Agent skill

Code Review

by LeoYeAI in LeoYeAI/openclaw-master-skills

Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to…

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
2.2k
Token cost
~3.1k tokens
SKILL.md length
1,490 words
Files
2
Skills in repo
1,215
Repo updated
First seen
Licence
MIT

At a glance

Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to…

  • Works in 4 steps: Read the PR description and linked issue → Scan the file list — does the change… → Check the overall approach — is this the… → …
  • Establishing review standards
  • SKILL.md covers Installation, Review Dimensions, Security Checklist and Performance Checklist, plus 8 more sections
  • Calls npx

What it does

Code Review is an agent skill from LeoYeAI/openclaw-master-skills. Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Development, covering Code review and Web application vulnerabilities. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Establishing review standards
  • Improving review quality

Example prompts

  • “/code-review”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the PR description and linked issue
  2. Scan the file list — does the change scope make sense?
  3. Check the overall approach — is this the right solution to the problem?
  4. Verify the change does not introduce architectural drift

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 3.1k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,490 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,490 words, ~3,059 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review
description
Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality.
model
reasoning
category
testing
version
1

Code Review Checklist

Thorough, structured approach to reviewing code. Work through each dimension systematically rather than scanning randomly.

Installation

OpenClaw / Moltbot / Clawbot
bash
npx clawhub@latest install code-review

Review Dimensions

DimensionFocusPriority
SecurityVulnerabilities, auth, data exposureCritical
PerformanceSpeed, memory, scalability bottlenecksHigh
CorrectnessLogic errors, edge cases, data integrityHigh
MaintainabilityReadability, structure, future-proofingMedium
TestingCoverage, quality, reliability of testsMedium
AccessibilityWCAG compliance, keyboard nav, screen readersMedium
DocumentationComments, API docs, changelog entriesLow

Security Checklist

Review every change for these vulnerabilities:

  • SQL Injection — All queries use parameterized statements or an ORM; no string concatenation with user input
  • XSS — User-provided content is escaped/sanitized before rendering; dangerouslySetInnerHTML or equivalent is justified and safe
  • CSRF Protection — State-changing requests require valid CSRF tokens; SameSite cookie attributes are set
  • Authentication — Every protected endpoint verifies the user is authenticated before processing
  • Authorization — Resource access is scoped to the requesting user's permissions; no IDOR vulnerabilities
  • Input Validation — All external input (params, headers, body, files) is validated for type, length, format, and range on the server side
  • Secrets Management — No API keys, passwords, tokens, or credentials in source code; secrets come from environment variables or a vault
  • Dependency Safety — New dependencies are from trusted sources, actively maintained, and free of known CVEs
  • Sensitive Data — PII, tokens, and secrets are never logged, included in error messages, or returned in API responses
  • Rate Limiting — Public and auth endpoints have rate limits to prevent brute-force and abuse
  • File Upload Safety — Uploaded files are validated for type and size, stored outside the webroot, and served with safe Content-Type headers
  • HTTP Security Headers — Content-Security-Policy, X-Content-Type-Options, Strict-Transport-Security are set

Performance Checklist

  • N+1 Queries — Database access patterns are batched or joined; no loops issuing individual queries
  • Unnecessary Re-renders — Components only re-render when their relevant state/props change; memoization is applied where measurable
  • Memory Leaks — Event listeners, subscriptions, timers, and intervals are cleaned up on unmount/disposal
  • Bundle Size — New dependencies are tree-shakeable; large libraries are loaded dynamically; no full-library imports for a single function
  • Lazy Loading — Heavy components, routes, and below-the-fold content use lazy loading / code splitting
  • Caching Strategy — Expensive computations and API responses use appropriate caching (memoization, HTTP cache headers, Redis)
  • Database Indexing — Queries filter/sort on indexed columns; new queries have been checked with EXPLAIN
  • Pagination — List endpoints and queries use pagination or cursor-based fetching; no unbounded SELECT *
  • Async Operations — Long-running tasks are offloaded to background jobs or queues rather than blocking request threads
  • Image & Asset Optimization — Images are properly sized, use modern formats (WebP/AVIF), and leverage CDN delivery

