PR Review State Fetch
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/code-review-pro .claude/skills/code-review-pro && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .claude/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OneWave-AI/claude-skills/tree/main/code-review-proType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/code-review-pro .agents/skills/code-review-pro && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .agents/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/code-review-pro .cursor/skills/code-review-pro && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .cursor/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OneWave-AI/claude-skills.git --path code-review-pro--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/code-review-pro .gemini/skills/code-review-pro && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .gemini/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OneWave-AI/claude-skills code-review-proInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/code-review-pro .github/skills/code-review-pro && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .github/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OneWave-AI/claude-skills --skill code-review-pro -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OneWave-AI/claude-skills code-review-pro --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/code-review-pro .opencode/skills/code-review-pro && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-pro" agent skill from https://github.com/OneWave-AI/claude-skills/tree/main/code-review-pro into .opencode/skills/code-review-pro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-pro", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-proPerforms a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…
Code Review Pro is an agent skill from OneWave-AI/claude-skills. Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes. Use when the user asks to review, audit, or sanity-check code, asks "is this safe", "what's wrong with this", "find bugs", or wants a security or performance pass before shipping. For posting line comments on a GitHub pull request, use…
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/checklist.md`).
It sits in Development, covering Code review, Web application vulnerabilities and Debugging. It works with Git and GitHub. The repository describes itself as: 200+ production-ready Claude Code skills for sales, marketing, design, engineering, and AI agent architecture. Built and maintained by OneWave AI. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fc5b785. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Pro loads about 1.2k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 482 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OneWave-AI/claude-skills at commit fc5b785, republished under its MIT licence (© OneWave-AI). 482 words, ~1,177 tokens.
.claude/skills/code-review-pro/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Find the problems that matter, prove each one, and show the fix. A short list of real issues beats a long list of maybes.
Set the scope. Decide what is under review: a pasted snippet, specific files, the working-tree diff (git diff, git diff --staged), or a branch against its base (git diff main...HEAD). For a diff, review the changed lines but read enough surrounding code to know how they are called.
Learn the context before judging. Identify language, framework and version (check package.json, pyproject.toml, go.mod, and so on), how the code is reached (HTTP handler, job, CLI, library), what input is untrusted, and any repo conventions (linters, CLAUDE.md, existing patterns). A pattern that is a bug in one framework can be safe in another; for example, React escapes JSX text, so XSS lives in dangerouslySetInnerHTML, href values, and raw HTML sinks.
Review in priority order, using references/checklist.md:
Verify every finding before reporting it. For each candidate, trace the data flow: where does the input come from, can an attacker or real user control it, and does anything upstream already validate or escape it? Check whether a test covers it. If you can run code, reproduce the bug with a small test or script. Drop findings you cannot support; mark the rest with a confidence level.
Rank and write the report in the format below. Lead with the highest severity. Group repeated instances of one problem into a single finding with all locations.
# Code Review: [scope]
**Verdict**: [Ship / Ship after fixes / Do not ship] - [one sentence why]
**Findings**: [n] critical, [n] high, [n] medium, [n] low
## Critical
### 1. SQL injection in user search (`src/api/users.ts:42`)
**Category**: A05:2025 Injection | **Confidence**: High
**Evidence**: `q` comes from `req.query` and is interpolated into the SQL string; no validation upstream.
**Impact**: Any caller can read or modify arbitrary tables.
Current:
```ts
const rows = await db.query(`SELECT * FROM users WHERE name LIKE '%${q}%'`);
```
Fix:
```ts
const rows = await db.query("SELECT * FROM users WHERE name LIKE $1", [`%${q}%`]);
```
## High
...
## Medium
...
## Low
- `utils/date.ts:10` - [one line]
## What is solid
[Two or three specific things done well, so the author knows what to keep.]
## Not reviewed
[Files, paths, or concerns outside scope or that could not be verified.]useMemo/useCallback advice changes when the React Compiler is enabled, and many Node APIs now ship built-ins (fetch, crypto.randomUUID, node:test).© OneWave-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in code-review-pro of OneWave-AI/claude-skills.
Open the folder on GitHubat commit fc5b785
Code Review Pro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Pro this skillOneWave-AI/claude-skills | 323 | — | ~1.2k | Automated safety check: Pass | MIT | |
| PR Review State Fetchprisma/orm | 48k | — | ~767 | Automated safety check: Pass | Apache-2.0 | |
| Git History Bug Auditben-manes/caffeine | 18k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Greploop Appsmichaelshimeles/skills | 1.3k | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Requesting Code ReviewHezaoHezao/poirot | 250 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | |
| PR Triagertk-ai/rtk | 83k | — | ~2.5k | Automated safety check: Notes | Apache-2.0 |
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
ben-manes/caffeine
Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.
michaelshimeles/skills
Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
rtk-ai/rtk
Audits a repository's open pull requests, deep-reviews chosen ones and drafts review comments that are only posted after you approve them.
yoshiko-pg/difit
Review a specific diff (branch, commit, or GitHub PR) and show the findings as comments inside difit, the local diff viewer.
OneWave-AI/claude-skills
Finds duplicate and junk records in a CRM CSV export with fuzzy matching, normalizes fields and writes a reviewable merge plan plus import-ready files without touching the live CRM.
OneWave-AI/claude-skills
Repairs broken decks and PDFs exported from Claude Design or similar AI deck generators: clipped text, wrong fonts and corrupted .pptx package structure.
OneWave-AI/claude-skills
Writes, explains, debugs, and optimizes BI calculations - Power BI / Fabric DAX measures and calculated columns, Tableau calculated fields (FIXED/INCLUDE/EXCLUDE LOD expressions, table…
OneWave-AI/claude-skills
Categorizes transactions, reconciles bank and card statements to the ledger, works a month-end checklist and prepares a close package, without ever forcing a balance.
OneWave-AI/claude-skills
Combines CSV, TSV and Excel files into one verified table with pandas, by stacking or joining, mapping columns, normalizing keys and removing duplicates.
OneWave-AI/claude-skills
Pulls financial statement numbers for US public companies straight from SEC EDGAR's free official XBRL APIs (companyfacts, companyconcept, frames, submissions) into a cited table.
Categories
Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…. Code Review Pro is an agent skill from OneWave-AI/claude-skills. Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes.
Code Review Pro fits situations like: the user asks to review; sanity-check code; asks is this safe; whats wrong with this.
Run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a claude-code`. Or copy the skill folder (code-review-pro in OneWave-AI/claude-skills) into .claude/skills/code-review-pro in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a codex`. Or copy the skill folder (code-review-pro in OneWave-AI/claude-skills) into .agents/skills/code-review-pro in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OneWave-AI/claude-skills --skill code-review-pro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-pro, .gemini/skills/code-review-pro, .github/skills/code-review-pro and .opencode/skills/code-review-pro in your project.
Going by SKILL.md and its folder, Code Review Pro needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review Pro is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Code Review Pro: PR Review State Fetch (prisma/orm, 48k stars), Git History Bug Audit (ben-manes/caffeine, 18k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Requesting Code Review (HezaoHezao/poirot, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OneWave-AI (a GitHub organization) maintains it in OneWave-AI/claude-skills, which has 323 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 2, 2026.
Source: OneWave-AI/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.