Agent skill

Code Reviewer

by revfactory in revfactory/harness-100

Full pipeline for automated code review. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add revfactory/harness-100 --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/21-code-reviewer/.claude/skills/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
1.3k
Token cost
~1.8k tokens
SKILL.md length
671 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Full pipeline for automated code review. An agent skill from revfactory/harness-100.

  • Works in 3 steps: Preparation (Performed directly by the… → Team Assembly and Execution → Integration and Final Artifacts
  • Any code review task including review this code
  • SKILL.md covers Execution Mode, Agent Composition, Workflow and Mode by Task Scale, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Reviewer is an agent skill from revfactory/harness-100. Full pipeline for automated code review. An agent team collaborates to systematically review 4 domains: style, security, performance, and architecture. Use this skill for any code review task including 'review this code', 'look at this code', 'code inspection', 'PR review', 'code quality analysis', 'security review', 'performance review', 'architecture review', 'code style check', etc. Also supports requests for specific domains only. Note: actual CI/CD integration, auto-fix, and Git commit/merge operations are…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Security review and Performance reviews. The licence is Apache-2.0.

When your agent uses it

  • Any code review task including review this code
  • Look at this code
  • Code inspection
  • Code quality analysis

Example prompts

  • “review this code”
  • “look at this code”
  • “code inspection”
  • “/code-reviewer”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Preparation (Performed directly by the orchestrator)
  2. Team Assembly and Execution
  3. Integration and Final Artifacts

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 1.8k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 671 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 671 words, ~1,790 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder).
name
code-reviewer
description
Full pipeline for automated code review. An agent team collaborates to systematically review 4 domains: style, security, performance, and architecture. Use this skill for any code review task including 'review this code', 'look at this code', 'code inspection', 'PR review', 'code quality analysis', 'security review', 'performance review', 'architecture review', 'code style check', etc. Also supports requests for specific domains only. Note: actual CI/CD integration, auto-fix, and Git commit/merge operations are outside the scope of this skill.

Code Reviewer — Automated Code Review Pipeline

An agent team systematically reviews code across style, security, performance, and architecture.

Execution Mode

Agent Team — 5 members communicate directly via SendMessage and cross-validate each other's work.

Agent Composition

AgentFileRoleType
style-inspector.claude/agents/style-inspector.mdConventions, formatting, naming, readabilitygeneral-purpose
security-analyst.claude/agents/security-analyst.mdVulnerabilities, injection, authentication, data exposuregeneral-purpose
performance-analyst.claude/agents/performance-analyst.mdComplexity, memory, concurrency, queriesgeneral-purpose
architecture-reviewer.claude/agents/architecture-reviewer.mdDesign patterns, SOLID, dependencies, couplinggeneral-purpose
review-synthesizer.claude/agents/review-synthesizer.mdPriority synthesis, conflict resolution, final verdictgeneral-purpose

Workflow

Phase 1: Preparation (Performed directly by the orchestrator)
  1. Extract from user input:
    • Target Code: File paths, PR number, diff, directory
    • Language/Framework: Auto-detect or user-specified
    • Review Scope (optional): If only specific domains were requested
    • Context (optional): PR description, related issues, change rationale
    • Style Guide (optional): Team-specific conventions
  2. Create the _workspace/ directory at the project root
  3. Organize the input and save to _workspace/00_input.md
  4. Identify the target code and determine the review scope
  5. If existing files are provided, copy them to _workspace/ and skip the corresponding phase
  6. Determine the execution mode based on the scope of the request
Phase 2: Team Assembly and Execution
OrderTaskOwnerDependenciesArtifact
1aStyle Reviewstyle-inspectorNone_workspace/01_style_review.md
1bSecurity Reviewsecurity-analystNone_workspace/02_security_review.md
1cPerformance Reviewperformance-analystNone_workspace/03_performance_review.md
1dArchitecture Reviewarchitecture-reviewerNone_workspace/04_architecture_review.md
2Comprehensive Reviewreview-synthesizerTasks 1a-1d_workspace/05_review_summary.md

Tasks 1a-1d (all 4 domain reviews) are all executed in parallel.

