Agent skill

Code Review And Quality

by hylarucoder in hylarucoder/hai-stack

Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review.

MITAuto-check passedDevelopment

Install Code Review And Quality

skills CLI
$ npx skills add hylarucoder/hai-stack --skill code-review-and-quality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hylarucoder/hai-stack code-review-and-quality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hylarucoder/hai-stack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review-and-quality .claude/skills/code-review-and-quality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-and-quality
GitHub stars
380
Token cost
~934 tokens
SKILL.md length
414 words
Files
7 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review.

  • Works in 7 steps: Read repository instructions, intended… → Read tests and their assertions, then… → Review relevant axes → …
  • Review this diff/PR、变更评审、代码审查、代码整洁度
  • SKILL.md covers Purpose, Modes, Workflow and Verification and boundaries
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review And Quality is an agent skill from hylarucoder/hai-stack. Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review. Use for review this diff/PR、变更评审、代码审查、代码整洁度. Return evidence-backed findings and a scoped verdict; diagnose without editing unless fixes are requested. Use hai-architecture for system design or a React component deep dive, and write-technical-acceptance-report for executed requirement acceptance.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/detailed-examples.md` and `references/language-patterns.md`).

It sits in Development, covering Refactoring, Code review and React components. The licence is MIT.

When your agent uses it

  • Review this diff/PR、变更评审、代码审查、代码整洁度
  • Tasks that involve Refactoring
  • Tasks that involve Code review

Example prompts

  • “Use the code-review-and-quality skill to review a code change for correctness, security, maintainability, architecture, performance, and…”
  • “/code-review-and-quality”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read repository instructions, intended behavior, diff, and relevant specs/contracts. Record
  2. Read tests and their assertions, then trace changed behavior into callers, state, error paths,
  3. Review relevant axes
  4. For each candidate, verify the triggering scenario and changed code. Distinguish regressions,
  5. Rank by user impact and change cost. Omit cosmetic preferences unless requested. Do not reject
  6. For requested repairs, apply the smallest complete fix and run appropriate checks. Use
  7. Read references/output-template.md and deliver findings, actual verification, and a scoped

What it can do on your machine

Read from SKILL.md and the folder at commit a6c7ed2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review And Quality loads about 934 tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 414 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~934
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hylarucoder/hai-stack at commit a6c7ed2, republished under its MIT licence (© hylarucoder). 414 words, ~934 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-and-quality/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
code-review-and-quality
description
Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review. Use for review this diff/PR、变更评审、代码审查、代码整洁度. Return evidence-backed findings and a scoped verdict; diagnose without editing unless fixes are requested. Use hai-architecture for system design or a React component deep dive, and write-technical-acceptance-report for executed requirement acceptance.

Code Review and Quality

Purpose

Find defects and costly design regressions in a defined change. Preserve the useful five-axis review method of the existing skill while scaling the work to actual risk. A review verdict is not permission to merge, publish, or message others.

Modes

  • Change review: review the named diff/PR/commit. If unspecified, inspect the local staged and unstaged changes plus relevant new files; state the baseline and scope.
  • Maintainability: inspect the named files/functions for code smells. Read references/maintainability.md and its relevant language/examples guidance. Preserve behavior.
  • Review and fix: when the user asks for repairs, implement clear in-scope fixes after diagnosis and verify them. An audit-only request remains read-only.

Workflow

  1. Read repository instructions, intended behavior, diff, and relevant specs/contracts. Record which files and paths were actually reviewed. Preserve unrelated work.
  2. Read tests and their assertions, then trace changed behavior into callers, state, error paths, persistence, and external effects where relevant. A passing test is only as good as its coverage.
  3. Review relevant axes:
    • Correctness: intended behavior, boundary cases, failure handling, state transitions, concurrency/idempotency where relevant.
    • Security: real trust/permission boundaries and untrusted data flow.
    • Maintainability: clear responsibility and vocabulary; unnecessary branches, abstractions, duplicated authority; project conventions over arbitrary style rules.
    • Architecture: ownership, dependency direction, contract changes, and whether complexity was reduced or merely relocated.
    • Performance: evidenced unbounded work, query growth, allocation/render pressure; do not invent latency estimates without measurement.
  4. For each candidate, verify the triggering scenario and changed code. Distinguish regressions, pre-existing issues, and unverified suspicions. Cite real file:line evidence.
  5. Rank by user impact and change cost. Omit cosmetic preferences unless requested. Do not reject a coherent change solely for its line count, number of implementations, or lack of abstraction.
  6. For requested repairs, apply the smallest complete fix and run appropriate checks. Use hai-tdd for behavior changes where a real RED is possible; structural work uses compiler, existing tests, and focused checks. Do not mix unrelated redesign into a bug fix.
  7. Read references/output-template.md and deliver findings, actual verification, and a scoped verdict. No findings means none were found in the inspected scope, not proof of perfection.
Show full SKILL.md (62 more words)Show less

Verification and boundaries

Review code and run relevant non-mutating checks when useful. Do not claim tests passed unless executed or clearly label the author's/historical evidence. Code inspection does not prove a deployed workflow passed; requirement-by-requirement acceptance belongs to write-technical-acceptance-report.

Unexplained runtime failures → hai-debug. A structural decision or deep React analysis → hai-architecture; a local naming decision → hai-naming. Reuse collected evidence when handing off.

© hylarucoder, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/code-review-and-quality of hylarucoder/hai-stack.

