Agent skill

Code Review

by evanca in evanca/flutter-ai-rules

A skill your agent uses when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add evanca/flutter-ai-rules --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install evanca/flutter-ai-rules code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/evanca/flutter-ai-rules.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
647
Token cost
~2.4k tokens
SKILL.md length
1,220 words
Files
4 (incl. scripts, references)
Skills in repo
37
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.

  • Works in 5 steps: Validate branch and merge target → Discover changes → Review each file → …
  • Asked to review a PR
  • SKILL.md covers When to Use, Review Workflow, Wrap-Up and Feedback Standards, plus 1 more section
  • Runs Shell scripts from its folder; calls curl; needs GITLAB_TOKEN and GITHUB_TOKEN

What it does

Code Review is an agent skill from evanca/flutter-ai-rules. Use when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/github-posting.md`, `references/gitlab-posting.md` and `scripts/protect-token.sh`).

It sits in Development, covering Code review, Cross-platform mobile apps and Code quality. The repository describes itself as: Flutter AI Skills and Rules for Claude, Codex, Cursor, and Other AI-Powered IDEs. The licence is MIT.

When your agent uses it

  • Asked to review a PR
  • Audit changed files
  • Check code quality

Example prompts

  • “/code-review”

Requirements

  • A Bash shell
  • A credential in GITLAB_TOKEN
  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Validate branch and merge target
  2. Discover changes
  3. Review each file
  4. Evaluate the overall change set
  5. Verify CI and tests

What it can do on your machine

Read from SKILL.md and the folder at commit 7b9cce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • refactoring.guru

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITLAB_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.4k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 27 tokens; SKILL.md has 1,220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from evanca/flutter-ai-rules at commit 7b9cce2, republished under its MIT licence (© evanca). 1,220 words, ~2,391 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
code-review
description
Use when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.
license
MIT

Code Review Skill

Perform structured, objective code reviews for Flutter/Dart projects following a repeatable checklist.

When to Use

Use this skill when:

  • Asked to review a pull request, merge request, or branch.
  • Evaluating changed, added, or deleted files for correctness and quality.
  • Auditing a diff before merging.
  • Checking whether new code meets project standards.

Review Workflow

Step 1 — Validate branch and merge target
  1. Confirm the current branch is a feature, bugfix, or PR/MR branch — not the project's primary branch (e.g. main, master, develop).
  2. Verify the branch is up-to-date with the target branch (no unresolved conflicts).
  3. Identify the target branch for the merge.

Checkpoint: If the branch is behind the target, flag it before proceeding.

Step 2 — Discover changes
  1. List all changed, added, and deleted files.
  2. For each change, look up the commit title and review how connected components are implemented.
  3. Analyze the change: is it clear why the change was made? If not, dig into the connected methods and files until it is. When you report, name which connected files/methods you analyzed and why — this shows the change was understood, not assumed.
  4. Never assume a change is correct without investigating the implementation.
  5. If a change remains unclear after investigation, note this explicitly in the report.
Step 3 — Review each file

Iterate through each changed file. For every file, verify the following:

AreaWhat to verify
Understand the changeWhy was it made? Review connected methods/files; note which ones you analyzed and why
LocationFile is in the correct directory
NamingFile name follows project naming conventions
ResponsibilityThe file's responsibility is clear; reason for change is understandable
ReadabilityVariable, function, and class names are descriptive and consistent
Logic & correctnessNo logic errors or missing edge cases
Code smellsScan for the smells in Code Smells Reference below
MaintainabilityCode is modular; no unnecessary duplication
Error handlingErrors and exceptions are handled appropriately
SecurityNo input validation gaps; no secrets committed to code
PerformanceNo obvious inefficiencies (e.g., unnecessary rebuilds, O(n^2) loops on large lists)
SOLID principlesAdherence assessed without forcing unnecessary boilerplate or over-abstraction
Flutter/Dart/<your-state-management-package> patternsMatch against the project's loaded guidelines and conventions
DocumentationPublic APIs, complex logic, and new modules are documented
Test coverageNew or changed logic has sufficient tests (see Step 4)
StyleCode matches the project's style guide and linting rules
Existing codeIf the new changes look fine, also review surrounding existing (unchanged) code for smells and suggest refactors where relevant

For generated files (e.g., *.g.dart, *.freezed.dart): confirm they are up-to-date and not manually modified.

