Agent skill

Code Review

by luongnv89 in luongnv89/skills

Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add luongnv89/skills --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luongnv89/skills code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
131
Token cost
~2.4k tokens
SKILL.md length
1,130 words
Files
24 (incl. references)
Skills in repo
37
Repo updated
First seen
Licence
MIT

At a glance

Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup.

  • Works in 3 steps: Explicit wins. If the request carries… → Otherwise infer from the request. When… → No match, or phrases from more than one…
  • Writing features
  • SKILL.md covers Modes, Selecting the mode, Safety: cleanup writes code —… and Repo Sync Before Edits…, plus 8 more sections
  • Calls git

What it does

Code Review is an agent skill from luongnv89/skills. Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup. Pass mode:review|perf|clean|cleanup or infer. Don't use for writing features or generating tests (use test-coverage).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including reference files (for example `agents/circular-dep-untangler.md`, `agents/deduplicator.md` and `agents/defensive-programming-remover.md`).

It sits in Development, covering Code quality, Code review and Test generation. The repository describes itself as: Supercharge your AI agents/bots with reusable skills. The licence is MIT.

When your agent uses it

  • Writing features
  • Generating tests (use test-coverage)

Example prompts

  • “/code-review”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Explicit wins. If the request carries mode:review|perf|clean|cleanup (or --mode ), use it.
  2. Otherwise infer from the request. When one matched phrase sits inside a longer matched
  3. No match, or phrases from more than one mode? Ask which mode, naming the four options. For

What it can do on your machine

Read from SKILL.md and the folder at commit 8f80262. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.4k tokens when it runs, and up to ~31k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 1,130 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~31k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from luongnv89/skills at commit 8f80262, republished under its MIT licence (© luongnv89). 1,130 words, ~2,398 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.
name
code-review
description
Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup. Pass mode:review|perf|clean|cleanup or infer. Don't use for writing features or generating tests (use test-coverage).
license
MIT
effort
high
metadata.version
2.2.1
metadata.author
Luong NGUYEN <luongnv89@gmail.com>
metadata.architecture
router (4 modes, each a self-contained workflow in references/)

Code Review

One skill for reviewing and improving code quality. Pick a mode by intent (or pass an explicit mode: parameter); each mode is a full, self-contained workflow in references/. Load only the mode you need — this protects the agent's context budget.

Modes

ModeUse when the user wants to...Reads / writesOutputWorkflow
review (default)find bugs, security holes, quality issues in a diff/PRread-onlyprioritized findings reportreferences/review-mode.md
perfmake code faster — bottlenecks, leaks, algorithmic wasteread-onlyperformance findings reportreferences/perf-mode.md
cleanaudit readability/standards vs the bbv Clean Code cheat sheetread-onlyCLEAN_CODE_AUDIT.mdreferences/clean-mode.md
cleanupactually refactor out AI slop, dead code, duplication, cruftWRITES CODEmodified source filesreferences/cleanup-mode.md

Selecting the mode

  1. Explicit wins. If the request carries mode:review|perf|clean|cleanup (or --mode <name>), use it.
  2. Otherwise infer from the request. When one matched phrase sits inside a longer matched phrase, only the longer one counts, so "clean code review" is a clean phrase only, not also a review phrase. Phrases that do not overlap all count, whatever their length (step 3).
    • "review", "find bugs", "security", "is this correct", "look for vulnerabilities" → review
    • "slow", "faster", "optimize", "bottleneck", "memory leak", "performance" → perf
    • "clean code audit" (or "clean-code audit"), "clean code review", "check this against clean code" → clean (user-invoked only — a bare "readability" or "audit against standards" ask is ambiguous: use step 3)
    • "remove slop", "clean up the codebase", "refactor out cruft / dead code / duplication" → cleanup
  3. No match, or phrases from more than one mode? Ask which mode, naming the four options. For example, "review and optimize" matches review and perf, so ask. Use review without asking only when the request contains a review phrase and no other mode's phrase.

