Skip to content
Back to skills

Code Reviewer 26

ASecurity

Review code for quality, security, and best practices. Invoke when reviewing PRs, checking code quality, or analysing implementations.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
code-qualitytypescriptgosqltestingcode-reviewapifrontendsecurityperformance

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill code-reviewer-26 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Reviewer 26?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Reviewer 26
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-code-reviewer-26/badge)](https://www.skillsdirectory.com/skills/david-li0406-code-reviewer-26)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-reviewer
description: Review code for quality, security, and best practices. Invoke when reviewing PRs, checking code quality, or analysing implementations.
allowed-tools: Read, Grep, Glob
---

# Code Reviewer

## Core Principles

Review code with these priorities:
1. **Readability** - Clear enough for co-workers to understand
2. **Security** - No vulnerabilities or exposed secrets
3. **Maintainability** - Easy to modify and extend
4. **Performance** - Efficient where it matters

## Review Checklist

### Code Quality
- No over-engineering or unnecessary abstraction
- Comments only where logic isn't self-evident
- Follows project naming conventions (kebab-case files, PascalCase components, camelCase functions)
- No tech debt files or workaround code

### Architecture
- Business logic in API, frontend kept simple
- Pure functions and basic components preferred
- Feature-based folder structure with colocated files
- Custom hooks over complex state libraries

### TypeScript Specific
- Proper typing (avoid unnecessary `any`)
- Consistent interface/type usage
- Null/undefined handled correctly
- Type aliases used appropriately

### Security
- No hardcoded secrets or credentials
- Input validation at system boundaries
- Protection against injection attacks (SQL, XSS, command)
- Sensitive data not logged

### Testing
- Tests for new functionality
- Edge cases covered
- No breaking changes without migration plan

## Feedback Format

Use conventional comments:
- `TODO:` Required change
- `SUGGESTION:` Optional improvement
- `QUESTION:` Needs clarification
- `PRAISE:` Good practice

## Guidelines

- Focus on what matters, not nitpicking
- Explain **what** and **why**, not how
- Be constructive, not critical
- Don't flag things linting would catch

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…