Agent skill

Structured Code Review

by FareedKhan-dev in FareedKhan-dev/claude-code-from-scratch

Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.

MITAuto-check passedDevelopment

Install Structured Code Review

skills CLI
$ npx skills add FareedKhan-dev/claude-code-from-scratch --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FareedKhan-dev/claude-code-from-scratch code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FareedKhan-dev/claude-code-from-scratch.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
298
Token cost
~809 tokens
SKILL.md length
326 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.

  • Works in 5 steps: Read before commenting → Understand intent → Categorise issues → …
  • Reviewing a file or function for bugs
  • SKILL.md covers When to use this skill, Review process, What good code review looks like and Common bugs to look for in…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The agent has to follow the same order every time. It reads the whole file and greps for callers, tests and imports; works out what the code is meant to do; sorts each issue into one of five categories (BUG, SECURITY, PERF, STYLE, SUGGEST); writes every finding with file, line, a one-sentence issue and why it matters; and closes with counts per category, the most critical problem and whether the code is safe to deploy as it stands.

Good findings cite a file and line, come with a suggested fix, separate blocking bugs from style nits and criticize the code rather than the author. The skill also lists common Python pitfalls such as mutable default arguments, typical mistakes in agent loops (unchecked tool output, missing timeouts, untruncated output, unhandled tool errors, no dangerous-command filter) and a security checklist covering secrets, shell injection and path traversal.

When your agent uses it

  • Reviewing a file or function for bugs
  • Auditing error handling and input validation in a module
  • Comparing two implementations of the same function
  • Checking a Python agent loop for missing timeouts and error handling

Example prompts

  • “Review src/agent.py for bugs and tell me whether it is safe to deploy.”
  • “Compare these two implementations of the retry helper and categorize the differences.”
  • “Audit tools/bash.py for security problems, with line numbers.”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Read before commenting
  2. Understand intent
  3. Categorise issues
  4. Write findings
  5. Summary

What it can do on your machine

Read from SKILL.md and the folder at commit fb9709e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Structured Code Review loads about 809 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 326 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~809

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FareedKhan-dev/claude-code-from-scratch at commit fb9709e, republished under its MIT licence (© FareedKhan-dev). 326 words, ~809 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Use when asked to review code, audit a file for bugs, check code quality, or suggest improvements. Provides a structured review process and issue categorisation.

Code Review Skill

When to use this skill

Load when the user asks you to:

  • Review a file or function for bugs
  • Check code quality or style
  • Suggest improvements or refactors
  • Audit security or error handling
  • Compare two implementations

Review process

Always follow this order. Do not skip steps.

Step 1 — Read before commenting

Use the read tool to read the full file first. Use grep to find related code (callers, tests, imports). Never comment on code you haven't fully read.

Step 2 — Understand intent

Ask: what is this code trying to do? Read any docstrings, comments, and function names. If the intent is unclear, note it — don't assume.

Step 3 — Categorise issues

Use these categories consistently:

CategoryWhen to use
BUGCode that will produce wrong results or crash
SECURITYInput not validated, secrets exposed, injection risks
PERFUnnecessary work, wrong data structure, O(n²) that could be O(n)
STYLEInconsistent naming, long functions, missing docstrings
SUGGESTOptional improvements — not required to fix
Step 4 — Write findings

Format each finding:

[CATEGORY] file.py:line_number
  Issue: one sentence describing the problem
  Why:   why this matters
  Fix:   concrete suggestion or corrected code snippet
Step 5 — Summary

End with:

  • Total issues found per category
  • The most critical issue (if any BUG or SECURITY)
  • Whether the code is safe to deploy as-is

What good code review looks like

  • Specific: cite file + line number, not "somewhere in the code"
  • Actionable: every issue has a suggested fix
  • Proportionate: distinguish blocking bugs from style nits
  • Respectful: review the code, not the author

