Agent skill

Code Review Checklist

by xenitV1 in xenitV1/Antigravity-Workflows

Code review guidelines covering code quality, security, and best practices.

MITAuto-check passedDevelopment

Install Code Review Checklist

skills CLI
$ npx skills add xenitV1/Antigravity-Workflows --skill code-review-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xenitV1/Antigravity-Workflows code-review-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-review-checklist .claude/skills/code-review-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review-checklist
GitHub stars
130
Token cost
~635 tokens
SKILL.md length
164 words
Files
1
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

Code review guidelines covering code quality, security, and best practices.

  • Tasks that involve Code review
  • SKILL.md covers Quick Review Checklist, AI & LLM Review Patterns (2025), Anti-Patterns to Flag and Review Comments Guide
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Code quality

What it does

Code Review Checklist is an agent skill from xenitV1/Antigravity-Workflows. Code review guidelines covering code quality, security, and best practices.

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Code quality. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Code quality

Example prompts

  • “/code-review-checklist”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit f0a1fa7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review Checklist loads about 635 tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~635

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xenitV1/Antigravity-Workflows at commit f0a1fa7, republished under its MIT licence (© xenitV1). 164 words, ~635 tokens.

Download SKILL.mdSave it as .claude/skills/code-review-checklist/SKILL.md (or your agent's skills folder).
name
code-review-checklist
description
Code review guidelines covering code quality, security, and best practices.
allowed-tools
Read, Glob, Grep

Code Review Checklist

Quick Review Checklist

Correctness
  • Code does what it's supposed to do
  • Edge cases handled
  • Error handling in place
  • No obvious bugs
Security
  • Input validated and sanitized
  • No SQL/NoSQL injection vulnerabilities
  • No XSS or CSRF vulnerabilities
  • No hardcoded secrets or sensitive credentials
  • AI-Specific: Protection against Prompt Injection (if applicable)
  • AI-Specific: Outputs are sanitized before being used in critical sinks
Performance
  • No N+1 queries
  • No unnecessary loops
  • Appropriate caching
  • Bundle size impact considered
Code Quality
  • Clear naming
  • DRY - no duplicate code
  • SOLID principles followed
  • Appropriate abstraction level
Testing
  • Unit tests for new code
  • Edge cases tested
  • Tests readable and maintainable
Documentation
  • Complex logic commented
  • Public APIs documented
  • README updated if needed

AI & LLM Review Patterns (2025)

Logic & Hallucinations
  • Chain of Thought: Does the logic follow a verifiable path?
  • Edge Cases: Did the AI account for empty states, timeouts, and partial failures?
  • External State: Is the code making safe assumptions about file systems or networks?
Prompt Engineering Review
markdown
// ❌ Vague prompt in code
const response = await ai.generate(userInput);

// ✅ Structured & Safe prompt
const response = await ai.generate({
  system: "You are a specialized parser...",
  input: sanitize(userInput),
  schema: ResponseSchema
});

Anti-Patterns to Flag

typescript
// ❌ Magic numbers
if (status === 3) { ... }

// ✅ Named constants
if (status === Status.ACTIVE) { ... }

// ❌ Deep nesting
if (a) { if (b) { if (c) { ... } } }

// ✅ Early returns
if (!a) return;
if (!b) return;
if (!c) return;
// do work

// ❌ Long functions (100+ lines)
// ✅ Small, focused functions

// ❌ any type
const data: any = ...

// ✅ Proper types
const data: UserData = ...

Review Comments Guide

// Blocking issues use 🔴
🔴 BLOCKING: SQL injection vulnerability here

// Important suggestions use 🟡
🟡 SUGGESTION: Consider using useMemo for performance

// Minor nits use 🟢
🟢 NIT: Prefer const over let for immutable variable

// Questions use ❓
❓ QUESTION: What happens if user is null here?

© xenitV1, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-review-checklist of xenitV1/Antigravity-Workflows.

