Agent skill

Code Review

by echoVic in echoVic/blade-code

Review frontend code for best practices, bugs, and improvements.

MITAuto-check: notesDevelopment

Install Code Review

skills CLI
$ npx skills add echoVic/blade-code --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install echoVic/blade-code code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.blade/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
180
Token cost
~377 tokens
SKILL.md length
81 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Review frontend code for best practices, bugs, and improvements.

  • Works in 3 steps: 读取指定的文件或目录 → 检查以下方面 → 提供具体的改进建议
  • Checking code quality
  • SKILL.md covers Instructions, 审查要点, Output Format and Examples
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review is an agent skill from echoVic/blade-code. Review frontend code for best practices, bugs, and improvements. Use when reviewing PRs, checking code quality, or before committing.

Its SKILL.md is about 380 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality and Code review. It works with TypeScript. The repository describes itself as: AI-powered CLI coding agent with 20+ built-in tools, MCP support, and multi-model providers. The licence is MIT.

When your agent uses it

  • Checking code quality
  • Before committing

Example prompts

  • “/code-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 读取指定的文件或目录
  2. 检查以下方面
  3. 提供具体的改进建议

What it can do on your machine

Read from SKILL.md and the folder at commit 30f8684. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 377 tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 81 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~377

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from echoVic/blade-code at commit 30f8684, republished under its MIT licence (© echoVic). 81 words, ~377 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Review frontend code for best practices, bugs, and improvements. Use when reviewing PRs, checking code quality, or before committing.
allowed-tools
Read, Grep, Glob, Bash
argument-hint
<file_path>
user-invocable
true

前端代码审查

对前端代码进行审查,检查最佳实践、潜在错误和改进建议。

Instructions

  1. 读取指定的文件或目录
  2. 检查以下方面:
    • 代码风格一致性(ESLint、Prettier 等)
    • 潜在的 bug 或错误
    • 性能问题
    • 安全漏洞
    • 可读性和可维护性
    • 前端特定问题(如 React hooks 规则、状态管理、组件设计等)
    • TypeScript 类型安全
    • CSS/样式最佳实践
  3. 提供具体的改进建议

审查要点

JavaScript/TypeScript
  • 检查未使用的变量和导入
  • 确保正确使用异步操作(async/await, Promise)
  • 检查错误处理是否完善
  • 验证 React hooks 使用是否符合规则
  • 检查状态管理是否合理
  • 确保组件设计遵循单一职责原则
性能
  • 检查不必要的组件重渲染
  • 验证是否使用了适当的 memoization
  • 检查是否有内存泄漏风险
  • 确保资源(如事件监听器)被正确清理
安全性
  • 检查 XSS 漏洞(如 dangerouslySetInnerHTML 的使用)
  • 验证用户输入是否被正确验证和转义
  • 检查 API 调用是否安全
可访问性 (Accessibility)
  • 检查是否使用了适当的 ARIA 属性
  • 验证语义化 HTML 标签的使用
  • 确保键盘导航支持
TypeScript
  • 检查类型定义是否完整和准确
  • 验证是否避免了 any 类型的滥用
  • 确保接口和类型定义清晰

Output Format

  • 问题严重程度:🔴 严重 | 🟡 警告 | 🔵 建议
  • 具体位置和代码片段
  • 问题描述
  • 改进建议和示例代码
  • 相关最佳实践链接(如适用)

Examples

严重问题示例
🔴 严重: 潜在 XSS 漏洞
文件: src/components/UserProfile.tsx:25
问题: 使用了 dangerouslySetInnerHTML 且未对内容进行适当清理
建议: 使用 React 组件替代或对内容进行适当的 HTML 转义
警告问题示例
🟡 警告: 性能问题
文件: src/components/ItemList.tsx:42
问题: 在渲染循环中创建新函数,可能导致不必要的重渲染
建议: 将函数移出渲染函数或使用 useCallback 包装
建议改进示例
🔵 建议: 代码可读性
文件: src/utils/helpers.ts:15
问题: 函数名称不够描述性
建议: 将函数名从 processData 更改为更具体的 transformUserData

© echoVic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .blade/skills/code-review of echoVic/blade-code.

