Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Review

ASecurity

Conduct effective code reviews: correctness, security, performance, style, and actionable feedback. Use for reviewing any pull request or diff.

2 stars
0 votes
0 copies
2 views
Added 9/29/2026
ai-agentspythongobashsqldjangocode-reviewgitapibackendsecurity

Works with

cursorapi

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/29/2026

$npx -y skills add ssrjkk/claude-skills --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-code-review/badge)](https://www.skillsdirectory.com/skills/ssrjkk-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-review
description: "Conduct effective code reviews: correctness, security, performance, style, and actionable feedback. Use for reviewing any pull request or diff."
category: engineering
tags: [code-review, quality, pull-request, best-practices, review, engineering]
models: [sonnet, opus, gpt-5, gemini-2.5, glm-4.6]
version: 1.0.0
created: 2026-09-20
updated: 2026-09-28
author: ssrjkk
---
# Code Review

> Conducting thorough, actionable code reviews.

## Quick Start
```bash
# Review a diff systematically
git diff main...HEAD
# check correctness, security, performance, and readability
```

## When to Use
- Every pull request before merge
- Security-sensitive changes (auth, payments, data)
- Refactors and large diffs
- Onboarding and knowledge sharing

## Best Practices

### Prioritize
- Review correctness and security first, style last
- Separate blocking issues from nits
- Focus on the diff, not the whole codebase
- Read tests: do they cover the change?

### Feedback Quality
- Ask questions instead of demanding changes
- Explain the "why" behind each suggestion
- Suggest concrete fixes with examples
- Acknowledge what is done well

### Security & Performance
- Look for injection, secrets, and unsafe deserialization
- Check authz on every endpoint
- Flag N+1 queries and O(n^2) patterns
- Watch for unbounded inputs and resource leaks

### Scope
- Review the intent: does it solve the stated problem?
- Check for dead code, leftovers, and debug output
- Verify tests, docs, and migrations are included
- Respect scope: propose follow-ups for large refactors

## Dependencies
```bash
# Tools that help: ruff, mypy, eslint, golangci-lint
# Static security scanning: bandit, semgrep, gitleaks
```

## Examples
```python
# Risk: user-supplied value in SQL query
query = f"SELECT * FROM users WHERE id = {request.user_id}"  # SQL injection
# Fix: parameterize
cursor.execute("SELECT * FROM users WHERE id = %s", (request.user_id,))
```
```python
# Risk: N+1 queries in a loop
for order in user.orders:           # 1 query per order
    items += order.items.all()
# Fix: eager load
from django.db.models import Prefetch
user.orders.prefetch_related(Prefetch("items"))
```
```python
# Risk: missing authorization check
@app.route("/admin/users/<uid>")
def delete_user(uid):
    User.objects.get(id=uid).delete()   # no authz check
# Fix: verify the caller is an admin first
```
```python
# Risk: secrets in code
API_KEY = "sk-live-abc123..."   # leaked secret
# Fix: use environment variables / secret manager
```

## Step-by-Step
1. Read the PR description and understand the intent.
2. Scan the diff for obvious correctness and security issues.
3. Read tests; check they assert real behavior.
4. Review each file in order of risk (backend, auth, data).
5. Run static analysis if not already in CI.
6. Write feedback: blocking issues, questions, nits.
7. Approve only when blockers are resolved.
8. Follow up on deferred suggestions as issues.

## Validation
1. No injection, broken authz, or leaked secrets
2. Tests cover the new behavior including edge cases
3. No N+1 queries or obvious performance regressions
4. Code matches project style and conventions
5. Every blocking comment addressed or justified

## Troubleshooting
- Large PR: request splitting or review by commits.
- Missing tests: ask for tests on the changed paths.
- Style bikeshedding: defer to the project linter/config.

Attribution

ssrjkkssrjkk
View sourceSee grades on GitHubMore from ssrjkk →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →