Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Review

ASecurity

Review changed code for correctness bugs — logic errors, nil/error handling, concurrency, resource leaks, edge cases, broken invariants. Reports findings first, ordered by severity, then fixes on request. Scoped to correctness, not quality or style cleanups. Use when the user says "code review", "review my changes", "any bugs", "find bugs", or asks whether a change is correct.

84 stars
0 votes
0 copies
0 views
Added 9/24/2026
ai-agentsgobashcode-reviewgitapisecurity

Works with

api

Security Analysis

A100/100

Scanned 9/24/2026

$npx -y skills add genai-io/san --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/genai-io-code-review/badge)](https://www.skillsdirectory.com/skills/genai-io-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-review
description: >-
  Review changed code for correctness bugs — logic errors, nil/error handling,
  concurrency, resource leaks, edge cases, broken invariants. Reports findings
  first, ordered by severity, then fixes on request. Scoped to correctness, not
  quality or style cleanups. Use when the user says "code review", "review my
  changes", "any bugs", "find bugs", or asks whether a change is correct.
allowed-tools:
  - Bash
  - Read
  - Glob
  - Grep
  - Edit
  - Agent
argument-hint: "[--fix] [focus area]"
---

# Code Review: Correctness

Review the changed code for **correctness bugs** — cases where it does the wrong
thing, crashes, corrupts state, or breaks a contract. This skill is deliberately
scoped to bugs. Do not report reuse, quality, style, or efficiency cleanups here;
those belong to a separate cleanup pass (San's `simplify` skill, where present).

If the arguments include `--fix`, apply fixes after reporting. Otherwise report
only and offer to fix. A leading focus area (e.g. `concurrency`) narrows the
review to that dimension.

## Phase 1: Identify Changes

Run `git diff` (or `git diff HEAD` when changes are staged) to see what changed.
If there are no git changes, review the most recently modified files the user
named or that you edited earlier in this conversation. Read enough of the
surrounding code that each changed line can be judged in context — a line is
rarely a bug on its own, only against the code that calls it and the code it
calls.

## Phase 2: Launch Review Agents in Parallel

Use the Agent tool to launch the dimension agents concurrently in a single
message (foreground — do NOT set `run_in_background`). Pass each agent the full
diff plus the context it needs. Each agent returns a list of findings; every
finding must carry:

- a **severity** — `critical` (crash, data loss, security), `high` (wrong result
  on a realistic input), `medium` (wrong only in an edge case), `low` (fragile,
  latent);
- a **`file:line`** reference;
- a **concrete failure scenario** — specific inputs or interleaving that lead to
  the wrong outcome. A finding with no scenario is a guess; drop it.

### Agent 1: Logic & Control Flow

- Off-by-one, wrong comparison or boolean operator, inverted condition.
- Incorrect boundary handling; loops that skip the first/last item or run one too
  many times.
- Branches that can't be reached, or that fall through when they shouldn't.
- Wrong operator precedence; integer division or truncation where not intended.

### Agent 2: Nil, Errors & Return Values

- Dereferencing a value that can be nil/null/undefined on some path.
- Errors that are swallowed, logged-and-continued when they should stop, or
  returned without wrapping context.
- Ignored return values that carry an error or a "not found" signal.
- Early returns that leave state half-updated.

### Agent 3: Concurrency & State

- Shared state read/written without synchronization; data races.
- Check-then-act races (TOCTOU) on files, maps, or shared fields.
- Deadlocks, lock ordering, holding a lock across a blocking call.
- Goroutine/task leaks; work started but never awaited or cancelled.
- Mutation of a value another reference still assumes is unchanged.

### Agent 4: Resources, Boundaries & Contracts

- Files, connections, handles, subscriptions opened but not closed on every path.
- Use-after-close / use-after-free; double free/close.
- Edge inputs: empty, zero, negative, very large, overflow, unexpected type.
- API misuse: violating a precondition of a function being called, or breaking an
  invariant a caller relies on.

## Phase 3: Verify, Then Report

Aggregate the findings. Before reporting each one, check it against the actual
code once more and discard anything you cannot tie to a concrete failure — false
positives cost the reader more than a missed nitpick. Deduplicate findings that
point at the same root cause.

**Report findings first**, ordered by severity, each as: `file:line` — one-line
statement of the bug — the failure scenario. Keep any summary short and after the
list. If nothing survives verification, say so plainly and name any residual risk
or gap in test coverage.

## Phase 4: Fix (on request)

If `--fix` was passed, or the user asks to fix after seeing the report, apply the
smallest change that removes each confirmed bug — nothing else (no refactors, no
cleanup; that is `simplify`'s job). Re-state what you changed. Where a fix is not
obvious or has trade-offs, present the options and ask rather than guessing.

Attribution

genai-iogenai-io
View sourceSee grades on GitHubMore from genai-io →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →