Agent skill
code-review
Comprehensive code review guidelines for ensuring code quality, security, and maintainability. Use when reviewing pull requests, refactoring code, or ensuring best practices.
Install this agent skill to your Project
npx add-skill https://github.com/uwe-schwarz/skills/tree/main/skills/code-review
Metadata
Additional technical details for this skill
- author
- your-name
- version
- 1.0.0
SKILL.md
Code Review Skill
Guidelines for thorough and effective code reviews.
When to Apply
Use these guidelines when:
- Reviewing pull requests
- Refactoring existing code
- Conducting code audits
- Ensuring code quality standards
Review Categories
1. Code Quality
- Check for consistent code style
- Ensure proper error handling
- Verify meaningful variable and function names
- Look for code duplication
2. Security
- Check for SQL injection vulnerabilities
- Verify input validation and sanitization
- Review authentication and authorization logic
- Check for sensitive data exposure
3. Performance
- Identify potential performance bottlenecks
- Check for unnecessary database queries
- Review algorithm efficiency
- Look for memory leaks
4. Testing
- Verify test coverage
- Check test quality and relevance
- Ensure edge cases are covered
- Review mocking and fixtures
5. Documentation
- Check for code comments
- Verify README updates
- Review API documentation
- Ensure changelog is updated
Review Process
-
Initial Review
- Read through the changes
- Understand the purpose
- Identify major issues first
-
Detailed Review
- Check each file
- Verify logic and implementation
- Test if necessary
-
Final Review
- Summarize findings
- Provide actionable feedback
- Verify fixes if needed
Best Practices
- Be constructive and respectful
- Explain the "why" behind comments
- Suggest improvements, not just problems
- Acknowledge good work
- Keep reviews timely
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
your-skill-name
A clear description of what this skill does and when to use it. This should be comprehensive so agents understand when to activate this skill.
example-skill
An example skill demonstrating the Agent Skills format. Use this as a template for creating your own skills.
documentation
Automated documentation generation and management. Use for creating, updating, and maintaining project documentation including README files, API docs, and inline code comments.
cost-estimate
Estimate the replacement cost, engineering effort, calendar time, and market-rate value of a software project by analyzing a repository's size, architecture, complexity, and delivery maturity. Use when asked for a build-cost estimate, rebuild quote, delivery timeline, stakeholder-facing budget range, pricing sanity check, or ROI/value analysis for work produced by Claude, Codex, OpenCode, Crush, or another AI coding agent.
upgrade-dependencies-pr
Update a JavaScript, TypeScript, or Python project's dependencies to the latest published versions, remove exact pinned JS semver specs when appropriate, convert stray JS `latest` tags back to explicit semver ranges, evaluate release impact against the codebase and official release notes, identify newly introduced features and enforcement changes, apply required small upgrade fixes, open GitHub issues for larger or optional follow-up work, and finish by creating a branch, commit, push, and PR. Use when asked to upgrade dependencies, refresh packages, unpin dependency versions, or ship an end-to-end dependency maintenance PR.
github-pr-review-workflow
Complete workflow for handling GitHub PR reviews using gh pr-review extension
Didn't find tool you were looking for?