Agent skill

Code Review Specialist

by luongnv89 in luongnv89/claude-howto

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

MITAuto-check passedDevelopment

Install Code Review Specialist

skills CLI
$ npx skills add luongnv89/claude-howto --skill code-review-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luongnv89/claude-howto code-review-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luongnv89/claude-howto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/03-skills/code-review-specialist .claude/skills/code-review-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-specialist
GitHub stars
42k
Token cost
~764 tokens
SKILL.md length
318 words
Files
5 (incl. scripts)
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

  • Works in 4 steps: Security Analysis → Performance Review → Code Quality → …
  • Reviewing a pull request before merge
  • SKILL.md covers Reference Files, Review Template and Version History
  • Runs Python scripts from its folder

What it does

The review covers four areas. Security looks at authentication and authorization problems, data exposure, injection, weak cryptography and sensitive data in logs. Performance covers algorithm efficiency, memory, database queries, caching and concurrency. Quality checks SOLID principles, design patterns, naming, documentation and test coverage, and maintainability covers readability, function size under 50 lines, cyclomatic complexity, dependencies and type safety.

Supporting files guide the work. templates/review-checklist.md makes sure no category is skipped, and templates/finding-template.md sets how each finding is written, with severity, location, code example and impact. scripts/analyze-metrics.py reports function and class counts, average line length and a complexity score for the file under review, and scripts/compare-complexity.py compares cyclomatic and cognitive complexity between two versions of a file when you review a refactor.

The write-up opens with a summary that includes an overall quality rating from 1 to 5, the number of findings and priority areas. It then lists critical issues with location, impact, severity and a fix, followed by findings grouped by category.

When your agent uses it

  • Reviewing a pull request before merge
  • Auditing a file for security and performance problems
  • Comparing complexity before and after a refactor
  • Getting a structured review with severity labels and fix suggestions

Example prompts

  • “Review src/auth/session.py for security and performance problems.”
  • “Compare the old and new versions of parser.js and tell me whether the refactor reduced complexity.”
  • “Review this pull request and list the critical issues first.”

Requirements

  • Python to run the two metrics scripts

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Security Analysis
  2. Performance Review
  3. Code Quality
  4. Maintainability

What it can do on your machine

Read from SKILL.md and the folder at commit 556af8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • code.claude.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Specialist loads about 764 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 318 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~764

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from luongnv89/claude-howto at commit 556af8d, republished under its MIT licence (© luongnv89). 318 words, ~764 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-specialist/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
code-review-specialist
description
Comprehensive code review with security, performance, and quality analysis. Use when users ask to review code, analyze code quality, evaluate pull requests, or mention code review, security analysis, or performance optimization.

Code Review Skill

This skill provides comprehensive code review capabilities focusing on:

  1. Security Analysis

    • Authentication/authorization issues
    • Data exposure risks
    • Injection vulnerabilities
    • Cryptographic weaknesses
    • Sensitive data logging
  2. Performance Review

    • Algorithm efficiency (Big O analysis)
    • Memory optimization
    • Database query optimization
    • Caching opportunities
    • Concurrency issues
  3. Code Quality

    • SOLID principles
    • Design patterns
    • Naming conventions
    • Documentation
    • Test coverage
  4. Maintainability

    • Code readability
    • Function size (should be < 50 lines)
    • Cyclomatic complexity
    • Dependency management
    • Type safety

Reference Files

This skill includes supporting files that you should read when performing reviews:

  • templates/review-checklist.md — Structured checklist covering security, performance, quality, and testing. Read this file and use it as a guide to ensure no category is missed during review.
  • templates/finding-template.md — Standard template for documenting individual findings with severity, location, code examples, and impact analysis. Read this file and use its format when reporting issues.
  • scripts/analyze-metrics.py — Python script that calculates code metrics (function count, class count, average line length, complexity score). Run this on the file under review to gather quantitative data.
  • scripts/compare-complexity.py — Python script that compares cyclomatic and cognitive complexity between two versions of a file. Run this with the before and after versions when reviewing refactoring changes.

