Agent skill

Code Review Pro

by OneWave-AI in OneWave-AI/claude-skills

Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…

MITAuto-check passedDevelopment

Install Code Review Pro

skills CLI
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/code-review-pro .claude/skills/code-review-pro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-pro
GitHub stars
323
Token cost
~1.2k tokens
SKILL.md length
482 words
Files
2 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
MIT

At a glance

Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…

  • Works in 5 steps: Set the scope. Decide what is under… → Learn the context before judging.… → Review in priority order, using… → …
  • The user asks to review
  • SKILL.md covers Workflow, Severity, Output format and Traps that cause bad reviews
  • Calls git

What it does

Code Review Pro is an agent skill from OneWave-AI/claude-skills. Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes. Use when the user asks to review, audit, or sanity-check code, asks "is this safe", "what's wrong with this", "find bugs", or wants a security or performance pass before shipping. For posting line comments on a GitHub pull request, use…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/checklist.md`).

It sits in Development, covering Code review, Web application vulnerabilities and Debugging. It works with Git and GitHub. The repository describes itself as: 200+ production-ready Claude Code skills for sales, marketing, design, engineering, and AI agent architecture. Built and maintained by OneWave AI. The licence is MIT.

When your agent uses it

  • The user asks to review
  • Sanity-check code
  • Asks is this safe
  • Whats wrong with this

Example prompts

  • “is this safe”
  • “s wrong with this”
  • “find bugs”
  • “/code-review-pro”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Set the scope. Decide what is under review: a pasted snippet, specific files, the working-tree diff (git diff, git diff --staged), or a…
  2. Learn the context before judging. Identify language, framework and version (check package.json, pyproject.toml, go.mod, and so on), how…
  3. Review in priority order, using references/checklist.md
  4. Verify every finding before reporting it. For each candidate, trace the data flow: where does the input come from, can an attacker or real…
  5. Rank and write the report in the format below. Lead with the highest severity. Group repeated instances of one problem into a single…

What it can do on your machine

Read from SKILL.md and the folder at commit fc5b785. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Pro loads about 1.2k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OneWave-AI/claude-skills at commit fc5b785, republished under its MIT licence (© OneWave-AI). 482 words, ~1,177 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-pro/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review-pro
description
Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes. Use when the user asks to review, audit, or sanity-check code, asks "is this safe", "what's wrong with this", "find bugs", or wants a security or performance pass before shipping. For posting line comments on a GitHub pull request, use git-pr-reviewer.

Code Review Pro

Find the problems that matter, prove each one, and show the fix. A short list of real issues beats a long list of maybes.

Workflow

  1. Set the scope. Decide what is under review: a pasted snippet, specific files, the working-tree diff (git diff, git diff --staged), or a branch against its base (git diff main...HEAD). For a diff, review the changed lines but read enough surrounding code to know how they are called.

  2. Learn the context before judging. Identify language, framework and version (check package.json, pyproject.toml, go.mod, and so on), how the code is reached (HTTP handler, job, CLI, library), what input is untrusted, and any repo conventions (linters, CLAUDE.md, existing patterns). A pattern that is a bug in one framework can be safe in another; for example, React escapes JSX text, so XSS lives in dangerouslySetInnerHTML, href values, and raw HTML sinks.

  3. Review in priority order, using references/checklist.md:

    1. Security
    2. Correctness and edge cases
    3. Performance
    4. Maintainability and conventions
  4. Verify every finding before reporting it. For each candidate, trace the data flow: where does the input come from, can an attacker or real user control it, and does anything upstream already validate or escape it? Check whether a test covers it. If you can run code, reproduce the bug with a small test or script. Drop findings you cannot support; mark the rest with a confidence level.

  5. Rank and write the report in the format below. Lead with the highest severity. Group repeated instances of one problem into a single finding with all locations.

Show full SKILL.md (217 more words)Show less

Severity

  • Critical - exploitable now or causes data loss/corruption: injection with user input, auth bypass, secrets in code, broken access control on real data.
  • High - likely bug or vulnerability under realistic conditions: race on shared state, missing authorization check, unbounded query on a user-facing path, swallowed errors that hide failures.
  • Medium - correct today but fragile: missing input validation behind a trusted caller, N+1 queries on small data, confusing ownership of state.
  • Low - style, naming, small simplifications. Report at most a handful; skip anything a linter or formatter already enforces.

Output format

markdown
# Code Review: [scope]

**Verdict**: [Ship / Ship after fixes / Do not ship] - [one sentence why]
**Findings**: [n] critical, [n] high, [n] medium, [n] low

## Critical

### 1. SQL injection in user search (`src/api/users.ts:42`)
**Category**: A05:2025 Injection | **Confidence**: High
**Evidence**: `q` comes from `req.query` and is interpolated into the SQL string; no validation upstream.
**Impact**: Any caller can read or modify arbitrary tables.

