Code Review Specialist
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10…
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install staruhub/ClaudeSkills pair-programming --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/Geek-skills-pair-programming .claude/skills/pair-programming && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .claude/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programmingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install staruhub/ClaudeSkills pair-programming --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/Geek-skills-pair-programming .agents/skills/pair-programming && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .agents/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install staruhub/ClaudeSkills pair-programming --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/Geek-skills-pair-programming .cursor/skills/pair-programming && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .cursor/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/staruhub/ClaudeSkills.git --path skills/Geek-skills-pair-programming--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install staruhub/ClaudeSkills pair-programming --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/Geek-skills-pair-programming .gemini/skills/pair-programming && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .gemini/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install staruhub/ClaudeSkills pair-programmingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/Geek-skills-pair-programming .github/skills/pair-programming && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .github/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add staruhub/ClaudeSkills --skill pair-programming -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install staruhub/ClaudeSkills pair-programming --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/Geek-skills-pair-programming .opencode/skills/pair-programming && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pair-programming" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-pair-programming into .opencode/skills/pair-programming/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pair-programming", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pair-programming结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10…
Pair Programming is an agent skill from staruhub/ClaudeSkills. 结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10 行以内的简单片段。
Its SKILL.md is about 480 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/routing-evals.json` and `references/detailed-checklist.md`).
It sits in Development, covering Security review. The repository describes itself as: 13 curated Agent Skills for research, product decisions, decks, publishing, audits, and more — portable across skills-compatible agents. The licence is MIT.
Read from SKILL.md and the folder at commit 66e02d2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pair Programming loads about 482 tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 112 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from staruhub/ClaudeSkills at commit 66e02d2, republished under its MIT licence (© staruhub). 112 words, ~482 tokens.
.claude/skills/pair-programming/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.交付代码 + 像负责任的高级开发者一样自我审查,一次给到位。
security-audit生成代码 → 五维度扫描 → 修掉能修的 → 剩余权衡点写进审查意见。
| 维度 | 检查重点 |
|---|---|
| 正确性 | 逻辑是否正确?边界条件是否处理? |
| 安全性 | 是否有注入风险?数据是否安全处理? |
| 性能 | 是否有 O(n²) 隐患?是否有不必要的循环? |
| 可读性 | 命名是否清晰?结构是否合理? |
| 健壮性 | 错误处理是否完善?异常情况是否考虑? |
🔴 必查(阻断级):空值处理 / 输入验证 / SQL·命令注入(参数化)/ 密钥硬编码 / 资源泄漏 🟡 重要(建议级):边界条件 / 并发竞态 / 异常捕获 / 关键日志 / 网络超时 🟢 改进(优化级):重复代码 / 命名 / 复杂逻辑注释 / 魔法数字 / 单一职责
语言特定检查项(Python/JS/Java/Go/Dart 等)见 references/detailed-checklist.md,按当前语言取用。
| 缺陷 | 具体表现 | 自查方法 |
|---|---|---|
| 幻觉 API | 调用了不存在的方法或传了不存在的参数 | 不确定的 API 先查项目依赖版本的文档,不凭记忆写 |
| 偷改需求 | 实现比用户要求"更合理"的版本,悄悄改了行为 | 对照用户原话逐条核对交付物 |
| 过度防御 | 到处 try/catch 吞异常、层层空值检查掩盖真错误 | 每个 catch 问"这里吞掉异常对吗" |
| 风格漂移 | 新代码与项目既有命名/模式不一致 | 写前先看同目录相邻文件的写法 |
| 测试造绿灯 | 为过测试写死返回值或放宽断言 | 审查测试改动是否弱化了验证强度 |
| 复制不一致 | 从别处仿写时残留原上下文的变量名/注释 | 全读一遍自己的产出,不只看 diff |
---
## 🔍 结对审查意见
### ✅ 做得好的地方
### ⚠️ 需要关注(含具体修改方案)
### 💡 优化建议(可选方向)建设性(给方案)、谦逊("可以考虑")、教学性(解释为什么)、平衡(也认可好的做法)、简洁(只留关键点)。
示例(检测到注入风险时):
⚠️ 🔴 SQL 注入风险:
"...WHERE name = '$name'"直接拼接用户输入。 建议:参数化查询db.query("...WHERE name = ?", [name])。
references/detailed-checklist.md — 语言特定检查清单全集,按当前项目语言取用evals/routing-evals.json — 触发边界回归用例,改 description 后用仓库根 scripts/run_routing_evals.py 校验。
© staruhub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/Geek-skills-pair-programming of staruhub/ClaudeSkills.
