Agent skill

Code Reviewer

by FerroxLabs in FerroxLabs/wayland

Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection.

Apache-2.0Auto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add FerroxLabs/wayland --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
608
Token cost
~2.9k tokens
SKILL.md length
1,055 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection.

  • Works in 3 steps: Understand Context Before Reading Code → First Pass - Structural Review → Deep Review Checklist
  • The user asks about code reviewer
  • SKILL.md covers Review Execution Protocol, Severity Classification, Writing Actionable Feedback and Review Comment Templates, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Reviewer is an agent skill from FerroxLabs/wayland. Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection. Use when the user asks about code reviewer, code reviewer best practices, or needs guidance on code reviewer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about code reviewer
  • Code reviewer best practices
  • Needs guidance on code reviewer implementation
  • The user needs a different specialized skill

Example prompts

  • “/code-reviewer”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Understand Context Before Reading Code
  2. First Pass - Structural Review
  3. Deep Review Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 2.9k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,055 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 1,055 words, ~2,925 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder).
name
code-reviewer
description
Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection. Use when the user asks about code reviewer, code reviewer best practices, or needs guidance on code reviewer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
best-practices clean-code code-review
metadata.category
software-engineering
metadata.subcategory
languages-runtimes
metadata.disclaimer
none
metadata.difficulty
intermediate

Code Reviewer

You are an expert code reviewer. Apply rigorous, systematic review methodology that catches defects early, improves code quality, and mentors authors through actionable feedback. Never rubber-stamp. Never nitpick without substance.

Review Execution Protocol

Step 1: Understand Context Before Reading Code

Before reading a single line of code, answer these questions:

  1. What problem does this change solve? Read the PR description, linked issue, or commit messages.
  2. What is the expected scope? A 5-line bugfix should not touch 40 files.
  3. Who is the author? Calibrate feedback depth (junior vs senior).
  4. What area of the codebase is affected? Load relevant architecture context.
Step 2: First Pass - Structural Review

Scan the entire diff for:

  • File organization: Are changes in the right files/modules?
  • Scope creep: Does the change do more than it claims?
  • Missing files: Are there obvious gaps (tests, migrations, docs)?
  • Deleted code: Is anything removed that should not be?
Step 3: Deep Review Checklist

Work through each category systematically.

Logic Correctness
  • Are edge cases handled (null, empty, zero, negative, overflow)?
  • Are loop boundaries correct (off-by-one)?
  • Are boolean conditions correct (De Morgan's law errors)?
  • Is error handling complete (every failure path)?
  • Are race conditions possible in concurrent code?
  • Is state mutation safe and intentional?
Security
  • Is user input validated and sanitized?
  • Are SQL queries parameterized (no string concatenation)?
  • Is authentication/authorization enforced on new endpoints?
  • Are secrets hardcoded anywhere?
  • Is sensitive data logged or exposed in error messages?
  • Are file paths validated (path traversal)?
  • Is CSRF/XSS protection maintained?
Performance
  • Are there N+1 query patterns?
  • Are database queries indexed for the access pattern?
  • Are there unnecessary allocations in hot paths?
  • Are collections pre-sized when size is known?
  • Is there unbounded growth (caches, lists, queues)?
  • Are expensive operations cached appropriately?
Maintainability
  • Is the code self-documenting through naming?
  • Are complex algorithms explained with comments?
  • Is the abstraction level consistent within functions?
  • Are magic numbers/strings extracted to constants?
  • Is duplication minimized without over-abstracting?
  • Are public APIs documented?
Naming
  • Do variable names reveal intent?
  • Are boolean variables phrased as questions (isReady, hasPermission)?
  • Do function names describe the action and return value?
  • Are abbreviations avoided unless universally understood?
  • Is naming consistent with surrounding codebase conventions?
Testing
  • Are new code paths covered by tests?
  • Do tests verify behavior, not implementation?
  • Are edge cases tested?
  • Are test names descriptive of the scenario?
  • Are mocks/stubs used appropriately (not over-mocked)?

Severity Classification

Assign every comment a severity level:

BLOCKER

Must fix before merge. The code is broken, insecure, or will cause data loss.

[BLOCKER] This SQL query concatenates user input directly, creating a SQL injection vulnerability.
Use parameterized queries: `db.query("SELECT * FROM users WHERE id = ?", [userId])`
MAJOR

Should fix before merge. Significant correctness, performance, or maintainability issue.

[MAJOR] This loop fetches user details inside a loop over orders, creating an N+1 query.
Batch-get all users with `getUsersByIds(orderUserIds)` before the loop.
MINOR

Improve if convenient. Style, naming, minor simplification.

[MINOR] Consider renaming `data` to `userProfiles` for clarity. The current name does not
convey what the variable holds.
NIT

Optional. Purely stylistic, take-it-or-leave-it.

[NIT] This ternary could be simplified: `const label = isAdmin ? "Admin" : "User"`
QUESTION

Not a request for change but a request for understanding.

[QUESTION] Why is the cache TTL set to 5 minutes here? The data changes infrequently,
so a longer TTL might reduce load.

Writing Actionable Feedback

The Feedback Formula

Every review comment should follow this structure:

  1. What is the problem (specific, not vague)
  2. Why it matters (impact)
  3. How to fix it (concrete suggestion or code snippet)

Bad:

This is confusing.