Open the folder on GitHubat commit f0a1fa7

Compare with similar skills

Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review Checklist this skillxenitV1/Antigravity-Workflows130—~635Automated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Skill Doli Code ReviewDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT
Dignified Python Standardsdocling-project/docling69k—~1.5kAutomated safety check: PassApache-2.0
Clean Code GuardamElnagdy/guard-skills1.3k2 repos~4.3kAutomated safety check: PassMIT
Archify Reviewtt-a1i/archify79k—~415Automated safety check: PassMIT

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Skill Doli Code Review

    Dolibarr/dolibarr

    Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

    7.7k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    69k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Clean Code Guard

    amElnagdy/guard-skills

    Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.

    1.3k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Archify Review

    tt-a1i/archify

    Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…

    79k GitHub stars~415 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes

More from xenitV1/Antigravity-Workflows

All 42 skills in this repo
  • Bash Linux

    xenitV1/Antigravity-Workflows

    Bash/Linux terminal patterns. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 9 repos~1k tokens
    Auto-check: notes
  • Mobile Design

    xenitV1/Antigravity-Workflows

    Mobile-first design thinking and decision-making for iOS and Android apps.

    130 GitHub starsUsed in 2 repos~3.7k tokens
    Auto-check: notes
  • Parallel Agents

    xenitV1/Antigravity-Workflows

    Native multi-agent orchestration using Claude Code's Agent Tool.

    130 GitHub starsUsed in 9 repos~1.3k tokens
    Auto-check passed
  • Behavioral Modes

    xenitV1/Antigravity-Workflows

    AI operational modes (brainstorm, implement, debug, review, teach, ship, orchestrate).

    130 GitHub starsUsed in 8 repos~1.3k tokens
    Auto-check passed
  • Performance Profiling

    xenitV1/Antigravity-Workflows

    Performance profiling principles. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 8 repos~772 tokens
    Auto-check: notes
  • Plan Writing

    xenitV1/Antigravity-Workflows

    Structured task planning with clear breakdowns, dependencies, and verification criteria.

    130 GitHub starsUsed in 8 repos~994 tokens
    Auto-check passed

Categories

Questions about Code Review Checklist

What does Code Review Checklist do?

Code review guidelines covering code quality, security, and best practices. Code Review Checklist is an agent skill from xenitV1/Antigravity-Workflows. Code review guidelines covering code quality, security, and best practices.

When should I use Code Review Checklist?

Code Review Checklist fits situations like: tasks that involve Code review; tasks that involve Code quality.

How do I install Code Review Checklist in Claude Code?

Run `npx skills add xenitV1/Antigravity-Workflows --skill code-review-checklist -a claude-code`. Or copy the skill folder (skills/code-review-checklist in xenitV1/Antigravity-Workflows) into .claude/skills/code-review-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Code Review Checklist in Codex?

Run `npx skills add xenitV1/Antigravity-Workflows --skill code-review-checklist -a codex`. Or copy the skill folder (skills/code-review-checklist in xenitV1/Antigravity-Workflows) into .agents/skills/code-review-checklist in your project. Codex loads it when a task matches its description.

Can I use Code Review Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xenitV1/Antigravity-Workflows --skill code-review-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-checklist, .gemini/skills/code-review-checklist, .github/skills/code-review-checklist and .opencode/skills/code-review-checklist in your project.

What does Code Review Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review Checklist is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep.

Does Code Review Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review Checklist use?

Code Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review Checklist use?

About 635 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review Checklist?

Skills that share tags, products or a category with Code Review Checklist: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Skill Doli Code Review (Dolibarr/dolibarr, 7.7k stars), Dignified Python Standards (docling-project/docling, 69k stars) and Clean Code Guard (amElnagdy/guard-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review Checklist?

xenitV1 (a GitHub user) maintains it in xenitV1/Antigravity-Workflows, which has 130 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on January 14, 2026.

Source: xenitV1/Antigravity-Workflows on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.