Agent skill

Code Review Checklist

by aiskillstore in aiskillstore/marketplace

Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks.

MITAuto-check passedDevelopment

Install Code Review Checklist

skills CLI
$ npx skills add aiskillstore/marketplace --skill code-review-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace code-review-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alapha888/code-review-checklist .claude/skills/code-review-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-checklist
GitHub stars
430
Used in
2 other repos
Token cost
~931 tokens
SKILL.md length
384 words
Files
2
Skills in repo
1,085
Repo updated
First seen
Licence
MIT

At a glance

Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks.

  • Works in 4 steps: Check the scope first: look at the diff… → Check axis by axis (order = priority) → Write the comments: fixed format —… → …
  • The user asks to review code
  • SKILL.md covers Workflow, Rules, Checklist (minimal executable… and Anti-patterns
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review Checklist is an agent skill from aiskillstore/marketplace. Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks. Use when the user asks to review code, a diff, or a pull request.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in Development, covering Code review, Plain language and style rules and Test coverage. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.

When your agent uses it

  • The user asks to review code
  • Tasks that involve Code review
  • Tasks that involve Plain language and style rules

Example prompts

  • “/code-review-checklist”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Check the scope first: look at the diff size. Over ~400 changed lines, ask for a split before reviewing — review quality on huge diffs…
  2. Check axis by axis (order = priority)
  3. Write the comments: fixed format — [axis] file:line problem → suggested fix. Only actionable suggestions; "could be optimized" is not one.
  4. Triage: Must fix (correctness / security) vs Should fix (readability / performance / tests). "Should fix" doesn't block the merge, but say…

What it can do on your machine

Read from SKILL.md and the folder at commit 4ac52da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Checklist loads about 931 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 384 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~931

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit 4ac52da, republished under its MIT licence (© aiskillstore). 384 words, ~931 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review-checklist
description
Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks. Use when the user asks to review code, a diff, or a pull request.
license
MIT

Code Review Checklist

One review answers a single question: "Will this code become someone else's problem within three months?" Walk the five axes in order; each axis gets pass / fail / N-A, and every failure must come with a concrete fix.

Workflow

  1. Check the scope first: look at the diff size. Over ~400 changed lines, ask for a split before reviewing — review quality on huge diffs always collapses.
  2. Check axis by axis (order = priority):
    • Correctness: edge cases (null, empty, zero, negative, oversized), concurrency/timing assumptions, error handling (are exceptions swallowed?). The only axis that can block a merge.
    • Security: is user input concatenated into SQL / shell commands / HTML; are secrets or tokens hard-coded; does logging leak sensitive data.
    • Readability: do names say what things are; does each function do one thing; are magic numbers named. Flag only what you can't understand — not "I'd write it differently."
    • Performance: repeated queries or recomputation inside loops; N+1 problems; avoidable large-object copies. No data-free performance speculation ("this might get slow" is not a comment).
    • Test coverage: does new logic have tests; do edge cases have cases. All-green tests with the critical path uncovered still get sent back.
  3. Write the comments: fixed format — [axis] file:line problem → suggested fix. Only actionable suggestions; "could be optimized" is not one.
  4. Triage: Must fix (correctness / security) vs Should fix (readability / performance / tests). "Should fix" doesn't block the merge, but say so explicitly.
Show full SKILL.md (149 more words)Show less

Rules

  • At most 10 comments per review. More than that means the code is too broken — send it back for a rewrite instead of grading 50 items.
  • No style policing: indentation, quotes, semicolons — that's the linter's job, not a human's.
  • Speak with the diff: every comment must cite a concrete line of code. A comment without a code reference is invalid.

Checklist (minimal executable version)

markdown
## Code review checklist

- [ ] Correctness: edge cases (null/0/negative/oversized) handled, exceptions not swallowed
- [ ] Correctness: concurrency/timing assumptions hold, no races
- [ ] Security: no SQL/shell/HTML injection points, no hard-coded secrets, no sensitive data in logs
- [ ] Readability: names are descriptive, functions have a single responsibility, no magic numbers
- [ ] Performance: no repeated queries/computation in loops, no N+1, no evidence-free performance worries
- [ ] Tests: new logic is covered, edge cases have cases
- [ ] Scope: diff ≤ ~400 lines, otherwise split first

