Agent skill

Code Review

by managedcode in managedcode/dotnet-skills

Review .NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add managedcode/dotnet-skills --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/dotnet-skills code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/Platform/Code-Review/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
486
Token cost
~976 tokens
SKILL.md length
368 words
Files
4 (incl. references)
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Review .NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them.

  • Works in 6 steps: Prioritize correctness, data loss,… → Check async flows, cancellation… → Verify tests cover the changed behavior,… → …
  • : reviewing a pull request
  • SKILL.md covers Trigger On, References, Workflow and Key Review Patterns, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review is an agent skill from managedcode/dotnet-skills. Review .NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them. USE FOR: reviewing a pull request or patch in a .NET repository; checking for behavioral regressions, API misuse, or missing tests; auditing architectural or framework-specific. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted files, and run…

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `manifest.json`, `references/checklist.md` and `references/patterns.md`). Compatibility notes: Works for application code, libraries, tests, tooling, and infrastructure changes.

It sits in Development, covering Code review, Codebase knowledge for agents and Pull requests. It works with .NET. The repository describes itself as: Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini. The licence is MIT.

When your agent uses it

  • : reviewing a pull request
  • Patch in a .NET repository
  • Checking for behavioral regressions
  • Auditing architectural

Example prompts

  • “/code-review”

Requirements

  • Compatibility (from SKILL.md): Works for application code, libraries, tests, tooling, and infrastructure changes.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Prioritize correctness, data loss, concurrency, security, lifecycle, and platform-compatibility issues before style concerns. Use the…
  2. Check async flows, cancellation propagation, exception handling, disposal, and transient versus singleton lifetime mistakes. Refer to…
  3. Verify tests cover the changed behavior, not only the happy path or refactored implementation details.
  4. Inspect framework-specific boundaries such as EF query translation, ASP.NET middleware order, Blazor render state, or MAUI UI-thread access.
  5. Call out missing observability, migration risk, or runtime configuration drift when those are part of the change. When reviewing AI or…
  6. Keep findings concrete, reproducible, and tied to specific files or behavior.

What it can do on your machine

Read from SKILL.md and the folder at commit 535dd55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • managed-code.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Works for application code, libraries, tests, tooling, and infrastructure changes.

    From compatibility in the SKILL.md frontmatter.

Context cost

Code Review loads about 976 tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 368 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~976
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/dotnet-skills at commit 535dd55, republished under its MIT licence (© managedcode). 368 words, ~976 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
code-review
description
Review .NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them. USE FOR: reviewing a pull request or patch in a .NET repository; checking for behavioral regressions, API misuse, or missing tests; auditing architectural or framework-specific. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
compatibility
Works for application code, libraries, tests, tooling, and infrastructure changes.

.NET Code Review

Trigger On

  • reviewing a pull request or patch in a .NET repository
  • checking for behavioral regressions, API misuse, or missing tests
  • auditing architectural or framework-specific correctness

References

Workflow

  1. Prioritize correctness, data loss, concurrency, security, lifecycle, and platform-compatibility issues before style concerns. Use the checklist P0-P2 categories first.
  2. Check async flows, cancellation propagation, exception handling, disposal, and transient versus singleton lifetime mistakes. Refer to patterns.md for common pitfalls.
  3. Verify tests cover the changed behavior, not only the happy path or refactored implementation details.
  4. Inspect framework-specific boundaries such as EF query translation, ASP.NET middleware order, Blazor render state, or MAUI UI-thread access.
  5. Call out missing observability, migration risk, or runtime configuration drift when those are part of the change. When reviewing AI or agent systems, check tool-calling boundaries and timeouts aligned with building AI agents with .NET.
  6. Keep findings concrete, reproducible, and tied to specific files or behavior.

Key Review Patterns

Show full SKILL.md (163 more words)Show less
Async Code
  • Async must propagate through the entire call chain; never use .Result, .Wait(), or .GetAwaiter().GetResult() in async contexts
  • Always propagate CancellationToken parameters
  • Use ConfigureAwait(false) in library code
  • Never use async void except for event handlers
Resource Disposal
  • Use using declarations or statements for all IDisposable resources
  • Use await using for IAsyncDisposable resources
  • Use IHttpClientFactory instead of creating HttpClient directly
  • Unsubscribe event handlers to prevent memory leaks
  • Validate DI service lifetimes to prevent captured dependencies
Security
  • Use parameterized queries or EF to prevent SQL injection
  • Validate all user input at system boundaries
  • Prevent path traversal by validating resolved paths stay within allowed directories
  • Never hardcode secrets; use configuration and secret management
  • Enforce authorization checks before accessing protected resources

Deliver

  • ranked review findings with file references
  • clear residual risks and test gaps
  • brief summary of what changed only after findings

Validate

  • findings describe user-visible or maintainability-impacting risk
  • assumptions are stated when repo context is incomplete
  • no trivial style nit hides a more serious issue

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in catalog/Platform/Code-Review/skills/code-review of managedcode/dotnet-skills.

