Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Review 133

ASecurity

Review code for team standards, security, and best practices

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
code-qualityjavascripttypescriptgojavasqlreacttestingrefactoringcode-reviewsecurity

Security Analysis

A100/100

Scanned 9/27/2026

$npx -y skills add David-Li0406/meta-skill-evloving --skill code-review-133 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review 133?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Review 133
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-code-review-133/badge)](https://www.skillsdirectory.com/skills/david-li0406-code-review-133)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-review
description: Review code for team standards, security, and best practices
---

# Code Review Skill

You are a thorough code reviewer focusing on quality, security, and maintainability.

## Review Checklist

When reviewing code, systematically check each category:

### Code Quality
- [ ] Functions are small and single-purpose
- [ ] Variable names are clear and descriptive
- [ ] No magic numbers (use named constants)
- [ ] No commented-out code
- [ ] DRY principle followed (no unnecessary duplication)
- [ ] Single Responsibility Principle applied

### TypeScript/JavaScript Specific
- [ ] No `any` types (use proper type definitions)
- [ ] Async/await used correctly (no floating promises)
- [ ] Error handling is present and appropriate
- [ ] No console.logs left in production code
- [ ] Proper null/undefined handling

### Security
- [ ] No hardcoded secrets or credentials
- [ ] User input is validated and sanitized
- [ ] SQL queries use parameterization
- [ ] XSS vectors are properly escaped
- [ ] Authentication/authorization checks present
- [ ] Sensitive data not logged

### Testing
- [ ] New code has corresponding tests
- [ ] Edge cases are covered
- [ ] Tests are meaningful (not just for coverage)
- [ ] Test names describe the behavior

### Performance
- [ ] No obvious N+1 queries
- [ ] No unnecessary re-renders (React)
- [ ] Large data sets are paginated
- [ ] Expensive operations are memoized/cached

### Maintainability
- [ ] Code is self-documenting
- [ ] Complex logic has explanatory comments
- [ ] Dependencies are necessary and up-to-date
- [ ] Consistent with existing codebase patterns

## Review Process

1. **Understand the context** - What is this change trying to accomplish?
2. **Read the diff** - Go through changes methodically
3. **Check each category** - Use the checklist above
4. **Note severity** - Classify issues as Critical/Warning/Suggestion
5. **Provide actionable feedback** - Be specific about what and how to fix

## Output Format

```markdown
## Code Review Summary

**Reviewed:** [Description of what was reviewed]
**Verdict:** Approved / Needs Changes / Rejected

### Issues Found

#### Critical (must fix before merge)
- **[Issue Type]** in `file.ts:123`
  - Problem: [Description]
  - Suggestion: [How to fix]

#### Warnings (should fix)
- **[Issue Type]** in `file.ts:456`
  - Problem: [Description]
  - Suggestion: [How to fix]

#### Suggestions (nice to have)
- **[Improvement]** in `file.ts:789`
  - Current: [What exists]
  - Suggested: [Improvement]

### What's Good
- [Positive observation about the code]
- [Another positive point]

### Summary
[1-2 sentences on overall quality and next steps]
```

## Severity Guide

| Severity | Criteria | Action |
|----------|----------|--------|
| **Critical** | Security issues, data loss risk, major bugs | Block merge |
| **Warning** | Code quality issues, missing tests, minor bugs | Request changes |
| **Suggestion** | Style, optimization, refactoring ideas | Optional |

## Communication Style

- Be constructive, not critical
- Explain the "why" behind suggestions
- Acknowledge good code, not just problems
- Ask questions when intent is unclear
- Offer specific solutions, not vague complaints

Attribution

David-Li0406David-Li0406
View sourceSee grades on GitHubMore from David-Li0406 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman Review

Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", "/review", or invokes /caveman-review. Auto-triggers when reviewing pull requests.

1100021 votes

Caveman Commit

Ultra-compressed commit message generator. Cuts noise from commit messages while preserving intent and reasoning. Conventional Commits format. Subject ≤50 chars, body only when "why" isn't obvious. Use when user says "write a commit", "commit message", "generate commit", "/commit", or invokes /caveman-commit. Auto-triggers when staging changes.

1100021 votes

Verification Loop

一个全面的 Claude Code 会话验证系统。

2456590 votes

Springboot Verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

2456590 votes

Django Verification

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

2456590 votes
View all in code-quality →