Agent skill

Code Review

by EliasOulkadi in EliasOulkadi/shokunin

Review code changes for correctness, security, performance, and code quality.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add EliasOulkadi/shokunin --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EliasOulkadi/shokunin code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
114
Token cost
~3.3k tokens
SKILL.md length
1,445 words
Files
1
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Review code changes for correctness, security, performance, and code quality.

  • Works in 4 steps: Obtain the diff → Gather context → Analyze changes → …
  • The user asks to review a diff
  • SKILL.md covers Inputs, Workflow, Review Tone & Psychology and Common P0/P1 Patterns To Watch…, plus 8 more sections
  • Calls git, npm and pip

What it does

Code Review is an agent skill from EliasOulkadi/shokunin. Review code changes for correctness, security, performance, and code quality. Use when the user asks to review a diff, review code changes, review commits, or perform a code review. Input can be: (1) a text diff pasted directly, (2) one or more git commit hashes to extract the diff from, or (3) a git range like abc123..def456. The user may also provide task description or requirements that motivated the change.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: opencode

It sits in Development, covering Code review. It works with Git. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.

When your agent uses it

  • The user asks to review a diff
  • Review code changes
  • Perform a code review

Example prompts

  • “/code-review”

Requirements

  • Compatibility (from SKILL.md): opencode

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Obtain the diff
  2. Gather context
  3. Analyze changes
  4. Produce the review

What it can do on your machine

Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Code Review loads about 3.3k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,445 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 1,445 words, ~3,296 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Review code changes for correctness, security, performance, and code quality. Use when the user asks to review a diff, review code changes, review commits, or perform a code review. Input can be: (1) a text diff pasted directly, (2) one or more git commit hashes to extract the diff from, or (3) a git range like abc123..def456. The user may also provide task description or requirements that motivated the change.
compatibility
opencode
triggers
review code, code review, review this change, review diff, check my code, code quality review, review my PR
negatives
comprehensive review, multi-model review, design review, UI review
license
MIT
metadata.version
1.0.0
metadata.workflow
quality
metadata.audience
developers

Code Review

Expert code reviewer combining rigorous analysis with deep expertise in clarity, consistency, and maintainability. Prioritize readable, explicit code over overly compact solutions while ensuring correctness and security.

Inputs

Accept any combination of:

  1. Text diff — pasted directly by the user
  2. Git commit hashes — one or more SHAs; extract the diff with git
  3. Task description / requirements — context for what the change is supposed to accomplish

Workflow

Step 1: Obtain the diff
  • If the user provided a text diff, use it directly.
  • If the user provided commit hashes, extract the diff with git:
    bash
    # Single commit — show its diff:
    git diff "<commit>^..<commit>"
    # Two commits — diff between them:
    git diff "<commit1>..<commit2>"
    # Range syntax (abc123..def456) — pass directly:
    git diff "<range>"
  • If the user provided a range (e.g. abc..def), pass it as a single argument.
  • If neither diff nor commits are provided, ask the user for input.
Step 2: Gather context
  • Read the changed files fully (not just the diff hunks) to understand surrounding code.
  • Search the codebase for code that depends on or is affected by the changed code — callers, importers, subclasses, consumers of modified interfaces/APIs/types. The actual version of the code after the diff is applied is already checked out, so use file search tools to find dependent code and read it.
  • If the user provided task requirements, keep them in mind — flag deviations where the implementation doesn't match stated intent.
Step 3: Analyze changes

Review against two tiers using the checklist below.

Priority Levels
LevelMeaningAction
P0Critical — security vulnerability, data loss risk, crashMust fix
P1Major — significant bug, performance regression, broken featureMust fix
P2Minor — code smell, clarity issue, inconsistencyNice to fix
P3Suggestion — improvement idea, optional refactorOptional
Critical Issues (P0–P1)

Correctness:

  • Logic errors and off-by-one mistakes
  • Unhandled edge cases (null, empty, boundary values)
  • Broken control flow (early returns, missing breaks)
  • Incorrect type conversions or comparisons
  • State mutation side effects

Security:

  • Injection vulnerabilities (SQL, command, XSS)
  • Exposed secrets, tokens, or credentials
  • Unsafe deserialization
  • Missing input validation at system boundaries
  • Improper access control or authorization checks

Performance:

  • Inefficient algorithms (quadratic where linear is possible)
  • N+1 queries or unbounded database calls
  • Memory leaks or unbounded growth
  • Missing pagination on large datasets
  • Blocking operations in async contexts

Data Integrity:

  • Race conditions in concurrent code
  • Missing transactions for multi-step writes
  • Data loss on error paths
  • Inconsistent state after partial failures
Code Quality (P2–P3)

Clarity:

  • Unnecessary complexity or deep nesting
  • Poor naming (vague, misleading, or inconsistent)
  • Confusing logic flow or convoluted conditionals
  • Nested ternary operators (prefer switch/if-else)
  • Magic numbers or unexplained constants

