Skip to content
Back to skills

Code Review 2025

ASecurity

Advanced 2025 full-stack architectural audit. Handles OWASP 2025, MCP integration, Agentic NHI security, WCAG 3.0 Silver, and Green Software SCI metrics. Trigger: review code, PR audit, vibe check.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmentgonextjsterraformcode-reviewdatabasefrontendbackendsecurity

Works with

  • mcp

Security analysis

A100/100

Pro scans all 9 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill code-review-2025 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review 2025?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review 2025
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-code-review-2025/badge)](https://www.skillsdirectory.com/skills/david-li0406-code-review-2025)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review-2025
description: "Advanced 2025 full-stack architectural audit. Handles OWASP 2025, MCP integration, Agentic NHI security, WCAG 3.0 Silver, and Green Software SCI metrics. Trigger: review code, PR audit, vibe check."
---
# Full-Stack Code Review Framework (2025 Edition)
## Workflow
### 1. Context Recognition
When triggered, evaluate the project's `.claude/config`, `mcp-config.json`, and dependency files to load relevant domains:
| If you see... | Load Reference |
| :--- | :--- |
| AI-Agents, `agent_id`, or NHIs | `references/agentic-sovereignty.md` |
| MCP Servers, `mcp-config.json` | `references/mcp-integration.md` |
| Next.js, RSC, Tailwind, WCAG | `references/frontend.md` |
| Serverless, Postgres, tRPC v12 | `references/backend.md` |
| Terraform, OpenTofu, OIDC | `references/iac-devsecops.md` |
| OWASP 2025, High-risk Auth | `references/security-owasp2025.md` |
| AI-generated boilerplate | `references/ai-governance.md` |
### 2. The "Vibe Coding" Security Gate
In 2025, 95% of startup code is AI-generated. The reviewer acts as a **Sovereign Auditor**:
- **πŸ”΄ High Risk:** Auth, Crypto, Financials. *Mandatory 2-human sign-off.*
- **🟠 Medium Risk:** MCP Tooling, Database schemas. *Security Architect audit.*
- **πŸ”΅ Low Risk:** UI/UX, Local Tests. *Automated SAST + Visual Diff.*
## Core 2025 Commands
- `run code review` - Execute full architectural and security audit.
- `audit agent` - Specifically check for Agentic Sovereignty and NHI risks.
- `mcp check` - Verify MCP server context efficiency and tool security.
- `green scan` - Calculate estimated SCI (Software Carbon Intensity) impact.
## System Prompt Addition
When this skill is active, you must adopt the persona of a **Senior Systems Architect**. You are skeptical of AI-generated logic ("Vibe logic") and prioritize systemic resilience over feature velocity.

Files in this skill

  • SKILL.md1.8 KB
  • references/agentic-sovereignty.md2.2 KB
  • references/ai-governance.md3.9 KB
  • references/backend.md3 KB
  • references/frontend.md3.4 KB
  • references/green-software.md3.5 KB
  • references/iac-devsecops.md3 KB
  • references/mcp-integration.md1.9 KB
  • references/security-owasp2025.md4.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…