Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "code-review" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
code-review
GitHub stars
2.2k
Token cost
~3.1k tokens
SKILL.md length
1,490 words
Files
2
Skills in repo
1,215
Repo updated
First seen
Licence
MIT
At a glance
Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to…
Works in 4 steps: Read the PR description and linked issue → Scan the file list — does the change… → Check the overall approach — is this the… → …
Establishing review standards
SKILL.md covers Installation, Review Dimensions, Security Checklist and Performance Checklist, plus 8 more sections
Calls npx
What it does
Code Review is an agent skill from LeoYeAI/openclaw-master-skills. Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).
It sits in Development, covering Code review and Web application vulnerabilities. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
When your agent uses it
Establishing review standards
Improving review quality
Example prompts
“/code-review”
Requirements
Node.js
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Read the PR description and linked issue
2Scan the file list — does the change scope make sense?
3Check the overall approach — is this the right solution to the problem?
4Verify the change does not introduce architectural drift
What it can do on your machine
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
npx
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Code Review loads about 3.1k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,490 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~75
When it runs· the whole SKILL.md, loaded when a task matches
~3.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review
description
Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality.
model
reasoning
category
testing
version
1
Code Review Checklist
Thorough, structured approach to reviewing code. Work through each dimension systematically rather than scanning randomly.
Installation
OpenClaw / Moltbot / Clawbot
bash
npx clawhub@latest install code-review
Review Dimensions
Dimension
Focus
Priority
Security
Vulnerabilities, auth, data exposure
Critical
Performance
Speed, memory, scalability bottlenecks
High
Correctness
Logic errors, edge cases, data integrity
High
Maintainability
Readability, structure, future-proofing
Medium
Testing
Coverage, quality, reliability of tests
Medium
Accessibility
WCAG compliance, keyboard nav, screen readers
Medium
Documentation
Comments, API docs, changelog entries
Low
Security Checklist
Review every change for these vulnerabilities:
SQL Injection — All queries use parameterized statements or an ORM; no string concatenation with user input
XSS — User-provided content is escaped/sanitized before rendering; dangerouslySetInnerHTML or equivalent is justified and safe
CSRF Protection — State-changing requests require valid CSRF tokens; SameSite cookie attributes are set
Authentication — Every protected endpoint verifies the user is authenticated before processing
Authorization — Resource access is scoped to the requesting user's permissions; no IDOR vulnerabilities
Input Validation — All external input (params, headers, body, files) is validated for type, length, format, and range on the server side
Secrets Management — No API keys, passwords, tokens, or credentials in source code; secrets come from environment variables or a vault
Dependency Safety — New dependencies are from trusted sources, actively maintained, and free of known CVEs
Sensitive Data — PII, tokens, and secrets are never logged, included in error messages, or returned in API responses
Rate Limiting — Public and auth endpoints have rate limits to prevent brute-force and abuse
File Upload Safety — Uploaded files are validated for type and size, stored outside the webroot, and served with safe Content-Type headers
HTTP Security Headers — Content-Security-Policy, X-Content-Type-Options, Strict-Transport-Security are set
Performance Checklist
N+1 Queries — Database access patterns are batched or joined; no loops issuing individual queries
Unnecessary Re-renders — Components only re-render when their relevant state/props change; memoization is applied where measurable
Memory Leaks — Event listeners, subscriptions, timers, and intervals are cleaned up on unmount/disposal
Bundle Size — New dependencies are tree-shakeable; large libraries are loaded dynamically; no full-library imports for a single function
Lazy Loading — Heavy components, routes, and below-the-fold content use lazy loading / code splitting
Caching Strategy — Expensive computations and API responses use appropriate caching (memoization, HTTP cache headers, Redis)
Database Indexing — Queries filter/sort on indexed columns; new queries have been checked with EXPLAIN
Pagination — List endpoints and queries use pagination or cursor-based fetching; no unbounded SELECT *
Async Operations — Long-running tasks are offloaded to background jobs or queues rather than blocking request threads
Image & Asset Optimization — Images are properly sized, use modern formats (WebP/AVIF), and leverage CDN delivery
Correctness Checklist
Edge Cases — Empty arrays, empty strings, zero values, negative numbers, and maximum values are handled
Null/Undefined Handling — Nullable values are checked before access; optional chaining or guards prevent runtime errors
Off-by-One Errors — Loop bounds, array slicing, pagination offsets, and range calculations are verified
Race Conditions — Concurrent access to shared state uses locks, transactions, or atomic operations
Timezone Handling — Dates are stored in UTC; display conversion happens at the presentation layer
Unicode & Encoding — String operations handle multi-byte characters; text encoding is explicit (UTF-8)
Integer Overflow / Precision — Arithmetic on large numbers or currency uses appropriate types (BigInt, Decimal)
Error Propagation — Errors from async calls and external services are caught and handled; promises are never silently swallowed
State Consistency — Multi-step mutations are transactional; partial failures leave the system in a valid state
Boundary Validation — Values at the boundaries of valid ranges (min, max, exactly-at-limit) are tested
Maintainability Checklist
Naming Clarity — Variables, functions, and classes have descriptive names that reveal intent
Single Responsibility — Each function/class/module does one thing; changes to one concern don't ripple through unrelated code
DRY — Duplicated logic is extracted into shared utilities; copy-pasted blocks are consolidated
Cyclomatic Complexity — Functions have low branching complexity; deeply nested chains are refactored
Error Handling — Errors are caught at appropriate boundaries, logged with context, and surfaced meaningfully
Dead Code Removal — Commented-out code, unused imports, unreachable branches, and obsolete feature flags are removed
Magic Numbers & Strings — Literal values are extracted into named constants with clear semantics
Consistent Patterns — New code follows the conventions already established in the codebase
Function Length — Functions are short enough to understand at a glance; long functions are decomposed
Dependency Direction — Dependencies point inward (infrastructure to domain); core logic does not import from UI or framework layers
Testing Checklist
Test Coverage — New logic paths have corresponding tests; critical paths have both happy-path and failure-case tests
Edge Case Tests — Tests cover boundary values, empty inputs, nulls, and error conditions
No Flaky Tests — Tests are deterministic; no reliance on timing, external services, or shared mutable state
Test Independence — Each test sets up its own state and tears it down; test order does not affect results
Meaningful Assertions — Tests assert on behavior and outcomes, not implementation details
Test Readability — Tests follow Arrange-Act-Assert; test names describe the scenario and expected outcome
Mocking Discipline — Only external boundaries (network, DB, filesystem) are mocked
Regression Tests — Bug fixes include a test that reproduces the original bug and proves it is resolved
Review Process
Work through the code in three passes. Do not try to catch everything in one read.