Scope discipline: Your job is not to comment on every change — it's to find errors and concrete improvement areas and comment on those. Don't manufacture comments where the code is fine.

Flutter-specific checks

(Note: The following is just an example using Bloc/Cubit; apply similar principles to Riverpod, Provider, or your chosen state management package.)

dart
// BAD — rebuilds entire tree on every state change
BlocBuilder<MyCubit, MyState>(
  builder: (context, state) => EntireScreen(state: state),
);

// GOOD — scope rebuilds to the widget that actually changes
BlocSelector<MyCubit, MyState, String>(
  selector: (state) => state.title,
  builder: (context, title) => Text(title),
);
  • Verify Key usage on dynamically generated widgets.
  • Check that dispose() is called for controllers, streams, and animation controllers.
  • Confirm const constructors are used where possible.
Code Smells Reference

For each file, check for common code smells. Use refactoring.guru/refactoring/smells for definitions and suggested refactorings.

CategorySmells
BloatersLong Method, Large Class, Primitive Obsession, Long Parameter List, Data Clumps
Object-Orientation AbusersAlternative Classes with Different Interfaces, Refused Bequest, Temporary Field, Switch Statements
Change PreventersDivergent Change, Parallel Inheritance Hierarchies, Shotgun Surgery
DispensablesComments (redundant), Duplicate Code, Data Class, Dead Code, Lazy Class, Speculative Generality
CouplersFeature Envy, Inappropriate Intimacy, Incomplete Library Class, Message Chains, Middle Man
Step 4 — Evaluate the overall change set
  1. Verify the change set is focused and scoped to its stated purpose — no unrelated changes.
  2. Check that the PR/MR description accurately reflects the changes.
Test coverage

Verify test coverage explicitly — this is easy to skip and easy to fake, so be deliberate:

  • For any new logic or significant change, search for the corresponding test file(s) and confirm tests actually exist.
  • Check that tests cover the changed functionality including edge cases, not just the happy path.
  • Evaluate whether tests could actually fail against real code, or only verify mocked behavior (a test that asserts a mock returns what the mock was told to return proves nothing).
  • If tests are missing or insufficient, comment on the lack of coverage — don't let it pass silently.
Show full SKILL.md (502 more words)Show less
Step 5 — Verify CI and tests
  1. Ensure all tests pass in CI.
  2. Check for new analyzer warnings or lint violations.
  3. Fetch official documentation when unsure about best practices for a package.

Checkpoint: If CI is red or tests are missing for new logic, flag as a blocking issue.


Wrap-Up

After the per-file pass, decide the outcome:

  • If everything looks good and no changes are needed: post an overall conclusion comment summarizing what the MR is about (what was done) plus any observations, and approve the MR.
  • If the new changes are clean but you spotted smells in existing code: include those as optional refactor suggestions rather than blockers.
  • If issues were found: summarize the key concerns clearly so the author knows what to address first.

Feedback Standards

  • Be objective and reasonable — avoid automatic praise or flattery.
  • Take a devil's advocate approach: give honest, thoughtful feedback.
  • Provide clear, constructive suggestions for every issue found.
  • Include requests for clarification for anything unclear.
  • Classify each finding by severity: suggestion, minor, or major.

Output Format

By default, provide the review as a chat response — a structured response covering each file:

  1. Summary — what changed and why.
  2. Issues — each with severity (suggestion / minor / major) and a concrete fix suggestion.
  3. Questions — specific clarification requests per file.
  4. Verdict — one of: Approved, Approved with suggestions, or Changes requested.

Posting comments online (opt-in only). After presenting the chat review, ask the user whether they'd prefer you to also post these comments online on the PR/MR — so the team can see them, review them, and reply. Only post online if the user explicitly says yes. Never post to the platform on your own initiative.

When the user does opt in, post issues as inline comments anchored to the right file and line (use proper position fields), with the conclusion/key-concerns as a top-level review comment and an approval when warranted. This requires a review-bot access token for the platform (GitHub/GitLab); if one isn't configured, let the user know and ask them to set it up before posting.

Token safety. The token is a secret. You may check whether it exists and report its length to confirm it's configured, but never read, echo, log, print, or otherwise reveal the token value — not in chat, not in a file, not in a commit. Pass it to curl only by referencing the env var (e.g. $GITLAB_TOKEN), never by inlining the literal value, and avoid curl -v/--verbose (it prints the auth header). This is enforced by a PreToolUse hook (scripts/protect-token.sh) that blocks any Bash command which would expose the value. See the "Handling the token safely" section in each reference file for the safe existence/length check.

