Official agent skill

Code Review

by langchain-ai in langchain-ai/langchain-azure

Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql…

OfficialMITAuto-check passedAI & LLM Engineering

Install Code Review

skills CLI
$ npx skills add langchain-ai/langchain-azure --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langchain-ai/langchain-azure code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langchain-ai/langchain-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
147
Token cost
~2.3k tokens
SKILL.md length
1,106 words
Files
11 (incl. references)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql…

  • Works in 5 steps: Identify the packages touched. Group… → Load the package's rules from the… → Read enough surrounding code to know… → …
  • Reviewing a pull request
  • SKILL.md covers What to report, Review workflow, Package routing and Repository gotchas, plus 2 more sections
  • Calls uv

What it does

Code Review is an agent skill from langchain-ai/langchain-azure, published by the product's own GitHub organization. Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql, langchain-azure-storage, langchain-sqlserver, and langchain-azure-dynamic-sessions, together with the LangChain, LangGraph, Deep Agents, and Azure SDK contracts each package must satisfy. Use this skill whenever reviewing a pull request or diff, checking code for bugs or regressions, or assessing changes under libs/, samples/, or…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `references/azure-ai.md`, `references/azure-compute.md` and `references/azure-cosmosdb.md`).

It sits in AI & LLM Engineering, covering Building AI agents. It works with Microsoft Azure, LangChain, LangGraph and Azure Cosmos DB. The repository describes itself as: Build secure LangChain applications on Azure. The licence is MIT.

When your agent uses it

  • Reviewing a pull request
  • Checking code for bugs
  • Assessing changes under libs/
  • .github/ in this repository

Example prompts

  • “review”
  • “look at”
  • “give feedback on”
  • “/code-review”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify the packages touched. Group changed files by libs//.
  2. Load the package's rules from the routing table below, plus any
  3. Read enough surrounding code to know what the changed lines actually do
  4. Check the upstream contract for the base class being implemented, using
  5. Confirm each finding before writing it. A finding must satisfy all four

What it can do on your machine

Read from SKILL.md and the folder at commit 5784474. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 175 tokens; SKILL.md has 1,106 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~175
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langchain-ai/langchain-azure at commit 5784474, republished under its MIT licence (© langchain-ai). 1,106 words, ~2,304 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
code-review
description
Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql, langchain-azure-storage, langchain-sqlserver, and langchain-azure-dynamic-sessions, together with the LangChain, LangGraph, Deep Agents, and Azure SDK contracts each package must satisfy. Use this skill whenever reviewing a pull request or diff, checking code for bugs or regressions, or assessing changes under libs/, samples/, or .github/ in this repository, including when the request is only to "review", "check", "look at", or "give feedback on" a change, and even when no package is named explicitly.
license
MIT

Reviewing langchain-azure changes

Every directory under libs/ is a separately versioned, separately released package with its own maintainers, dependency manager, conventions, and upstream contracts. A finding is only useful if it is correct for the package it lands in, so the first job in any review is to work out which package changed and load that package's rules before judging anything.

What to report

Report defects the change introduces: incorrect behavior, broken edge cases, regressions in released public API, violations of an upstream contract (LangChain, LangGraph, Deep Agents, Azure SDK), breakage on a supported Python version, and security, credential-leak, data-loss, resource-leak, or concurrency problems.

Stay silent about everything else. In particular, do not comment on formatting, naming, or docstring wording that ruff and mypy already enforce; do not restate what the diff does; do not raise pre-existing issues the change merely touches; and do not suggest refactors that are not required for correctness. Returning no comments on a correct change is a good review — never manufacture findings to look thorough.

Copilot code review never sees **/*.lock, **/*.svg, **/*.log, or **/dist/**, so uv.lock is invisible to you. Excluded files are also stripped from the file list you receive, so you cannot tell a lockfile that was never updated from one that was updated and hidden from you. Never write a finding about lockfile contents or lockfile presence; instead, see the lockfile gotcha below.

Review workflow

  1. Identify the packages touched. Group changed files by libs/<package>/. Treat each package as an independent review.
  2. Load the package's rules from the routing table below, plus any AGENTS.md or .github/copilot-instructions.md along the changed path. The repository root AGENTS.md is already in your context; do not re-derive it.
  3. Read enough surrounding code to know what the changed lines actually do: the function, its callers, its sync or async twin, and the nearest tests. Never review a hunk in isolation.
  4. Check the upstream contract for the base class being implemented, using ecosystem contracts and Azure SDK contracts.
  5. Confirm each finding before writing it. A finding must satisfy all four: the changed code causes it; a realistic supported input or code path reaches it; the consequence is concrete; and you can point at the specific lines. If any of these is missing, drop it.