Correctness Checklist

  • Edge Cases — Empty arrays, empty strings, zero values, negative numbers, and maximum values are handled
  • Null/Undefined Handling — Nullable values are checked before access; optional chaining or guards prevent runtime errors
  • Off-by-One Errors — Loop bounds, array slicing, pagination offsets, and range calculations are verified
  • Race Conditions — Concurrent access to shared state uses locks, transactions, or atomic operations
  • Timezone Handling — Dates are stored in UTC; display conversion happens at the presentation layer
  • Unicode & Encoding — String operations handle multi-byte characters; text encoding is explicit (UTF-8)
  • Integer Overflow / Precision — Arithmetic on large numbers or currency uses appropriate types (BigInt, Decimal)
  • Error Propagation — Errors from async calls and external services are caught and handled; promises are never silently swallowed
  • State Consistency — Multi-step mutations are transactional; partial failures leave the system in a valid state
  • Boundary Validation — Values at the boundaries of valid ranges (min, max, exactly-at-limit) are tested

Maintainability Checklist

  • Naming Clarity — Variables, functions, and classes have descriptive names that reveal intent
  • Single Responsibility — Each function/class/module does one thing; changes to one concern don't ripple through unrelated code
  • DRY — Duplicated logic is extracted into shared utilities; copy-pasted blocks are consolidated
  • Cyclomatic Complexity — Functions have low branching complexity; deeply nested chains are refactored
  • Error Handling — Errors are caught at appropriate boundaries, logged with context, and surfaced meaningfully
  • Dead Code Removal — Commented-out code, unused imports, unreachable branches, and obsolete feature flags are removed
  • Magic Numbers & Strings — Literal values are extracted into named constants with clear semantics
  • Consistent Patterns — New code follows the conventions already established in the codebase
  • Function Length — Functions are short enough to understand at a glance; long functions are decomposed
  • Dependency Direction — Dependencies point inward (infrastructure to domain); core logic does not import from UI or framework layers

Testing Checklist

  • Test Coverage — New logic paths have corresponding tests; critical paths have both happy-path and failure-case tests
  • Edge Case Tests — Tests cover boundary values, empty inputs, nulls, and error conditions
  • No Flaky Tests — Tests are deterministic; no reliance on timing, external services, or shared mutable state
  • Test Independence — Each test sets up its own state and tears it down; test order does not affect results
  • Meaningful Assertions — Tests assert on behavior and outcomes, not implementation details
  • Test Readability — Tests follow Arrange-Act-Assert; test names describe the scenario and expected outcome
  • Mocking Discipline — Only external boundaries (network, DB, filesystem) are mocked
  • Regression Tests — Bug fixes include a test that reproduces the original bug and proves it is resolved

Review Process

Work through the code in three passes. Do not try to catch everything in one read.

PassFocusTimeWhat to Look For
FirstHigh-level structure2-5 minArchitecture fit, file organization, API design, overall approach
SecondLine-by-line detailBulkLogic errors, security issues, performance problems, edge cases
ThirdEdge cases & hardening5 minFailure modes, concurrency, boundary values, missing tests
Show full SKILL.md (610 more words)Show less
First Pass (2-5 minutes)
  1. Read the PR description and linked issue
  2. Scan the file list — does the change scope make sense?
  3. Check the overall approach — is this the right solution to the problem?
  4. Verify the change does not introduce architectural drift
Second Pass (bulk of review time)
  1. Read each file diff top to bottom
  2. Check every function change against the checklists above
  3. Verify error handling at every I/O boundary
  4. Flag anything that makes you pause — trust your instincts
Third Pass (5 minutes)
  1. Think about what could go wrong in production
  2. Check for missing tests on the code paths you flagged
  3. Verify rollback safety — can this change be reverted without data loss?
  4. Confirm documentation and changelog are updated if needed

Severity Levels

Classify every comment by severity so the author knows what blocks merge.

LevelLabelMeaningBlocks Merge?
Critical[CRITICAL]Security vulnerability, data loss, or crash in productionYes
Major[MAJOR]Bug, logic error, or significant performance regressionYes
Minor[MINOR]Improvement that would reduce future maintenance costNo
Nitpick[NIT]Style preference, naming suggestion, or trivial cleanupNo

Always prefix your review comment with the severity label. This removes ambiguity about what matters.


