Agent skill

Code Review Checklist

by shareAI-lab in shareAI-lab/learn-claude-code

Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

MITAuto-check passedDevelopment

Install Code Review Checklist

skills CLI
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shareAI-lab/learn-claude-code code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
78k
Used in
5 other repos
Token cost
~1.1k tokens
SKILL.md length
258 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

  • Works in 5 steps: Security (Critical) → Correctness → Performance → …
  • Reviewing a pull request before merge
  • SKILL.md covers Review Checklist, Review Output Format, Common Patterns to Flag and Review Commands, plus 1 more section
  • Calls npm, git and pip

What it does

The agent works through five groups of checks. Security covers injection, authentication and authorization flaws, data exposure, weak cryptography and vulnerable dependencies, with `npm audit` and `pip-audit` suggested for quick scans. Correctness looks at logic errors, race conditions, resource leaks, error handling and type safety. Performance looks for N+1 queries, memory problems, blocking calls in async code, inefficient algorithms and missing caching.

Maintainability checks naming, complexity (functions over 50 lines or nesting deeper than three levels), duplication, dead code and comments, and testing checks coverage of critical paths, edge cases, mocking and meaningful assertions. Results go into a markdown template headed by the file or component name with a summary section. The skill also lists patterns to flag in Python and JavaScript or TypeScript, such as SQL built by string formatting and prototype pollution through `Object.assign`, plus git commands for viewing recent changes.

When your agent uses it

  • Reviewing a pull request before merge
  • Auditing a module for security and performance problems
  • Checking a change for missing tests and edge cases

Example prompts

  • “Review the changes in src/auth for security and correctness issues.”
  • “Audit this service for N+1 queries and blocking calls in async code.”
  • “Do a code review of my last five commits and list the problems you find.”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Security (Critical)
  2. Correctness
  3. Performance
  4. Maintainability
  5. Testing

What it can do on your machine

Read from SKILL.md and the folder at commit ce8f9f1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git
    • pip
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, git and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Checklist loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 258 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shareAI-lab/learn-claude-code at commit ce8f9f1, republished under its MIT licence (© shareAI-lab). 258 words, ~1,067 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.

Code Review Skill

You now have expertise in conducting comprehensive code reviews. Follow this structured approach:

Review Checklist

1. Security (Critical)

Check for:

  • Injection vulnerabilities: SQL, command, XSS, template injection
  • Authentication issues: Hardcoded credentials, weak auth
  • Authorization flaws: Missing access controls, IDOR
  • Data exposure: Sensitive data in logs, error messages
  • Cryptography: Weak algorithms, improper key management
  • Dependencies: Known vulnerabilities (check with npm audit, pip-audit)
bash
# Quick security scans
npm audit                    # Node.js
pip-audit                    # Python
cargo audit                  # Rust
grep -r "password\|secret\|api_key" --include="*.py" --include="*.js"
2. Correctness

Check for:

  • Logic errors: Off-by-one, null handling, edge cases
  • Race conditions: Concurrent access without synchronization
  • Resource leaks: Unclosed files, connections, memory
  • Error handling: Swallowed exceptions, missing error paths
  • Type safety: Implicit conversions, any types
3. Performance

Check for:

  • N+1 queries: Database calls in loops
  • Memory issues: Large allocations, retained references
  • Blocking operations: Sync I/O in async code
  • Inefficient algorithms: O(n^2) when O(n) possible
  • Missing caching: Repeated expensive computations
4. Maintainability

Check for:

  • Naming: Clear, consistent, descriptive
  • Complexity: Functions > 50 lines, deep nesting > 3 levels
  • Duplication: Copy-pasted code blocks
  • Dead code: Unused imports, unreachable branches
  • Comments: Outdated, redundant, or missing where needed
5. Testing

Check for:

  • Coverage: Critical paths tested
  • Edge cases: Null, empty, boundary values
  • Mocking: External dependencies isolated
  • Assertions: Meaningful, specific checks

Review Output Format

markdown
## Code Review: [file/component name]

### Summary
[1-2 sentence overview]

### Critical Issues
1. **[Issue]** (line X): [Description]
   - Impact: [What could go wrong]
   - Fix: [Suggested solution]

