Official agent skill

Code Review Expert

by microsoft in microsoft/Huabu

Expert code review of current git changes with a senior engineer lens.

OfficialMITAuto-check passedDevelopment

Install Code Review Expert

skills CLI
$ npx skills add microsoft/Huabu --skill code-review-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/Huabu code-review-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/Huabu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review-expert .claude/skills/code-review-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-expert
GitHub stars
157
Used in
2 other repos
Token cost
~1.5k tokens
SKILL.md length
507 words
Files
7 (incl. references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Expert code review of current git changes with a senior engineer lens.

  • Works in 7 steps: Preflight context → SOLID + architecture smells → Removal candidates + iteration plan → …
  • Tasks that involve Code review
  • SKILL.md covers Overview, Severity Levels, Workflow and Resources
  • Calls git

What it does

Code Review Expert is an agent skill from microsoft/Huabu, published by the product's own GitHub organization. Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `README.md`, `agents/agent.yaml` and `references/code-quality-checklist.md`).

It sits in Development, covering Code review. It works with Git. The repository describes itself as: Huabu, where you and your agents think together. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/code-review-expert”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Preflight context
  2. SOLID + architecture smells
  3. Removal candidates + iteration plan
  4. Security and reliability scan
  5. Code quality scan
  6. Output format
  7. Next steps confirmation

What it can do on your machine

Read from SKILL.md and the folder at commit dc0cfa9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Expert loads about 1.5k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 507 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/Huabu at commit dc0cfa9, republished under its MIT licence (© microsoft). 507 words, ~1,461 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-expert/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
code-review-expert
description
Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.

Code Review Expert

Overview

Perform a structured review of the current git changes with focus on SOLID, architecture, removal candidates, and security risks. Default to review-only output unless the user asks to implement changes.

Severity Levels

LevelNameDescriptionAction
P0CriticalSecurity vulnerability, data loss risk, correctness bugMust block merge
P1HighLogic error, significant SOLID violation, performance regressionShould fix before merge
P2MediumCode smell, maintainability concern, minor SOLID violationFix in this PR or create follow-up
P3LowStyle, naming, minor suggestionOptional improvement

Workflow

1) Preflight context
  • Use git status -sb, git diff --stat, and git diff to scope changes.
  • If needed, use rg or grep to find related modules, usages, and contracts.
  • Identify entry points, ownership boundaries, and critical paths (auth, payments, data writes, network).

Edge cases:

  • No changes: If git diff is empty, inform user and ask if they want to review staged changes or a specific commit range.
  • Large diff (>500 lines): Summarize by file first, then review in batches by module/feature area.
  • Mixed concerns: Group findings by logical feature, not just file order.
2) SOLID + architecture smells
  • Load references/solid-checklist.md for specific prompts.
  • Look for:
    • SRP: Overloaded modules with unrelated responsibilities.
    • OCP: Frequent edits to add behavior instead of extension points.
    • LSP: Subclasses that break expectations or require type checks.
    • ISP: Wide interfaces with unused methods.
    • DIP: High-level logic tied to low-level implementations.
  • When you propose a refactor, explain why it improves cohesion/coupling and outline a minimal, safe split.
  • If refactor is non-trivial, propose an incremental plan instead of a large rewrite.
3) Removal candidates + iteration plan
  • Load references/removal-plan.md for template.
  • Identify code that is unused, redundant, or feature-flagged off.
  • Distinguish safe delete now vs defer with plan.
  • Provide a follow-up plan with concrete steps and checkpoints (tests/metrics).
Show full SKILL.md (210 more words)Show less
4) Security and reliability scan
  • Load references/security-checklist.md for coverage.
  • Check for:
    • XSS, injection (SQL/NoSQL/command), SSRF, path traversal
    • AuthZ/AuthN gaps, missing tenancy checks
    • Secret leakage or API keys in logs/env/files
    • Rate limits, unbounded loops, CPU/memory hotspots
    • Unsafe deserialization, weak crypto, insecure defaults
    • Race conditions: concurrent access, check-then-act, TOCTOU, missing locks
  • Call out both exploitability and impact.
5) Code quality scan
  • Load references/code-quality-checklist.md for coverage.
  • Check for:
    • Error handling: swallowed exceptions, overly broad catch, missing error handling, async errors
    • Performance: N+1 queries, CPU-intensive ops in hot paths, missing cache, unbounded memory
    • Boundary conditions: null/undefined handling, empty collections, numeric boundaries, off-by-one
  • Flag issues that may cause silent failures or production incidents.
6) Output format

Structure your review as follows:

markdown
## Code Review Summary

**Files reviewed**: X files, Y lines changed
**Overall assessment**: [APPROVE / REQUEST_CHANGES / COMMENT]

---

## Findings

### P0 - Critical

(none or list)

### P1 - High

1. **[file:line]** Brief title

- Description of issue
- Suggested fix

### P2 - Medium

2. (continue numbering across sections)

- ...