Package routing

Read the file for each package that changed. Skip the rest.

Changed pathPackageRead
libs/azure-ai/langchain-azure-aiazure-ai.md
libs/azure-compute/langchain-azure-computeazure-compute.md
libs/azure-cosmosdb/langchain-azure-cosmosdbazure-cosmosdb.md
libs/azure-postgresql/langchain-azure-postgresqlazure-postgresql.md
libs/azure-storage/langchain-azure-storageazure-storage.md
libs/sqlserver/langchain-sqlserversqlserver.md
libs/azure-dynamic-sessions/deprecatedazure-dynamic-sessions.md
.github/, samples/, root docsrepo infrastructurerepo-infrastructure.md

Also read ecosystem contracts when the change implements or overrides a LangChain, LangGraph, or Deep Agents base class, and Azure SDK contracts when it constructs an Azure client, handles credentials, or maps service errors.

Repository gotchas

These are the mistakes that pass local review and break later. They are specific to this repository and override any general instinct.

  • Never report a missing or stale uv.lock. CI runs uv lock --check on every touched package and fails the PR if a lockfile is stale or absent, so this is already gated far more reliably than you can infer it. You cannot observe lockfiles: they are excluded from your view and omitted from the file list you receive. A reviewed-file count below the PR's total changed-file count (for example "30/37 files reviewed") means excluded files exist, and on a dependency change those are almost always the very uv.lock updates you would otherwise flag as missing. Absence of evidence here is not evidence of absence — stay silent and let CI decide.
  • Raising the minimum Python version is not a breaking change here. The repository follows a Python support policy, and dropping an end-of-life interpreter changes no API or behavior on any still-supported version. requires-python makes older runtimes resolve to the previous release rather than install an incompatible one, so nothing breaks silently. These ship as patch releases; demanding a **[Breaking change]:** marker on one contradicts the version being shipped. Do not ask for that marker on a support-policy change — see release-notes for the classification rules.
  • CI only runs Python 3.11 and 3.14, but the support range is 3.11–3.14. A construct that breaks only on 3.12–3.13 passes CI. Reason about the whole range rather than trusting a green build.
  • langchain-azure-compute enforces 100% coverage (fail_under = 100). A new uncovered branch there fails CI, so a new if or except without a test is a real finding in that package only.
  • langchain-azure-ai lazy imports must be updated in three places — the TYPE_CHECKING import, __all__, and _module_lookup. Updating fewer makes the symbol import-time-invisible or __all__-inconsistent, and unit tests catch only some of these.
  • Deprecation decorators differ per package. azure-ai and azure-dynamic-sessions use their own _api.base (deprecated, experimental); the other packages use langchain_core._api (beta, deprecated). Do not flag one package for using the other's convention.
  • New Azure client construction must stamp the package user agent. Each package defines its own constant or helper (USER_AGENT, _user_agent, get_user_agent, with_user_agent). A new client path that omits it silently drops partner telemetry attribution.
  • asyncio_mode = "auto" in every package: async tests need no @pytest.mark.asyncio. Do not ask for it.
  • --strict-markers and --strict-config are set: a new pytest.mark.* must be registered in that package's pyproject.toml or collection fails.
  • azure-cosmosdb's local instructions still describe poetry, but its Makefile and CI use uv run --frozen. The Makefile is authoritative; do not flag correct uv usage there.
  • azure-postgresql's local instructions ask for Sphinx-style docstrings while its ruff config sets pydocstyle convention to google. Follow the style already used in the file being changed and raise no docstring-style findings in that package.
  • Unit tests must not touch the network. azure-ai enforces this with pytest-socket; the same expectation applies everywhere. A new unit test that reaches a live service is a finding.
Show full SKILL.md (148 more words)Show less

Severity

Copilot code review labels comments High, Medium, or Low. Use that vocabulary.

  • High — data loss, credential or secret exposure, a regression in released public API, or a failure most users of the changed path will hit.
  • Medium — a real correctness, compatibility, or resource-handling defect on a narrower but supported path.
  • Low — a genuine but minor defect worth fixing.

If a finding does not clear the Low bar, leave it out.

Comment format

Keep each comment to the smallest useful line range and this shape:

[Severity] Short imperative title

What breaks, and the specific input or code path that triggers it. Which contract or package rule it violates. One concrete suggested fix, only when it is short and unambiguous.

Cite the contract by name (for example, "VectorStore.get_by_ids must not raise for missing IDs") rather than linking to documentation, and prefer one precise sentence over a paragraph of hedging.

