Analyzes Rails code quality, architecture, and patterns without modifying code.

MITAuto-check: notesDevelopment

Install Code Review

skills CLI
$ npx skills add ThibautBaissac/rails_ai_agents --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ThibautBaissac/rails_ai_agents code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
665
Token cost
~697 tokens
SKILL.md length
185 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Analyzes Rails code quality, architecture, and patterns without modifying code.

  • Works in 3 steps: Run Static Analysis → Analyze Code → Structured Feedback
  • The user wants a code review
  • SKILL.md covers Review Process, Anti-Pattern Examples and Review Checklist
  • Calls bundle

What it does

Code Review is an agent skill from ThibautBaissac/rails_ai_agents. Analyzes Rails code quality, architecture, and patterns without modifying code. Use when the user wants a code review, quality analysis, architecture audit, or when user mentions review, audit, code quality, anti-patterns, or SOLID principles. WHEN NOT: Actually implementing fixes (use specialist agents), writing new tests (use rspec-agent), or generating new features.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Backend development and Design patterns. The repository describes itself as: Specialized AI skills, agents, rules and hooks for modern Rails AI driven-development + Spec-Driven-Development kit + MCP. The licence is MIT.

When your agent uses it

  • The user wants a code review
  • Quality analysis
  • Architecture audit
  • User mentions review

Example prompts

  • “Use the code-review skill to analyz Rails code quality, architecture, and patterns without modifying code”
  • “/code-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Run Static Analysis
  2. Analyze Code
  3. Structured Feedback

What it can do on your machine

Read from SKILL.md and the folder at commit 03622f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 697 tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~697

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ThibautBaissac/rails_ai_agents at commit 03622f2, republished under its MIT licence (© ThibautBaissac). 185 words, ~697 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Analyzes Rails code quality, architecture, and patterns without modifying code. Use when the user wants a code review, quality analysis, architecture audit, or when user mentions review, audit, code quality, anti-patterns, or SOLID principles. WHEN NOT: Actually implementing fixes (use specialist agents), writing new tests (use rspec-agent), or generating new features.
allowed-tools
Read, Grep, Glob, Bash
context
fork
agent
general-purpose
model
sonnet
user-invocable
true
argument-hint
[file or directory path]

Code Review

You are an expert code reviewer specialized in Rails applications. You NEVER modify code — you only read, analyze, and report findings.

Review Process

Step 1: Run Static Analysis
bash
bin/brakeman
bin/bundler-audit
bundle exec rubocop
Step 2: Analyze Code

Read and evaluate against these focus areas:

  1. SOLID Principles — SRP violations, hard-coded conditionals, missing DI
  2. Rails Anti-Patterns — Fat controllers/models, N+1 queries, callback hell
  3. Security — Mass assignment, SQL injection, XSS, missing authorization
  4. Performance — Missing indexes, inefficient queries, caching opportunities
  5. Code Quality — Naming, duplication, method complexity, test coverage
Step 3: Structured Feedback

Format your review as:

  1. Summary: High-level overview
  2. Critical Issues (P0): Security, data loss risks
  3. Major Issues (P1): Performance, maintainability
  4. Minor Issues (P2-P3): Style, improvements
  5. Positive Observations: What was done well

For each issue: What → Where (file:line) → Why → How (code example)

Anti-Pattern Examples

Fat Controller → Service Object:

ruby
# Bad
class EntitiesController < ApplicationController
  def create
    @entity = Entity.new(entity_params)
    @entity.calculate_metrics
    @entity.send_notifications
    if @entity.save then ... end
  end
end

# Good
class EntitiesController < ApplicationController
  def create
    result = Entities::CreateService.call(entity_params)
  end
end

N+1 Query → Eager Loading:

ruby
# Bad
@entities.each { |e| e.user.name }

# Good
@entities = Entity.includes(:user)

Missing Authorization:

ruby
# Bad
@entity = Entity.find(params[:id])

# Good
@entity = Entity.find(params[:id])
authorize @entity

Review Checklist

  • Security: Brakeman clean
  • Dependencies: Bundler Audit clean
  • Style: RuboCop compliant
  • Architecture: SOLID principles respected
  • Patterns: No fat controllers/models
  • Performance: No N+1, indexes present
  • Authorization: Pundit policies used
  • Tests: Coverage adequate
  • Naming: Clear, consistent
  • Duplication: No repeated code

© ThibautBaissac, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-review of ThibautBaissac/rails_ai_agents.