### P3 - Low

...

---

## Removal/Iteration Plan

(if applicable)

## Additional Suggestions

(optional improvements, not blocking)

Inline comments: Use this format for file-specific findings:

::code-comment{file="path/to/file.ts" line="42" severity="P1"}
Description of the issue and suggested fix.
::

Clean review: If no issues found, explicitly state:

  • What was checked
  • Any areas not covered (e.g., "Did not verify database migrations")
  • Residual risks or recommended follow-up tests
7) Next steps confirmation

After presenting findings, ask user how to proceed:

markdown
---

## Next Steps

I found X issues (P0: _, P1: _, P2: _, P3: _).

**How would you like to proceed?**

1. **Fix all** - I'll implement all suggested fixes
2. **Fix P0/P1 only** - Address critical and high priority issues
3. **Fix specific items** - Tell me which issues to fix
4. **No changes** - Review complete, no implementation needed

Please choose an option or provide specific instructions.

Important: Do NOT implement any changes until user explicitly confirms. This is a review-first workflow.

Resources

references/
FilePurpose
solid-checklist.mdSOLID smell prompts and refactor heuristics
security-checklist.mdWeb/app security and runtime risk checklist
code-quality-checklist.mdError handling, performance, boundary conditions
removal-plan.mdTemplate for deletion candidates and follow-up plan

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .agents/skills/code-review-expert of microsoft/Huabu.

  • SKILL.md
  • README.md
  • agents/agent.yaml
  • references/code-quality-checklist.md
  • references/removal-plan.md
  • references/security-checklist.md
  • references/solid-checklist.md

Open the folder on GitHubat commit dc0cfa9

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in microsoft/Huabu, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Review Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Expert this skillmicrosoft/Huabu1572 repos~1.5kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Knowledge Graph PR Review

    tirth8205/code-review-graph

    Reviews a pull request or branch diff with a code knowledge graph and produces a structured review that includes blast-radius analysis.

    32k GitHub stars~452 tokensUpdated today
    DevelopmentAuto-check passed

More from microsoft/Huabu

All 10 skills in this repo
  • Release

    microsoft/Huabu

    Official

    Use ONLY when the user explicitly asks to cut/publish a Huabu desktop release or tag a version.

    157 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Official

    Review the quality of an agent's tool descriptions, system/agent prompts, or SKILL.md files against current agent-engineering best practices.

    157 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Space

    microsoft/Huabu

    Official

    Space mental model (the infinite work surface), tool boundaries, and command reference.

    157 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Review Huabu Agent

    microsoft/Huabu

    Official

    Review the Huabu operate agent's three steering artifacts at their fixed repo locations — system prompt, tool descriptions, and skills.

    157 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Issue Tracker

    microsoft/Huabu

    Official

    Coordinate one or more GitHub issues through isolated Git worktrees, durable Huabu Tasks, and dedicated Fixing Agent Threads.

    157 GitHub stars~279 tokensUpdated today
    Auto-check passed
  • Deepv Slides Maker

    microsoft/Huabu

    Official

    Create and revise editable slide decks, PowerPoint files, and slide images with DeepV.

    157 GitHub stars~276 tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Code Review Expert

What does Code Review Expert do?

Expert code review of current git changes with a senior engineer lens. Code Review Expert is an agent skill from microsoft/Huabu, published by the product's own GitHub organization. Expert code review of current git changes with a senior engineer lens.

When should I use Code Review Expert?

Code Review Expert fits situations like: tasks that involve Code review.

How do I install Code Review Expert in Claude Code?

Run `npx skills add microsoft/Huabu --skill code-review-expert -a claude-code`. Or copy the skill folder (.agents/skills/code-review-expert in microsoft/Huabu) into .claude/skills/code-review-expert in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Expert in Codex?

Run `npx skills add microsoft/Huabu --skill code-review-expert -a codex`. Or copy the skill folder (.agents/skills/code-review-expert in microsoft/Huabu) into .agents/skills/code-review-expert in your project. Codex loads it when a task matches its description.

Can I use Code Review Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/Huabu --skill code-review-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-expert, .gemini/skills/code-review-expert, .github/skills/code-review-expert and .opencode/skills/code-review-expert in your project.

What does Code Review Expert need to run?

Going by SKILL.md and its folder, Code Review Expert needs the command-line tools its instructions call (git).

Does Code Review Expert access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Expert use?

Code Review Expert is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Expert use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Code Review Expert?

Skills that share tags, products or a category with Code Review Expert: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars) and Open Code Review Delegate (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Expert?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/Huabu, which has 157 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/Huabu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.