Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install luongnv89/claude-howto code-review-specialist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/03-skills/code-review-specialist .claude/skills/code-review-specialist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .claude/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install luongnv89/claude-howto code-review-specialist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .agents/skills && cp -r skills-src/03-skills/code-review-specialist .agents/skills/code-review-specialist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .agents/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install luongnv89/claude-howto code-review-specialist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/03-skills/code-review-specialist .cursor/skills/code-review-specialist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .cursor/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/luongnv89/claude-howto.git --path 03-skills/code-review-specialist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install luongnv89/claude-howto code-review-specialist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/03-skills/code-review-specialist .gemini/skills/code-review-specialist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .gemini/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install luongnv89/claude-howto code-review-specialistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .github/skills && cp -r skills-src/03-skills/code-review-specialist .github/skills/code-review-specialist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .github/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install luongnv89/claude-howto code-review-specialist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/03-skills/code-review-specialist .opencode/skills/code-review-specialist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-specialist" agent skill from https://github.com/luongnv89/claude-howto/tree/main/03-skills/code-review-specialist into .opencode/skills/code-review-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-specialist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-specialistReviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
The review covers four areas. Security looks at authentication and authorization problems, data exposure, injection, weak cryptography and sensitive data in logs. Performance covers algorithm efficiency, memory, database queries, caching and concurrency. Quality checks SOLID principles, design patterns, naming, documentation and test coverage, and maintainability covers readability, function size under 50 lines, cyclomatic complexity, dependencies and type safety.
Supporting files guide the work. templates/review-checklist.md makes sure no category is skipped, and templates/finding-template.md sets how each finding is written, with severity, location, code example and impact. scripts/analyze-metrics.py reports function and class counts, average line length and a complexity score for the file under review, and scripts/compare-complexity.py compares cyclomatic and cognitive complexity between two versions of a file when you review a refactor.
The write-up opens with a summary that includes an overall quality rating from 1 to 5, the number of findings and priority areas. It then lists critical issues with location, impact, severity and a fix, followed by findings grouped by category.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 556af8d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
code.claude.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Specialist loads about 764 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 318 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from luongnv89/claude-howto at commit 556af8d, republished under its MIT licence (© luongnv89). 318 words, ~764 tokens.
.claude/skills/code-review-specialist/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.This skill provides comprehensive code review capabilities focusing on:
Security Analysis
Performance Review
Code Quality
Maintainability
This skill includes supporting files that you should read when performing reviews:
templates/review-checklist.md — Structured checklist covering security, performance, quality, and testing. Read this file and use it as a guide to ensure no category is missed during review.templates/finding-template.md — Standard template for documenting individual findings with severity, location, code examples, and impact analysis. Read this file and use its format when reporting issues.scripts/analyze-metrics.py — Python script that calculates code metrics (function count, class count, average line length, complexity score). Run this on the file under review to gather quantitative data.scripts/compare-complexity.py — Python script that compares cyclomatic and cognitive complexity between two versions of a file. Run this with the before and after versions when reviewing refactoring changes.For each piece of code reviewed, provide:
List security vulnerabilities with examples
List performance problems with complexity analysis
List code quality issues with refactoring suggestions
List maintainability problems with improvements
Last Updated: August 4, 2026 Claude Code Version: 2.1.220 Sources:
© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in 03-skills/code-review-specialist of luongnv89/claude-howto.
Open the folder on GitHubat commit 556af8d
Code Review Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Specialist this skillluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Code Review Skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Code Review SkillRain-kl/OpenFlare | 288 | — | ~2.3k | Automated safety check: Notes | MIT | |
| Code Review Excellenceandrew-yangy/gru-ai | 155 | — | ~1.7k | Automated safety check: Notes | MIT | |
| Codebase Review SwarmZaxbyHub/opencode-swarm | 490 | — | ~2.8k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
Rain-kl/OpenFlare
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.
andrew-yangy/gru-ai
Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.
ZaxbyHub/opencode-swarm
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
luongnv89/claude-howto
Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.
luongnv89/claude-howto
Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.
luongnv89/claude-howto
Guides drafting a blog post from an idea and optional source material: research, brainstorming, outlining and version-tracked drafts, with user approval at each step.
luongnv89/claude-howto
Ensure all communication matches brand voice and tone guidelines. Use when creating marketing copy, customer communications, public-facing content, or when…
luongnv89/claude-howto
Runs a quick or deep quiz on Claude Code skills, scores ten feature areas and generates a personalized learning path with prioritized next steps.
luongnv89/claude-howto
Quizzes a learner on one lesson of the Claude Code tutorial with ten questions, scores the answers and points out weak spots.
Works with
Categories
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts. The review covers four areas. Security looks at authentication and authorization problems, data exposure, injection, weak cryptography and sensitive data in logs.
Code Review Specialist fits situations like: reviewing a pull request before merge; auditing a file for security and performance problems; comparing complexity before and after a refactor; getting a structured review with severity labels and fix suggestions.
Run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a claude-code`. Or copy the skill folder (03-skills/code-review-specialist in luongnv89/claude-howto) into .claude/skills/code-review-specialist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a codex`. Or copy the skill folder (03-skills/code-review-specialist in luongnv89/claude-howto) into .agents/skills/code-review-specialist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-specialist, .gemini/skills/code-review-specialist, .github/skills/code-review-specialist and .opencode/skills/code-review-specialist in your project.
Going by SKILL.md and its folder, Code Review Specialist needs Python for the scripts in its folder. Our summary lists: Python to run the two metrics scripts.
SKILL.md names 1 domain. As links in the text: code.claude.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Code Review Specialist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 764 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Specialist: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Skill (Rain-kl/OpenFlare, 288 stars) and Code Review Excellence (andrew-yangy/gru-ai, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
luongnv89 (a GitHub user) maintains it in luongnv89/claude-howto, which has 41,769 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on September 30, 2026.
Source: luongnv89/claude-howto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.