Code Reviewer
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shareAI-lab/learn-claude-code code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shareAI-lab/learn-claude-code code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/code-review .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shareAI-lab/learn-claude-code code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/code-review .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/shareAI-lab/learn-claude-code.git --path skills/code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shareAI-lab/learn-claude-code code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/code-review .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shareAI-lab/learn-claude-code code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/code-review .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shareAI-lab/learn-claude-code --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shareAI-lab/learn-claude-code code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shareAI-lab/learn-claude-code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/code-review .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/shareAI-lab/learn-claude-code/tree/main/skills/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewReviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
The agent works through five groups of checks. Security covers injection, authentication and authorization flaws, data exposure, weak cryptography and vulnerable dependencies, with `npm audit` and `pip-audit` suggested for quick scans. Correctness looks at logic errors, race conditions, resource leaks, error handling and type safety. Performance looks for N+1 queries, memory problems, blocking calls in async code, inefficient algorithms and missing caching.
Maintainability checks naming, complexity (functions over 50 lines or nesting deeper than three levels), duplication, dead code and comments, and testing checks coverage of critical paths, edge cases, mocking and meaningful assertions. Results go into a markdown template headed by the file or component name with a summary section. The skill also lists patterns to flag in Python and JavaScript or TypeScript, such as SQL built by string formatting and prototype pollution through `Object.assign`, plus git commands for viewing recent changes.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ce8f9f1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmgitpipcargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, git and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Checklist loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 258 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from shareAI-lab/learn-claude-code at commit ce8f9f1, republished under its MIT licence (© shareAI-lab). 258 words, ~1,067 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder).You now have expertise in conducting comprehensive code reviews. Follow this structured approach:
Check for:
npm audit, pip-audit)# Quick security scans
npm audit # Node.js
pip-audit # Python
cargo audit # Rust
grep -r "password\|secret\|api_key" --include="*.py" --include="*.js"Check for:
Check for:
Check for:
Check for:
## Code Review: [file/component name]
### Summary
[1-2 sentence overview]
### Critical Issues
1. **[Issue]** (line X): [Description]
- Impact: [What could go wrong]
- Fix: [Suggested solution]
### Improvements
1. **[Suggestion]** (line X): [Description]
### Positive Notes
- [What was done well]
### Verdict
[ ] Ready to merge
[ ] Needs minor changes
[ ] Needs major revision# Bad: SQL injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good:
cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,))
# Bad: Command injection
os.system(f"ls {user_input}")
# Good:
subprocess.run(["ls", user_input], check=True)
# Bad: Mutable default argument
def append(item, lst=[]): # Bug: shared mutable default
# Good:
def append(item, lst=None):
lst = lst or []// Bad: Prototype pollution
Object.assign(target, userInput)
// Good:
Object.assign(target, sanitize(userInput))
// Bad: eval usage
eval(userCode)
// Good: Never use eval with user input
// Bad: Callback hell
getData(x => process(x, y => save(y, z => done(z))))
// Good:
const data = await getData();
const processed = await process(data);
await save(processed);# Show recent changes
git diff HEAD~5 --stat
git log --oneline -10
# Find potential issues
grep -rn "TODO\|FIXME\|HACK\|XXX" .
grep -rn "password\|secret\|token" . --include="*.py"
# Check complexity (Python)
pip install radon && radon cc . -a
# Check dependencies
npm outdated # Node
pip list --outdated # Python© shareAI-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/code-review of shareAI-lab/learn-claude-code.
Open the folder on GitHubat commit ce8f9f1
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in shareAI-lab/learn-claude-code, which our catalogue first saw on October 7, 2026.
Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Checklist this skillshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Code Reviewerjewbetcha/opentrace | 116 | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Code Review Specialistluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT | |
| Cross-Language Coding Standardszereight/gitlab-mcp | 2k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Coding Agentmastra-ai/mastra | 29k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Tbdjlevy/strif | 131 | — | ~3.5k | Automated safety check: Pass | MIT |
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
zereight/gitlab-mcp
Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.
mastra-ai/mastra
Authoring playbook for building agents that write, edit, review, or refactor code.
jlevy/strif
Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.
Prorise-cool/Claude-Code-Multi-Agent
Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.
shareAI-lab/learn-claude-code
Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
shareAI-lab/learn-claude-code
Gives the agent command-line and Python recipes for reading, creating, merging and splitting PDF files, plus tips for large and scanned documents.
Works with
Categories
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format. The agent works through five groups of checks. Security covers injection, authentication and authorization flaws, data exposure, weak cryptography and vulnerable dependencies, with `npm audit` and `pip-audit` suggested for quick scans.
Code Review Checklist fits situations like: reviewing a pull request before merge; auditing a module for security and performance problems; checking a change for missing tests and edge cases.
Run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a claude-code`. Or copy the skill folder (skills/code-review in shareAI-lab/learn-claude-code) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a codex`. Or copy the skill folder (skills/code-review in shareAI-lab/learn-claude-code) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shareAI-lab/learn-claude-code --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
Going by SKILL.md and its folder, Code Review Checklist needs the command-line tools its instructions call (npm, git, pip and cargo).
SKILL.md contains no URLs. Its commands use npm, git and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Checklist: Code Reviewer (jewbetcha/opentrace, 116 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars) and Coding Agent (mastra-ai/mastra, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shareAI-lab (a GitHub organization) maintains it in shareAI-lab/learn-claude-code, which has 78,078 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 28, 2026.
Source: shareAI-lab/learn-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.