© langchain-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in .github/skills/code-review of langchain-ai/langchain-azure.

  • SKILL.md
  • references/azure-ai.md
  • references/azure-compute.md
  • references/azure-cosmosdb.md
  • references/azure-dynamic-sessions.md
  • references/azure-postgresql.md
  • references/azure-sdk-contracts.md
  • references/azure-storage.md
  • references/ecosystem-contracts.md
  • references/repo-infrastructure.md
  • references/sqlserver.md

Open the folder on GitHubat commit 5784474

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skilllangchain-ai/langchain-azure147—~2.3kAutomated safety check: PassMIT
Agent Prompt Engineeringagentailor/fullstack-langgraph-nextjs-agent132—~3.6kAutomated safety check: PassMIT
Agent Eval Casesagentailor/fullstack-langgraph-nextjs-agent132—~5.3kAutomated safety check: PassMIT
Deep Agents to Pydantic AI Migrationpydantic/pydantic-ai20k—~1.7kAutomated safety check: PassMIT
Chat Gun Backend ContractHsienW/chat-gun143—~2.1kAutomated safety check: PassCustom licence
Mem0 Platform SDKmem0ai/mem067k1 repos~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Agent Prompt Engineering

    agentailor/fullstack-langgraph-nextjs-agent

    Comprehensive guide for designing, refining, and auditing system prompts for autonomous AI agents based on Anthropic's production practices.

    132 GitHub stars~3.6k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agent Eval Cases

    agentailor/fullstack-langgraph-nextjs-agent

    Decide which AI agent behaviors are worth an eval case, then write those cases — harness-, framework-, and language-agnostic.

    132 GitHub stars~5.3k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Official

    Migrates Python LangChain Deep Agents applications to Pydantic AI and Pydantic AI Harness while preserving the application's observed behavior.

    20k GitHub stars~1.7k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Apply when creating, modifying, refactoring, debugging, testing, or reviewing TypeScript, LangGraph JS, LangChain, provider adapter, tool, MCP, prompt, state, checkpoint, runtime event, or backend…

    143 GitHub stars~2.1k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Adds persistent memory to AI apps with the Mem0 Python and TypeScript SDKs: store, search, update and delete user memories, with framework integrations.

    67k GitHub starsUsed in 1 repo~1.9k tokens
    AI & LLM EngineeringAuto-check passed
  • LangSmith Trace Debugging

    ComposioHQ/awesome-claude-skills

    Debugs LangChain and LangGraph agents by pulling recent execution traces with the langsmith-fetch CLI and reporting errors, tool calls, timings and token use.

    77k GitHub starsUsed in 9 repos~2.7k tokens
    AI & LLM EngineeringAuto-check passed

More from langchain-ai/langchain-azure

  • Release Notes

    langchain-ai/langchain-azure

    Official

    Skill for compiling and writing release notes for langchain-azure packages.

    147 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Questions about Code Review

What does Code Review do?

Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql…. Code Review is an agent skill from langchain-ai/langchain-azure, published by the product's own GitHub organization. Reviews changes in the langchain-azure monorepo using package-specific knowledge of langchain-azure-ai, langchain-azure-compute, langchain-azure-cosmosdb, langchain-azure-postgresql, langchain-azure-storage, langchain-sqlserver, and langchain-azure-dynamic-sessions, together with the LangChain, LangGraph, Deep Agents, and Azure SDK contracts each package must satisfy.

When should I use Code Review?

Code Review fits situations like: reviewing a pull request; checking code for bugs; assessing changes under libs/; .github/ in this repository.

How do I install Code Review in Claude Code?

Run `npx skills add langchain-ai/langchain-azure --skill code-review -a claude-code`. Or copy the skill folder (.github/skills/code-review in langchain-ai/langchain-azure) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add langchain-ai/langchain-azure --skill code-review -a codex`. Or copy the skill folder (.github/skills/code-review in langchain-ai/langchain-azure) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langchain-ai/langchain-azure --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (uv). Our summary lists: Python 3.

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Agent Prompt Engineering (agentailor/fullstack-langgraph-nextjs-agent, 132 stars), Agent Eval Cases (agentailor/fullstack-langgraph-nextjs-agent, 132 stars), Deep Agents to Pydantic AI Migration (pydantic/pydantic-ai, 20k stars) and Chat Gun Backend Contract (HsienW/chat-gun, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

langchain-ai (a GitHub organization, an official publisher) maintains it in langchain-ai/langchain-azure, which has 147 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: langchain-ai/langchain-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.