Agent skill

Review Code

by PacificStudio in PacificStudio/openase

Review behavior, risk, performance, and test coverage before style nits.

Apache-2.0Auto-check passedDevelopment

Install Review Code

skills CLI
$ npx skills add PacificStudio/openase --skill review-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PacificStudio/openase review-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PacificStudio/openase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/builtin/skills/review-code .claude/skills/review-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-code
GitHub stars
268
Token cost
~751 tokens
SKILL.md length
379 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review behavior, risk, performance, and test coverage before style nits.

  • Works in 6 steps: Identify the review scope. → Check behavioral correctness first. → Review the main quality categories. → …
  • Tasks that involve Code review
  • SKILL.md covers Overview, When To Use, Review Workflow and Review Categories, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review Code is an agent skill from PacificStudio/openase. Review behavior, risk, performance, and test coverage before style nits.

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Test coverage. The repository describes itself as: Ticket-Driven Automated Software Engineering. OpenASE is an all-in-one platform that turns tickets into working code — AI agents automatically pick up tickets, execute workflows… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Test coverage

Example prompts

  • “/review-code”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the review scope.
  2. Check behavioral correctness first.
  3. Review the main quality categories.
  4. Evaluate the test story.
  5. Rate findings by severity.
  6. Report findings in priority order.

What it can do on your machine

Read from SKILL.md and the folder at commit e530faf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Code loads about 751 tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 379 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~751

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PacificStudio/openase at commit e530faf, republished under its Apache-2.0 licence (© PacificStudio). 379 words, ~751 tokens.

Download SKILL.mdSave it as .claude/skills/review-code/SKILL.md (or your agent's skills folder).
name
review-code
description
Review behavior, risk, performance, and test coverage before style nits.

Review Code

Overview

Conduct a thorough code review for quality, security, performance, and maintainability. Focus on the real risks first, then provide concrete, severity-rated feedback with file and line references where possible.

When To Use

  • Before merging a pull request.
  • After implementing a feature or refactor.
  • When the user asks for a review of changed files or a branch.
  • When the code looks correct at first glance but may still hide regressions or design debt.

Review Workflow

  1. Identify the review scope.

    • Review the current diff, named files, or the whole change set.
    • Prefer reviewing the actual changed surface before expanding further.
  2. Check behavioral correctness first.

    • Regressions against existing behavior.
    • Missing edge-case handling.
    • Broken invariants or data consistency risks.
  3. Review the main quality categories.

    • Security risks.
    • Code quality and complexity.
    • Performance concerns.
    • Error handling and observability.
    • Maintainability, coupling, and testability.
  4. Evaluate the test story.

    • Are the important paths covered?
    • Are the tests proving behavior rather than implementation trivia?
    • Is there an obvious missing regression test for the change?
  5. Rate findings by severity.

    • CRITICAL: must fix before merge; security or correctness issue with serious impact.
    • HIGH: should fix before merge; likely bug, major regression risk, or serious design flaw.
    • MEDIUM: worthwhile fix; non-blocking but meaningful quality issue.
    • LOW: suggestion, cleanup, or style improvement.
  6. Report findings in priority order.

    • File and line reference.
    • What is wrong.
    • Why it matters.
    • Concrete fix guidance.
Show full SKILL.md (144 more words)Show less

Review Categories

  • Security: secrets, unsafe input handling, authz gaps, injection, XSS, CSRF.
  • Code quality: complexity, duplication, large functions, fragile branching.
  • Performance: avoidable repeated work, inefficient algorithms, N+1 patterns, unnecessary re-renders.
  • Maintainability: unclear naming, tight coupling, hidden assumptions, hard-to-test logic.
  • Reliability: missing error handling, weak retries, silent failures, incomplete logging.

Operating Rules

  • Lead with findings, not praise.
  • Prioritize behavior and risk before style nits.
  • Prefer evidence and concrete examples over general taste.
  • If there are no findings, say so explicitly and still mention residual risks or test gaps.
  • Keep recommendations actionable enough that another engineer can implement them directly.

Default Deliverable Shape

Return these sections:

  1. Findings - ordered by severity, each with file and line references.
  2. Open Questions / Assumptions - only if they affect confidence.
  3. Residual Risks - what was not fully proven by the review.
  4. Short Summary - brief overall assessment after the findings.

© PacificStudio, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in internal/builtin/skills/review-code of PacificStudio/openase.

