Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

MITAuto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
2k
Token cost
~4k tokens
SKILL.md length
1,920 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

  • Works in 10 steps: Security → Performance → Backwards Compatibility → …
  • Tasks that involve Code review
  • SKILL.md covers Review Priorities, What NOT to Focus On, Review Approach and Severity Guidelines
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review is an agent skill from MichaelGrafnetter/DSInternals. Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. It works with PowerShell and C++. The repository describes itself as: Directory Services Internals (DSInternals) PowerShell Module and Framework. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/code-review”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Security
  2. Performance
  3. Backwards Compatibility
  4. Cross-Component Interactions
  5. Correctness and Edge Cases
  6. Design and Architecture
  7. Testing
  8. C++/CLI Specific Concerns
  9. PowerShell Specific Concerns
  10. Documentation and Code Clarity

What it can do on your machine

Read from SKILL.md and the folder at commit 917bc84. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 4k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,920 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MichaelGrafnetter/DSInternals at commit 917bc84, republished under its MIT licence (© MichaelGrafnetter). 1,920 words, ~4,047 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

Code Review Instructions for DSInternals

These instructions guide code reviews for the DSInternals repository, which contains C#, C++/CLI, and PowerShell code for Active Directory security auditing, offline database manipulation, and password management. Focus on higher-level concerns that require expert judgment rather than stylistic or syntactic issues handled by automated tooling.

If there are no code changes to review, perform a review of the entire codebase based on these guidelines to identify potential improvements or issues. Do not rely solely on targeted searches for specific artefacts. Systematically read all source files to ensure comprehensive coverage. For each file read, apply all the review priorities documented below. Do not skip files even if they appear simple—security issues often hide in seemingly innocuous code.

Review Priorities

1. Security

Critical Security Concerns (Especially Important for AD Security Tooling):

  • Credential Handling: Ensure passwords, hashes (NT, LM, Kerberos keys), and secrets are securely handled, never logged, and properly cleared from memory when no longer needed
    • Use SecureString where appropriate for password input
    • Clear sensitive byte arrays with Array.Clear() or CryptographicOperations.ZeroMemory() in finally blocks
    • Pin sensitive data in memory during cryptographic operations to prevent GC relocation
  • Cryptographic Operations: Verify proper use of cryptographic APIs for password hashing (MD4, MD5, SHA-1, PBKDF2), key derivation, and encryption/decryption operations
    • Use RandomNumberGenerator for cryptographically secure random bytes, never System.Random
    • Ensure proper IV/nonce generation (unique per encryption operation)
    • Verify constant-time comparison for secret data using CryptographicOperations.FixedTimeEquals() to prevent timing attacks
  • Buffer Overflows (C++/CLI): In native C++/CLI code, check for proper bounds checking, safe memory operations, and correct use of RPC marshaling
  • Input Validation & Sanitization: Ensure all external inputs (Active Directory data, ntds.dit database content, network data from MS-DRSR/MS-SAMR protocols) are properly validated
    • Validate string lengths before buffer operations
    • Check array bounds before indexing
    • Validate enum values are within expected ranges
  • Path Traversal: Check for potential path traversal vulnerabilities when handling file paths (especially for ntds.dit database files)
    • Use Path.GetFullPath() and validate paths are within expected directories
  • Injection Vulnerabilities: Check for potential LDAP injection, command injection, or code injection risks
  • Authentication & Authorization: Ensure proper handling of Kerberos, NTLM, and other AD authentication mechanisms
  • Information Disclosure: Watch for accidental logging or exposure of sensitive data (password hashes, DPAPI keys, BitLocker recovery keys, certificates)
    • Ensure ToString() overrides don't expose sensitive fields
    • Check exception messages don't leak sensitive information
  • Deserialization: Ensure safe deserialization practices, especially when parsing AD replication data or database records
  • Race Conditions: Identify potential TOCTOU vulnerabilities, especially when accessing ntds.dit database files or AD replication streams
  • Exception Handling for Crypto: Catch and handle CryptographicException appropriately; avoid leaking information about why decryption failed
2. Performance

Performance Considerations:

