Agent skill

Thorough Code Review

by pretend1111 in pretend1111/claude-desktop-app

Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

Custom licenceAuto-check passedDevelopment

Install Thorough Code Review

skills CLI
$ npx skills add pretend1111/claude-desktop-app --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pretend1111/claude-desktop-app code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pretend1111/claude-desktop-app.git skills-src && mkdir -p .claude/skills && cp -r skills-src/electron/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
494
Used in
1 other repo
Token cost
~502 tokens
SKILL.md length
251 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Custom licence

At a glance

Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

  • Works in 4 steps: Identify What to Review → Read the Code → Analyze → …
  • Reviewing a file or pasted snippet for bugs and security issues
  • Calls git
  • Checking recent uncommitted changes before committing

What it does

The agent picks what to review: a file path or pasted code you provide, otherwise the output of `git diff`, and if there are no git changes it asks. It reads the full files to understand context, then checks four groups of problems: bugs and correctness (logic errors, off-by-one errors, null handling, race conditions), security (injection risks, hardcoded secrets, unsafe deserialization, path traversal, missing input validation), performance (redundant work, N+1 queries, leaks, blocking calls in async code) and maintainability (naming, complexity, missing error handling, dead code).

Findings are reported by severity as Critical, Important or Suggestions, and each one states the issue, explains why it is a problem and shows the fix. Categories with nothing to report are skipped, and if the code is clean the agent says so rather than inventing issues.

When your agent uses it

  • Reviewing a file or pasted snippet for bugs and security issues
  • Checking recent uncommitted changes before committing
  • Auditing code quality and getting feedback on an implementation

Example prompts

  • “Review src/auth/session.ts for bugs and security problems.”
  • “Look over my recent changes and tell me what's critical to fix.”
  • “Here's my new caching helper. Review it for performance issues.”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify What to Review
  2. Read the Code
  3. Analyze
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 8cbd7b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Thorough Code Review loads about 502 tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 251 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~502

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 251 words (~502 tokens).

“Review the provided code or recent changes with a focus on correctness, maintainability, and best practices.”

— opening of SKILL.md by pretend1111, Custom licence
name
code-review

Read the full SKILL.md on GitHub

Files

Just SKILL.md in electron/skills/code-review of pretend1111/claude-desktop-app.

Open the folder on GitHubat commit 8cbd7b7

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in pretend1111/claude-desktop-app, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Thorough Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Thorough Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Thorough Code Review this skillpretend1111/claude-desktop-app4941 repos~502Automated safety check: PassCustom licence
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Handsontable Code Reviewhandsontable/handsontable22k—~999Automated safety check: PassCustom licence
Senior Code Criticnekomangaorg/Neko2.8k—~1.8kAutomated safety check: PassApache-2.0
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Codexqa Rootcause Analyzeropenqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Handsontable Code Review

    handsontable/handsontable

    Reviews Handsontable monorepo changes across architecture, code quality, performance and accessibility, and tests, with a confidence rating on every finding.

    22k GitHub stars~999 tokensUpdated today
    DevelopmentAuto-check passed
  • Senior Code Critic

    nekomangaorg/Neko

    Performs rigorous, adversarial senior-staff code reviews that ruthlessly uncover architectural anti-patterns, edge cases, lifecycle hazards, memory leaks, type-safety gaps, and performance pitfalls.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

    152 GitHub stars~2.6k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • WordPress Code Guard

    amElnagdy/guard-skills

    Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

    1.3k GitHub stars~2.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from pretend1111/claude-desktop-app

  • Skill Creator

    pretend1111/claude-desktop-app

    Walks through creating a new Claude skill from scratch or improving an existing one, asking what it should do, when it should trigger, and in what format.

    494 GitHub starsUsed in 1 repo~591 tokens
    Auto-check passed
  • Project Scaffolder

    pretend1111/claude-desktop-app

    Scaffolds a complete, runnable project from scratch, covering web, Python and Node.js projects, with a working entry point and no placeholder code.

    494 GitHub starsUsed in 1 repo~498 tokens
    Auto-check passed
  • Frontend Design Principles

    pretend1111/claude-desktop-app

    Gives practical design rules for polished HTML, CSS and JavaScript interfaces and browser games, covering spacing, type, color, components, motion and responsive breakpoints.

    494 GitHub starsUsed in 1 repo~824 tokens
    Auto-check passed
  • Doc Writer

    pretend1111/claude-desktop-app

    Generate README, API docs, or user guides for code and projects.

    494 GitHub starsUsed in 1 repo~375 tokens
    Auto-check passed

Works with

Questions about Thorough Code Review

What does Thorough Code Review do?

Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. The agent picks what to review: a file path or pasted code you provide, otherwise the output of `git diff`, and if there are no git changes it asks. It reads the full files to understand context, then checks four groups of problems: bugs and correctness (logic errors, off-by-one errors, null handling, race conditions), security (injection risks, hardcoded secrets, unsafe deserialization, path traversal, missing input validation), performance (redundant work, N+1 queries, leaks, blocking calls in async code) and maintainability (naming, complexity, missing error handling, dead code).

When should I use Thorough Code Review?

Thorough Code Review fits situations like: reviewing a file or pasted snippet for bugs and security issues; checking recent uncommitted changes before committing; auditing code quality and getting feedback on an implementation.

How do I install Thorough Code Review in Claude Code?

Run `npx skills add pretend1111/claude-desktop-app --skill code-review -a claude-code`. Or copy the skill folder (electron/skills/code-review in pretend1111/claude-desktop-app) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Thorough Code Review in Codex?

Run `npx skills add pretend1111/claude-desktop-app --skill code-review -a codex`. Or copy the skill folder (electron/skills/code-review in pretend1111/claude-desktop-app) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Thorough Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pretend1111/claude-desktop-app --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Thorough Code Review need to run?

Going by SKILL.md and its folder, Thorough Code Review needs the command-line tools its instructions call (git).

Does Thorough Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Thorough Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Thorough Code Review use?

Thorough Code Review has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Thorough Code Review use?

About 502 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Thorough Code Review?

Skills that share tags, products or a category with Thorough Code Review: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Handsontable Code Review (handsontable/handsontable, 22k stars), Senior Code Critic (nekomangaorg/Neko, 2.8k stars) and Code Review Specialist (luongnv89/claude-howto, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Thorough Code Review?

pretend1111 (a GitHub user) maintains it in pretend1111/claude-desktop-app, which has 494 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on April 22, 2026.

Source: pretend1111/claude-desktop-app on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.