Agent skill

Code Review And Security Audit

by hiroshiyui in hiroshiyui/GuilelessBopomofo

Review code for quality, correctness, and security vulnerabilities.

GPL-3.0Auto-check passedDevelopment

Install Code Review And Security Audit

skills CLI
$ npx skills add hiroshiyui/GuilelessBopomofo --skill code-review-and-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hiroshiyui/GuilelessBopomofo code-review-and-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hiroshiyui/GuilelessBopomofo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review-and-security-audit .claude/skills/code-review-and-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-and-security-audit
GitHub stars
135
Token cost
~1.6k tokens
SKILL.md length
748 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
GPL-3.0

At a glance

Review code for quality, correctness, and security vulnerabilities.

  • Works in 2 steps: Code Review — correctness, readability,… → Security Audit — identifying…
  • The user asks to review code
  • SKILL.md covers Scope, Review Checklist, Output Format and How to Run, plus 1 more section
  • Calls git

What it does

Code Review And Security Audit is an agent skill from hiroshiyui/GuilelessBopomofo. Review code for quality, correctness, and security vulnerabilities. Use when the user asks to review code, audit for security issues, or check for bugs and anti-patterns.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Security review and Refactoring. It works with Android. The repository describes itself as: Guileless Bopomofo - A Bopomofo (Zhuyin) software keyboard (aka input method editor) on Android, which is utilizing libchewing for intelligent phonetic processing. 樸實注音鍵盤是… The licence is GPL-3.0.

When your agent uses it

  • The user asks to review code
  • Audit for security issues
  • Check for bugs and anti-patterns

Example prompts

  • “/code-review-and-security-audit”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Code Review — correctness, readability, maintainability, and adherence to project conventions.
  2. Security Audit — identifying vulnerabilities, unsafe patterns, and potential attack surfaces.

What it can do on your machine

Read from SKILL.md and the folder at commit e41eac5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review And Security Audit loads about 1.6k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 748 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hiroshiyui/GuilelessBopomofo at commit e41eac5, republished under its GPL-3.0 licence (© hiroshiyui). 748 words, ~1,599 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-and-security-audit/SKILL.md (or your agent's skills folder).
name
code-review-and-security-audit
description
Review code for quality, correctness, and security vulnerabilities. Use when the user asks to review code, audit for security issues, or check for bugs and anti-patterns.
argument-hint
file path, component name, or scope of review

Code Review and Security Audit

You are performing code review and security auditing for Guileless Bopomofo.

Scope

This skill covers two complementary concerns:

  1. Code Review — correctness, readability, maintainability, and adherence to project conventions.
  2. Security Audit — identifying vulnerabilities, unsafe patterns, and potential attack surfaces.

Review Checklist

Code Quality
  • Null safety: proper use of Kotlin null-safe operators; avoid !! unless justified.
  • Thread safety: correct use of coroutines, synchronized access to shared state.
  • Resource management: no leaked cursors, streams, or native resources.
  • Error handling: appropriate use of try/catch; no silently swallowed exceptions.
  • Consistency: follows existing patterns in the codebase (EventBus for events, ViewBinding for views, etc.).
  • No dead code, unused imports, or redundant logic.
Code Smells
  • Long methods: methods doing too many things; should be broken into smaller, focused functions.
  • Large classes: classes with too many responsibilities; consider splitting by concern.
  • Duplicated code: repeated logic that should be extracted into a shared function.
  • Deep nesting: excessive if/when/try nesting that harms readability; consider early returns or extraction.
  • Magic numbers/strings: unexplained literal values that should be named constants.
  • Feature envy: a method that uses another class's data more than its own.
  • Inappropriate intimacy: classes that depend too heavily on each other's internals.
  • Primitive obsession: overuse of primitives where a domain type (enum, data class) would be clearer.
  • Long parameter lists: functions with many parameters; consider grouping into a data class or builder.
  • Mutable shared state: prefer immutable data and local state; flag unnecessary var or global mutable collections.
Code Refactoring Suggestions
  • Extract method: identify blocks of code within a method that perform a distinct task and can be extracted.
  • Extract class/interface: when a class handles multiple responsibilities, suggest splitting into focused classes or introducing an interface.
  • Replace conditional with polymorphism: complex when/if-else chains that switch on type can often be replaced with polymorphic dispatch.
  • Introduce sealed class/enum: when a set of related constants or states is represented loosely (strings, ints), suggest modeling with a sealed class or enum.
  • Use Kotlin idioms: replace Java-style patterns with idiomatic Kotlin — e.g., let/apply/also scope functions, destructuring, extension functions, buildList/buildString.
  • Simplify lifecycle management: leverage lifecycleScope, repeatOnLifecycle, or LifecycleObserver to reduce manual lifecycle bookkeeping.
  • Reduce coupling: identify tight coupling between components and suggest dependency injection, event-driven patterns (EventBus is already used), or interface abstractions.
  • Consolidate duplicate logic: when similar logic appears in virtual and physical key handlers (keys/virtual/ vs keys/physical/), suggest a shared base or utility.
  • Improve testability: flag code that is hard to unit test (e.g., direct static calls, hidden dependencies) and suggest restructuring for easier testing.
Show full SKILL.md (330 more words)Show less
JNI / Native Security