Review Template

For each piece of code reviewed, provide:

Summary
  • Overall quality assessment (1-5)
  • Key findings count
  • Recommended priority areas
Critical Issues (if any)
  • Issue: Clear description
  • Location: File and line number
  • Impact: Why this matters
  • Severity: Critical/High/Medium
  • Fix: Code example
Findings by Category
Security (if issues found)

List security vulnerabilities with examples

Performance (if issues found)

List performance problems with complexity analysis

Quality (if issues found)

List code quality issues with refactoring suggestions

Maintainability (if issues found)

List maintainability problems with improvements

Version History

  • v1.0.0 (2024-12-10): Initial release with security, performance, quality, and maintainability analysis

Last Updated: August 4, 2026 Claude Code Version: 2.1.220 Sources:

© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in 03-skills/code-review-specialist of luongnv89/claude-howto.

  • SKILL.md
  • scripts/analyze-metrics.py
  • scripts/compare-complexity.py
  • templates/finding-template.md
  • templates/review-checklist.md

Open the folder on GitHubat commit 556af8d

Compare with similar skills

Code Review Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Specialist this skillluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Code Review Excellenceandrew-yangy/gru-ai155—~1.7kAutomated safety check: NotesMIT
Codebase Review SwarmZaxbyHub/opencode-swarm490—~2.8kAutomated safety check: PassMIT

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    490 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed

More from luongnv89/claude-howto

All 25 skills in this repo
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 8 days ago
    Auto-check passed
  • Code Refactoring Workflow

    luongnv89/claude-howto

    Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.

    42k GitHub stars~3.1k tokensUpdated 8 days ago
    Auto-check passed
  • Blog Post Drafting

    luongnv89/claude-howto

    Guides drafting a blog post from an idea and optional source material: research, brainstorming, outlining and version-tracked drafts, with user approval at each step.

    42k GitHub stars~2.1k tokensUpdated 8 days ago
    Auto-check passed
  • Brand Voice Guide

    luongnv89/claude-howto

    Ensure all communication matches brand voice and tone guidelines. Use when creating marketing copy, customer communications, public-facing content, or when…

    42k GitHub stars~609 tokensUpdated 8 days ago
    Auto-check passed
  • Claude Code Skill Assessment

    luongnv89/claude-howto

    Runs a quick or deep quiz on Claude Code skills, scores ten feature areas and generates a personalized learning path with prioritized next steps.

    42k GitHub stars~5.5k tokensUpdated 8 days ago
    Auto-check passed
  • Claude Code Lesson Quiz

    luongnv89/claude-howto

    Quizzes a learner on one lesson of the Claude Code tutorial with ten questions, scores the answers and points out weak spots.

    42k GitHub stars~2.3k tokensUpdated 8 days ago
    Auto-check passed

Works with

Questions about Code Review Specialist

What does Code Review Specialist do?

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts. The review covers four areas. Security looks at authentication and authorization problems, data exposure, injection, weak cryptography and sensitive data in logs.

When should I use Code Review Specialist?

Code Review Specialist fits situations like: reviewing a pull request before merge; auditing a file for security and performance problems; comparing complexity before and after a refactor; getting a structured review with severity labels and fix suggestions.

How do I install Code Review Specialist in Claude Code?

Run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a claude-code`. Or copy the skill folder (03-skills/code-review-specialist in luongnv89/claude-howto) into .claude/skills/code-review-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Specialist in Codex?

Run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a codex`. Or copy the skill folder (03-skills/code-review-specialist in luongnv89/claude-howto) into .agents/skills/code-review-specialist in your project. Codex loads it when a task matches its description.

Can I use Code Review Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/claude-howto --skill code-review-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-specialist, .gemini/skills/code-review-specialist, .github/skills/code-review-specialist and .opencode/skills/code-review-specialist in your project.

What does Code Review Specialist need to run?

Going by SKILL.md and its folder, Code Review Specialist needs Python for the scripts in its folder. Our summary lists: Python to run the two metrics scripts.

Does Code Review Specialist access the network?

SKILL.md names 1 domain. As links in the text: code.claude.com. This is read from the text; nothing was executed.

Is Code Review Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Review Specialist use?

Code Review Specialist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Specialist use?

About 764 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Specialist?

Skills that share tags, products or a category with Code Review Specialist: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Skill (Rain-kl/OpenFlare, 288 stars) and Code Review Excellence (andrew-yangy/gru-ai, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Specialist?

luongnv89 (a GitHub user) maintains it in luongnv89/claude-howto, which has 41,769 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on September 30, 2026.

Source: luongnv89/claude-howto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.