Safety: cleanup writes code — the other three do not

review, perf, and clean are source-read-only: they analyze and report without touching source files. Review and perf may write only the named report artifact their mode specifies (CODE_REVIEW.md for review; perf returns its report in the response). During review/perf analysis, they must not otherwise mutate the index, refs, stash, branch, worktree, or remote state. clean retains its own report-writing and sync contract. cleanup modifies files. Therefore:

  • Never enter cleanup by weak inference. Run it only when the user explicitly asks to refactor / clean up the codebase (or passes mode:cleanup). A plain "review my code" must never rewrite files — stay in a read-only mode.
  • Review and perf analysis record git rev-parse HEAD, git status, and local tracking observations without claiming remote freshness. They do not fetch, stash, pull, rebase, checkout/switch, create or delete branches/worktrees, or apply source fixes. A separately approved mutation workflow owns its own freshness and stash-first sync contract.
  • Confirm before the first write in cleanup, and follow that mode's own gating.

Repo Sync Before Edits (mandatory)

Applies to clean (writes CLEAN_CODE_AUDIT.md) and cleanup (writes source) only. review and perf never sync (see the Safety section). Before the first write in either mode:

bash
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin && git pull --rebase origin "$branch"
  • If the working tree is dirty in clean, stash first, sync, then pop the stash.
  • If the working tree is dirty in cleanup, stop and ask the user to commit or stash first.
  • If origin is missing, or the pull or stash pop conflicts, stop and ask the user. Do not write any file.
  • If the target is not a git repo, clean skips the sync and notes that in its report.

The full step, with recovery commands, is in references/clean-mode.md and references/cleanup-mode.md.

Run the mode's workflow

Read the selected mode's reference file and execute its steps exactly. Supporting files each mode uses (already colocated under this skill):

  • review → references/review-mode.md — agents agents/reviewer.md, agents/file-reviewer.md, agents/report-assembler.md; refs references/subagent-architecture.md, references/code-smells.md
  • perf → references/perf-mode.md — ref references/language-checks.md
  • clean → references/clean-mode.md — refs references/clean-code-checklist.md, references/tdd-checklist.md, references/html-report-guide.md, references/report-template.html
  • cleanup → references/cleanup-mode.md — the 8 cleaner agents in agents/ (deduplicator.md, type-consolidator.md, unused-code-killer.md, circular-dep-untangler.md, weak-type-strengthener.md, defensive-programming-remover.md, legacy-code-remover.md, slop-comment-cleaner.md)

Environment Check

If the Agent tool is available, modes that use subagents (review, cleanup) spawn them per their workflow — fresh-context validation and parallel work. If it is unavailable (e.g., Claude.ai), execute each mode's phases inline (less rigorous, but functional).

Show full SKILL.md (462 more words)Show less

Chaining modes

Modes compose: a common flow is clean (audit → CLEAN_CODE_AUDIT.md) then cleanup (apply the refactors), or review/perf to find issues before fixing. Run one mode at a time; confirm with the user before switching into the code-writing cleanup mode.

Prerequisites

  • If no target diff, PR, file set, or repository is named, ask for the scope before starting.
  • If a reference or agent file listed for the selected mode is missing, stop and name the missing path.
  • For clean or cleanup, follow that mode's sync, backup, dry-run, confirmation, and rollback steps in order. If a sync or safety check fails, stop before the first write.

Acceptance Criteria

Verify every run against the selected mode's own acceptance criteria, then assert all of these router criteria:

  • Exactly one mode was selected and its reference workflow was followed end to end.
  • Read-only modes changed no source files; verify with a path-scoped git diff when applicable.
  • Every finding cites concrete evidence and the expected output artifact or report was produced.
  • Tests or validation commands required by the selected mode completed with their expected result.
  • Edge cases, limitations, skipped files, and degraded subagent coverage are disclosed.

Also check that a reader can use the final response:

  • Result is findable: the first line after Mode: states the result and PASS, PARTIAL, or FAIL.
  • Facts and assumptions are separate: verified claims name the check that was run; inferences, skipped scope, and untested behavior are labeled under Uncertainty.
  • Claims are traceable: each finding points to a file:line, a command output, or a report section. An intermediate step passing does not count as the whole run passing.
  • Next decision is clear: Decision names the approval needed (for example, starting cleanup), or says "No approval needed", and lists any remaining user action.

Agent inspection cannot confirm that a human understood the output. If no human feedback was given, report human understanding as unconfirmed; do not count it as a failure or a pass.