Consistency:

  • Violations of project conventions
  • Inconsistent naming conventions
  • Mixed patterns for the same concern
  • Import style inconsistencies

Maintainability:

  • Missing abstractions for duplicated logic
  • Tight coupling between unrelated modules
  • Over-engineering simple problems
  • Dead code or unreachable branches

Simplification:

  • Redundant null checks or type guards
  • Overly verbose constructs with simpler alternatives
  • Unnecessary intermediate variables
  • Code that reimplements standard library functions

Principles:

  • Only flag issues introduced by the change, not pre-existing problems.
  • Preserve functionality — suggest changes to HOW, never WHAT.
  • Prefer explicit code over clever one-liners.
  • Consider the user's stated requirements when judging correctness.
Step 4: Produce the review

Output this format:

## Code Review

**Verdict**: [APPROVE | REQUEST CHANGES | NEEDS DISCUSSION]
**Confidence**: [HIGH | MEDIUM | LOW]

### Summary
[1-2 sentences: what the change does and overall assessment]

### Findings

| Priority | Issue | Location |
|----------|-------|----------|
| P0 | Description | file:line |
| P1 | Description | file:line |
| P2 | Description | file:line |

### Details

#### [P0/P1] Issue title
**File:** `path/to/file.ext:line`

Description of the issue and why it matters.

**Suggested fix:**
\```
code suggestion
\```

(Repeat for each P0/P1 finding. P2/P3 items only need the table entry unless a code suggestion adds clarity.)

### Recommendation
[Concise actionable recommendation for the author]

Rules:

  • Use APPROVE only when there are no P0 or P1 findings.
  • Use REQUEST CHANGES when P0 or P1 findings exist.
  • Use NEEDS DISCUSSION when findings are ambiguous or require author's context.
  • Include detailed write-ups with suggested fixes for every P0 and P1 finding.
  • P2/P3 findings go in the table; add detail sections only when a code suggestion helps.
  • Keep it concise — don't pad with praise or filler.

Review Tone & Psychology

SituationApproachWhy
First-time contributorMore context, more encouragement, fewer P2/P3Build confidence, don't overwhelm
Senior teammate regularDirect, skip obvious nits, focus on P0/P1Respect their experience
Critical security fixMaximum rigor, verify every pathOne oversight = incident
Design/style PRSuggest alternatives, not absolutesStyle is subjective, solve the problem
Junior developerExplain the "why" behind every findingTeach fundamentals, not just "fix this"

Always assume positive intent. Phrase findings as observations: "This path returns null when..." not "You forgot to handle..."

Common P0/P1 Patterns To Watch For

PatternWhy it's dangerousHow to detect
Missing auth check on new endpointUnauthenticated access to dataCheck if the endpoint/service is behind auth middleware
SQL concatenationInjection vulnerabilityLook for ${var} in query strings
Hardcoded secret/tokenCredential exposureGrep for sk-, AKIA, -----BEGIN
No input validation on user-facing APIMalformed data crashes the systemCheck API boundary for validation middleware
Unbounded array/list growthMemory exhaustionCheck if push/add has a limit check
Swallowing errors silentlySilent data corruptionLook for empty catch {} blocks
Race condition in concurrent codeData corruptionCheck shared state without locks
Missing pagination on list endpointPerformance regression under loadCheck if query has LIMIT/OFFSET

Review Speed Guide

Diff SizeApproachEstimated time
1-50 linesFull line-by-line review2-5 min
50-200 linesRead all, focus on changed logic5-10 min
200-500 linesRead structure, sample key paths10-15 min
500+ linesRead description + key files; flag if too large15+ min
Generated/auto-formatted codeCheck output correctness only1-2 min

Show full SKILL.md (622 more words)Show less

Error Handling

CauseFix
User provides no diff, no commits, no rangeAsk for input before proceeding. Don't guess or review random code.
Git diff on a single commit returns emptyUse git diff <commit>^..<commit> to show changes introduced by that commit.
Diff exceeds 500 lines and is unreviewableFlag the size as a P3 finding. Review structure only, sample key paths.
Changed file deleted in working treeVerify file still exists before reading. Note the deletion in review.
Diff contains binary or generated filesSkip binary files. For generated code, check output correctness only.
Reference code (callers/importers) not foundNote limited context in review. Flag that surrounding analysis was incomplete.
Task requirements contradict the diffFlag the deviation as a finding. Note what the requirement says vs what the code does.
Multiple commit hashes provided, one is invalidVerify each hash with git cat-file -t <hash>. Skip invalid hashes, review remaining.

