Agent skill

Code Review

by ziggy42 in ziggy42/epsilon

A skill your agent uses when the user asks for a code review.

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add ziggy42/epsilon --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ziggy42/epsilon code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ziggy42/epsilon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
439
Token cost
~1.7k tokens
SKILL.md length
796 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks for a code review.

  • Works in 7 steps: Preparation → Build & Test Verification → Performance Verification → …
  • The user asks for a code review
  • SKILL.md covers Overview and Procedure
  • Calls make, git and go; reaches apache.org

What it does

Code Review is an agent skill from ziggy42/epsilon. Use this skill when the user asks for a code review. It automates checks and analysis.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. It works with WebAssembly, Go and Git. The repository describes itself as: A WASM virtual machine written in Go with 0 dependencies. The licence is Apache-2.0.

When your agent uses it

  • The user asks for a code review
  • Tasks that involve Code review

Example prompts

  • “/code-review”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Preparation
  2. Build & Test Verification
  3. Performance Verification
  4. Dependency Check
  5. License Header Check
  6. Code Review
  7. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 64a2225. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • git
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • apache.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 1.7k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 796 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ziggy42/epsilon at commit 64a2225, republished under its Apache-2.0 licence (© ziggy42). 796 words, ~1,657 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Use this skill when the user asks for a code review. It automates checks and analysis.

Code Review

Overview

This skill provides a comprehensive code review process for the current branch. It verifies the code builds and passes tests across platforms, checks for performance regressions, and reviews the diff for bugs, improvements, and adherence to project standards.

Procedure

1. Preparation
  1. Check Branch: Run git branch --show-current. If the output is main, inform the user that the current branch is main and reviews on main are not supported yet.
  2. Check Remote: Run git fetch origin main. This ensures origin/main is up-to-date for accurate comparison.
  3. Get Branch Point: Determine the merge base with git merge-base origin/main HEAD. Store this for later use.
2. Build & Test Verification
  1. Build for All Platforms:
    • Run make build-all (covers Linux, Darwin, and Windows cross-compile, regardless of host OS).
    • Cleanup afterwards: make clean.
    • If any build fails, stop and report the error.
  2. Lint & Format:
    • Run make fmt. If any files are modified, stop and report the error.
    • Run make fmt-md. If any files are modified, stop and report the error (Markdown is not formatted).
    • Run make vet. If any issues are found, stop and report the error.
  3. Run All Tests:
    • Run make test to execute Go tests (unit + spec).
    • If tests fail, stop and report the errors.
  4. Run WASI Tests:
    • Run make test-wasi to verify the WASI Preview 1 implementation.
    • If WASI tests fail, stop and report the errors.
3. Performance Verification
  1. Compare Benchmarks: Run make bench-compare TARGET=. to compare performance against the main branch (the default base). NOTE: This can take several minutes as it runs the benchmark suite twice.
  2. Review Results: Present the benchmark results to the user. Flag any regressions where:
    • Time (ns/op) increased by more than 5%.
    • Memory (B/op) increased.
    • Allocations (allocs/op) increased.
4. Dependency Check
  1. Detect New Dependencies: Run git diff origin/main..HEAD -- go.mod go.sum.
  2. Verify Module Consistency:
    • Run go mod tidy.
    • Run git diff --name-only go.mod go.sum.
    • If there are changes, stop and report that go mod tidy needs to be run.
  3. Report Changes: If there are any changes to go.mod or go.sum:
    • CRITICAL: This project is pure Go with no CGo. New dependencies are strongly discouraged.
    • Report exactly what dependencies were added or modified.
    • Ask the user to confirm the dependency changes are intentional.
5. License Header Check
  1. Find New Files: Run git diff --name-status origin/main..HEAD | grep '^A' to list all newly added files.

  2. Check Headers: For each new source file (.go, .py, .yml, etc.), verify it contains the proper license header:

    // Copyright [Year] Google LLC
    //
    // Licensed under the Apache License, Version 2.0 (the "License");
    // you may not use this file except in compliance with the License.
    // You may obtain a copy of the License at
    //
    //     http://www.apache.org/licenses/LICENSE-2.0
    //
    // Unless required by applicable law or agreed to in writing, software
    // distributed under the License is distributed on an "AS IS" BASIS,
    // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    // See the License for the specific language governing permissions and
    // limitations under the License.