Example review comments:

text
[Must fix][Correctness] order.py:87 empty order list triggers IndexError → guard for empty before taking [0]
[Should fix][Readability] order.py:92 magic number 86400 → name it SECONDS_PER_DAY

Anti-patterns

  • ❌ Drive-by LGTM: approving before reading the whole diff — the review is theater.
  • ❌ Style police: 18 of 20 comments about quotes and line breaks while a null-pointer dereference slips through.
  • ❌ Comments without code: "this logic looks off" — which logic? Which line? Unsaid means invalid.
  • ❌ Performance speculation: "this loop might be slow at scale" — a performance comment without data is noise.
  • ❌ Grading 50 items: when there are too many problems to list, the right move is "rewrite and resubmit", not playing teacher.

© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/alapha888/code-review-checklist of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 4ac52da

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Checklist this skillaiskillstore/marketplace4302 repos~931Automated safety check: PassMIT
Automated Test Planningtestdouble/han279—~6.7kAutomated safety check: PassMIT
Manual Test Planningtestdouble/han279—~2.9kAutomated safety check: PassMIT
Worktrunk Tend CI Guidancemax-sixty/worktrunk8.9k—~6.4kAutomated safety check: PassCustom licence
Graph-Based Change Reviewtirth8205/code-review-graph32k1 repos~331Automated safety check: PassMIT
Cyclomatic Complexitysaurabhkumar8112/cyclomatic-complexity-skill405—~761Automated safety check: PassApache-2.0

Similar skills

  • Produce a standalone test plan by analyzing code for test coverage gaps and edge cases.

    279 GitHub stars~6.7k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Manual Test Planning

    testdouble/han

    Produce a plain-language manual test plan from the context supplied to it — an executive summary, a high-level list of named tests, and a detail section per test with the steps a person follows by…

    279 GitHub stars~2.9k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Worktrunk Tend CI Guidance

    max-sixty/worktrunk

    Adds Worktrunk-specific rules to the tend CI workflows: Codecov polling, Rust test commands, labels and review criteria for pull requests handled in CI.

    8.9k GitHub stars~6.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Change Review

    tirth8205/code-review-graph

    Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.

    32k GitHub starsUsed in 1 repo~331 tokens
    DevelopmentAuto-check passed
  • Cyclomatic Complexity

    saurabhkumar8112/cyclomatic-complexity-skill

    Refactor code to reduce cyclomatic complexity so it stays readable, maintainable, and aligned with the long-term vision of the codebase, not just optimized for AI comprehension.

    405 GitHub stars~761 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Software Design Philosophy

    luoling8192/software-design-philosophy-skill

    Software design philosophy guide based on John Ousterhout's "A Philosophy of Software Design." Use this skill during: code reviews, architecture discussions, API design, module decomposition…

    344 GitHub stars~3.4k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from aiskillstore/marketplace

All 1,085 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Categories

Questions about Code Review Checklist

What does Code Review Checklist do?

Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks. Code Review Checklist is an agent skill from aiskillstore/marketplace. Five-axis code review checklist (correctness, security, readability, performance, test coverage) producing actionable comments instead of style nitpicks.

When should I use Code Review Checklist?

Code Review Checklist fits situations like: the user asks to review code; tasks that involve Code review; tasks that involve Plain language and style rules.

How do I install Code Review Checklist in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill code-review-checklist -a claude-code`. Or copy the skill folder (skills/alapha888/code-review-checklist in aiskillstore/marketplace) into .claude/skills/code-review-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Checklist in Codex?

Run `npx skills add aiskillstore/marketplace --skill code-review-checklist -a codex`. Or copy the skill folder (skills/alapha888/code-review-checklist in aiskillstore/marketplace) into .agents/skills/code-review-checklist in your project. Codex loads it when a task matches its description.

Can I use Code Review Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill code-review-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-checklist, .gemini/skills/code-review-checklist, .github/skills/code-review-checklist and .opencode/skills/code-review-checklist in your project.

What does Code Review Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review Checklist is instructions for the agent only.

Does Code Review Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Checklist use?

Code Review Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Checklist use?

About 931 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Checklist?

Skills that share tags, products or a category with Code Review Checklist: Automated Test Planning (testdouble/han, 279 stars), Manual Test Planning (testdouble/han, 279 stars), Worktrunk Tend CI Guidance (max-sixty/worktrunk, 8.9k stars) and Graph-Based Change Review (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Checklist?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,085 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.