A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

MITAuto-check passedDevelopment

Install Code Review Expert

skills CLI
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-review-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-review-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review-expert .claude/skills/code-review-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-expert
GitHub stars
235
Token cost
~806 tokens
SKILL.md length
141 words
Files
8 (incl. references)
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

  • 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查
  • SKILL.md covers Inputs / Outputs / Gates /…, 严重度分级, 工作流 and 警告:当你想直接修改代码时, plus 1 more section
  • Calls git
  • Tasks that involve Code review

What it does

Code Review Expert is an agent skill from ProgrammerAnthony/Expert-Coding-Harness. Use when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `README.md`, `references/quality-checklist.md` and `references/quality-gates-checklist.md`).

It sits in Development, covering Code review. The repository describes itself as: 生产级 AI Agent 技能集,辅助AI Harness应用于企业开发,覆盖代码审查、代码安全审计、TDD、需求工程、实施计划与子代理编排、架构设计、调试、前端开发与技能创建全流程。 The licence is MIT.

When your agent uses it

  • 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查
  • Tasks that involve Code review

Example prompts

  • “/code-review-expert”

What it can do on your machine

Read from SKILL.md and the folder at commit ab0b827. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Expert loads about 806 tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 35 tokens; SKILL.md has 141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~806
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ProgrammerAnthony/Expert-Coding-Harness at commit ab0b827, republished under its MIT licence (© ProgrammerAnthony). 141 words, ~806 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-expert/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
code-review-expert
description
Use when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

代码审查专家

铁律:默认只输出审查报告,不实现任何修改。未经用户明确确认,不得编写或修改任何代码。

<HARD-GATE>
审查报告输出完毕后,必须等待用户从第七步的选项中明确选择后续操作,才能进行任何代码修改。
不得根据"用户肯定想修复"的假设主动修改代码。
</HARD-GATE>

Inputs / Outputs / Gates / Handoffs(统一契约)

  • Inputs(最小输入):审查范围(默认:当前 git diff;或用户指定 commit/目录);运行/测试命令(如有);风险偏好(例如“安全优先/交付优先”)。
  • Outputs(产物形态):结构化审查报告(结构参考 references/review-report-template.md)。
  • Gates(继续前必须满足):
    • 默认只输出报告;用户明确选择“修复”选项前禁止修改代码(保持与本文件 HARD-GATE 一致)。
    • 所有问题必须给证据(文件/行号/调用路径);不确定要明确标注。
    • 通用门控清单可复制使用:references/quality-gates-checklist.md。
  • Handoffs(推荐下游):
    • writing-plans(实施计划编写):先写可执行修复计划
    • subagent-driven-development(子代理驱动开发):按计划逐任务执行

严重度分级

级别名称说明处置
P0致命安全漏洞、数据丢失风险、逻辑错误必须阻止合并
P1严重重大 SOLID 违反、性能回退、业务逻辑缺陷合并前应修复
P2中等代码异味、可维护性问题、轻微 SOLID 违反本 PR 修复或创建后续 Issue
P3建议风格、命名、优化建议可选改进

工作流

第一步:预检与上下文收集

执行以下命令建立审查范围:

git status -sb
git diff --stat
git diff

边界情况处理:

  • 无变更:告知用户,询问是否审查暂存区或指定提交范围
  • 大型 diff(>500行):先按文件汇总,再按模块/功能区域分批审查
  • 混合关注点:按功能特性分组,而非按文件顺序

若需要,用 rg 查找相关模块、用法和接口契约,识别入口点、权限边界和关键路径(认证、数据写入、网络调用)。

第二步:SOLID 与架构审查

加载 references/solid-checklist.md 进行系统检查。

重点关注:

  • SRP:类/函数是否承担多个职责
  • OCP:是否通过修改而非扩展来增加功能
  • LSP:子类是否破坏父类契约
  • ISP:接口是否过于臃肿
  • DIP:是否直接依赖具体实现而非抽象

提出重构建议时,必须说明为何能改善内聚性/耦合度,并给出最小化、安全的拆分方案。非简单重构时,提出渐进式计划而非大规模重写。

第三步:可删除代码与迭代计划

加载 references/refactor-plan.md。

识别:无用代码、冗余逻辑、功能开关保护的死代码。 分类为:立即安全删除 vs 延后处理(附计划与检查节点)。

第四步:安全与可靠性扫描

加载 references/security-checklist.md。

覆盖:

  • 注入:SQL 注入、命令注入、LDAP 注入、模板注入
  • 认证与授权:Token 校验缺失、越权访问、会话固定
  • 文件操作:路径穿越、任意文件读写、上传校验不足
  • SSRF:不受限的外部 URL 请求
  • 加密:弱算法、硬编码密钥、不安全随机数
  • 敏感信息:日志泄露、错误信息暴露、配置文件明文
  • 竞态条件与反序列化:并发漏洞、不可信数据反序列化
第五步:代码质量扫描