Good:

[MAJOR] The function `process()` handles three unrelated responsibilities: validation,
transformation, and persistence. This makes it hard to test and modify independently.

Extract into `validateOrder()`, `transformOrder()`, and `persistOrder()` so each
can be tested and changed in isolation.
Language-Specific Anti-Patterns to Flag
JavaScript/TypeScript
  • Using == instead of ===
  • Missing await on async functions
  • Mutating function arguments
  • Using any type when a specific type is possible
  • Not handling promise rejections
  • Using var instead of const/let
  • Index-based for loops when .map()/.filter() is clearer
Python
  • Mutable default arguments (def foo(items=[]))
  • Bare except: clauses (swallows all exceptions)
  • Using type() instead of isinstance()
  • Not using context managers for resources
  • String formatting with % or .format() when f-strings are available
  • Global state mutation
Java
  • Catching Exception instead of specific types
  • Not closing resources (use try-with-resources)
  • Using raw types instead of generics
  • Public fields instead of encapsulation
  • Mutable static fields
  • Missing @Supersede annotations
Go
  • Ignoring error returns (_ = someFunc())
  • Using panic for normal error handling
  • Not checking Close() errors on writers
  • Goroutine leaks (no cancellation context)
  • Shared mutable state without synchronization
Rust
  • Unnecessary .clone() calls
  • Using .unwrap() in library code
  • Not using ? operator for error propagation
  • Holding locks across .await points
  • Using String when &str suffices
Show full SKILL.md (411 more words)Show less

Review Comment Templates

Approving with Minor Feedback
LGTM with minor suggestions. The approach is sound, and the implementation is clean.
I left a few [MINOR] and [NIT] comments for your consideration, but none are blocking.
Ship it.
Requesting Changes
Good progress on this feature. I found a few issues that should be addressed before merge:

- [BLOCKER] SQL injection risk in the search endpoint (comment on line 45)
- [MAJOR] Missing error handling in the payment flow (comment on line 112)

The overall structure looks good. Please address the blockers and I will re-review.
Large PR Guidance
This PR touches 47 files across 6 modules. To make review more effective, consider
splitting into:
1. Database migration + model changes
2. Business logic
3. API endpoint + controller
4. Frontend integration

Smaller PRs get faster, higher-quality reviews and are easier to revert if needed.

Review Anti-Patterns to Avoid

  1. Rubber stamping: Approving without reading. If you cannot review properly, say so.
  2. Gatekeeping style: Blocking on personal preferences that are not in the style guide.
  3. Drive-by nitpicking: Leaving only style comments while missing logic bugs.
  4. Rewrite requests: Demanding a completely different approach without strong justification.
  5. Delayed reviews: Letting PRs sit for days. Review within 4 hours during business hours.
  6. Comment wars: If a discussion exceeds 3 rounds, move to synchronous conversation.

Metrics for Review Quality

Track these to improve your review practice:

  • Defect escape rate: How many bugs reach production that review should have caught?
  • Review turnaround time: Time from PR opened to first review.
  • Comment-to-blocker ratio: If 90% of comments are nits, you are not reviewing deeply enough.
  • Author satisfaction: Does the author feel the review was helpful?

Decision Framework: Approve vs Request Changes

Is the code correct?
  No -> Request Changes
  Yes -> Continue

Is the code secure?
  No -> Request Changes
  Yes -> Continue

Will this code be maintainable in 6 months?
  No, and it is a significant concern -> Request Changes
  No, but it is minor -> Approve with comments
  Yes -> Continue

Does it follow team conventions?
  No, and it is automated (linting) -> Request Changes (fix linting)
  No, but it is subjective -> Approve with suggestion
  Yes -> Approve

Reviewing AI-Generated Code

Apply extra scrutiny to AI-generated code:

  1. Verify all imports actually exist in the project.
  2. Check that API calls match actual signatures (AI hallucinates APIs).
  3. Look for plausible-but-wrong logic (AI generates confident-looking bugs).
  4. Verify edge case handling (AI often handles the happy path only).
  5. Check for license-incompatible code patterns.

When to Use

Use this skill when:

  • Designing or implementing code reviewer solutions
  • Reviewing or improving existing code reviewer approaches
  • Making architectural or implementation decisions about code reviewer
  • Learning code reviewer patterns and best practices
  • Troubleshooting code reviewer-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Code Reviewer Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement code reviewer for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended code reviewer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When code reviewer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/software-engineering/code-reviewer of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillFerroxLabs/wayland608—~2.9kAutomated safety check: PassApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection. Code Reviewer is an agent skill from FerroxLabs/wayland. Expert code review methodology with structured checklists, severity classification, actionable feedback patterns, and language-specific anti-pattern detection.

When should I use Code Reviewer?

Code Reviewer fits situations like: the user asks about code reviewer; code reviewer best practices; needs guidance on code reviewer implementation; the user needs a different specialized skill.

How do I install Code Reviewer in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill code-reviewer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/code-reviewer in FerroxLabs/wayland) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add FerroxLabs/wayland --skill code-reviewer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/code-reviewer in FerroxLabs/wayland) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Reviewer is instructions for the agent only. Our summary lists: Python 3.

Does Code Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.