Giving Feedback

Principles
  • Be specific — Point to the exact line and explain the issue, not just "this is wrong"
  • Explain why — State the risk or consequence, not just the rule
  • Suggest a fix — Offer a concrete alternative or code snippet when possible
  • Ask, don't demand — Use questions for subjective points: "What do you think about...?"
  • Acknowledge good work — Call out clean solutions, clever optimizations, or thorough tests
  • Separate blocking from non-blocking — Use severity labels so the author knows what matters
Example Comments

Bad:

This is wrong. Fix it.

Good:

[MAJOR] This query interpolates user input directly into the SQL string (line 42), which is vulnerable to SQL injection. Consider using a parameterized query:

sql
SELECT * FROM users WHERE id = $1

Bad:

Why didn't you add tests?

Good:

[MINOR] The new calculateDiscount() function has a few branching paths — could we add tests for the zero-quantity and negative-price edge cases to prevent regressions?

Bad:

I would have done this differently.

Good:

[NIT] This works well. An alternative approach could be extracting the retry logic into a shared withRetry() wrapper — but that's optional and could be a follow-up.


Review Anti-Patterns

Avoid these common traps that waste time and damage team trust:

Anti-PatternDescription
Rubber-StampingApproving without reading. Creates false confidence and lets bugs through.
BikesheddingSpending 30 minutes debating a variable name while ignoring a race condition.
Blocking on StyleRefusing to approve over formatting that a linter should enforce automatically.
GatekeepingRequiring your personal preferred approach when the submitted one is correct.
Drive-by ReviewsLeaving one vague comment and disappearing. Commit to following through.
Scope Creep ReviewsRequesting unrelated refactors that should be separate PRs.
Stale ReviewsLetting PRs sit for days. Review within 24 hours or hand off to someone else.
Emotional Language"This is terrible" or "obviously wrong." Critique the code, not the person.

NEVER Do

  1. NEVER approve without reading every changed line — rubber-stamping is worse than no review
  2. NEVER block a PR solely for style preferences — use a linter; humans review logic
  3. NEVER leave feedback without a severity level — ambiguity causes wasted cycles
  4. NEVER request changes without explaining why — "fix this" teaches nothing
  5. NEVER review more than 400 lines in one sitting — comprehension drops sharply; break large PRs into sessions
  6. NEVER skip the security checklist — one missed vulnerability outweighs a hundred style nits
  7. NEVER make it personal — review the code, never the coder; assume good intent

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/code-review of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillLeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Reviewmaiobarbero/my-ai-workflow140—~1.2kAutomated safety check: PassNone
Cwe Code ReviewSpecterOps/skills702—~2.4kAutomated safety check: PassApache-2.0
Advpl Code Reviewthalysjuvenal/advpl-specialist185—~604Automated safety check: PassMIT
Suede Code ReviewJasonColapietro/suede-creator-skills127—~7.1kAutomated safety check: PassMIT

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review

    maiobarbero/my-ai-workflow

    Perform a language-agnostic first-pass code review covering logic errors, bad practices, operation ordering, magic strings, pattern improvements, strict type checking, and SQL injection.

    140 GitHub stars~1.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 14 days ago
    DevelopmentAuto-check passed
  • Advpl Code Review

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…

    185 GitHub stars~604 tokensUpdated 23 days ago
    DevelopmentAuto-check passed
  • Suede Code Review

    JasonColapietro/suede-creator-skills

    Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.

    127 GitHub stars~7.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    186 GitHub stars~549 tokensUpdated 12 days ago
    DevelopmentAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,215 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to…. Code Review is an agent skill from LeoYeAI/openclaw-master-skills. Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid.

When should I use Code Review?

Code Review fits situations like: establishing review standards; improving review quality.

How do I install Code Review in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in LeoYeAI/openclaw-master-skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a codex`. Or copy the skill folder (skills/code-review in LeoYeAI/openclaw-master-skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review (maiobarbero/my-ai-workflow, 140 stars), Cwe Code Review (SpecterOps/skills, 702 stars) and Advpl Code Review (thalysjuvenal/advpl-specialist, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.