The hook fires in both the Claude Code CLI and the Agent SDK. (SDK apps that set settingSources/setting_sources explicitly must include "project" for skill hooks to load; it's included by default.)

For platform-specific API details, curl formats, and approval steps, follow:

© evanca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/code-review of evanca/flutter-ai-rules.

  • SKILL.md
  • references/github-posting.md
  • references/gitlab-posting.md
  • scripts/protect-token.sh

Open the folder on GitHubat commit 7b9cce2

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillevanca/flutter-ai-rules647—~2.4kAutomated safety check: PassMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Reviewdotnet/maui23k—~8.2kAutomated safety check: PassMIT
Code Revieweralirezarezvani/claude-skills28k1 repos~1.6kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Skill Doli Code ReviewDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Code Review

    dotnet/maui

    Official

    Deep code review of PR or materialized candidate-patch changes for correctness, safety, and MAUI conventions.

    23k GitHub stars~8.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-skills

    Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C, .NET, Java, C, C++, Rust, Ruby, PHP, and Dart/Flutter.

    28k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Skill Doli Code Review

    Dolibarr/dolibarr

    Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

    7.7k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from evanca/flutter-ai-rules

All 37 skills in this repo
  • Developing Genkit Dart

    evanca/flutter-ai-rules

    A skill your agent uses when building AI agents in Dart, implementing Genkit flows or tools, integrating LLMs into Dart or Flutter applications, or using Genkit Dart plugins.

    647 GitHub stars~961 tokensUpdated 23 days ago
    Auto-check passed
  • Generate Images With Firebase AI

    evanca/flutter-ai-rules

    A skill your agent uses when generating or editing images from Flutter/Dart with Firebase AI Logic and a Gemini image model (Nano Banana), making the first call work, choosing Gemini Developer API…

    647 GitHub stars~2.3k tokensUpdated 23 days ago
    Auto-check passed
  • Flutter Use Column Row First

    evanca/flutter-ai-rules

    A skill your agent uses when building any Flutter screen or component to choose responsive Row, Column, Expanded, Flexible, and Spacer layouts before fixed-size or coordinate-based alternatives.

    647 GitHub stars~1.3k tokensUpdated 23 days ago
    Auto-check passed
  • Architecture Feature First

    evanca/flutter-ai-rules

    A skill your agent uses when creating a feature, designing folder structure, adding repositories/services/view models, wiring dependency injection, or deciding which layer owns logic.

    647 GitHub stars~1.9k tokensUpdated 23 days ago
    Auto-check passed
  • Bloc

    evanca/flutter-ai-rules

    A skill your agent uses when creating a Cubit or Bloc, modeling state with sealed classes or status enums, wiring BlocBuilder/BlocListener/BlocProvider, writing bloc tests, or choosing between Cubit…

    647 GitHub stars~2.8k tokensUpdated 23 days ago
    Auto-check passed
  • Dart 3 Updates

    evanca/flutter-ai-rules

    A skill your agent uses when writing switch statements, refactoring if-else chains, creating data classes, choosing records vs classes, destructuring values, or modernizing pre-Dart-3 code.

    647 GitHub stars~2k tokensUpdated 23 days ago
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

A skill your agent uses when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality. Code Review is an agent skill from evanca/flutter-ai-rules. Use when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.

When should I use Code Review?

Code Review fits situations like: asked to review a PR; audit changed files; check code quality.

How do I install Code Review in Claude Code?

Run `npx skills add evanca/flutter-ai-rules --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in evanca/flutter-ai-rules) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add evanca/flutter-ai-rules --skill code-review -a codex`. Or copy the skill folder (skills/code-review in evanca/flutter-ai-rules) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add evanca/flutter-ai-rules --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs a shell for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named GITLAB_TOKEN and GITHUB_TOKEN. Our summary lists: A Bash shell; A credential in GITLAB_TOKEN; A credential in GITHUB_TOKEN.

Does Code Review access the network?

SKILL.md names 1 domain. As links in the text: refactoring.guru. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Review use?

Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review (dotnet/maui, 23k stars), Code Reviewer (alirezarezvani/claude-skills, 28k stars) and WooCommerce Code Review (woocommerce/woocommerce, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

evanca (a GitHub user) maintains it in evanca/flutter-ai-rules, which has 647 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on September 14, 2026.

Source: evanca/flutter-ai-rules on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.