Current:
```ts
const rows = await db.query(`SELECT * FROM users WHERE name LIKE '%${q}%'`);
```

Fix:
```ts
const rows = await db.query("SELECT * FROM users WHERE name LIKE $1", [`%${q}%`]);
```

## High
...

## Medium
...

## Low
- `utils/date.ts:10` - [one line]

## What is solid
[Two or three specific things done well, so the author knows what to keep.]

## Not reviewed
[Files, paths, or concerns outside scope or that could not be verified.]

Traps that cause bad reviews

  • Reporting without reading the caller. "Missing validation" is often validated one layer up. Look before flagging.
  • Generic advice. "Consider adding error handling" is not a finding. Name the failure: which call throws, what the user sees, what state is left behind.
  • Style as severity. Line length, bracket placement, or personal preference never rank above Low.
  • Outdated rules. Check against the version in use: useMemo/useCallback advice changes when the React Compiler is enabled, and many Node APIs now ship built-ins (fetch, crypto.randomUUID, node:test).
  • Fixes that do not compile. Every "Fix" block must be valid for the language and version in the repo. If unsure, say so.
  • Flooding. More than about 15 findings buries the critical ones. Summarize the long tail in one line.

© OneWave-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in code-review-pro of OneWave-AI/claude-skills.

  • SKILL.md
  • references/checklist.md

Open the folder on GitHubat commit fc5b785

Compare with similar skills

Code Review Pro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Pro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Pro this skillOneWave-AI/claude-skills323—~1.2kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Git History Bug Auditben-manes/caffeine18k—~3.3kAutomated safety check: PassApache-2.0
Greploop Appsmichaelshimeles/skills1.3k1 repos~3.6kAutomated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2505 repos~1.6kAutomated safety check: PassMIT
PR Triagertk-ai/rtk83k—~2.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Greploop Apps

    michaelshimeles/skills

    Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.

    1.3k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    250 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • PR Triage

    rtk-ai/rtk

    Audits a repository's open pull requests, deep-reviews chosen ones and drafts review comments that are only posted after you approve them.

    83k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Difit Review

    yoshiko-pg/difit

    Review a specific diff (branch, commit, or GitHub PR) and show the findings as comments inside difit, the local diff viewer.

    3.2k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from OneWave-AI/claude-skills

All 70 skills in this repo
  • CRM Data Cleanup

    OneWave-AI/claude-skills

    Finds duplicate and junk records in a CRM CSV export with fuzzy matching, normalizes fields and writes a reviewable merge plan plus import-ready files without touching the live CRM.

    323 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Design Export Repair

    OneWave-AI/claude-skills

    Repairs broken decks and PDFs exported from Claude Design or similar AI deck generators: clipped text, wrong fonts and corrupted .pptx package structure.

    323 GitHub stars~2.6k tokensUpdated 6 days ago
    Auto-check passed
  • Bi Measure Builder

    OneWave-AI/claude-skills

    Writes, explains, debugs, and optimizes BI calculations - Power BI / Fabric DAX measures and calculated columns, Tableau calculated fields (FIXED/INCLUDE/EXCLUDE LOD expressions, table…

    323 GitHub stars~2.2k tokensUpdated 6 days ago
    Auto-check passed
  • Bookkeeping Close

    OneWave-AI/claude-skills

    Categorizes transactions, reconciles bank and card statements to the ledger, works a month-end checklist and prepares a close package, without ever forcing a balance.

    323 GitHub stars~2k tokensUpdated 6 days ago
    Auto-check passed
  • CSV and Excel Merger

    OneWave-AI/claude-skills

    Combines CSV, TSV and Excel files into one verified table with pandas, by stacking or joining, mapping columns, normalizing keys and removing duplicates.

    323 GitHub stars~1.6k tokensUpdated 6 days ago
    Auto-check passed
  • Sec Filing Puller

    OneWave-AI/claude-skills

    Pulls financial statement numbers for US public companies straight from SEC EDGAR's free official XBRL APIs (companyfacts, companyconcept, frames, submissions) into a cited table.

    323 GitHub stars~2.1k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Code Review Pro

What does Code Review Pro do?

Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…. Code Review Pro is an agent skill from OneWave-AI/claude-skills. Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes.

When should I use Code Review Pro?

Code Review Pro fits situations like: the user asks to review; sanity-check code; asks is this safe; whats wrong with this.

How do I install Code Review Pro in Claude Code?

Run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a claude-code`. Or copy the skill folder (code-review-pro in OneWave-AI/claude-skills) into .claude/skills/code-review-pro in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Pro in Codex?

Run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a codex`. Or copy the skill folder (code-review-pro in OneWave-AI/claude-skills) into .agents/skills/code-review-pro in your project. Codex loads it when a task matches its description.

Can I use Code Review Pro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-pro, .gemini/skills/code-review-pro, .github/skills/code-review-pro and .opencode/skills/code-review-pro in your project.

What does Code Review Pro need to run?

Going by SKILL.md and its folder, Code Review Pro needs the command-line tools its instructions call (git).

Does Code Review Pro access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review Pro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Pro use?

Code Review Pro is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Pro use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Code Review Pro?

Skills that share tags, products or a category with Code Review Pro: PR Review State Fetch (prisma/orm, 48k stars), Git History Bug Audit (ben-manes/caffeine, 18k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Requesting Code Review (HezaoHezao/poirot, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Pro?

OneWave-AI (a GitHub organization) maintains it in OneWave-AI/claude-skills, which has 323 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 2, 2026.

Source: OneWave-AI/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.