  • Algorithmic Complexity: Identify inefficient algorithms, especially when processing large AD databases with millions of objects
  • Memory Allocations (C#): Watch for excessive allocations in hot paths, consider Span<T>, stackalloc, or object pooling where appropriate
  • Memory Management (C++/CLI): Ensure proper use of native/managed memory boundaries, avoid unnecessary marshaling overhead
  • Boxing: Identify unnecessary boxing of value types (SIDs, GUIDs, timestamps)
  • String Operations: Check for string concatenation in loops (use StringBuilder), especially when building distinguished names or LDAP filters
  • ESE/JET Database Access: Ensure efficient cursor operations, proper index usage, and minimal database round-trips when querying ntds.dit
  • RPC Call Efficiency: Optimize MS-DRSR/MS-SAMR RPC calls to minimize network round-trips
  • Collection Choices: Verify appropriate collection types for access patterns (especially when handling SID histories, group memberships)
  • Lazy Initialization: Check for opportunities to defer expensive operations (schema loading, database connections)
  • Native Interop: Ensure P/Invoke and C++/CLI interop calls are efficient with minimal marshaling overhead
  • Async/Await Best Practices:
    • Use ConfigureAwait(false) in library code (DSInternals Framework) to avoid deadlocks and improve performance
    • Avoid async void except for event handlers; use async Task instead
    • Support CancellationToken for long-running operations (database enumeration, RPC calls)
    • Prefer ValueTask over Task for hot paths that often complete synchronously
    • Avoid blocking on async code (no .Result, .Wait(), or .GetAwaiter().GetResult() in async contexts)
    • Don't use Task.Run() to wrap synchronous code in library methods; let the caller decide
    • Ensure proper exception handling in async methods (exceptions are captured in the returned Task)
3. Backwards Compatibility

Compatibility Requirements:

  • Public API Changes: Any change to DSInternals Framework public APIs requires careful scrutiny
    • Breaking changes are generally not acceptable
    • New optional parameters, overloads, and interface implementations need careful consideration
    • Verify that API additions follow existing patterns and naming conventions
  • PowerShell Cmdlet Compatibility: Ensure cmdlet parameter sets, output types, and behavior remain consistent
    • Parameter names and aliases must be preserved
    • Output object properties must maintain backwards compatibility
    • Pipeline behavior must be preserved
  • Multi-Framework Support: Changes must work on both .NET Framework 4.8 and .NET 10.0
  • Serialization Compatibility: Ensure changes don't break serialization of persisted data (e.g., exported credentials)
  • Behavioral Changes: Even non-breaking changes can break consumers if behavior changes unexpectedly
    • Document behavioral changes clearly in CHANGELOG.md
  • Obsolete APIs: Check that proper obsolescence process is followed (ObsoleteAttribute, documentation, migration path)
4. Cross-Component Interactions

Integration Points:

  • C#/C++/CLI Boundaries: Verify proper marshaling of data structures between managed C# and C++/CLI code
    • Ensure correct memory ownership semantics
    • Check for proper exception handling across managed/native boundaries
  • PowerShell/Framework Boundaries: Ensure clean separation between cmdlet implementations and underlying framework code
    • Cmdlets should be thin wrappers delegating to framework classes
    • Error handling should translate framework exceptions to appropriate PowerShell errors
  • RPC Protocol Interactions: Verify correct implementation of MS-DRSR (replication) and MS-SAMR (SAM) protocols
    • Check for proper handling of protocol version differences
    • Ensure correct RPC stub memory allocation/deallocation
  • ESE/JET Database Access: Ensure proper database session management, cursor handling, and transaction semantics
  • Threading Models: Ensure thread-safety is maintained, especially for database connections and RPC handles
  • Lifecycle Management: Verify proper initialization, disposal patterns (IDisposable), and cleanup across component boundaries
  • Error Handling: Ensure exceptions and error codes are properly propagated across component boundaries
5. Correctness and Edge Cases

Code Correctness:

  • Null Handling: While the compiler enforces nullable reference types, verify runtime null checks for AD data that may be absent
  • Boundary Conditions: Test for empty collections, null attributes, maximum SID lengths, large group memberships
  • AD Data Variations: Handle variations in AD data across different domain/forest functional levels and schema versions
  • Error Paths: Ensure error handling is correct and complete; database cursors and RPC handles are properly cleaned up
  • Concurrency: Identify race conditions, especially when accessing shared database connections
  • Exception Safety: Verify operations maintain invariants even when exceptions occur (especially in C++/CLI code)
  • Resource Management: Ensure IDisposable is implemented correctly; database sessions, RPC connections, and native handles are not leaked
  • Numeric Overflow: Check for potential integer overflow when handling RID pools, USNs, or large object counts
  • Encoding Issues: Verify proper handling of Unicode strings, UTF-8/UTF-16 conversions, and binary attribute data
  • Time Handling: Check for proper handling of AD timestamps (FILETIME, GeneralizedTime, epoch differences)
Show full SKILL.md (819 more words)Show less
6. Design and Architecture