Open the folder on GitHubat commit 03622f2

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillThibautBaissac/rails_ai_agents665—~697Automated safety check: NotesMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Architectural Code ReviewDonchitos/Claude-Code-Game-Studios26k—~3.5kAutomated safety check: PassMIT
Brooks Reviewhyhmrright/brooks-lint1.5k1 repos~430Automated safety check: PassMIT
Uncle Bob Craftsickn33/agentic-awesome-skills47k2 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Architectural Code Review

    Donchitos/Claude-Code-Game-Studios

    Performs an architectural review of code against coding standards, SOLID, testability and performance, and reports no verdict when the inputs are missing.

    26k GitHub stars~3.5k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Brooks Review

    hyhmrright/brooks-lint

    PR code review that surfaces decay risks, design smells, and maintainability issues with concrete Symptom → Source → Consequence → Remedy findings, drawing on twelve classic engineering books.

    1.5k GitHub starsUsed in 1 repo~430 tokens
    DevelopmentAuto-check passed
  • Uncle Bob Craft

    sickn33/agentic-awesome-skills

    A skill your agent uses when performing code review, writing or refactoring code, or discussing architecture; complements clean-code and does not replace project linter/formatter.

    47k GitHub starsUsed in 2 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Expert Code Reviewer

    GulajavaMinistudio/Mayukai-Theme

    Language-agnostic workflow for code reviews and security audits against Clean Code/SOLID principles, generating formal refactoring plans.

    139 GitHub stars~1.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from ThibautBaissac/rails_ai_agents

All 19 skills in this repo
  • Accessibility Review

    ThibautBaissac/rails_ai_agents

    Audits Rails application accessibility against WCAG 2.2 Level AA, detects violations with axe-core / Lighthouse / Pa11y, and reports remediation guidance for ERB views, ViewComponents, Stimulus…

    665 GitHub stars~2.9k tokensUpdated 4 mo ago
    Auto-check: notes
  • Action Cable Patterns

    ThibautBaissac/rails_ai_agents

    Implements real-time features with Action Cable and WebSockets.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Active Storage Setup

    ThibautBaissac/rails_ai_agents

    Configures Active Storage for file uploads with variants and direct uploads.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Authentication Flow

    ThibautBaissac/rails_ai_agents

    Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents.

    665 GitHub stars~1.9k tokensUpdated 4 mo ago
    Auto-check passed
  • Caching Strategies

    ThibautBaissac/rails_ai_agents

    Implements Rails caching patterns for performance optimization.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • I18n Patterns

    ThibautBaissac/rails_ai_agents

    Implements internationalization with Rails I18n for multi-language support.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

Analyzes Rails code quality, architecture, and patterns without modifying code. Code Review is an agent skill from ThibautBaissac/rails_ai_agents. Analyzes Rails code quality, architecture, and patterns without modifying code.

When should I use Code Review?

Code Review fits situations like: the user wants a code review; quality analysis; architecture audit; user mentions review.

How do I install Code Review in Claude Code?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in ThibautBaissac/rails_ai_agents) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in ThibautBaissac/rails_ai_agents) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ThibautBaissac/rails_ai_agents --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (bundle). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 697 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Skill (Rain-kl/OpenFlare, 288 stars), Architectural Code Review (Donchitos/Claude-Code-Game-Studios, 26k stars) and Brooks Review (hyhmrright/brooks-lint, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

ThibautBaissac (a GitHub user) maintains it in ThibautBaissac/rails_ai_agents, which has 665 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 1, 2026.

Source: ThibautBaissac/rails_ai_agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.