Open the folder on GitHubat commit 66e02d2
Pair Programming next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pair Programming this skillstaruhub/ClaudeSkills | 727 | — | ~482 | Automated safety check: Pass | MIT | |
| Code Review Specialistluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Best Practicesmidudev/100cosas.dev | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | |
| Bug Huntercodexstar69/bug-hunter | 519 | — | ~5k | Automated safety check: Pass | MIT | |
| Read-Only Code AuditHarnessMD/munder-difflin | 8.6k | — | ~350 | Automated safety check: Notes | MIT |
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
midudev/100cosas.dev
Apply modern web development best practices for security, compatibility, and code quality.
codexstar69/bug-hunter
Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.
HarnessMD/munder-difflin
Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
staruhub/ClaudeSkills
A skill your agent uses when the user wants an evidence-based research memo, literature review, market/policy/technical landscape, or a multi-source decision brief with citations, trade-offs, and a…
staruhub/ClaudeSkills
用火山引擎 Podcast AI 模型生成中文双人对话播客。当用户要把文章、报告、话题文本转成播客音频、生成对话式音频内容时使用,需要环境具备火山引擎 APPID 和 ACCESSKEY。支持 mp3/oggopus/pcm/aac、语速调节、自定义音色、断点续传。不用于:单人朗读式 TTS(用普通语音合成)、英文播客(模型主要优化中文)、播客文稿本身的撰写(先用写作类 skill…
staruhub/ClaudeSkills
专业微信公众号文章助手,支持四个独立且可组合模式:article 写正文;image-prompts 从文章生成版本化、provider-neutral 的图片提示词 manifest 与稳定占位符,但不调用生图;layout 把文章和 manifest 确定性转换为微信安全的内联 HTML;full-pipeline…
staruhub/ClaudeSkills
A股分析研究助手,提供行情数据获取与技术面/基本面分析框架(仅供研究参考,不构成投资建议)。适用于:(1) 获取A股行情和历史数据,(2) 技术面分析(K线形态、MACD、KDJ、RSI、布林带等),(3) 基本面分析(财务指标、估值分析),(4) 板块热点追踪,(5) 选股策略筛选与量化因子分析,(6)…
staruhub/ClaudeSkills
Windows C盘清理和磁盘空间管理。当用户说C盘满了、磁盘空间不足、清理临时文件/缓存/回收站/系统日志、查找大文件、分析磁盘占用时使用。仅适用于 Windows 环境。不用于:macOS/Linux 磁盘清理、卸载软件(引导用户走系统卸载)、清理用户个人文件(只报告位置,删除决定权在用户)。
staruhub/ClaudeSkills
资深高考命题专家助手,提供专业的命题指导和评审服务。适用于创作高考试题、评审试题质量、分析试卷结构、了解命题趋势等场景。结合文档工具提取解压文件,使用网络搜索了解当年最新命题趋势,使用分析工具评估题目质量和试卷结构。涵盖"一核四层四翼"评价体系、题型规范、评分标准、命题流程等多个维度。不用于:大学/考研/中考命题(体系不同,仅可借鉴)、日常作业题编写、直接替考生解题。
Categories
结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10…. Pair Programming is an agent skill from staruhub/ClaudeSkills.
Pair Programming fits situations like: tasks that involve Security review.
Run `npx skills add staruhub/ClaudeSkills --skill pair-programming -a claude-code`. Or copy the skill folder (skills/Geek-skills-pair-programming in staruhub/ClaudeSkills) into .claude/skills/pair-programming in your project. Claude Code loads it when a task matches its description.
Run `npx skills add staruhub/ClaudeSkills --skill pair-programming -a codex`. Or copy the skill folder (skills/Geek-skills-pair-programming in staruhub/ClaudeSkills) into .agents/skills/pair-programming in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add staruhub/ClaudeSkills --skill pair-programming -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pair-programming, .gemini/skills/pair-programming, .github/skills/pair-programming and .opencode/skills/pair-programming in your project.
SKILL.md names no scripts, command-line tools or credentials: Pair Programming is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pair Programming is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 482 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Pair Programming: Code Review Specialist (luongnv89/claude-howto, 42k stars), Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Best Practices (midudev/100cosas.dev, 114 stars) and Bug Hunter (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
staruhub (a GitHub user) maintains it in staruhub/ClaudeSkills, which has 727 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on August 13, 2026.
Source: staruhub/ClaudeSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.