    Use the appropriate comment syntax for the file type (e.g., # for Python and YAML).

  3. Report Missing Headers: List any files missing the license header.

Show full SKILL.md (353 more words)Show less
6. Code Review
  1. Get the Diff: Run git diff origin/main..HEAD to see all changes.

  2. Review for Issues: Analyze the diff and check for:

    Bugs & Correctness:

    • Logic errors and edge cases.
    • Improper error handling (errors must be handled or propagated, never ignored).
    • Data races or concurrency issues.
    • Off-by-one errors.

    Security & Sandboxing: Treat untrusted Wasm and host inputs as hostile. The bullets below are a floor, not a ceiling — hunt for classes of flaw they don't name.

    • Validator is the boundary: the VM trusts it, so any skipped or weakened check there is exploitable.
    • Untrusted Wasm or invalid host inputs must never panic — failures surface as standard Go errors.
    • Sandbox escapes: untrusted code reaching host state it shouldn't see.

    Performance (especially in hot paths like the VM loop):

    • Unnecessary heap allocations.
    • Inefficient algorithms.
    • Missed opportunities to reuse buffers/slices.
    • Unnecessary copying of data.

    Simplicity & Readability:

    • Overly complex code that could be simplified.
    • Duplicate code that could be refactored.
    • Poor variable naming (names should be self-explanatory).
    • Unnecessary comments (code should be self-explanatory). Verify no "TODO", "FIXME", or placeholder comments were left behind.

    Documentation:

    • Ensure README.md and other documentation is updated if new features, flags, or configuration options were added.
    • Ensure AGENTS.md is still accurate after the change: if the diff alters the project layout, build/test commands, conventions, or constraints it documents, it must be updated to match.

    Modern Go Features:

    • Opportunities to use newer Go features (e.g., generics, improved slices package, range-over-int, etc.).
    • Deprecated patterns that should be updated.

    Project Standards:

    • Adherence to rules in AGENTS.md.
    • Consistent style with existing code.
  3. Compile Findings: Create a structured report with:

    • Critical Issues: Bugs, correctness problems, or security concerns that must be fixed.
    • Suggestions: Performance improvements, simplifications, or style enhancements.
    • Notes: Minor observations or questions.
7. Report

Present a summary to the user containing:

  1. ✅ or ❌ for each verification step (build, lint, tests, spec tests, WASI tests).
  2. Benchmark comparison results with any regressions highlighted.
  3. Dependency change report (if any).
  4. List of files missing license headers (if any).
  5. Code review findings organized by severity.
  6. An overall recommendation: Ready to Merge or Needs Changes.

© ziggy42, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-review of ziggy42/epsilon.

Open the folder on GitHubat commit 64a2225

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillziggy42/epsilon439—~1.7kAutomated safety check: PassApache-2.0
Code Reviewyaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review

    yaklang/yakit

    对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

    7.8k GitHub stars~1.4k tokensUpdated 7 days ago
    DevelopmentAuto-check: notes
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from ziggy42/epsilon

  • Security Audit

    ziggy42/epsilon

    A skill your agent uses to perform a security-focused audit of the codebase to identify vulnerabilities, sandbox escapes, and logic flaws.

    439 GitHub stars~924 tokensUpdated 3 days ago
    Auto-check passed
  • Release

    ziggy42/epsilon

    A skill your agent uses when the user wants to cut a new release.

    439 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

A skill your agent uses when the user asks for a code review. Code Review is an agent skill from ziggy42/epsilon. Use this skill when the user asks for a code review.

When should I use Code Review?

Code Review fits situations like: the user asks for a code review; tasks that involve Code review.

How do I install Code Review in Claude Code?

Run `npx skills add ziggy42/epsilon --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in ziggy42/epsilon) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add ziggy42/epsilon --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in ziggy42/epsilon) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ziggy42/epsilon --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (make, git and go). Our summary lists: Python 3.

Does Code Review access the network?

SKILL.md names 1 domain. In commands or code: apache.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review (yaklang/yakit, 7.8k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

ziggy42 (a GitHub user) maintains it in ziggy42/epsilon, which has 439 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 4, 2026.

Source: ziggy42/epsilon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.