Expected Output

Every mode's final response carries these five items, in this order. Keep each item to one or two lines; the mode's report artifact holds the detail.

text
Mode: review
Result: PARTIAL — 1 critical, 2 major, 0 minor findings; reviewer pass incomplete for 3 files
Evidence: CODE_REVIEW.md written; reviewer agent validated 41/44 files; `git diff --stat -- src/` empty
Uncertainty: 3 generated files skipped (listed in CODE_REVIEW.md); no tests were run
Decision: No approval needed. To apply fixes, ask for a separate `cleanup` run.

Step Completion Reports

After routing and after the selected workflow, emit a compact report:

text
◆ Code Review ([mode])
  Mode selection:      √ pass
  Workflow criteria:   √ pass
  Output verified:     √ pass
  Safety boundary:     √ pass
  Result:              PASS | FAIL | PARTIAL

Use × fail — reason for any unmet check. Never report PASS while a selected-mode acceptance criterion, expected output, required test, or safety guardrail is unresolved.

Edge Cases

  • Unknown mode: value → reject it and list the four valid modes.
  • Mixed intents across modes → ask which mode to run first; never merge workflows implicitly.
  • Missing target or inaccessible files → stop and request a concrete scope instead of guessing.
  • Agent tool unavailable → use the selected reference's inline fallback and disclose reduced coverage.
  • A read-only mode requests edits mid-run → finish the report, then require explicit approval before starting a separate cleanup run.

© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 23 other files (references) in skills/code-review of luongnv89/skills.

  • SKILL.md
  • agents/circular-dep-untangler.md
  • agents/deduplicator.md
  • agents/defensive-programming-remover.md
  • agents/file-reviewer.md
  • agents/legacy-code-remover.md
  • agents/report-assembler.md
  • agents/reviewer.md
  • agents/slop-comment-cleaner.md
  • agents/type-consolidator.md
  • agents/unused-code-killer.md
  • agents/weak-type-strengthener.md
  • docs/README.md
  • references/clean-code-checklist.md
  • references/clean-mode.md
  • references/cleanup-mode.md
  • references/code-smells.md
  • references/html-report-guide.md
  • … and 6 more

Open the folder on GitHubat commit 8f80262

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillluongnv89/skills131—~2.4kAutomated safety check: PassMIT
Code Quality ReviewStudentWeis/ropy193—~2.2kAutomated safety check: PassMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Code Quality Review

    StudentWeis/ropy

    Review a code change, diff, pull request, module, or test suite for code quality, comment and documentation quality, and test quality.

    193 GitHub stars~2.2k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    488 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed

More from luongnv89/skills

All 37 skills in this repo
  • Dont Make Me Think

    luongnv89/skills

    Review UI usability using Steve Krug's principles and produce a scannable report.

    131 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Herdr Agent

    luongnv89/skills

    Manage AI agent fleets in Herdr: tile root + sub-agents in one tab, start/prompt/wait/read/monitor via the herdr agent CLI, steer any pane; help lists every operation.

    131 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Ollama Optimizer

    luongnv89/skills

    Optimize Ollama configuration for the current machine's hardware.

    131 GitHub stars~4.1k tokensUpdated today
    Auto-check: notes
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Tasks Generator

    luongnv89/skills

    Generate sprint-based development tasks from a PRD. An agent skill from luongnv89/skills.

    131 GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Tmux Agent Comms

    luongnv89/skills

    Manage AI agents in tmux: spawn sessions, send messages, wait, capture replies, inspect fleets, and tear down safely.

    131 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup. Code Review is an agent skill from luongnv89/skills. Review or improve code — one skill, four modes: bug/security review (default), performance, clean-code audit, slop cleanup.

When should I use Code Review?

Code Review fits situations like: writing features; generating tests (use test-coverage).

How do I install Code Review in Claude Code?

Run `npx skills add luongnv89/skills --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in luongnv89/skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add luongnv89/skills --skill code-review -a codex`. Or copy the skill folder (skills/code-review in luongnv89/skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (git).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Quality Review (StudentWeis/ropy, 193 stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Specialist (luongnv89/claude-howto, 42k stars) and Code Review Skill (Rain-kl/OpenFlare, 288 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

luongnv89 (a GitHub user) maintains it in luongnv89/skills, which has 131 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 7, 2026.

Source: luongnv89/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.