Open the folder on GitHubat commit e530faf

Compare with similar skills

Review Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Code this skillPacificStudio/openase268—~751Automated safety check: PassApache-2.0
Code Reviewpolyipseity/obsidian-terminal948—~1.6kAutomated safety check: PassAGPL-3.0
Core Components Code Reviewcore-ds/core-components137—~5.4kAutomated safety check: PassMIT
Reviewmhmzdev/the-holy-quran-app889—~907Automated safety check: PassMIT
Docs Syncmicrosoft/apm4k—~3kAutomated safety check: PassMIT
Code ReviewPrismer-AI/PrismerCloud1.6k—~2.1kAutomated safety check: NotesMIT

Similar skills

  • Code Review

    polyipseity/obsidian-terminal

    A skill your agent uses when reviewing PRs, code changes, or conducting code audits in obsidian-terminal.

    948 GitHub stars~1.6k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Core Components Code Review

    core-ds/core-components

    Review a Pull Request or diff in the @alfalab/core-components UI library — correctness bugs, public API/breaking changes, accessibility, keyboard/focus/pointer interaction, component states…

    137 GitHub stars~5.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Review

    mhmzdev/the-holy-quran-app

    Review The Holy Qur'an app code against the project's own conventions — layering (UI → Bloc → Repo → DataProvider), bloc anatomy, Provider tier, configs tokens, class widgets, Hive typeId safety…

    889 GitHub stars~907 tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Docs Sync

    microsoft/apm

    Official

    A skill your agent uses whenever a pull request is opened, reopened, or synchronized in microsoft/apm to assess whether and how the documentation corpus must change to stay truthful with the…

    4k GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    Prismer-AI/PrismerCloud

    Review a diff against its acceptance criteria in four segments (convention adherence, bug scan, historical-context regressions, test-coverage gaps) as a NON-implementing agent.

    1.6k GitHub stars~2.1k tokensUpdated 7 days ago
    DevelopmentAuto-check: notes
  • Review Code

    tobihagemann/turbo

    Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…

    407 GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed

More from PacificStudio/openase

All 14 skills in this repo
  • Deploy Coolify Review Env

    PacificStudio/openase

    Create or update a branch-scoped Coolify review environment with one command, and delete it with one command.

    268 GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check: notes
  • Deploy Openase

    PacificStudio/openase

    Build and locally redeploy OpenASE from the current branch, including web static assets and the Go binary, then restart the local service and verify health.

    268 GitHub stars~564 tokensUpdated 2 mo ago
    Auto-check: notes
  • Local Bootstrap CLI Auth Debug

    PacificStudio/openase

    Diagnose and repair OpenASE CLI access in local bootstrap mode.

    268 GitHub stars~778 tokensUpdated 2 mo ago
    Auto-check passed
  • Push

    PacificStudio/openase

    Push current branch changes to origin and create or update the corresponding pull request for OpenASE; use when asked to push, publish updates, or create a pull request.

    268 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Report Issue

    PacificStudio/openase

    Create a detailed GitHub issue for OpenASE and add it to the OpenASE Automation project with a caller-selected status (defaults to Todo).

    268 GitHub stars~631 tokensUpdated 2 mo ago
    Auto-check: notes
  • Auto Harness

    PacificStudio/openase

    Diagnose and strengthen a repository's harness layer: AGENTS.md rules, knowledge layout, architecture boundaries, lint and type gates, API and generated-client contracts, test scaffolding…

    268 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Review Code

What does Review Code do?

Review behavior, risk, performance, and test coverage before style nits. Review Code is an agent skill from PacificStudio/openase. Review behavior, risk, performance, and test coverage before style nits.

When should I use Review Code?

Review Code fits situations like: tasks that involve Code review; tasks that involve Test coverage.

How do I install Review Code in Claude Code?

Run `npx skills add PacificStudio/openase --skill review-code -a claude-code`. Or copy the skill folder (internal/builtin/skills/review-code in PacificStudio/openase) into .claude/skills/review-code in your project. Claude Code loads it when a task matches its description.

How do I install Review Code in Codex?

Run `npx skills add PacificStudio/openase --skill review-code -a codex`. Or copy the skill folder (internal/builtin/skills/review-code in PacificStudio/openase) into .agents/skills/review-code in your project. Codex loads it when a task matches its description.

Can I use Review Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PacificStudio/openase --skill review-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-code, .gemini/skills/review-code, .github/skills/review-code and .opencode/skills/review-code in your project.

What does Review Code need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Code is instructions for the agent only.

Does Review Code access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Code use?

Review Code is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Code use?

About 751 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Code?

Skills that share tags, products or a category with Review Code: Code Review (polyipseity/obsidian-terminal, 948 stars), Core Components Code Review (core-ds/core-components, 137 stars), Review (mhmzdev/the-holy-quran-app, 889 stars) and Docs Sync (microsoft/apm, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Code?

PacificStudio (a GitHub organization) maintains it in PacificStudio/openase, which has 268 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on August 9, 2026.

Source: PacificStudio/openase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.