Agent skill

Code Review

by llama-farm in llama-farm/llamafarm

Comprehensive code review for diffs. An agent skill from llama-farm/llamafarm.

Apache-2.0Auto-check: notesDevelopment

Install Code Review

skills CLI
$ npx skills add llama-farm/llamafarm --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install llama-farm/llamafarm code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/llama-farm/llamafarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
836
Token cost
~2.3k tokens
SKILL.md length
942 words
Files
3
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensive code review for diffs. An agent skill from llama-farm/llamafarm.

  • Works in 6 steps: Parse the Diff → Initialize the Review Document → Review Changed Code → …
  • Tasks that involve Code review
  • SKILL.md covers Input Model, Domain Detection, Review Process and Generic Review Categories, plus 7 more sections
  • Calls git

What it does

Code Review is an agent skill from llama-farm/llamafarm. Comprehensive code review for diffs. Analyzes changed code for security vulnerabilities, anti-patterns, and quality issues. Auto-detects domain (frontend/backend) from file paths.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `backend.md` and `frontend.md`).

It sits in Development, covering Code review. It works with Git. The repository describes itself as: Deploy any AI model, agent, database, RAG, and pipeline locally or remotely in minutes. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/code-review”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Edit, Write, Grep, Glob, Task

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse the Diff
  2. Initialize the Review Document
  3. Review Changed Code
  4. Impact Analysis
  5. Document Each Finding
  6. Finalize the Report

What it can do on your machine

Read from SKILL.md and the folder at commit 6244d46. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit
    • Write
    • Grep
    • Glob
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.3k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 942 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit, Write, Grep, Glob, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from llama-farm/llamafarm at commit 6244d46, republished under its Apache-2.0 licence (© llama-farm). 942 words, ~2,337 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
code-review
description
Comprehensive code review for diffs. Analyzes changed code for security vulnerabilities, anti-patterns, and quality issues. Auto-detects domain (frontend/backend) from file paths.
allowed-tools
Bash, Read, Edit, Write, Grep, Glob, Task

Code Review Skill

You are performing a comprehensive code review on a diff. Your task is to analyze the changed code for security vulnerabilities, anti-patterns, and quality issues.

Input Model

This skill expects a diff to be provided in context before invocation. The caller is responsible for generating the diff.

Example invocations:

  • User pastes PR diff, then runs /code-review
  • Agent runs git diff HEAD~1, then invokes this skill
  • CI tool provides diff content for review

If no diff is present in context, ask the user to provide one or offer to generate one (e.g., git diff, git diff main..HEAD).


Domain Detection

Auto-detect which checklists to apply based on directory paths in the diff:

DirectoryDomainChecklist
designer/FrontendRead frontend.md
server/BackendRead backend.md
rag/BackendRead backend.md
runtimes/universal/BackendRead backend.md
cli/CLI/GoGeneric checks only
config/ConfigGeneric checks only

If the diff spans multiple domains, load all relevant checklists.


Review Process

Step 1: Parse the Diff

Extract from the diff:

  • List of changed files
  • Changed lines (additions and modifications)
  • Detected domains based on file paths
Step 2: Initialize the Review Document

Create a review document using the temp-files pattern:

bash
SANITIZED_PATH=$(echo "$PWD" | tr '/' '-')
REPORT_DIR="/tmp/claude/${SANITIZED_PATH}/reviews"
mkdir -p "$REPORT_DIR"
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
FILEPATH="${REPORT_DIR}/code-review-${TIMESTAMP}.md"

Initialize with this schema:

markdown
# Code Review Report

**Date**: {current date}
**Reviewer**: Code Review Agent
**Source**: {e.g., "PR diff", "unstaged changes", "main..HEAD"}
**Files Changed**: {count}
**Domains Detected**: {list}
**Status**: In Progress

## Summary

| Category | Items Checked | Passed | Failed | Findings |
|----------|---------------|--------|--------|----------|
| Security | 0 | 0 | 0 | 0 |
| Code Quality | 0 | 0 | 0 | 0 |
| LLM Code Smells | 0 | 0 | 0 | 0 |
| Impact Analysis | 0 | 0 | 0 | 0 |
| Simplification | 0 | 0 | 0 | 0 |
{domain-specific categories added based on detected domains}

## Detailed Findings

{findings added here as review progresses}
Step 3: Review Changed Code

For EACH checklist item:

  1. Scope feedback to diff lines only - Only flag issues in the changed code
  2. Use file context - Read full file content to understand surrounding code
  3. Apply relevant checks - Use domain-appropriate checklist items
  4. Document findings - Record each violation found in changed code

Key principle: The diff is what gets reviewed. The rest of the file provides context to make that review accurate.

