Agent skill

Code Review

by jackfranklin in jackfranklin/dotfiles

Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add jackfranklin/dotfiles --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jackfranklin/dotfiles code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jackfranklin/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
255
Token cost
~2k tokens
SKILL.md length
950 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency.

  • Works in 5 steps: Code Smells Baseline (Fowler… → Quality, Robustness & Maintainability → Code Reuse & Integration → …
  • Tasks that involve Code review
  • SKILL.md covers Core Principles, Workflow and Review Checklist
  • Calls git

What it does

Code Review is an agent skill from jackfranklin/dotfiles. Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency. Activate this skill ANY TIME the user asks for a code review or when you need to perform a senior-level, thorough analysis of code changes.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Type safety and Internationalization. It works with Git. The repository describes itself as: My dotfiles for my dev environment, compromising of tmux, vim, zsh and git. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Type safety
  • Tasks that involve Internationalization

Example prompts

  • “/code-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Code Smells Baseline (Fowler Refactoring, Ch. 3)
  2. Quality, Robustness & Maintainability
  3. Code Reuse & Integration
  4. Efficiency & Performance
  5. Unit Test Quality (If tests changed)

What it can do on your machine

Read from SKILL.md and the folder at commit 48208f5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 950 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jackfranklin/dotfiles at commit 48208f5, republished under its MIT licence (© jackfranklin). 950 words, ~1,973 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency. Activate this skill ANY TIME the user asks for a code review or when you need to perform a senior-level, thorough analysis of code changes.

Code Review

Harsh, expert code review focused on implementation quality, aggressive simplification, and long-term maintainability. Be ambitious. Do not merely identify local cleanup opportunities; actively search for "code judo" moves that make the implementation dramatically simpler and more elegant.

Core Principles

  1. Code Judo: Actively look for restructurings that delete complexity rather than rearranging it. Reframe the problem so branches, helpers, or layers disappear entirely.
  2. Zero Spaghetti: Ban ad-hoc conditionals and scattered special cases in unrelated flows. Push logic into dedicated abstractions or state machines.
  3. Direct & Boring: Prefer explicit, legible code over hacky, magical, or thin abstractions that add indirection without value.
  4. Strict Boundaries: Enforce clean type contracts. Flag unnecessary optionality, any, unknown, or excessive casting. Banish as any unless explicitly permitted.
  5. Canonical Home: Put logic in the correct layer and reuse existing utilities instead of building bespoke ones.

Workflow

  1. Context: Read the commit message (if any) and identify staged/unstaged changes. When diffing against a base branch, use git diff <base>...HEAD (three-dot range) rather than git diff $(git merge-base <base> HEAD) HEAD — the three-dot form avoids a subshell so it matches the Bash permission allowlist without extra prompts.
  2. Scope: Review each changed file statically (do not build or run tests). Inspect the diff and read unchanged files (signatures, constants, types) to understand the full impact.
  3. Apply Checklists: For each file, evaluate changes against the checklists below.
  4. Report: Synthesize observations into a single cohesive report, grouped by impact (critical bugs, architectural, minor).

Review Checklist

Do not approve merely because the code works. Apply the following checks:

1. Code Smells Baseline (Fowler Refactoring, Ch. 3)

Review the diff against this checklist of common smells. Each smell is a judgment call, never a hard violation. A documented repository standard overrides this baseline.

  • Mysterious Name — Function, variable, or type name doesn't reveal intent. → Suggest a rename.
  • Primitive Obsession — Raw strings/primitives used for domain concepts. → Suggest enums, union types, or custom types.
  • Data Clumps — Same groups of parameters/fields travel together. → Suggest bundling into an object or type.
  • Duplicated Code — Same logic shape appears in multiple places. → Suggest extracting a shared helper.
  • Shotgun Surgery — A single logical change forces edits across many files. → Suggest grouping them into one module.
  • Divergent Change — A module is edited for multiple unrelated reasons. → Suggest splitting the module.
  • Feature Envy — A method accesses another object's data more than its own. → Suggest moving the method onto the envied object.
  • Speculative Generality — Hooks/parameters added for future needs. → Suggest deleting/inlining until a real need arises.
  • Message Chains — Long navigation chains (e.g. a.b().c()). → Suggest hiding the traversal behind a single delegate method.
  • Middle Man — A class/function mostly delegates directly to another. → Suggest removing the middle man.
  • Refused Bequest — Subclass ignores/overrides inherited features. → Suggest composition over inheritance.
  • Repeated Switches — Same switch/if cascade on a type is repeated. → Suggest polymorphism or a shared mapping.
Show full SKILL.md (475 more words)Show less
2. Quality, Robustness & Maintainability

Reject the change if it introduces:

  • Tangled Flow — Ad-hoc branching or complex conditional trees. → Suggest guard clauses or state machines.
  • Scattered Logic — Feature-specific logic placed in shared/common modules. → Suggest moving it to the feature domain.
  • Weak Abstraction — Indirection that doesn't simplify or reuse code. → Suggest inlining or reverting to direct calls.
  • Redundant State — Duplicate state or cached values that can be derived. → Suggest deriving values dynamically.
  • Parameter Sprawl — Function parameter list grows excessively. → Suggest bundling into a config object.
  • Stringly-typed Code — Raw strings used instead of constants/unions. → Suggest converting to enums or string union types.
  • Loose Typing — Unjustified usage of any, unknown, or casting. → Suggest precise types or type guards.
  • Type Boundary Drift — Deserialization/API boundaries are not validated. → Suggest schema validation (e.g., Zod) or type assertions at the boundary.
  • Resource Leak — Timers, event listeners, or streams registered without cleanup. → Suggest adding cleanup in teardown hooks (e.g., ngOnDestroy).
  • Connection Leak — DB/network handles left open in error paths. → Suggest closing handles in finally blocks.
  • Robustness Flaw — Unhandled boundary cases (null, empty, large payloads) or ungraceful crash on network/file failures. → Suggest guard clauses and graceful fallback handling.
  • Unsanitized Input — User/external inputs not escaped. → Suggest escaping control characters (e.g. *, _, ` in markdown; <, >, & in HTML).
  • Doc Drift — Public API changes lack corresponding JSDoc updates. → Suggest updating documentation.
  • Dependency Issues — Missing or unused dependencies in build configs. → Suggest resolving dependencies.
3. Code Reuse & Integration