Pass
Focus
Time
What to Look For
First
High-level structure
2-5 min
Architecture fit, file organization, API design, overall approach
Scan the file list — does the change scope make sense?
Check the overall approach — is this the right solution to the problem?
Verify the change does not introduce architectural drift
Second Pass (bulk of review time)
Read each file diff top to bottom
Check every function change against the checklists above
Verify error handling at every I/O boundary
Flag anything that makes you pause — trust your instincts
Third Pass (5 minutes)
Think about what could go wrong in production
Check for missing tests on the code paths you flagged
Verify rollback safety — can this change be reverted without data loss?
Confirm documentation and changelog are updated if needed
Severity Levels
Classify every comment by severity so the author knows what blocks merge.
Level
Label
Meaning
Blocks Merge?
Critical
[CRITICAL]
Security vulnerability, data loss, or crash in production
Yes
Major
[MAJOR]
Bug, logic error, or significant performance regression
Yes
Minor
[MINOR]
Improvement that would reduce future maintenance cost
No
Nitpick
[NIT]
Style preference, naming suggestion, or trivial cleanup
No
Always prefix your review comment with the severity label. This removes ambiguity about what matters.
Giving Feedback
Principles
Be specific — Point to the exact line and explain the issue, not just "this is wrong"
Explain why — State the risk or consequence, not just the rule
Suggest a fix — Offer a concrete alternative or code snippet when possible
Ask, don't demand — Use questions for subjective points: "What do you think about...?"
Acknowledge good work — Call out clean solutions, clever optimizations, or thorough tests
Separate blocking from non-blocking — Use severity labels so the author knows what matters
Example Comments
Bad:
This is wrong. Fix it.
Good:
[MAJOR] This query interpolates user input directly into the SQL string (line 42), which is vulnerable to SQL injection. Consider using a parameterized query:
sql
SELECT * FROM users WHERE id = $1
Bad:
Why didn't you add tests?
Good:
[MINOR] The new calculateDiscount() function has a few branching paths — could we add tests for the zero-quantity and negative-price edge cases to prevent regressions?
Bad:
I would have done this differently.
Good:
[NIT] This works well. An alternative approach could be extracting the retry logic into a shared withRetry() wrapper — but that's optional and could be a follow-up.
Review Anti-Patterns
Avoid these common traps that waste time and damage team trust:
Anti-Pattern
Description
Rubber-Stamping
Approving without reading. Creates false confidence and lets bugs through.
Bikeshedding
Spending 30 minutes debating a variable name while ignoring a race condition.
Blocking on Style
Refusing to approve over formatting that a linter should enforce automatically.
Gatekeeping
Requiring your personal preferred approach when the submitted one is correct.
Drive-by Reviews
Leaving one vague comment and disappearing. Commit to following through.
Scope Creep Reviews
Requesting unrelated refactors that should be separate PRs.
Stale Reviews
Letting PRs sit for days. Review within 24 hours or hand off to someone else.
Emotional Language
"This is terrible" or "obviously wrong." Critique the code, not the person.
NEVER Do
NEVER approve without reading every changed line — rubber-stamping is worse than no review
NEVER block a PR solely for style preferences — use a linter; humans review logic
NEVER leave feedback without a severity level — ambiguity causes wasted cycles
NEVER request changes without explaining why — "fix this" teaches nothing
NEVER review more than 400 lines in one sitting — comprehension drops sharply; break large PRs into sessions
NEVER skip the security checklist — one missed vulnerability outweighs a hundred style nits
NEVER make it personal — review the code, never the coder; assume good intent
Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Code Review compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Code Review this skillLeoYeAI/openclaw-master-skills
A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in LeoYeAI/openclaw-master-skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
How do I install Code Review in Codex?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a codex`. Or copy the skill folder (skills/code-review in LeoYeAI/openclaw-master-skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
What does Code Review need to run?
Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
Does Code Review access the network?
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Code Review safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Code Review use?
Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Code Review use?
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Code Review?
Skills that share tags, products or a category with Code Review: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review (maiobarbero/my-ai-workflow, 140 stars), Cwe Code Review (SpecterOps/skills, 702 stars) and Advpl Code Review (thalysjuvenal/advpl-specialist, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Code Review?
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.