Design Quality:

  • API Design: Ensure new APIs are intuitive, follow .NET Framework Design Guidelines, and are hard to misuse
  • Abstraction Level: Verify abstractions are at the appropriate level
    • Framework classes should not depend on PowerShell
    • Protocol implementations should be separate from data model classes
  • Separation of Concerns: Check that responsibilities are properly separated
    • DSInternals.Common: Shared utilities and cryptographic functions
    • DSInternals.DataStore: Offline database access only
    • DSInternals.Replication: Protocol implementation only
    • DSInternals.PowerShell: Cmdlet implementations only
  • SOLID Principles: Evaluate adherence to single responsibility, open/closed, and other design principles
  • Code Duplication: Identify opportunities to reduce duplication between .NET Framework and .NET versions
  • Testability: Ensure the code is designed to be testable (proper dependency injection, separation of concerns)
7. Testing

Test Quality:

  • Coverage: Ensure new functionality has appropriate test coverage
    • C# unit tests using MSTest framework
    • PowerShell Pester tests for cmdlet behavior
  • Test Scenarios: Verify tests cover happy paths, error paths, and edge cases
  • Test Data: Ensure tests use appropriate test data (sample ntds.dit databases, mock AD objects)
  • Test Reliability: Watch for flaky tests (timing dependencies, environmental assumptions)
  • Test Performance: Ensure tests run efficiently and don't unnecessarily slow down CI
  • Regression Tests: Check that bugs being fixed have corresponding regression tests
8. C++/CLI Specific Concerns

Native Code Quality:

  • Memory Safety: Check for buffer overflows, use-after-free, double-free, and memory leaks
    • Prefer std::unique_ptr and std::vector over raw pointers and C-style arrays where possible
    • Use SecureZeroMemory() to clear sensitive data before freeing
  • RPC Memory Management: Verify correct use of MIDL-generated allocation/deallocation functions
    • Match MIDL_user_allocate() with MIDL_user_free()
    • Check for proper cleanup in error paths
  • Exception Handling: Ensure native exceptions are properly caught and converted to managed exceptions
    • Use SEH (__try/__except) for Win32 exceptions where appropriate
    • Never let native exceptions propagate to managed code unhandled
  • Resource Cleanup: Verify proper cleanup of native handles, RPC bindings, and allocated buffers
  • Preprocessor Usage: Check for proper use of conditional compilation for multi-platform/multi-framework builds
  • Header Dependencies: Minimize header dependencies to improve build times

C++/CLI Security:

  • Buffer Security: Ensure /GS (Buffer Security Check) compiler flag is enabled
  • Safe Integer Arithmetic: Use SafeInt<T> or check for overflow before arithmetic operations on sizes/lengths
  • Secure CRT Functions: Prefer _s suffixed functions (strcpy_s, memcpy_s, sprintf_s) over unsafe versions
  • Format String Safety: Never pass user-controlled strings as format specifiers to printf-family functions
  • Stack Allocations: Validate sizes before _alloca() or prefer heap allocation for variable-sized buffers
  • Uninitialized Memory: Ensure all variables are initialized; uninitialized stack variables can leak sensitive data
  • Pointer Validation: Check pointers for null before dereferencing, especially for RPC output parameters
9. PowerShell Specific Concerns

Cmdlet Quality:

  • Parameter Validation: Ensure proper use of validation attributes (ValidateNotNull, ValidatePattern, etc.)
  • Pipeline Support: Verify proper implementation of pipeline input (ValueFromPipeline, ValueFromPipelineByPropertyName)
  • Output Types: Ensure cmdlets declare and return correct output types
  • Error Handling: Use appropriate error types (terminating vs. non-terminating errors)
  • Help Documentation: Ensure cmdlet help documentation is complete and accurate
  • Credential Handling: Use SecureString for password parameters where appropriate
  • ShouldProcess: Implement -WhatIf and -Confirm for cmdlets that modify data
10. Documentation and Code Clarity

Documentation:

  • XML Documentation: New public APIs must have clear XML documentation explaining purpose, parameters, return values, and exceptions. Do not comment on existing APIs that lack documentation.
  • PowerShell Help: Cmdlets should have comprehensive comment-based or external help (MAML)
  • Complex Logic: Comments should explain the "why" behind non-obvious decisions, especially for AD protocol quirks or cryptographic operations
  • TODOs and FIXMEs: Ensure they are tracked with issues and are appropriate for the change
  • Breaking Changes: Must be clearly documented in CHANGELOG.md with migration guidance