Flag these opportunities:

  • Duplicate Utility — Logic duplicates existing helper functions. → Suggest using the existing helper.
  • Hand-rolled Utility — Inline code implements common utility tasks (path handling, environment/flag checks). → Suggest using standard codebase utilities.
  • Search Rule — generic-looking code patterns are added without checking. → Actively search for existing helpers using grep_search.
4. Efficiency & Performance

Reject the change if it introduces:

  • Waste — Redundant computations, repeated file reads, or duplicate API calls. → Suggest caching or batching.
  • Sequential Async — Independent async calls run sequentially. → Suggest combining via Promise.all or Promise.allSettled.
  • Hot-Path Bloat — Blocking tasks in startup, request handlers, or render loops. → Suggest async processing or lazy loading.
  • TOCTOU Check — Pre-checking resource existence before operating (e.g. checking file existence). → Suggest operating directly and catching errors (e.g. ENOENT).
  • Broad Scopes — Reading/loading entire files/datasets when filtering is possible. → Suggest scoped reads or query-level filtering.
5. Unit Test Quality (If tests changed)

Reject the change if it introduces:

  • Mock Drift — Mocks that drift from real signatures or use generic any structures. → Suggest type-safe mock frameworks.
  • Bespoke Mocks — Manual component/DOM construction in tests. → Suggest reusing testing factories or helpers.
  • Weak Assertions — Assertions that are trivial or verify properties unrelated to the behavior under test. → Suggest precise assertions verifying behavioral side-effects.
  • Bloated Setup — Repeated boilerplate/mock setups across tests. → Suggest extracting to beforeEach hooks or shared helpers.
  • Inconsistent Style — Test structure diverges from surrounding tests. → Suggest aligning with local patterns.
  • Missing Coverage — New complex logic or branches added without tests. → Reject change and request new unit tests.

© jackfranklin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude/skills/code-review of jackfranklin/dotfiles.

Open the folder on GitHubat commit 48208f5

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skilljackfranklin/dotfiles255—~2kAutomated safety check: PassMIT
Code Reviewpolyipseity/obsidian-terminal948—~1.6kAutomated safety check: PassAGPL-3.0
Senior Code Criticnekomangaorg/Neko2.8k—~1.8kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review

    polyipseity/obsidian-terminal

    A skill your agent uses when reviewing PRs, code changes, or conducting code audits in obsidian-terminal.

    948 GitHub stars~1.6k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Senior Code Critic

    nekomangaorg/Neko

    Performs rigorous, adversarial senior-staff code reviews that ruthlessly uncover architectural anti-patterns, edge cases, lifecycle hazards, memory leaks, type-safety gaps, and performance pitfalls.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline…

    9.5k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed

More from jackfranklin/dotfiles

All 19 skills in this repo
  • GitHub Code Review

    jackfranklin/dotfiles

    Perform a thorough, read-only review of one GitHub pull request.

    255 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Adr

    jackfranklin/dotfiles

    Capture an Architecture Decision Record (ADR) for a significant decision made in the current project.

    255 GitHub stars~962 tokensUpdated today
    Auto-check passed
  • Jack References

    jackfranklin/dotfiles

    Manage Jack's personal technical reference library at ~/git/references.

    255 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Later

    jackfranklin/dotfiles

    Log items to come back to later — bugs found mid-task, feature ideas, project feedback — as GitHub Issues.

    255 GitHub stars~767 tokensUpdated today
    Auto-check passed
  • New Deno App

    jackfranklin/dotfiles

    Scaffold a new Deno 2 + Hono + Deno KV + Eta + HTMX app with password auth and PWA support.

    255 GitHub stars~3.6k tokensUpdated today
    Auto-check: notes
  • Resolve Merge Conflict

    jackfranklin/dotfiles

    A skill your agent uses when you need to resolve an in-progress git merge/rebase conflict.

    255 GitHub starsUsed in 23 repos~427 tokens
    Auto-check passed

Works with

Categories

Questions about Code Review

What does Code Review do?

Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency. Code Review is an agent skill from jackfranklin/dotfiles. Aggressive maintainability review focused on structural simplification, deleting complexity, type safety compiler soundness, resource leaks, accessibility, localization, and concurrency.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review; tasks that involve Type safety; tasks that involve Internationalization.

How do I install Code Review in Claude Code?

Run `npx skills add jackfranklin/dotfiles --skill code-review -a claude-code`. Or copy the skill folder (claude/skills/code-review in jackfranklin/dotfiles) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add jackfranklin/dotfiles --skill code-review -a codex`. Or copy the skill folder (claude/skills/code-review in jackfranklin/dotfiles) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jackfranklin/dotfiles --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review (polyipseity/obsidian-terminal, 948 stars), Senior Code Critic (nekomangaorg/Neko, 2.8k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

jackfranklin (a GitHub user) maintains it in jackfranklin/dotfiles, which has 255 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: jackfranklin/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.