Inter-team communication flow:

  • style-inspector -> Delivers sensitive info in comments to security-analyst, complex function lists to performance-analyst
  • security-analyst -> Delivers security measure performance impact to performance-analyst, authentication architecture to architecture-reviewer
  • performance-analyst -> Delivers structural bottlenecks to architecture-reviewer
  • review-synthesizer integrates all reviews. Requests additional analysis from relevant analysts when cross-domain conflicts are found
Phase 3: Integration and Final Artifacts

Organize the final artifacts based on the comprehensive report:

  1. Verify all reviews in _workspace/
  2. Determine the final verdict (Approve/Request Changes/Reject)
  3. Report the final summary to the user

Mode by Task Scale

User Request PatternExecution ModeAgents Deployed
"Review this code", "full review"Full ReviewAll 5 agents
"Security review only"Security Modesecurity-analyst + review-synthesizer
"Analyze performance"Performance Modeperformance-analyst + review-synthesizer
"Architecture review"Architecture Modearchitecture-reviewer + review-synthesizer
"Just check code style"Style Modestyle-inspector + review-synthesizer

PR Review: When a PR number is provided, extract the diff and focus review on changed code. Reference full file context but concentrate the review on the diff.

Show full SKILL.md (277 more words)Show less

Data Transfer Protocol

StrategyMethodPurpose
File-based_workspace/ directoryStore and share primary artifacts
Message-basedSendMessageReal-time delivery of key information, additional analysis requests
Task-basedTaskCreate/TaskUpdateProgress tracking, dependency management

File naming convention: {order}_{agent}_{artifact}.{extension}

Error Handling

Error TypeStrategy
Language not identifiedAuto-detect from file extensions + code patterns
Large codebaseFocus on changed or core files; note the scope in the review report
Agent failureRetry once -> If still fails, proceed without that domain; note the omission in the comprehensive report
Cross-domain conflictreview-synthesizer performs trade-off analysis and renders verdict
Insufficient contextReview based on code alone if no PR description or issue number; note limitations

Test Scenarios

Normal Flow

Prompt: "Do a full code review of this Python Flask project" + code files/directory Expected Result:

  • Style: PEP 8 standards, naming/formatting/readability checks, Black/flake8 config suggestions
  • Security: SQL injection, XSS, hardcoded secrets, dependency CVE checks
  • Performance: Query optimization, N+1, memory usage, caching opportunities
  • Architecture: MVC pattern compliance, SOLID, dependency analysis
  • Comprehensive: Unified priorities, final verdict, action items
Existing File Flow

Prompt: "Review only the security of this PR" + PR diff Expected Result:

  • Security mode: deploy security-analyst + review-synthesizer
  • Diff-focused review, full file context for reference
  • Skip style-inspector, performance-analyst, architecture-reviewer
Error Flow

Prompt: "Look at this code" + single file (under 100 lines) Expected Result:

  • Small codebase -> Architecture review shifts to function separation/module design perspective
  • Run in full review mode, but each domain adjusts to code scale
  • Comprehensive report notes "single file review, architecture assessment limited"

Agent Extension Skills

Extension skills that enhance each agent's domain expertise:

SkillTarget AgentRole
vulnerability-patternssecurity-analystCWE classification, language-specific vulnerability patterns, safe alternatives
refactoring-catalogarchitecture-reviewer, performance-analystCode smell to refactoring mapping, SOLID violations, complexity metrics

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/21-code-reviewer/.claude/skills/code-reviewer of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillrevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Code Review Excellenceandrew-yangy/gru-ai155—~1.7kAutomated safety check: NotesMIT
Conduct Code Review RoundFerroxLabs/wayland608—~3.9kAutomated safety check: PassApache-2.0
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes
  • Conduct Code Review Round

    FerroxLabs/wayland

    Orchestrates a thorough code review process by chaining four engineering skills into a structured review pipeline.

    608 GitHub stars~3.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Reviews a pull request against the Pascal editor's architectural rules: package boundaries, registry-driven node composition, hook hygiene and selector performance.

    25k GitHub stars~7.5k tokensUpdated today
    DevelopmentAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Full pipeline for automated code review. An agent skill from revfactory/harness-100. Code Reviewer is an agent skill from revfactory/harness-100. Full pipeline for automated code review.

When should I use Code Reviewer?

Code Reviewer fits situations like: any code review task including review this code; look at this code; code inspection; code quality analysis.

How do I install Code Reviewer in Claude Code?

Run `npx skills add revfactory/harness-100 --skill code-reviewer -a claude-code`. Or copy the skill folder (en/21-code-reviewer/.claude/skills/code-reviewer in revfactory/harness-100) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add revfactory/harness-100 --skill code-reviewer -a codex`. Or copy the skill folder (en/21-code-reviewer/.claude/skills/code-reviewer in revfactory/harness-100) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Reviewer is instructions for the agent only. Our summary lists: Python 3.

Does Code Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Skill (Rain-kl/OpenFlare, 288 stars), Code Review Excellence (andrew-yangy/gru-ai, 155 stars) and Conduct Code Review Round (FerroxLabs/wayland, 608 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.