What NOT to Focus On

The following are handled by automated tooling and don't need review comments:

  • Code formatting and style (handled by .editorconfig and analyzers)
  • Naming convention violations (handled by analyzers)
  • Missing using directives (handled by compiler)
  • Most syntax errors (handled by compiler)
  • Simple code style preferences without technical merit
  • PowerShell script formatting (handled by PSScriptAnalyzer)

Review Approach

  1. Understand the Context: Read the PR description and linked issues to understand the goal. Consider as much relevant code from the containing project as possible. For public APIs, review any code in the repo that consumes the method.
  2. Assess the Scope: Verify the change is focused and not mixing unrelated concerns
  3. Evaluate Risk: Consider the risk level based on what components are affected
    • DSInternals.Common changes affect all other components
    • C++/CLI changes may have memory safety implications
    • PowerShell changes may affect user-facing behavior
  4. Think Like an Attacker: For security-sensitive code (credential handling, crypto, protocol implementations), consider how it might be exploited
  5. Think Like a Consumer: Consider how the API or cmdlet will be used by security researchers and AD administrators
  6. Consider Maintenance: Think about long-term maintenance burden, especially for multi-framework targeting

Severity Guidelines

  • Critical: Security vulnerabilities (credential exposure, buffer overflows), data corruption, crashes, breaking changes
  • High: Memory leaks in C++/CLI, performance regressions, incorrect AD data handling, resource leaks
  • Medium: Edge case bugs, suboptimal design, missing documentation, PowerShell parameter issues
  • Low: Code clarity issues, minor inefficiencies, nice-to-have improvements

© MichaelGrafnetter, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-review of MichaelGrafnetter/DSInternals.

Open the folder on GitHubat commit 917bc84

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillMichaelGrafnetter/DSInternals2k—~4kAutomated safety check: PassMIT
ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime22k—~3.3kAutomated safety check: PassMIT
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
Qt Cpp ReviewSerial-Studio/Serial-Studio7.2k—~4.3kAutomated safety check: PassCustom licence
SeekDB Code Reviewoceanbase/seekdb3.1k—~2.1kAutomated safety check: PassApache-2.0
OpenROAD PR ReviewThe-OpenROAD-Project/OpenROAD3.2k—~1.4kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Official

    Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

    22k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Qt Cpp Review

    Serial-Studio/Serial-Studio

    Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.

    7.2k GitHub stars~4.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • SeekDB Code Review

    oceanbase/seekdb

    Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.

    3.1k GitHub stars~2.1k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • OpenROAD PR Review

    The-OpenROAD-Project/OpenROAD

    Reviews an OpenROAD pull request in the project's priority order and prints draft review notes for a human reviewer to inspect and post.

    3.2k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    hpcc-systems/HPCC-Platform

    Code review checklist for the HPCC Platform. An agent skill from hpcc-systems/HPCC-Platform.

    616 GitHub stars~903 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from MichaelGrafnetter/DSInternals

  • Doc Comments

    MichaelGrafnetter/DSInternals

    Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation.

    2k GitHub stars~1.2k tokensUpdated 26 days ago
    Auto-check passed
  • Release Preparation

    MichaelGrafnetter/DSInternals

    Prepare the DSInternals project for a new release by updating version numbers, release notes, and changelog.

    2k GitHub stars~752 tokensUpdated 26 days ago
    Auto-check passed
  • Update Copyright Year

    MichaelGrafnetter/DSInternals

    Update copyright year references across the project at the beginning of each calendar year.

    2k GitHub stars~404 tokensUpdated 26 days ago
    Auto-check passed

Works with

Questions about Code Review

What does Code Review do?

Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles. Code Review is an agent skill from MichaelGrafnetter/DSInternals. Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review.

How do I install Code Review in Claude Code?

Run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in MichaelGrafnetter/DSInternals) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in MichaelGrafnetter/DSInternals) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Qt Cpp Review (Serial-Studio/Serial-Studio, 7.2k stars) and SeekDB Code Review (oceanbase/seekdb, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

MichaelGrafnetter (a GitHub user) maintains it in MichaelGrafnetter/DSInternals, which has 1,968 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 11, 2026.

Source: MichaelGrafnetter/DSInternals on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.