### Improvements
1. **[Suggestion]** (line X): [Description]

### Positive Notes
- [What was done well]

### Verdict
[ ] Ready to merge
[ ] Needs minor changes
[ ] Needs major revision

Common Patterns to Flag

Python
python
# Bad: SQL injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good:
cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,))

# Bad: Command injection
os.system(f"ls {user_input}")
# Good:
subprocess.run(["ls", user_input], check=True)

# Bad: Mutable default argument
def append(item, lst=[]):  # Bug: shared mutable default
# Good:
def append(item, lst=None):
    lst = lst or []
JavaScript/TypeScript
javascript
// Bad: Prototype pollution
Object.assign(target, userInput)
// Good:
Object.assign(target, sanitize(userInput))

// Bad: eval usage
eval(userCode)
// Good: Never use eval with user input

// Bad: Callback hell
getData(x => process(x, y => save(y, z => done(z))))
// Good:
const data = await getData();
const processed = await process(data);
await save(processed);

Review Commands

bash
# Show recent changes
git diff HEAD~5 --stat
git log --oneline -10

# Find potential issues
grep -rn "TODO\|FIXME\|HACK\|XXX" .
grep -rn "password\|secret\|token" . --include="*.py"

# Check complexity (Python)
pip install radon && radon cc . -a

# Check dependencies
npm outdated  # Node
pip list --outdated  # Python

Review Workflow

  1. Understand context: Read PR description, linked issues
  2. Run the code: Build, test, run locally if possible
  3. Read top-down: Start with main entry points
  4. Check tests: Are changes tested? Do tests pass?
  5. Security scan: Run automated tools
  6. Manual review: Use checklist above
  7. Write feedback: Be specific, suggest fixes, be kind

© shareAI-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-review of shareAI-lab/learn-claude-code.

Open the folder on GitHubat commit ce8f9f1

Used in 6 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in shareAI-lab/learn-claude-code, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Checklist this skillshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT
Coding Agentmastra-ai/mastra29k—~2.3kAutomated safety check: PassCustom licence
Tbdjlevy/strif131—~3.5kAutomated safety check: PassMIT

Similar skills

  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Coding Agent

    mastra-ai/mastra

    Authoring playbook for building agents that write, edit, review, or refactor code.

    29k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Tbd

    jlevy/strif

    Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.

    131 GitHub stars~3.5k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    305 GitHub stars~3.6k tokensUpdated 21 days ago
    DevelopmentAuto-check: notes

More from shareAI-lab/learn-claude-code

  • Agent Builder

    shareAI-lab/learn-claude-code

    Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.

    78k GitHub starsUsed in 6 repos~1.2k tokens
    Auto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Auto-check passed
  • PDF Processing Guide

    shareAI-lab/learn-claude-code

    Gives the agent command-line and Python recipes for reading, creating, merging and splitting PDF files, plus tips for large and scanned documents.

    78k GitHub starsUsed in 5 repos~646 tokens
    Auto-check passed

Categories

Questions about Code Review Checklist

What does Code Review Checklist do?

Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format. The agent works through five groups of checks. Security covers injection, authentication and authorization flaws, data exposure, weak cryptography and vulnerable dependencies, with `npm audit` and `pip-audit` suggested for quick scans.

When should I use Code Review Checklist?

Code Review Checklist fits situations like: reviewing a pull request before merge; auditing a module for security and performance problems; checking a change for missing tests and edge cases.

How do I install Code Review Checklist in Claude Code?

Run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in shareAI-lab/learn-claude-code) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Checklist in Codex?

Run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a codex`. Or copy the skill folder (skills/code-review in shareAI-lab/learn-claude-code) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review Checklist need to run?

Going by SKILL.md and its folder, Code Review Checklist needs the command-line tools its instructions call (npm, git, pip and cargo).

Does Code Review Checklist access the network?

SKILL.md contains no URLs. Its commands use npm, git and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Checklist use?

Code Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Checklist use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Checklist?

Skills that share tags, products or a category with Code Review Checklist: Code Reviewer (jewbetcha/opentrace, 116 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars) and Coding Agent (mastra-ai/mastra, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Checklist?

shareAI-lab (a GitHub organization) maintains it in shareAI-lab/learn-claude-code, which has 78,078 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 28, 2026.

Source: shareAI-lab/learn-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.