  • SKILL.md
  • LICENSE
  • agents/openai.yaml
  • references/detailed-examples.md
  • references/language-patterns.md
  • references/maintainability.md
  • references/output-template.md

Open the folder on GitHubat commit a6c7ed2

Compare with similar skills

Code Review And Quality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review And Quality compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review And Quality this skillhylarucoder/hai-stack380—~934Automated safety check: PassMIT
Component Refactoringlangflow-ai/langflow156k—~3.5kAutomated safety check: PassMIT
@pierre/diffs Code Renderingpierrecomputer/pierre6.2k2 repos~803Automated safety check: PassApache-2.0
Component RefactoringPageAI-Pro/ralph-loop311—~1.8kAutomated safety check: PassMIT
Tsh Reviewing FrontendTheSoftwareHouse/copilot-collections284—~4.4kAutomated safety check: PassMIT
React Composition Patternsvercel-labs/openreview1.7k58 repos~721Automated safety check: PassMIT

Similar skills

  • Component Refactoring

    langflow-ai/langflow

    Refactor high-complexity React components in Langflow frontend.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • @pierre/diffs Code Rendering

    pierrecomputer/pierre

    Guides an agent through using @pierre/diffs to render syntax-highlighted files and diffs, and to build editing and review surfaces in React or plain JavaScript.

    6.2k GitHub starsUsed in 2 repos~803 tokens
    DevelopmentAuto-check passed
  • Component Refactoring

    PageAI-Pro/ralph-loop

    Refactor high-complexity React components in frontend. An agent skill from PageAI-Pro/ralph-loop.

    311 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Tsh Reviewing Frontend

    TheSoftwareHouse/copilot-collections

    Frontend-specific code review criteria, component anti-patterns, hooks quality, rendering correctness, accessibility and performance spot-checks, and module organization issues.

    284 GitHub stars~4.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • React Composition Patterns

    vercel-labs/openreview

    Official

    Rules for structuring React components with composition instead of boolean props, covering compound components, lifted state, variants and React 19 changes.

    1.7k GitHub starsUsed in 58 repos~721 tokens
    Frontend & DesignAuto-check passed
  • Official

    React and Next.js performance optimization guidelines from Vercel Engineering.

    6.4k GitHub starsUsed in 130 repos~1.6k tokens
    Frontend & DesignAuto-check passed

More from hylarucoder/hai-stack

All 18 skills in this repo
  • Verify a defined software change against requirements and produce a proportional, evidence-backed acceptance report with specification precedence, scope boundaries, requirement-to-evidence…

    380 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Hai Ast Grep

    hylarucoder/hai-stack

    Produces a ready-to-run ast-grep command or reusable YAML lint/codemod rule, validated against positive and negative fixtures.

    380 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Readme Beautifier

    hylarucoder/hai-stack

    Reformats and restructures a README or similar Markdown project document without changing its factual content, voice, or scope, then summarizes formatting-only edits.

    380 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Hai Visual Explainer

    hylarucoder/hai-stack

    Turns supplied content into self-contained HTML and PNG in two modes: card for one shareable frame(知识卡、信息卡、金句卡、封面、把要点做成一张图), report for multi-section documents(可视化报告、HTML 汇报页、PRD/计划/评审做成网页).

    380 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Entity Model Auditor

    hylarucoder/hai-stack

    Audits an entity model field by field: what should exist, what exists now, where each value belongs (column, config, computed runtime value, or removal), and what must migrate.

    380 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Geju

    hylarucoder/hai-stack

    Challenges an overly conservative, incremental, or compatibility-led proposal with a bold target model, a concrete kill/merge/split list, materially different options, and a falsifiable first proof…

    380 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Code Review And Quality

What does Code Review And Quality do?

Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review. Code Review And Quality is an agent skill from hylarucoder/hai-stack. Reviews a code change for correctness, security, maintainability, architecture, performance, and verification gaps, or performs a local code-smell review.

When should I use Code Review And Quality?

Code Review And Quality fits situations like: review this diff/PR、变更评审、代码审查、代码整洁度; tasks that involve Refactoring; tasks that involve Code review.

How do I install Code Review And Quality in Claude Code?

Run `npx skills add hylarucoder/hai-stack --skill code-review-and-quality -a claude-code`. Or copy the skill folder (skills/code-review-and-quality in hylarucoder/hai-stack) into .claude/skills/code-review-and-quality in your project. Claude Code loads it when a task matches its description.

How do I install Code Review And Quality in Codex?

Run `npx skills add hylarucoder/hai-stack --skill code-review-and-quality -a codex`. Or copy the skill folder (skills/code-review-and-quality in hylarucoder/hai-stack) into .agents/skills/code-review-and-quality in your project. Codex loads it when a task matches its description.

Can I use Code Review And Quality in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hylarucoder/hai-stack --skill code-review-and-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-and-quality, .gemini/skills/code-review-and-quality, .github/skills/code-review-and-quality and .opencode/skills/code-review-and-quality in your project.

What does Code Review And Quality need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review And Quality is instructions for the agent only.

Does Code Review And Quality access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review And Quality safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review And Quality use?

Code Review And Quality is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review And Quality use?

About 934 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Code Review And Quality?

Skills that share tags, products or a category with Code Review And Quality: Component Refactoring (langflow-ai/langflow, 156k stars), @pierre/diffs Code Rendering (pierrecomputer/pierre, 6.2k stars), Component Refactoring (PageAI-Pro/ralph-loop, 311 stars) and Tsh Reviewing Frontend (TheSoftwareHouse/copilot-collections, 284 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review And Quality?

hylarucoder (a GitHub user) maintains it in hylarucoder/hai-stack, which has 380 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 5, 2026.

Source: hylarucoder/hai-stack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.