This project bridges Kotlin and native C/C++ via JNI. Pay special attention to:

  • Buffer overflows: check that JNI string and array operations use correct lengths.
  • Null pointer dereference: validate JNI references before use (e.g., FindClass, GetMethodID return values).
  • JNI reference leaks: ensure local references are released when no longer needed, especially in loops.
  • Input validation: verify that data crossing the JNI boundary is validated on both sides.
  • Memory management: check for proper allocation/deallocation of native memory.
  • Review app/src/main/cpp/libchewing_android_jni.cpp as the primary JNI surface.
Android-Specific Security
  • Input method security: as an IME, this app handles all user keystrokes. Ensure no logging or leaking of user input.
  • SharedPreferences: verify no sensitive data is stored in plain text.
  • Intent handling: check for intent injection or unvalidated intent extras.
  • WebView (if applicable): check for JavaScript injection, insecure addJavascriptInterface usage.
  • Export controls: verify that components (activities, services, receivers) are not inadvertently exported.
  • ProGuard/R8: ensure obfuscation rules don't strip security-critical code.
General Security
  • No hardcoded secrets, API keys, or credentials.
  • No command injection via Runtime.exec() or ProcessBuilder.
  • No path traversal vulnerabilities in file operations.
  • No insecure random number generation for security-sensitive operations.
  • Dependencies: check for known vulnerabilities in third-party libraries.

Output Format

Report findings using this structure:

Critical / High

Issues that must be fixed — security vulnerabilities, crashes, data loss risks.

Medium

Issues that should be fixed — logic bugs, thread safety concerns, code smell.

Low / Informational

Suggestions for improvement — style, readability, minor optimizations.

For each finding, include:

  • File and line number (e.g., Chewing.kt:42)
  • Description of the issue
  • Impact — what could go wrong
  • Recommendation — how to fix it, with code if appropriate

How to Run

When invoked without arguments, review recently changed files:

bash
git diff --name-only HEAD~5

When invoked with a specific scope (file, directory, or component name), focus the review on that area.

For a full audit, systematically review:

  1. JNI layer (app/src/main/cpp/)
  2. Service layer (GuilelessBopomofoService.kt)
  3. Data handling (Chewing.kt, ChewingBridge.kt)
  4. UI layer (key handlers, KeyboardPanel.kt)
  5. Configuration (AndroidManifest.xml, ProGuard rules)
  6. Dependencies (gradle/libs.versions.toml)

Task: $ARGUMENTS

© hiroshiyui, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/code-review-and-security-audit of hiroshiyui/GuilelessBopomofo.

