Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Review a set of code changes against Sculptor's review categories and produce a markdown findings table.
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install imbue-ai/sculptor code-review-checklist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review-checklist .claude/skills/code-review-checklist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .claude/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install imbue-ai/sculptor code-review-checklist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/code-review-checklist .agents/skills/code-review-checklist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .agents/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install imbue-ai/sculptor code-review-checklist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/code-review-checklist .cursor/skills/code-review-checklist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .cursor/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/imbue-ai/sculptor.git --path .claude/skills/code-review-checklist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install imbue-ai/sculptor code-review-checklist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/code-review-checklist .gemini/skills/code-review-checklist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .gemini/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install imbue-ai/sculptor code-review-checklistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/code-review-checklist .github/skills/code-review-checklist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .github/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add imbue-ai/sculptor --skill code-review-checklist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install imbue-ai/sculptor code-review-checklist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imbue-ai/sculptor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/code-review-checklist .opencode/skills/code-review-checklist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/imbue-ai/sculptor/tree/main/.claude/skills/code-review-checklist into .opencode/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-checklistReview a set of code changes against Sculptor's review categories and produce a markdown findings table.
Code Review Checklist is an agent skill from imbue-ai/sculptor. Review a set of code changes against Sculptor's review categories and produce a markdown findings table. Use when reviewing code (your own or others').
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review. It works with Git. The repository describes itself as: Build product with grounded, parallel coding agents. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f847102. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitjustFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Checklist loads about 3.6k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 1,902 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from imbue-ai/sculptor at commit f847102, republished under its MIT licence (© imbue-ai). 1,902 words, ~3,568 tokens.
.claude/skills/code-review-checklist/SKILL.md (or your agent's skills folder).Review a set of code changes against the categories below and produce a markdown findings table.
git commands. Default: the current repo.<base>...<head> (three dots). Default if
not specified: git diff origin/main...HEAD.Read it before reading the diff so the goal is fresh while you're reviewing.
Run git diff <base>...<head> in the working directory and read the full
output. For very large diffs, also list changed files
(git diff --stat <base>...<head>) and prioritize files most relevant to the
stated goal.
Also read the commit messages in the range (git log <base>..<head>) — they
are part of what you review (see "Public-facing text" and "Git hygiene").
For each category below, look for issues in the diff. Be exhaustive — a single file can have multiple issues of the same type. Don't skip categories that look empty at a glance; spend a moment confirming.
For frontend (.tsx) changes, you MUST read docs/development/review/react.md
(generic React rules), docs/development/review/sculptor.md (Sculptor-specific
conventions: backend data hooks, Jotai atoms, component invariants),
docs/development/review/design.md (design-system usage, existing patterns,
UI copy), and docs/development/review/file_structure.md (file placement,
feature layout, naming) in full and apply every rule in them. Do not skip this
step. Do not rely on summaries elsewhere in this checklist or on prior
knowledge — the docs are the source of truth and are updated independently.
The file-structure doc also applies to frontend .ts changes (new files,
moves, renames).
For integration test changes (under sculptor/tests/integration/), you MUST
read the file docs/development/review/integration_tests.md in full and apply every rule
in it. Same reasoning as above.
Output one section per category in the order they appear under "Categories" below. Every category must have a section in your output — including ones where you found no issues. This forces you to confirm you actually reviewed each category rather than letting empty ones slip past unnoticed.
For each category, write a heading with the category name, then either prose findings or an explicit "no issues" line.
Write each finding as a short paragraph, not as a table row. Lead with the severity tag in bold, then the file path and line numbers, then a one- to three-sentence explanation of what's wrong and why it matters. Multiple findings in the same category go as separate paragraphs, blank-line separated.
Example output:
### Correctness
**HIGH** — `path/foo.py:42-48`. `bar()` is called with `None` when `x` is
empty, and `bar` does not guard against that. This will raise an
`AttributeError` at runtime on the empty-list path, which the new tests
don't cover.
**MEDIUM** — `path/baz.py:101`. The loop runs `range(len(items) - 1)`, so
the last item is silently skipped. Likely an off-by-one introduced when the
slice was removed in this change.
### Consistency with stated goal
No stated goal provided — section skipped.
### Test coverage
No issues found.Each section must be one of:
No issues found., ORNo stated goal provided — section skipped.Do NOT collapse multiple empty categories into a single "no issues" note. Do NOT omit a category section. If you do, it signals you didn't review it. Do NOT use markdown tables — prose only.
Severity:
After the per-category sections, write a short summary (2–4 bullets):
None/empty/zero/negative inputs, boundary valuesxfail/disabled without justificationThis category applies when the stated goal is an MR/PR body produced by an autonomous workflow (e.g. /sculptor-workflow:fix-bug). Skip the category if no stated goal was provided, or if the stated goal is a spec/ticket rather than an MR body.
sculptor/frontend/, any .tsx, .css, or other UI surface) and the MR body's "Before" or "After" slots lack an embedded image (e.g. <img src="..."> or a markdown image link), flag it as HIGH. Test output is not a substitute.<hash>" with a placeholder or empty hash, flag it.TODO/FIXME/XXX comments without an owner or ticketconsole.log, print(...), pdb, breakpoint(),
debuggeragent_docs/...
paths, REQ-* requirement IDs, or implementation-plan phase references.