加载 references/quality-checklist.md。

覆盖:错误处理完备性、性能热点、边界条件、可测试性。

第六步:输出报告

输出格式固定如下:

markdown
## 代码审查报告

### 总览
[变更范围概述,受影响的核心模块与影响面评估]

### 发现问题

#### P0 致命问题
- **[文件:行号]** 问题描述
  - 原因:[为什么这是问题]
  - 修复建议:[具体如何修复,可含代码示例]

#### P1 严重问题
[同上格式]

#### P2 中等问题
[同上格式]

#### P3 建议
[同上格式]

### 可删除/重构计划
[来自 refactor-plan 的识别结果]

### 安全摘要
[安全扫描结论,无问题则明确说明已覆盖的检查项]

### 亮点
[代码中做得好的部分,平衡批评]

内联注释格式:::code-comment{file=路径 line=行号 severity=P0}

无问题时,明确说明已覆盖的检查范围与未覆盖项(如已排除的文件)。

第七步:确认下一步

列出选项(等待用户选择,不要自动执行):

请选择后续操作:
1. 修复全部问题(P0 + P1 + P2)
2. 仅修复阻塞性问题(P0 + P1)
3. 指定修复某个问题(请说明编号)
4. 暂不修改,仅保留报告

在用户选择前,不实现任何修改。

警告:当你想直接修改代码时

遇到以下想法,立刻停下——先输出报告,再等待用户指令:

借口现实
"P0 问题这么严重,我帮用户直接修吧"用户可能有不同的修复方案或上下文。先报告,等确认。
"修复很简单,顺手就改了""顺手修复"绕过了用户的决策权,可能引入用户不想要的变更。
"用户肯定想让我修""肯定"不是确认。等待用户从选项中明确选择。
"我跳过安全检查,这个项目看起来没安全问题"安全问题从来不是"看起来"没有就没有。必须按清单逐项检查。
"代码变更太小,不用走完整流程"小变更也会引入 SQL 注入、越权等高危漏洞。没有可以跳过的情况。
"这个问题我已经在报告里提了,顺手修了也无妨"无妨不等于对。铁律:未经确认,不写代码。

参考资源

  • references/solid-checklist.md — SOLID 原则详细检查项
  • references/security-checklist.md — 安全漏洞检查清单
  • references/quality-checklist.md — 代码质量检查清单
  • references/refactor-plan.md — 可删除代码与重构计划模板

© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/code-review-expert of ProgrammerAnthony/Expert-Coding-Harness.

  • SKILL.md
  • README.md
  • references/quality-checklist.md
  • references/quality-gates-checklist.md
  • references/refactor-plan.md
  • references/review-report-template.md
  • references/security-checklist.md
  • references/solid-checklist.md

Open the folder on GitHubat commit ab0b827

Compare with similar skills

Code Review Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Expert this skillProgrammerAnthony/Expert-Coding-Harness235—~806Automated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from ProgrammerAnthony/Expert-Coding-Harness

All 23 skills in this repo
  • Architecture Advisor

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要设计新系统架构、评审或优化已有系统架构、选择技术方案时。触发场景:架构分析、架构设计、系统设计、architecture、架构优化、系统架构、架构评审、架构咨询、技术方案、技术设计、如何组织代码结构、模块划分、服务拆分、数据库选型、微服务设计。

    235 GitHub stars~673 tokensUpdated 4 mo ago
    Auto-check passed
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Debug Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 程序出现错误、异常、崩溃,或行为与预期不符,或测试失败,或无法定位问题根因时。触发场景:调试、debug、报错、错误、异常、bug、问题排查、故障排查、不工作、崩溃、无法运行、出错了、为什么不生效、运行报错、跑不起来、程序挂了。

    235 GitHub stars~986 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Code Review

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。

    235 GitHub stars~614 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Performance Optimization

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要优化前端性能、提升页面加载速度、减少白屏时间、优化交互流畅度、进行性能排查时。触发场景:前端性能优化、页面加载慢、白屏时间长、卡顿、LCP/FID/CLS指标优化、前端性能分析、打包体积优化。

    235 GitHub stars~701 tokensUpdated 4 mo ago
    Auto-check passed
  • Prd Engineer

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要编写产品需求文档、整理功能需求、拆解 GitHub Issues 或制定实施计划时。触发场景:写PRD、产品需求、需求文档、prd、需求分析、功能设计、产品设计、需求评审、需求拆解、issue拆解、帮我写需求、整理功能点、我有个想法要落地、新功能规划。

    235 GitHub stars~624 tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Code Review Expert

What does Code Review Expert do?

A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。. Code Review Expert is an agent skill from ProgrammerAnthony/Expert-Coding-Harness.

When should I use Code Review Expert?

Code Review Expert fits situations like: 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查; tasks that involve Code review.

How do I install Code Review Expert in Claude Code?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-review-expert -a claude-code`. Or copy the skill folder (skills/code-review-expert in ProgrammerAnthony/Expert-Coding-Harness) into .claude/skills/code-review-expert in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Expert in Codex?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-review-expert -a codex`. Or copy the skill folder (skills/code-review-expert in ProgrammerAnthony/Expert-Coding-Harness) into .agents/skills/code-review-expert in your project. Codex loads it when a task matches its description.

Can I use Code Review Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-review-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-expert, .gemini/skills/code-review-expert, .github/skills/code-review-expert and .opencode/skills/code-review-expert in your project.

What does Code Review Expert need to run?

Going by SKILL.md and its folder, Code Review Expert needs the command-line tools its instructions call (git).

Does Code Review Expert access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Expert use?

Code Review Expert is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Expert use?

About 806 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.9k tokens, read only when the agent opens those files.

What are the alternatives to Code Review Expert?

Skills that share tags, products or a category with Code Review Expert: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Expert?

ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Expert-Coding-Harness, which has 235 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on May 11, 2026.

Source: ProgrammerAnthony/Expert-Coding-Harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.