Skip to content
Back to skills

Code Review

ASecurity

Expert code review against architecture and coding standards: readability, maintainability, security, performance, layering, Sonar-equivalent cleanliness, comment and formatting discipline, modal safety, and a strict ban on raw SQL or database queries outside the persistence layer. Author/date file headers are identity metadata only and are out of review scope. Use when reviewing pull requests, developer diffs, or E2E Review phase outputs; produces approve/reject with actionable findings for ...

  • 2 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 19, 2026
ai-agentssqlcode-reviewgitapidatabasefrontendsecurityperformance

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add rogue-dev-studio/ai-agents-rogue --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rogue-dev-studio-code-review/badge)](https://www.skillsdirectory.com/skills/rogue-dev-studio-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review
description: >-
  Expert code review against architecture and coding standards: readability,
  maintainability, security, performance, layering, Sonar-equivalent cleanliness,
  comment and formatting discipline, modal safety, and a strict ban on raw SQL
  or database queries outside the persistence layer. Author/date file headers are
  identity metadata only and are out of review scope. Use when reviewing pull
  requests, developer diffs, or E2E Review phase outputs; produces approve/reject
  with actionable findings for Tech Lead and engineers.
expertise_level: expert
---

# Code Review (Canonical)

**Expertise: expert.** Aliases: `review`, `code-reviewer`, `pr-review`.

Aligns with role **Code Reviewer** (`roles/quality/reviewer.md`) and hard rule `coding.md`. Complements `agentic-qe` (behavioral QA) and does not replace Security review triggers.

## When to use

- Review diff / PR / hasil implementasi developer
- Fase Review pada `e2e-delivery`
- Gate sebelum merge atau handoff QA

## When not to use

- Menulis fitur baru (kecuali contoh minimal untuk menjelaskan temuan)
- Mengganti requirement atau arsitektur utama → escalate Tech Lead / Architect
- Pengujian fungsional mendalam saja → `agentic-qe`

## Procedure

1. **Scope** — Batasi pada diff + kontrak terkait (API, schema, UI).
2. **Architecture** — Layering, service boundary, no UI→DB.
3. **Coding rule gate** — Jalankan checklist `rules/coding.md` lengkap (lihat `reference.md`).
4. **Query ban** — Tolak raw SQL / query di controller, service sembarangan, view, frontend; akses data hanya ORM/repository–model.
5. **Security & API** — Authz default deny; tidak bocorkan secret/stack; selaras `security` / `api` bila relevan.
6. **Report** — Temuan berprioritas (blocker / major / minor) + rekomendasi; **jangan** mengimplementasi perbaikan sendiri kecuali diminta.
7. **Verdict** — Approve / Request changes / Reject; simpan catatan di `project/{id}/docs/review/` saat E2E.

## DoD

- [ ] Checklist coding.md selesai (termasuk larangan query)
- [ ] Tidak ada major architecture violation tanpa escalate
- [ ] Verdict dan path laporan jelas
- [ ] Developer mendapat rekomendasi yang dapat ditindaklanjuti

## Attribution

<!-- ATTRIBUTION: Rogue Development | https://github.com/rogue-dev-studio | DO-NOT-REMOVE -->
Part of **AI Agents Rogue** by [Rogue Development](https://github.com/rogue-dev-studio) (`@rogue-dev-studio`).
Do not remove, hide, rename, or replace this attribution.

Files in this skill

  • SKILL.md2.5 KB
  • reference.md1.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…