Code Reviewer
Yikai-Liao/symusic
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…
Structured code review workflow for .NET projects using Roslyn MCP tools.
$ npx skills add Resgrid/Core --skill code-review-workflow -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Resgrid/Core code-review-workflow --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.forge/skills/code-review-workflow .claude/skills/code-review-workflow && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .claude/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflowType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Resgrid/Core --skill code-review-workflow -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Resgrid/Core code-review-workflow --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.forge/skills/code-review-workflow .agents/skills/code-review-workflow && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .agents/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Resgrid/Core --skill code-review-workflow -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Resgrid/Core code-review-workflow --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.forge/skills/code-review-workflow .cursor/skills/code-review-workflow && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .cursor/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Resgrid/Core.git --path .forge/skills/code-review-workflow--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Resgrid/Core --skill code-review-workflow -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Resgrid/Core code-review-workflow --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.forge/skills/code-review-workflow .gemini/skills/code-review-workflow && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .gemini/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Resgrid/Core code-review-workflowInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Resgrid/Core --skill code-review-workflow -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .github/skills && cp -r skills-src/.forge/skills/code-review-workflow .github/skills/code-review-workflow && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .github/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Resgrid/Core --skill code-review-workflow -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Resgrid/Core code-review-workflow --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Resgrid/Core.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.forge/skills/code-review-workflow .opencode/skills/code-review-workflow && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-workflow" agent skill from https://github.com/Resgrid/Core/tree/master/.forge/skills/code-review-workflow into .opencode/skills/code-review-workflow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-workflow", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-workflowStructured code review workflow for .NET projects using Roslyn MCP tools.
Code Review Workflow is an agent skill from Resgrid/Core. Structured code review workflow for .NET projects using Roslyn MCP tools. Multi-dimensional review covering correctness, security, performance, architecture compliance, and test coverage. Load when: "review PR", "review code", "code review", "PR review", "review changes", "review my code", "check code quality".
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review, Pull requests and Test coverage. It works with .NET. The repository describes itself as: The Open Source Computer Aided Dispatch (CAD), Personnel, Shift Management, Automatic Vehicle Location (AVL) and Emergency Management Platform that powers Resgrid.com. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a31015f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Workflow loads about 2.1k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 529 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Resgrid/Core at commit a31015f, republished under its Apache-2.0 licence (© Resgrid). 529 words, ~2,144 tokens.
.claude/skills/code-review-workflow/SKILL.md (or your agent's skills folder).detect_antipatterns catches more than manual scanning, get_diagnostics finds what the compiler knows, and find_references reveals blast radius. Only read files for context that tools can't provide..Include() or using a projection" is.Use for non-trivial PRs (3+ files changed, new features, refactors). Execute steps in order:
Step 1: Understand the change scope Get changed files from git diff or user input. Categorize:
Step 2: Automated analysis Run MCP tools on changed files:
→ detect_antipatterns (file: each changed .cs file)
Catch: async void, sync-over-async, DateTime.Now, new HttpClient(), broad catch, etc.
→ get_diagnostics (scope: file, path: each changed file)
Catch: new compiler warnings, nullability issues, unused variables
→ get_public_api (typeName: each modified type)
Check: API surface changes — new public members, removed members, signature changesStep 3: Blast radius assessment For each changed public API:
→ find_references (symbolName: changedMethod)
Count callers. High count = high risk. Flag breaking changes.Step 4: Architecture compliance
→ get_project_graph
Verify: dependency direction is correct (Domain → nothing, Infra → Domain, Api → Application)
Flag: circular references, wrong-direction dependenciesStep 5: Test coverage check
→ get_test_coverage_map (projectFilter: changed project)
Check: do test files exist for every changed type?
Flag: new types without tests, modified logic without test updatesStep 6: Manual review Read changed files for things tools can't catch:
Step 7: Produce review
## Review Summary
[1-2 sentence overall assessment: scope, risk level, recommendation]
## Critical (must fix)
- **[File:Line] [Title]** — [What's wrong]. [Why it matters]. [How to fix].
- ...
## Warnings (should fix)
- **[File:Line] [Title]** — [What's wrong]. [Impact if not fixed]. [Suggested fix].
- ...
## Suggestions (nice to have)
- **[File:Line] [Title]** — [Current approach]. [Better alternative]. [Why].
- ...
## Architecture Compliance
[Dependency direction check results. Layer violation findings. Module boundary enforcement.]
## Test Coverage
[Which changed types have tests. Which are missing. Specific test scenarios to add.]
## What's Good
- [Positive finding 1 — reinforce good patterns]
- [Positive finding 2]
- ...Use for small changes (1-2 files, bug fixes, config changes). Lightweight — skip blast radius and architecture checks.
Steps:
detect_antipatterns on changed filesget_diagnostics on changed files## Quick Review
[1 sentence assessment]
### Issues
- [Finding with severity tag: 🔴 Critical / 🟡 Warning / 🔵 Suggestion]
### What's Good
- [Positive note]Standalone check for architecture-level concerns. Use when reviewing project structure changes, new project additions, or module boundary modifications.
Steps:
get_project_graph — visualize the full dependency tree| Architecture | Rule | Violation Example |
|---|---|---|
| VSA | Features don't reference each other | Feature A imports from Feature B |
| Clean Architecture | Domain has zero project references | Domain references Infrastructure |
| DDD | Aggregates don't reference other aggregates | Order aggregate imports Product aggregate |
| Modular Monolith | Modules communicate only via integration events | Module A directly references Module B's DbContext |
find_references on module/layer boundary types to verify encapsulation:→ find_references(symbolName: "OrdersDbContext")
Should only be referenced within the Orders module.
