(items, "items must not be null");
}

Flags:

  • Boolean parameters (prefer enums)
  • Methods with > 3 parameters (consider parameter object)
  • Inconsistent null handling across similar methods
  • Missing validation on public API inputs
8. Performance Considerations

Check for:

java
// ❌ String concatenation in loop
String result = "";
for (String s : strings) {
    result += s;  // Creates new String each iteration
}

// ✅ StringBuilder
StringBuilder sb = new StringBuilder();
for (String s : strings) {
    sb.append(s);
}

// ❌ Regex compilation in loop
for (String line : lines) {
    if (line.matches("pattern.*")) { }  // Compiles regex each time
}

// ✅ Pre-compiled pattern
private static final Pattern PATTERN = Pattern.compile("pattern.*");
for (String line : lines) {
    if (PATTERN.matcher(line).matches()) { }
}

// ❌ N+1 in loops
for (User user : users) {
    List<Order> orders = orderRepo.findByUserId(user.getId());
}

// ✅ Batch fetch
Map<Long, List<Order>> ordersByUser = orderRepo.findByUserIds(userIds);

Flags:

  • String concatenation in loops
  • Regex compilation in loops
  • N+1 query patterns
  • Creating objects in tight loops that could be reused
  • Not using primitive streams (IntStream, LongStream)
9. Testing Hints

Suggest tests for:

  • Null inputs
  • Empty collections
  • Boundary values
  • Exception cases
  • Concurrent access (if applicable)

Severity Guidelines

SeverityCriteria
CriticalSecurity vulnerability, data loss risk, production crash
HighBug likely, significant performance issue, breaks API contract
MediumCode smell, maintainability issue, missing best practice
LowStyle, minor optimization, suggestion

Token Optimization

  • Focus on changed lines (use git diff)
  • Don't repeat obvious issues - group similar findings
  • Reference line numbers, not full code quotes
  • Skip files that are auto-generated or test fixtures

Quick Reference Card

CategoryKey Checks
Null SafetyChained calls, Optional misuse, null returns
ExceptionsEmpty catch, broad catch, lost stack trace
CollectionsModification during iteration, stream vs loop
ConcurrencyShared mutable state, check-then-act
Idiomsequals/hashCode pair, toString, builders
Resourcestry-with-resources, connection leaks
APIBoolean params, null handling, validation
PerformanceString concat, regex in loop, N+1

© decebals, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/java-code-review of decebals/claude-code-java.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 0d98fe9

Compare with similar skills

Java Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Java Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Java Code Review this skilldecebals/claude-code-java750—~2.5kAutomated safety check: PassMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
SeekDB Code Reviewoceanbase/seekdb3.1k—~2.1kAutomated safety check: PassApache-2.0
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT
Code Qualitypiomin/claude-ai-spring-boot1.3k—~2.2kAutomated safety check: PassApache-2.0
Code Review Excellenceandrew-yangy/gru-ai155—~1.7kAutomated safety check: NotesMIT

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • SeekDB Code Review

    oceanbase/seekdb

    Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.

    3.1k GitHub stars~2.1k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Quality

    piomin/claude-ai-spring-boot

    Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

    1.3k GitHub stars~2.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes
  • Code Review

    ClickHouse/clickhouse-java

    Review changes in clickhouse-java for correctness, compatibility, API stability, and missing tests.

    1.6k GitHub stars~290 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from decebals/claude-code-java

All 18 skills in this repo
  • REST API Contract Review

    decebals/claude-code-java

    Reviews REST API design for correct HTTP verbs, versioning, DTO use, consistent responses and backward compatibility before an API change ships.

    750 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check passed
  • Java Architecture Review

    decebals/claude-code-java

    Reviews a Java project's architecture at the macro level: package structure, module boundaries, dependency direction and layering.

    750 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Java Design Patterns Reference

    decebals/claude-code-java

    A practical Java reference for Builder, Factory, Singleton, Strategy, Observer and other patterns, with a table matching problems to patterns.

    750 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Jpa Patterns

    decebals/claude-code-java

    JPA/Hibernate patterns and common pitfalls (N+1, lazy loading, transactions, queries).

    750 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Logging Patterns

    decebals/claude-code-java

    Java logging best practices with SLF4J, structured logging (JSON), and MDC for request tracing.

    750 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Changelog Generator for Java

    decebals/claude-code-java

    Builds changelog entries from conventional commits in a Java project, after working out whether it uses SemVer, two-part versions or calendar versions.

    750 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Java Code Review

What does Java Code Review do?

Checklist-driven review of Java code covering null safety, exception handling, collections and streams, and concurrency, with findings reported by severity. The skill makes the agent review Java changes in three steps: a quick scan to understand intent and scope, a pass through a category checklist, and a summary that lists findings from critical down to minor. Findings follow a fixed markdown output format that starts with a Critical section.

When should I use Java Code Review?

Java Code Review fits situations like: reviewing a Java pull request before it is merged; checking a newly implemented Java feature for common defects; auditing Java code for null-pointer and exception-handling problems; spotting thread-safety problems in shared Java state.

How do I install Java Code Review in Claude Code?

Run `npx skills add decebals/claude-code-java --skill java-code-review -a claude-code`. Or copy the skill folder (skills/java-code-review in decebals/claude-code-java) into .claude/skills/java-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Java Code Review in Codex?

Run `npx skills add decebals/claude-code-java --skill java-code-review -a codex`. Or copy the skill folder (skills/java-code-review in decebals/claude-code-java) into .agents/skills/java-code-review in your project. Codex loads it when a task matches its description.

Can I use Java Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add decebals/claude-code-java --skill java-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/java-code-review, .gemini/skills/java-code-review, .github/skills/java-code-review and .opencode/skills/java-code-review in your project.

What does Java Code Review need to run?

Going by SKILL.md and its folder, Java Code Review needs the command-line tools its instructions call (git).

Does Java Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Java Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Java Code Review use?

Java Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Java Code Review use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Java Code Review?

Skills that share tags, products or a category with Java Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), SeekDB Code Review (oceanbase/seekdb, 3.1k stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars) and Code Quality (piomin/claude-ai-spring-boot, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Java Code Review?

decebals (a GitHub user) maintains it in decebals/claude-code-java, which has 750 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 6, 2026.

Source: decebals/claude-code-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.