Common bugs to look for in Python

python
# Mutable default argument (very common)
def append(item, lst=[]):   # BUG: lst shared across all calls
    lst.append(item)

# Exception swallowed silently
try:
    do_something()
except Exception:            # BUG: hides errors, use `except Exception as e: log(e)`
    pass

# Off-by-one in slices
items[1:len(items)]          # STYLE: prefer items[1:]

# Late binding closure
fns = [lambda: i for i in range(5)]   # BUG: all return 4
fns = [lambda i=i: i for i in range(5)]  # Fix

# Forgetting to close resources
f = open("file.txt")        # BUG: use `with open("file.txt") as f:`

Common bugs to look for in agents

  • Tool outputs not checked before use (model assumes success)
  • No timeout on subprocess calls (agent hangs forever)
  • Output not truncated (enormous tool results fill context)
  • Missing tool error handling (exception crashes the loop)
  • No dangerous command filter in bash tool

Security checklist

  • No secrets, tokens, or keys in code or comments
  • Shell commands not built from user input (injection risk)
  • File paths validated (no ../../../etc/passwd traversal)
  • External input not eval'd or exec'd
  • Dependencies pinned to versions in requirements.txt

© FareedKhan-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-review of FareedKhan-dev/claude-code-from-scratch.

Open the folder on GitHubat commit fb9709e

Compare with similar skills

Structured Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Structured Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Structured Code Review this skillFareedKhan-dev/claude-code-from-scratch298—~809Automated safety check: PassMIT
Dignified Python Standardsdocling-project/docling68k—~1.5kAutomated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 28 days ago
    DevelopmentAuto-check: notes
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes

More from FareedKhan-dev/claude-code-from-scratch

  • Agent Harness Builder

    FareedKhan-dev/claude-code-from-scratch

    Gives patterns, a tool design checklist and an architecture decision tree for building agent harnesses, tools and multi-agent setups around a model.

    298 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • PDF Library Guide

    FareedKhan-dev/claude-code-from-scratch

    Picks the right Python library for PDF jobs, with examples for text and table extraction, merging, splitting and page extraction, plus OCR and memory fixes.

    298 GitHub stars~785 tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Structured Code Review

What does Structured Code Review do?

Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary. The agent has to follow the same order every time. It reads the whole file and greps for callers, tests and imports; works out what the code is meant to do; sorts each issue into one of five categories (BUG, SECURITY, PERF, STYLE, SUGGEST); writes every finding with file, line, a one-sentence issue and why it matters; and closes with counts per category, the most critical problem and whether the code is safe to deploy as it stands.

When should I use Structured Code Review?

Structured Code Review fits situations like: reviewing a file or function for bugs; auditing error handling and input validation in a module; comparing two implementations of the same function; checking a Python agent loop for missing timeouts and error handling.

How do I install Structured Code Review in Claude Code?

Run `npx skills add FareedKhan-dev/claude-code-from-scratch --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in FareedKhan-dev/claude-code-from-scratch) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Structured Code Review in Codex?

Run `npx skills add FareedKhan-dev/claude-code-from-scratch --skill code-review -a codex`. Or copy the skill folder (skills/code-review in FareedKhan-dev/claude-code-from-scratch) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Structured Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FareedKhan-dev/claude-code-from-scratch --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Structured Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Structured Code Review is instructions for the agent only.

Does Structured Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Structured Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Structured Code Review use?

Structured Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Structured Code Review use?

About 809 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Structured Code Review?

Skills that share tags, products or a category with Structured Code Review: Dignified Python Standards (docling-project/docling, 68k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Reviewer (jewbetcha/opentrace, 116 stars) and Code Review Specialist (luongnv89/claude-howto, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Structured Code Review?

FareedKhan-dev (a GitHub user) maintains it in FareedKhan-dev/claude-code-from-scratch, which has 298 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on April 5, 2026.

Source: FareedKhan-dev/claude-code-from-scratch on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.