Skip to content
Back to skills

Code Review

ASecurity

Structured workflow for conducting thorough code reviews. Use when the user asks to review code, a PR, or specific files.

  • 30 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
developmentgotestingcode-reviewdatabasesecurityperformance

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add girijashankarj/cursor-handbook --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/girijashankarj-code-review/badge)](https://www.skillsdirectory.com/skills/girijashankarj-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review
description: Structured workflow for conducting thorough code reviews. Use when the user asks to review code, a PR, or specific files.
---

# Skill: Code Review Workflow

## Trigger
When the user asks to review code, a PR, or specific files.

## Steps

### Step 1: Understand Context
- [ ] Read the PR description or user's explanation
- [ ] Identify the type of change (feature, bug fix, refactor, test)
- [ ] Check which files are modified

### Step 2: High-Level Review
- [ ] Does the change accomplish its stated goal?
- [ ] Is the approach appropriate for the problem?
- [ ] Are there simpler alternatives?
- [ ] Does it follow project architecture patterns?

### Step 3: Security Review
- [ ] No hardcoded secrets or credentials
- [ ] No PII in logs or error messages
- [ ] Input validation on all external inputs
- [ ] Parameterized database queries
- [ ] Proper authentication/authorization checks
- [ ] No sensitive data in URLs or headers

### Step 4: Code Quality Review
- [ ] Functions are single-responsibility and < 30 lines
- [ ] Naming is clear and consistent
- [ ] No code duplication
- [ ] Error handling is comprehensive
- [ ] Logging includes correlationId
- [ ] Import order follows conventions

### Step 5: Testing Review
- [ ] Tests exist for new/changed code
- [ ] Success and error paths tested
- [ ] Edge cases covered
- [ ] Mocks are appropriate (not over-mocking)
- [ ] Test names are descriptive

### Step 6: Performance Review
- [ ] No N+1 database queries
- [ ] Appropriate use of indexes
- [ ] No unnecessary data loading
- [ ] Caching where appropriate
- [ ] No memory leaks

### Step 7: Provide Feedback
Use this format:
- πŸ”΄ **Critical**: Must fix before merge
- 🟑 **Suggestion**: Should improve
- 🟒 **Nitpick**: Optional improvement
- πŸ‘ **Positive**: Things done well

## Completion
Review is complete with actionable feedback categorized by priority.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…