The comment must stand on its own.dev, foo,
alice) for usernames in /Users/<name>/ paths or example branch names.except: or unconditional except Exception:except: pass etc.)Any types unless justifiedElementIDs changed, run
just generate-api.tsx changes)Required: Read docs/development/review/react.md (generic React rules),
docs/development/review/sculptor.md (Sculptor-specific frontend conventions),
docs/development/review/design.md (design-system usage, existing patterns, UI copy),
and docs/development/review/file_structure.md (file placement, feature layout,
naming — also applies to frontend .ts changes) in full with the Read tool, and
apply every rule in them. The rules cover effects,
state, refs, render purity, performance, props, lists, backend data hooks,
Jotai atom usage, component-level invariants, design-token and component-reuse
conventions, UI copy, code placement, and naming — detailed enough that
summarizing them here would lose
information, so this section intentionally does not list them. If you find
yourself reviewing a .tsx change without having opened all four docs in the
current session, stop and read them.
Beyond the docs: IconButton in a Flex uses gap="2" (per CLAUDE.md).
sculptor/tests/integration/)Required: Read docs/development/review/integration_tests.md in full with the Read
tool and apply every rule in it. The rules cover Playwright assertion
patterns, test isolation, and POM usage — they're detailed enough that
summarizing them here would lose information, so this section intentionally
does not list them. If you find yourself reviewing an integration test change
without having opened that doc in the current session, stop and read it.
# noqa: E402)is_/has_/should_/etc.num_ prefix (use count_ or _idx suffix)just ratchets if you suspect any counts changed; flag any increasesCommit messages and the PR/MR title and description are published to a public
repository — review them as permanently, world-readable artifacts. Read the
commit messages in the range (git log <base>..<head>) as well as the stated
goal (the PR/MR body, when one was provided). Flag any of the following:
/Users/<name>/).
These should be reworded to roles or generic placeholders (dev, <user>).SCU-1447) is fine; pasting the ticket's private
contents is not.This is the same standard as the Comments category, extended from code comments to the commit/PR prose. See also CLAUDE.md, "Public Visibility: Commit Messages and PR Descriptions".
© imbue-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/code-review-checklist of imbue-ai/sculptor.
Open the folder on GitHubat commit f847102
Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Checklist this skillimbue-ai/sculptor | 237 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 45k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 86k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Open Code Review Delegatealibaba/open-code-review | 45k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Code Reviewflutter/flutter | 179k | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
alibaba/open-code-review
Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.
flutter/flutter
Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
imbue-ai/sculptor
QA the Sculptor mobile web UI on a real iOS Simulator, driven headlessly from a Mac.
imbue-ai/sculptor
Compare React component render counts between origin/main and the current branch during a user-defined UI scenario (e.g.
imbue-ai/sculptor
Post a one-line PR announcement to a Slack channel, and mark it :merged: when the PR merges.
imbue-ai/sculptor
Run Claude programmatically against collections of files in the codebase.
imbue-ai/sculptor
Build or modify a Sculptor extension — a runtime ESM module loaded into the Sculptor UI.
imbue-ai/sculptor
Cut a new Sculptor release candidate from main: run just cut-release (which creates the release/sculptor-vX.Y.0 branch at X.Y.0rc1, pushes the tag that triggers the RC build, and opens a PR bumping…
Works with
Categories
Review a set of code changes against Sculptor's review categories and produce a markdown findings table. Code Review Checklist is an agent skill from imbue-ai/sculptor. Review a set of code changes against Sculptor's review categories and produce a markdown findings table.
Code Review Checklist fits situations like: reviewing code (your own; tasks that involve Code review.
Run `npx skills add imbue-ai/sculptor --skill code-review-checklist -a claude-code`. Or copy the skill folder (.claude/skills/code-review-checklist in imbue-ai/sculptor) into .claude/skills/code-review-checklist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add imbue-ai/sculptor --skill code-review-checklist -a codex`. Or copy the skill folder (.claude/skills/code-review-checklist in imbue-ai/sculptor) into .agents/skills/code-review-checklist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imbue-ai/sculptor --skill code-review-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-checklist, .gemini/skills/code-review-checklist, .github/skills/code-review-checklist and .opencode/skills/code-review-checklist in your project.
Going by SKILL.md and its folder, Code Review Checklist needs the command-line tools its instructions call (git and just).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Checklist: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Open Code Review CLI (alibaba/open-code-review, 45k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars) and Open Code Review Delegate (alibaba/open-code-review, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
imbue-ai (a GitHub organization) maintains it in imbue-ai/sculptor, which has 237 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 8, 2026.
Source: imbue-ai/sculptor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.