Anti-Patterns

PatternProblemFix
Reviewing pre-existing code not in the diffScope creep. Overwhelms the author with unrelated issues.Only flag issues introduced by the change. Mention pre-existing issues separately if critical.
Flagging style preferences as P0/P1 bugsDilutes severity. Authors ignore future reviews.P0 = crash/security/data loss. P1 = broken feature. P2 = code smell. P3 = preference.
Suggesting functional changes beyond the diff scopeChanges WHAT the code does, not HOWPreserve functionality. Only suggest changes to implementation approach.
"This could be simplified" with no specific alternativeVague, unactionable, frustratingAlways provide a concrete suggested fix with code example.
Reviewing generated or vendored code line-by-lineWaste of reviewer timeCheck only output correctness. Skip formatting/style on generated code.
Using absolute language ("This is wrong") without evidenceDefensive response from authorPhrase as observation: "This path returns null when..." with evidence.
Padding review with praise or fillerWastes author's reading timeKeep it concise. Verdict, findings table, details for P0/P1 only.
Not reading surrounding code for contextMisses callers, importers, and downstream effectsRead changed files fully. Search for dependents. Understand the blast radius.

Security Review Checklist

  • Input validation: all user input validated at boundary
  • SQL: parameterized queries (no string interpolation)
  • Authentication: every endpoint checks auth
  • Authorization: resource ownership verified server-side
  • Secrets: no API keys, tokens, or passwords in code
  • Error messages: no stack traces or internal paths exposed
  • File uploads: type validated, size limited, stored outside webroot
  • Rate limiting: on auth, password reset, and email endpoints
  • Dependencies: npm audit or pip check passes with zero HIGH/CRITICAL

Performance Review Patterns

  • Database: no N+1 queries. Check ORM eager loading.
  • Caching: expensive computations cached. Cache invalidation strategy documented.
  • Bundle size: new dependency impact checked. Tree-shaking verified.
  • Lazy loading: heavy modules split into dynamic imports
  • Memory: no unbounded arrays or maps. Large datasets use pagination/cursors.
  • Network: requests batched. No waterfall of sequential API calls.
  • Render: no unnecessary re-renders. Memoization where appropriate.

Architectural Review Guidelines

  • Single responsibility: each module has one reason to change
  • Dependency direction: high-level modules don't depend on low-level details
  • Testing: new code has tests. Tests cover happy path + error + edge cases.
  • Documentation: public APIs documented. Complex logic has inline comments explaining WHY.
  • Migration: breaking changes have clear migration path or compatibility layer.

Sources

  • Google Engineering Practices — "How to Do a Code Review" (google.github.io/eng-practices)
  • SmartBear — "Best Practices for Code Review" (smartbear.com)
  • Palantir — "Code Review Best Practices" (blog.palantir.com)
  • Microsoft — "Code Review Checklist" (learn.microsoft.com)
  • OWASP Code Review Guide — owasp.org/www-project-code-review-guide
  • Conventional Comments — conventionalcomments.org
  • Philipp Hauer — "Code Review Guidelines for Humans" (philipphauer.de)
  • Trisha Gee — "Code Review Best Practices" (trishagee.com)

Checklist

  • Skill loads without errors in the AI agent
  • YAML frontmatter is valid (description, compatibility, audience)
  • Workflow section provides clear step-by-step instructions
  • Error handling section covers common failure modes
  • All referenced files (references/, scripts/, assets/) exist
  • Skill triggers correctly for intended use cases
  • No broken links or missing resources

© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .pack/skills/code-review of EliasOulkadi/shokunin.

Open the folder on GitHubat commit 4c68e5b

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillEliasOulkadi/shokunin114—~3.3kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything86k—~1.4kAutomated safety check: PassMIT
Open Code Review Delegatealibaba/open-code-review46k—~2.3kAutomated safety check: PassApache-2.0
Code Reviewflutter/flutter179k—~1.4kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    46k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed

More from EliasOulkadi/shokunin

All 49 skills in this repo
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Component Forge

    EliasOulkadi/shokunin

    Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…

    114 GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check: notes
  • DB Admin

    EliasOulkadi/shokunin

    PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…

    114 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check: notes
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 5 days ago
    Auto-check: notes
  • Docker

    EliasOulkadi/shokunin

    Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

    114 GitHub stars~3.8k tokensUpdated 5 days ago
    Auto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check: notes

Works with

Categories

Questions about Code Review

What does Code Review do?

Review code changes for correctness, security, performance, and code quality. Code Review is an agent skill from EliasOulkadi/shokunin. Review code changes for correctness, security, performance, and code quality.

When should I use Code Review?

Code Review fits situations like: the user asks to review a diff; review code changes; perform a code review.

How do I install Code Review in Claude Code?

Run `npx skills add EliasOulkadi/shokunin --skill code-review -a claude-code`. Or copy the skill folder (.pack/skills/code-review in EliasOulkadi/shokunin) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add EliasOulkadi/shokunin --skill code-review -a codex`. Or copy the skill folder (.pack/skills/code-review in EliasOulkadi/shokunin) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git, npm and pip). Compatibility (from SKILL.md): opencode.

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Open Code Review CLI (alibaba/open-code-review, 46k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars) and Open Code Review Delegate (alibaba/open-code-review, 46k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.

Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.