Step 4: Impact Analysis

Check if the diff might affect other parts of the codebase:

  • Changed exports/interfaces - Search for usages elsewhere that may break
  • Modified API signatures - Check for callers that need updating
  • Altered shared utilities - Look for consumers that may be affected
  • Config/schema changes - Find code that depends on old structure

Report any unaccounted-for impacts as findings with severity based on risk.

Step 5: Document Each Finding

For each issue found, add an entry:

markdown
### [{CATEGORY}] {Item Name}

**Status**: FAIL
**Severity**: Critical | High | Medium | Low
**Scope**: Changed code | Impact analysis

#### Violation

- **File**: `path/to/file.ext`
- **Line(s)**: 42-48 (from diff)
- **Code**:

// problematic code snippet from diff

- **Issue**: {explanation of what's wrong}
- **Recommendation**: {how to fix it}
Step 6: Finalize the Report

After completing all checks:

  1. Update the summary table with final counts
  2. Add an executive summary:
    • Total issues found
    • Critical issues requiring immediate attention
    • Impact analysis results
    • Recommended priority order for fixes
  3. Update status to "Complete"
  4. Inform the user of the report location

Generic Review Categories

These checks apply to ALL changed code regardless of domain.


Category: Security Fundamentals

Hardcoded Secrets

Check diff for:

  • API keys, passwords, secrets in changed code
  • Patterns: api_key, apiKey, password, secret, token, credential with literal values

Pass criteria: No hardcoded secrets in diff (should use environment variables) Severity: Critical


Eval and Dynamic Code Execution

Check diff for:

  • JavaScript/TypeScript: eval(, new Function(, setTimeout(", setInterval("
  • Python: eval(, exec(, compile(

Pass criteria: No dynamic code execution in changed lines Severity: Critical


Command Injection

Check diff for:

  • Python: subprocess with shell=True, os.system(
  • Go: exec.Command( with unsanitized input

Pass criteria: No unvalidated user input in shell commands Severity: Critical


Category: Code Quality

Console/Print Statements

Check diff for:

  • JavaScript/TypeScript: console.log, console.debug, console.info
  • Python: print( statements

Pass criteria: No debug statements in production code changes Severity: Low


TODO/FIXME Comments

Check diff for:

  • TODO:, FIXME:, HACK:, XXX: comments

Pass criteria: New TODOs should be tracked in issues Severity: Low


Show full SKILL.md (389 more words)Show less
Empty Catch/Except Blocks

Check diff for:

  • JavaScript/TypeScript: catch { } or catch(e) { }
  • Python: except: pass or empty except blocks

Pass criteria: All error handlers log or rethrow Severity: High


Category: LLM Code Smells

Placeholder Implementations

Check diff for:

  • TODO, PLACEHOLDER, IMPLEMENT, NotImplemented
  • Functions that just return None, return [], return {}

Pass criteria: No placeholder implementations in production code Severity: High


Overly Generic Abstractions

Check diff for:

  • New classes/functions with names like GenericHandler, BaseManager, AbstractFactory
  • Abstractions without clear reuse justification

Pass criteria: Abstractions are justified by actual reuse Severity: Low


Category: Impact Analysis

Breaking Changes

Check if diff modifies:

  • Exported functions/classes - search for imports elsewhere
  • API endpoints - search for callers
  • Shared types/interfaces - search for usages
  • Config schemas - search for consumers

Pass criteria: All impacted code identified and accounted for Severity: High (if unaccounted impacts found)


Category: Simplification

Duplicate Logic

Check diff for:

  • Repeated code patterns (not just syntactic similarity)
  • Copy-pasted code with minor variations
  • Similar validation, transformation, or formatting logic