External references = module boundary violation.detect_circular_dependencies to find cycles:→ detect_circular_dependencies(scope: projects)
Flag any project-level cycles.
→ detect_circular_dependencies(scope: types, projectFilter: "MyApp.Application")
Flag type-level cycles within the application layer.# BAD — Reading every file manually, missing patterns across the codebase
"Let me read OrderService.cs... looks fine to me."
# Missed: 3 DateTime.Now usages, 1 async void, 2 compiler warnings# GOOD — MCP-first, then targeted file reads
→ detect_antipatterns: Found 3 DateTime.Now (AP004), 1 async void (AP001)
→ get_diagnostics: 2 CS8600 warnings in OrderService.cs
"I found 6 issues via static analysis. Let me read the files for business logic review..."# BAD
"The code could be better."
"This doesn't look right."
"Consider refactoring this."# GOOD
"OrderService.cs:47 — `DateTime.Now` should be `TimeProvider.GetUtcNow()`.
DateTime.Now is untestable and uses local timezone. Inject TimeProvider
via primary constructor and call GetUtcNow()."# BAD — Only checking code style and patterns
"Code looks clean, approved!"
# Missed: SQL injection in raw query, missing authorization attribute, exposed PII in logs# GOOD — Security is a review dimension
"## Critical
- **OrderController.cs:23** Missing `[Authorize]` — endpoint exposes order data without auth
- **SearchService.cs:45** SQL injection — user input concatenated into raw SQL. Use parameterized query.
## Suggestions
- **LoggingMiddleware.cs:12** PII exposure — email logged at Information level. Mask or use Debug level."# BAD — 10 comments about naming, 0 about the race condition
"Rename `svc` to `service`. Use `var` instead of explicit type. Add XML docs."# GOOD — Prioritize by impact
"## Critical
- Race condition in OrderService.ProcessAsync — concurrent calls can double-charge
## Suggestions
- Consider renaming `svc` to `service` for clarity"| Scenario | Review Type | MCP Tools |
|---|---|---|
| Feature PR (3+ files) | Full PR Review | All tools |
| Bug fix (1-2 files) | Quick Review | detect_antipatterns, get_diagnostics |
| Config/infra changes | Quick Review + Manual | get_project_graph |
| New project/module added | Architecture Compliance | get_project_graph, detect_circular_dependencies |
| Refactor PR | Full PR Review + Architecture | All tools + find_references (blast radius) |
| Security-sensitive change | Full PR Review → escalate to security-auditor | detect_antipatterns + manual security review |
| Test-only changes | Quick Review | get_diagnostics only |
| Performance-critical path | Full PR Review → escalate to performance-analyst | get_diagnostics + manual review |
© Resgrid, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .forge/skills/code-review-workflow of Resgrid/Core.
Open the folder on GitHubat commit a31015f
Code Review Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Workflow this skillResgrid/Core | 229 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Code ReviewerYikai-Liao/symusic | 189 | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Code Reviewsbroenne/mcp-windows | 105 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Code Quality ReviewStudentWeis/ropy | 193 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Health Checkcodewithmukesh/dotnet-claude-kit | 751 | 1 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Reviewing Changesbitwarden/ios | 694 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 |
Yikai-Liao/symusic
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…
sbroenne/mcp-windows
Review pull requests in mcp-windows for concrete bugs in MCP and CLI contracts, Windows UI automation, element identity, snapshots, bounded searches, and service lifetime.
StudentWeis/ropy
Review a code change, diff, pull request, module, or test suite for code quality, comment and documentation quality, and test quality.
codewithmukesh/dotnet-claude-kit
Multi-dimensional health assessment for .NET projects with letter grades (A-F) using Roslyn MCP tools.
bitwarden/ios
Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.
paralleldrive/aidd
Conduct a thorough code review focusing on code quality, best practices, security, test coverage, and adherence to project standards and functional requirements.
Resgrid/Core
Focus code review effort on the 20% of code that causes 80% of issues.
Resgrid/Core
Autonomous iteration loops for .NET development: build-fix, test-fix, refactor, and scaffold loops.
Resgrid/Core
Auto-document insights and discoveries during development sessions.
Resgrid/Core
Observability for .NET 10 applications. An agent skill from Resgrid/Core.
Resgrid/Core
Strategic Codex model selection for .NET development workflows.
Resgrid/Core
Strategic Claude model selection for .NET development workflows.
Works with
Categories
Structured code review workflow for .NET projects using Roslyn MCP tools. Code Review Workflow is an agent skill from Resgrid/Core.NET projects using Roslyn MCP tools.
Code Review Workflow fits situations like: tasks that involve Code review; tasks that involve Pull requests; tasks that involve Test coverage.
Run `npx skills add Resgrid/Core --skill code-review-workflow -a claude-code`. Or copy the skill folder (.forge/skills/code-review-workflow in Resgrid/Core) into .claude/skills/code-review-workflow in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Resgrid/Core --skill code-review-workflow -a codex`. Or copy the skill folder (.forge/skills/code-review-workflow in Resgrid/Core) into .agents/skills/code-review-workflow in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Resgrid/Core --skill code-review-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-workflow, .gemini/skills/code-review-workflow, .github/skills/code-review-workflow and .opencode/skills/code-review-workflow in your project.
SKILL.md names no scripts, command-line tools or credentials: Code Review Workflow is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review Workflow is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Workflow: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review (sbroenne/mcp-windows, 105 stars), Code Quality Review (StudentWeis/ropy, 193 stars) and Health Check (codewithmukesh/dotnet-claude-kit, 751 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Resgrid (a GitHub organization) maintains it in Resgrid/Core, which has 229 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.
Source: Resgrid/Core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.