Open the folder on GitHubat commit 30f8684

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillechoVic/blade-code180—~377Automated safety check: NotesMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT
Code Reviewbennycode/trading-signals994—~203Automated safety check: PassNone
Code Revieweralirezarezvani/claude-code-tresor777—~1.8kAutomated safety check: PassMIT
Code ReviewerLeoYeAI/openclaw-master-skills2.2k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Review

    bennycode/trading-signals

    Repository coding standards for reviewing pull requests. An agent skill from bennycode/trading-signals.

    994 GitHub stars~203 tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Reviewer

    LeoYeAI/openclaw-master-skills

    Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin.

    2.2k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Code Quality

    waybarrios/opencode-power-pack

    Agents should invoke this skill for code reviews, linting/formatting setup, maintainability checks, complexity concerns, warning cleanup, coding standards, or quality gates in Rust, TypeScript…

    533 GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from echoVic/blade-code

All 38 skills in this repo
  • Base64 Parser

    echoVic/blade-code

    Base64 编解码工具,支持编码/解码文本、JSON、二进制文件,自动检测格式,支持批量处理. An agent skill from echoVic/blade-code.

    180 GitHub stars~545 tokensUpdated 10 days ago
    Auto-check: notes
  • GitHub Explorer

    echoVic/blade-code

    Explore and summarize popular GitHub projects. An agent skill from echoVic/blade-code.

    180 GitHub stars~434 tokensUpdated 10 days ago
    Auto-check passed
  • 覆盖 Session 级 LSP 配置快照、stdio 进程、文档同步、语义查询、诊断回注、崩溃恢复 和子 Session 继承。进入条件:新增语言服务器、修改 LSP 工具、排查诊断缺失/重复、 处理 worktree 或 ACP 差异、修复进程泄漏或 transport 代际问题。不包含:VS Code 扩展桥接(见…

    180 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed
  • 覆盖 SkillRegistry、SKILL.md 延迟加载、自定义命令 Markdown 解析、来源覆盖、插件 命名空间、Session 快照和模型/用户调用入口。进入条件:新增 Skill 或命令字段、调整 发现优先级、调试 /command 或 Skill 工具、修改 Prompt 元数据或消费者集成。不包含: 插件安装生命周期(见…

    180 GitHub stars~2.1k tokensUpdated 10 days ago
    Auto-check passed
  • Covers 领域能力如何包装成内置工具、getBuiltinTools 的 Session 依赖注入、ToolSearch 延迟激活,以及 Goal/Task/Team/Plan/Skill/LSP/MCP/Web/Config/Worktree 适配边界。

    180 GitHub stars~2.1k tokensUpdated 10 days ago
    Auto-check passed
  • 覆盖 Blade 的用户/项目/local/调用级配置合并、workspace 定向解析、运行时 Store 投影和字段持久化路由。

    180 GitHub stars~1.7k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Code Review

What does Code Review do?

Review frontend code for best practices, bugs, and improvements. Code Review is an agent skill from echoVic/blade-code. Review frontend code for best practices, bugs, and improvements.

When should I use Code Review?

Code Review fits situations like: checking code quality; before committing.

How do I install Code Review in Claude Code?

Run `npx skills add echoVic/blade-code --skill code-review -a claude-code`. Or copy the skill folder (.blade/skills/code-review in echoVic/blade-code) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add echoVic/blade-code --skill code-review -a codex`. Or copy the skill folder (.blade/skills/code-review in echoVic/blade-code) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add echoVic/blade-code --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 377 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Reviewer (jewbetcha/opentrace, 116 stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars), Code Review (bennycode/trading-signals, 994 stars) and Code Reviewer (alirezarezvani/claude-code-tresor, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

echoVic (a GitHub user) maintains it in echoVic/blade-code, which has 180 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 27, 2026.

Source: echoVic/blade-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.