Pass criteria: No obvious duplication in changed code Severity: Medium Suggestion: Extract shared logic into reusable functions


Unnecessary Complexity

Check diff for:

  • Deeply nested conditionals (more than 3 levels)
  • Functions doing multiple unrelated things
  • Overly complex control flow

Pass criteria: Code is reasonably flat and focused Severity: Medium Suggestion: Use early returns, extract helper functions


Verbose Patterns

Check diff for:

  • Patterns that have simpler alternatives in the language
  • Redundant null checks or type assertions
  • Unnecessary intermediate variables

Pass criteria: Code uses idiomatic patterns Severity: Low Suggestion: Simplify using language built-ins


Domain-Specific Review Items

Based on detected domains, read and apply the appropriate checklists:

  • Frontend detected (designer/): Read frontend.md and apply those checks to changed code
  • Backend detected (server/, rag/, runtimes/): Read backend.md and apply those checks to changed code

Final Summary Template

markdown
## Executive Summary

**Review completed**: {timestamp}
**Total findings**: {count}

### Critical Issues (Must Fix)
1. {issue 1}
2. {issue 2}

### Impact Analysis Results
- {summary of any breaking changes or unaccounted impacts}

### High Priority (Should Fix)
1. {issue 1}
2. {issue 2}

### Recommendations
{Overall recommendations based on the changes reviewed}

Notes for the Agent

  1. Scope to diff: Only flag issues in the changed lines. Don't review unchanged code.

  2. Use context: Read full files to understand the changes, but feedback targets the diff only.

  3. Check impacts: When changes touch exports, APIs, or shared code, search for affected consumers.

  4. Be specific: Include file paths, line numbers (from diff), and code snippets for every finding.

  5. Prioritize: Flag critical security issues immediately.

  6. Provide solutions: Each finding should include a recommendation for how to fix it.

  7. Update incrementally: Update the review document after each category, not at the end.

© llama-farm, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .claude/skills/code-review of llama-farm/llamafarm.

  • SKILL.md
  • backend.md
  • frontend.md

Open the folder on GitHubat commit 6244d46

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillllama-farm/llamafarm836—~2.3kAutomated safety check: NotesApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Hunk Diff Session Controlmodem-dev/hunk9.5k1 repos~3.4kAutomated safety check: PassMIT
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline…

    9.5k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from llama-farm/llamafarm

All 19 skills in this repo
  • Reflect

    llama-farm/llamafarm

    Analyze the current session and propose improvements to skills.

    836 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • RAG Skills

    llama-farm/llamafarm

    RAG-specific best practices for LlamaIndex, ChromaDB, and Celery workers.

    836 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Temp Files

    llama-farm/llamafarm

    Guidelines for creating temporary files in system temp directory.

    836 GitHub stars~515 tokensUpdated 4 mo ago
    Auto-check: notes
  • Runtime Skills

    llama-farm/llamafarm

    Universal Runtime best practices for PyTorch inference, Transformers models, and FastAPI serving.

    836 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • CLI Skills

    llama-farm/llamafarm

    CLI best practices for LlamaFarm. An agent skill from llama-farm/llamafarm.

    836 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Commit Push PR

    llama-farm/llamafarm

    Commit changes, push to GitHub, and open a PR. An agent skill from llama-farm/llamafarm.

    836 GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Code Review

What does Code Review do?

Comprehensive code review for diffs. An agent skill from llama-farm/llamafarm. Code Review is an agent skill from llama-farm/llamafarm. Comprehensive code review for diffs.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review.

How do I install Code Review in Claude Code?

Run `npx skills add llama-farm/llamafarm --skill code-review -a claude-code`. Or copy the skill folder (.claude/skills/code-review in llama-farm/llamafarm) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add llama-farm/llamafarm --skill code-review -a codex`. Or copy the skill folder (.claude/skills/code-review in llama-farm/llamafarm) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add llama-farm/llamafarm --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Bash, Read, Edit, Write, Grep, Glob, Task.

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars) and Hunk Diff Session Control (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

llama-farm (a GitHub organization) maintains it in llama-farm/llamafarm, which has 836 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 10, 2026.

Source: llama-farm/llamafarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.