Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests.

MITAuto-check passedDevelopment

Install Java Code Review

skills CLI
$ npx skills add sivaprasadreddy/sivalabs-agent-skills --skill java-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sivaprasadreddy/sivalabs-agent-skills java-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sivaprasadreddy/sivalabs-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/java-code-review .claude/skills/java-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
java-code-review
GitHub stars
188
Token cost
~1.2k tokens
SKILL.md length
520 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests.

  • Works in 4 steps: If the user explicitly specifies files,… → Otherwise inspect the git worktree and… → Include only Java and Java-adjacent… → …
  • Explicitly names files
  • SKILL.md covers Establish the review scope, Review for, Validate findings and Write review.md, plus 1 more section
  • Calls git

What it does

Java Code Review is an agent skill from sivaprasadreddy/sivalabs-agent-skills. Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests. By default review files modified in git; when the user explicitly names files, classes, packages, or a diff, review that scope instead. Generate a detailed review.md report with actionable comments and fixes.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. It works with Java and Git. The repository describes itself as: Spring Boot skills for AI coding agents. The licence is MIT.

When your agent uses it

  • Explicitly names files
  • Review that scope instead

Example prompts

  • “/java-code-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. If the user explicitly specifies files, classes, packages, commits, or a
  2. Otherwise inspect the git worktree and review modified, added, or renamed
  3. Include only Java and Java-adjacent files relevant to behavior (for
  4. Read enough surrounding code, callers, tests, configuration, and interfaces

What it can do on your machine

Read from SKILL.md and the folder at commit e9f9861. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Java Code Review loads about 1.2k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 520 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sivaprasadreddy/sivalabs-agent-skills at commit e9f9861, republished under its MIT licence (© sivaprasadreddy). 520 words, ~1,210 tokens.

Download SKILL.mdSave it as .claude/skills/java-code-review/SKILL.md (or your agent's skills folder).
name
java-code-review
description
Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests. By default review files modified in git; when the user explicitly names files, classes, packages, or a diff, review that scope instead. Generate a detailed review.md report with actionable comments and fixes.

Java Code Review

Perform a focused, evidence-based review of Java code and write the findings to review.md in the repository root unless the user specifies another location. This skill reviews code; do not modify production code unless the user explicitly asks for fixes.

Establish the review scope

  1. If the user explicitly specifies files, classes, packages, commits, or a diff, use that scope and do not silently broaden it.
  2. Otherwise inspect the git worktree and review modified, added, or renamed files. Use git status --short and the relevant git diff (including staged changes when present). For renamed files, review the resulting file and the meaningful diff.
  3. Include only Java and Java-adjacent files relevant to behavior (for example, tests, SQL migrations, configuration, or API schemas) when they affect the reviewed Java code. State the selected scope in the report.
  4. Read enough surrounding code, callers, tests, configuration, and interfaces to validate each finding. Do not report a concern based only on a name or a generic best practice.

Review for

  • Potential bugs: incorrect conditions, null/empty handling, state or transaction errors, exception handling, resource leaks, concurrency issues, security or authorization gaps, API/serialization mismatches, persistence mistakes, and boundary cases.
  • Duplicate code: repeated logic, copy-pasted branches, duplicated mappings/validation, and abstractions that would reduce meaningful drift.
  • Needs improvement: unclear or brittle design, excessive coupling, misleading names, avoidable complexity, test gaps, performance concerns, and violations of established project conventions.

Prioritize correctness and impact over style. Do not flag formatting or an opinionated alternative unless it creates a concrete maintenance, reliability, security, or performance problem. Distinguish confirmed issues from risks or questions, and avoid speculative findings.

Validate findings

For every finding, trace the relevant control flow and data flow. Check nearby tests and, when practical, run the narrowest useful test, compile, static analysis, or reproduction command. Do not change files to make validation pass. If validation cannot be run, say why. Check whether a suspected issue is already handled by a caller, framework contract, annotation, or configuration.

Show full SKILL.md (188 more words)Show less

Write review.md

Before writing, check whether the requested output file already exists.

  • If it exists, ask the user whether to overwrite it or use a new filename; do not overwrite without that choice.
  • If the user chooses a new filename, use exactly that filename (within the repository or requested output location).
  • If no report exists, create review.md.

The report must be self-contained and include:

markdown
# Java Code Review

## Scope
<!-- files/diff reviewed, review date, and validation performed -->

## Summary
<!-- concise overall assessment and finding counts by severity -->

## Findings

### [SEVERITY] Short title
- **Location:** `path/to/File.java:line`
- **Category:** Bug | Duplicate code | Improvement
- **Confidence:** High | Medium | Low

**Problem**
Explain the concrete behavior and why it matters, citing the relevant code.

**Suggested fix**
Give a specific implementation approach, including edge cases and tests to
add or update. Do not merely say “refactor” or “add validation.”