Open the folder on GitHubat commit e41eac5

Compare with similar skills

Code Review And Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review And Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review And Security Audit this skillhiroshiyui/GuilelessBopomofo135—~1.6kAutomated safety check: PassGPL-3.0
Copilot Code Coachtimothywarner/chatgptclass143—~1.9kAutomated safety check: PassCustom licence
Expert Code ReviewerGulajavaMinistudio/Mayukai-Theme139—~1.4kAutomated safety check: PassMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Bug Huntercodexstar69/bug-hunter519—~5kAutomated safety check: PassMIT

Similar skills

  • Copilot Code Coach

    timothywarner/chatgptclass

    Socratic coding tutor powered by GitHub Copilot. An agent skill from timothywarner/chatgptclass.

    143 GitHub stars~1.9k tokensUpdated 19 days ago
    DevelopmentAuto-check passed
  • Expert Code Reviewer

    GulajavaMinistudio/Mayukai-Theme

    Language-agnostic workflow for code reviews and security audits against Clean Code/SOLID principles, generating formal refactoring plans.

    139 GitHub stars~1.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Bug Hunter

    codexstar69/bug-hunter

    Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

    519 GitHub stars~5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    490 GitHub stars~2.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from hiroshiyui/GuilelessBopomofo

  • Commit And Push

    hiroshiyui/GuilelessBopomofo

    Commit code changes and push via Git. An agent skill from hiroshiyui/GuilelessBopomofo.

    135 GitHub stars~793 tokensUpdated 11 days ago
    Auto-check: notes
  • Docs Engineering

    hiroshiyui/GuilelessBopomofo

    Writing/updating project documentation (README, PRIVACY-POLICY, NOTICES, changelogs) and maintaining F-Droid metadata.

    135 GitHub stars~806 tokensUpdated 11 days ago
    Auto-check passed
  • Release Engineering

    hiroshiyui/GuilelessBopomofo

    Release engineering tasks including version bumping, building release APKs, creating git tags, writing changelogs, and preparing F-Droid releases.

    135 GitHub stars~1.6k tokensUpdated 11 days ago
    Auto-check passed

Works with

Questions about Code Review And Security Audit

What does Code Review And Security Audit do?

Review code for quality, correctness, and security vulnerabilities. Code Review And Security Audit is an agent skill from hiroshiyui/GuilelessBopomofo. Review code for quality, correctness, and security vulnerabilities.

When should I use Code Review And Security Audit?

Code Review And Security Audit fits situations like: the user asks to review code; audit for security issues; check for bugs and anti-patterns.

How do I install Code Review And Security Audit in Claude Code?

Run `npx skills add hiroshiyui/GuilelessBopomofo --skill code-review-and-security-audit -a claude-code`. Or copy the skill folder (.claude/skills/code-review-and-security-audit in hiroshiyui/GuilelessBopomofo) into .claude/skills/code-review-and-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Code Review And Security Audit in Codex?

Run `npx skills add hiroshiyui/GuilelessBopomofo --skill code-review-and-security-audit -a codex`. Or copy the skill folder (.claude/skills/code-review-and-security-audit in hiroshiyui/GuilelessBopomofo) into .agents/skills/code-review-and-security-audit in your project. Codex loads it when a task matches its description.

Can I use Code Review And Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hiroshiyui/GuilelessBopomofo --skill code-review-and-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-and-security-audit, .gemini/skills/code-review-and-security-audit, .github/skills/code-review-and-security-audit and .opencode/skills/code-review-and-security-audit in your project.

What does Code Review And Security Audit need to run?

Going by SKILL.md and its folder, Code Review And Security Audit needs the command-line tools its instructions call (git).

Does Code Review And Security Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review And Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review And Security Audit use?

Code Review And Security Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review And Security Audit use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review And Security Audit?

Skills that share tags, products or a category with Code Review And Security Audit: Copilot Code Coach (timothywarner/chatgptclass, 143 stars), Expert Code Reviewer (GulajavaMinistudio/Mayukai-Theme, 139 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars) and Verdaccio Code Review (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review And Security Audit?

hiroshiyui (a GitHub user) maintains it in hiroshiyui/GuilelessBopomofo, which has 135 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 27, 2026.

Source: hiroshiyui/GuilelessBopomofo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.