Skip to content
Back to skills

Code Review

ASecurity

Conduct effective code reviews: correctness, security, performance, style, and actionable feedback. Use for reviewing any pull request or diff.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentspythongobashsqldjangocode-reviewgitapibackendsecurity

Works with

  • cursor
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add ssrjkk/agent-skills --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-code-review-agent-skills/badge)](https://www.skillsdirectory.com/skills/ssrjkk-code-review-agent-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review
description: "Conduct effective code reviews: correctness, security, performance, style, and actionable feedback. Use for reviewing any pull request or diff."
category: engineering
tags: [code-review, quality, pull-request, best-practices, review, engineering]
models: [sonnet, opus, gpt-6, gemini-3, glm-5]
version: 1.0.0
created: 2026-09-20
updated: 2026-09-28
author: ssrjkk
---
# Code Review

> Conducting thorough, actionable code reviews.

## Quick Start
```bash
# Review a diff systematically
git diff main...HEAD
# check correctness, security, performance, and readability
```

## When to Use
- Every pull request before merge
- Security-sensitive changes (auth, payments, data)
- Refactors and large diffs
- Onboarding and knowledge sharing

## Best Practices

### Prioritize
- Review correctness and security first, style last
- Separate blocking issues from nits
- Focus on the diff, not the whole codebase
- Read tests: do they cover the change?

### Feedback Quality
- Ask questions instead of demanding changes
- Explain the "why" behind each suggestion
- Suggest concrete fixes with examples
- Acknowledge what is done well

### Security & Performance
- Look for injection, secrets, and unsafe deserialization
- Check authz on every endpoint
- Flag N+1 queries and O(n^2) patterns
- Watch for unbounded inputs and resource leaks

### Scope
- Review the intent: does it solve the stated problem?
- Check for dead code, leftovers, and debug output
- Verify tests, docs, and migrations are included
- Respect scope: propose follow-ups for large refactors

## Dependencies
```bash
# Tools that help: ruff, mypy, eslint, golangci-lint
# Static security scanning: bandit, semgrep, gitleaks
```

## Examples
```python
# Risk: user-supplied value in SQL query
query = f"SELECT * FROM users WHERE id = {request.user_id}"  # SQL injection
# Fix: parameterize
cursor.execute("SELECT * FROM users WHERE id = %s", (request.user_id,))
```
```python
# Risk: N+1 queries in a loop
for order in user.orders:           # 1 query per order
    items += order.items.all()
# Fix: eager load
from django.db.models import Prefetch
user.orders.prefetch_related(Prefetch("items"))
```
```python
# Risk: missing authorization check
@app.route("/admin/users/<uid>")
def delete_user(uid):
    User.objects.get(id=uid).delete()   # no authz check
# Fix: verify the caller is an admin first
```
```python
# Risk: secrets in code
API_KEY = "sk-live-abc123..."   # leaked secret
# Fix: use environment variables / secret manager
```

## Step-by-Step
1. Read the PR description and understand the intent.
2. Scan the diff for obvious correctness and security issues.
3. Read tests; check they assert real behavior.
4. Review each file in order of risk (backend, auth, data).
5. Run static analysis if not already in CI.
6. Write feedback: blocking issues, questions, nits.
7. Approve only when blockers are resolved.
8. Follow up on deferred suggestions as issues.

## Validation
1. No injection, broken authz, or leaked secrets
2. Tests cover the new behavior including edge cases
3. No N+1 queries or obvious performance regressions
4. Code matches project style and conventions
5. Every blocking comment addressed or justified

## Troubleshooting
- Large PR: request splitting or review by commits.
- Missing tests: ask for tests on the changed paths.
- Style bikeshedding: defer to the project linter/config.

Files in this skill

  • SKILL.md3.3 KB
  • SKILL.ru.md5.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…