  • SKILL.md
  • manifest.json
  • references/checklist.md
  • references/patterns.md

Open the folder on GitHubat commit 535dd55

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillmanagedcode/dotnet-skills486—~976Automated safety check: PassMIT
MAUI PR Performance Analysisdotnet/maui23k—~2.4kAutomated safety check: PassMIT
Code Reviewjonathanpeppers/dotnes780—~2.1kAutomated safety check: PassMIT
Find Reviewable MAUI PRsdotnet/maui23k—~1.7kAutomated safety check: PassMIT
Code Reviewsbroenne/mcp-windows106—~1.6kAutomated safety check: PassMIT
.NET MAUI Code Reviewdotnet/efcore15k—~2kAutomated safety check: PassMIT

Similar skills

  • Official

    Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.

    23k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    jonathanpeppers/dotnes

    Review dotnes pull requests against established repository rules.

    780 GitHub stars~2.1k tokensUpdated 14 days ago
    DevelopmentAuto-check passed
  • Official

    Lists open pull requests in dotnet/maui and dotnet/docs-maui that are worth reviewing next, ranked by priority labels, milestone and partner or community origin.

    23k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    sbroenne/mcp-windows

    Review pull requests in mcp-windows for concrete bugs in MCP and CLI contracts, Windows UI automation, element identity, snapshots, bounded searches, and service lifetime.

    106 GitHub stars~1.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Deep code-only review of a pull request or candidate patch for correctness, safety and .NET MAUI conventions, judging the code before reading the PR description.

    15k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Runs a three-phase review of a dotnet/maui pull request (pre-flight, try-fix, report), writing results to local files and never posting comments to the PR.

    23k GitHub stars~3.6k tokensUpdated today
    DevelopmentAuto-check passed

More from managedcode/dotnet-skills

All 81 skills in this repo
  • Analyzer Config

    managedcode/dotnet-skills

    Use a repo-root .editorconfig to configure free .NET analyzer and style rules.

    486 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Archunitnet

    managedcode/dotnet-skills

    Use the open-source free ArchUnitNET library for architecture rules in .NET tests.

    486 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aspire

    managedcode/dotnet-skills

    Build, upgrade, and operate Aspire 13.5.x C or TypeScript application hosts with the current CLI, AppHost, ServiceDefaults, integrations, dashboard, testing, MCP, and deployment patterns for…

    486 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Aspnet Core

    managedcode/dotnet-skills

    Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

    486 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Azure Functions

    managedcode/dotnet-skills

    Build, review, or migrate Azure Functions in .NET with correct execution model, isolated worker setup, bindings, DI, and Durable Functions patterns.

    486 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Code Review

What does Code Review do?

Review .NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them. Code Review is an agent skill from managedcode/dotnet-skills.NET changes for bugs, regressions, architectural drift, missing tests, incorrect async or disposal behavior, and platform-specific pitfalls before you approve or merge them.

When should I use Code Review?

Code Review fits situations like: : reviewing a pull request; patch in a .NET repository; checking for behavioral regressions; auditing architectural.

How do I install Code Review in Claude Code?

Run `npx skills add managedcode/dotnet-skills --skill code-review -a claude-code`. Or copy the skill folder (catalog/Platform/Code-Review/skills/code-review in managedcode/dotnet-skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add managedcode/dotnet-skills --skill code-review -a codex`. Or copy the skill folder (catalog/Platform/Code-Review/skills/code-review in managedcode/dotnet-skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/dotnet-skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only. Compatibility (from SKILL.md): Works for application code, libraries, tests, tooling, and infrastructure changes..

Does Code Review access the network?

SKILL.md names 1 domain. As links in the text: managed-code.com. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 976 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: MAUI PR Performance Analysis (dotnet/maui, 23k stars), Code Review (jonathanpeppers/dotnes, 780 stars), Find Reviewable MAUI PRs (dotnet/maui, 23k stars) and Code Review (sbroenne/mcp-windows, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

managedcode (a GitHub organization) maintains it in managedcode/dotnet-skills, which has 486 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.