## Positive observations
<!-- optional; mention useful safeguards or clear design choices -->

## Validation
<!-- commands run and their outcomes, or why validation was unavailable -->

Use severity consistently: Blocker (unsafe or clearly broken), High (likely production failure or serious security/data issue), Medium (meaningful bug or maintainability risk), and Low (minor but actionable). Order findings by severity, then by file and line. Include one finding per distinct problem, avoid duplicates, and use precise line references that still make sense in the reviewed version. If no findings are found, say so clearly and still include scope, validation, and positive observations.

Final response

Tell the user that the report was created and link to the generated file. Give the finding count and briefly call out any Blocker or High findings. If the report could not be created because an existing file needs a choice, ask the overwrite/new-filename question and stop before writing.

© sivaprasadreddy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/java-code-review of sivaprasadreddy/sivalabs-agent-skills.

Open the folder on GitHubat commit e9f9861

Compare with similar skills

Java Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Java Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Java Code Review this skillsivaprasadreddy/sivalabs-agent-skills188—~1.2kAutomated safety check: PassMIT
Git History Bug Auditben-manes/caffeine18k—~3.3kAutomated safety check: PassApache-2.0
Parallel Adversarial Change Reviewben-manes/caffeine18k—~1.9kAutomated safety check: NotesApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Runs three parallel reviewers on a diff or branch, one blind, one design-aware and one matching past bug patterns, then triages their findings.

    18k GitHub stars~1.9k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline…

    9.5k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed

More from sivaprasadreddy/sivalabs-agent-skills

  • Jspecify Skill

    sivaprasadreddy/sivalabs-agent-skills

    A skill your agent uses when asked to perform any of the following actions in a Java project: - To add jspecify support - To prevent NullPointerExceptions - To better handle Nullability This skill…

    188 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check passed
  • Apply Renovate PRs

    sivaprasadreddy/sivalabs-agent-skills

    Apply the changes from all open Renovate bot pull requests of a GitHub repository into the local working tree.

    188 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check passed
  • Progen

    sivaprasadreddy/sivalabs-agent-skills

    A skill your agent uses when the user wants to create/generate/scaffold a new Spring Boot project (Maven or Gradle, REST API / Web App / Spring Boot + Angular full stack).

    188 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check: notes
  • Spring Modulith Verifier

    sivaprasadreddy/sivalabs-agent-skills

    Verifies whether code follows Spring Modulith code structure or not.

    188 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Spring Boot Skill

    sivaprasadreddy/sivalabs-agent-skills

    Build Spring Boot 4.x applications following the best practices.

    188 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Java Code Review

What does Java Code Review do?

Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests. Java Code Review is an agent skill from sivaprasadreddy/sivalabs-agent-skills. Review Java code for bugs, duplicate code, correctness risks, maintainability improvements, and missing tests.

When should I use Java Code Review?

Java Code Review fits situations like: explicitly names files; review that scope instead.

How do I install Java Code Review in Claude Code?

Run `npx skills add sivaprasadreddy/sivalabs-agent-skills --skill java-code-review -a claude-code`. Or copy the skill folder (skills/java-code-review in sivaprasadreddy/sivalabs-agent-skills) into .claude/skills/java-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Java Code Review in Codex?

Run `npx skills add sivaprasadreddy/sivalabs-agent-skills --skill java-code-review -a codex`. Or copy the skill folder (skills/java-code-review in sivaprasadreddy/sivalabs-agent-skills) into .agents/skills/java-code-review in your project. Codex loads it when a task matches its description.

Can I use Java Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sivaprasadreddy/sivalabs-agent-skills --skill java-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/java-code-review, .gemini/skills/java-code-review, .github/skills/java-code-review and .opencode/skills/java-code-review in your project.

What does Java Code Review need to run?

Going by SKILL.md and its folder, Java Code Review needs the command-line tools its instructions call (git).

Does Java Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Java Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Java Code Review use?

Java Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Java Code Review use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Java Code Review?

Skills that share tags, products or a category with Java Code Review: Git History Bug Audit (ben-manes/caffeine, 18k stars), Parallel Adversarial Change Review (ben-manes/caffeine, 18k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Java Code Review?

sivaprasadreddy (a GitHub user) maintains it in sivaprasadreddy/sivalabs-agent-skills, which has 188 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: sivaprasadreddy/sivalabs-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.