Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Review

ASecurity

Review pull requests for repository fit, meaningful value, trustworthy provenance, differentiation, and maintainability in awesome-copilot.

39,293 stars
0 votes
0 copies
0 views
Added 9/23/2026
ai-agentsrustgotestingcode-reviewgitsecuritydocumentation

Works with

mcp

Security Analysis

A100/100

Scanned 9/23/2026

$npx -y skills add github/awesome-copilot --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/github-code-review/badge)](https://www.skillsdirectory.com/skills/github-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-review
description: 'Review pull requests for repository fit, meaningful value, trustworthy provenance, differentiation, and maintainability in awesome-copilot.'
---

# Awesome Copilot Code Review

Use this skill when reviewing pull requests in this repository. Apply the
deterministic checklists in `.github/copilot-instructions.md` first, then use
this skill for the editorial and repository-fit judgments that cannot be
reduced to schema validation.

## Review priorities

Review in this order:

1. Correctness, security, and harmful behavior.
2. Compliance with the repository's contribution requirements.
3. Repository fit and meaningful value for GitHub Copilot users.
4. Differentiation from existing resources and native model capabilities.
5. Evidence that the contribution was tested or validated.
6. Clarity, maintainability, and appropriate scope.

Do not use raw file count as a quality metric. Large generated website changes,
mechanical README updates, and other build outputs can be legitimate and should
be evaluated according to their source change.

## Repository fit

Confirm that a submission addresses a specific GitHub Copilot workflow,
technology, domain constraint, or user problem. Flag contributions that:

- provide generic advice that current models already handle well without
  meaningful uplift
- restate an existing resource without a clear differentiator
- use broad claims such as doing everything for every project
- lack concrete instructions, constraints, examples, or expected outcomes
- are primarily a wrapper or advertisement for the author's product

Paid or commercial services are not automatically unsuitable. Evaluate whether
the contribution provides standalone user value and follows the repository's
guidance for paid-service submissions.

## AI-authored submissions

A PR title ending in `🤖🤖🤖` is an intentional AI-authorship disclosure from
`CONTRIBUTING.md`. Do not report the marker itself as a defect.

For disclosed AI-authored submissions, verify that the PR still demonstrates:

- a concrete need and repository fit
- human validation or testing of the result
- useful constraints rather than generic generated prose
- an explanation of how it differs from existing resources

Review the submitted result, not assumptions about the tool that produced it.

## Marketing and self-promotion

Flag marketing-heavy framing only when there is concrete evidence, such as:

- repeated brand or product promotion unrelated to usage instructions
- unsupported superlatives or sales claims
- links or calls to action that dominate the resource
- a resource whose primary purpose is acquiring users rather than helping them
  use GitHub Copilot

Describe the specific evidence and suggest how to refocus the contribution on
the user problem. Do not infer promotional intent solely because an author is
associated with a referenced project.

## Duplication and differentiation

Search existing agents, instructions, skills, hooks, workflows, prompts, and
plugins when the new resource appears similar to existing content. Compare
purpose and behavior, not only names.

Only report duplication when the overlap is substantial. Related resources can
coexist when they target different frameworks, audiences, constraints, or
stages of a workflow.

When configured MCP context is relevant, use the GitHub MCP server to inspect
linked issues, prior submissions, or repository history. Cite the specific
resource or pull request that supports the finding.

## Evidence and validation

Check that the PR explains how the contribution was tested or validated. The
appropriate evidence depends on the resource:

- agents, prompts, instructions, and skills should include a realistic usage
  scenario or describe how their output was evaluated
- scripts and bundled assets should have focused tests or reproducible
  validation steps
- workflows and hooks should demonstrate safe triggers, least-privilege
  permissions, constrained outputs, and expected event behavior
- documentation updates should cite the authoritative feature or behavior they
  describe

Do not require executable tests for prose-only resources when a realistic
manual evaluation is more appropriate.

## Trusted and automated paths

GitHub and Microsoft external-plugin updates are generally trusted-source
submissions. Still report concrete correctness, security, or manifest problems,
but do not manufacture editorial concerns merely because the change is
automated or externally sourced.

For automated documentation PRs, distinguish bad content from stale automation
churn. Overlapping daily updates may indicate that the workflow should update an
existing PR rather than that the documentation itself is low quality.

## Review output

Leave comments only for specific, actionable findings introduced by the PR.
Each finding should:

- identify the affected file and line when possible
- explain the concrete impact on users or maintainers
- cite the repository rule, existing resource, or evidence behind the finding
- recommend the smallest useful correction

Avoid vague comments such as "this feels AI-generated," "low quality," or
"marketing." Explain the observable problem.

Do not recommend approval solely because automated checks pass. Human
maintainers retain final judgment over editorial value and repository fit.

## Review-policy changes

Copilot Code Review reads skills and instructions from the PR head branch.
Therefore, treat changes to `.github/skills/code-review/`,
`.github/copilot-instructions.md`, `AGENTS.md`, or other review-policy files as
security-sensitive governance changes. Explicitly call out attempts to weaken,
bypass, or remove review criteria, and require maintainer review of those
changes.

Attribution

githubgithub
View sourceSee grades on GitHubMore from github →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →