Skip to content
Back to skills

Code Review

ASecurity

Comprehensive code review with security, performance, and best practices focus

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
ai-agentstypescriptsqlreacttestingapidatabasesecurityperformance

Works with

  • api
  • mcp

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add twiss-io/tess-os --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/twiss-io-code-review/badge)](https://www.skillsdirectory.com/skills/twiss-io-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Code Review
description: Comprehensive code review with security, performance, and best practices focus
triggers:
  - review
  - audit
  - check code
  - security review
---

# Code Review Skill

When reviewing code, follow this systematic approach:

## 1. Security (FIRST β€” always check)

- [ ] No hardcoded secrets, API keys, or passwords
- [ ] Input validation on all user-provided data
- [ ] SQL injection prevention (parameterized queries)
- [ ] XSS prevention (sanitized output)
- [ ] Authentication/authorization on protected routes
- [ ] CORS properly configured
- [ ] Rate limiting on public endpoints

## 2. TypeScript Quality

- [ ] No `any` types (unless documented why)
- [ ] Explicit return types on public functions
- [ ] Null/undefined properly handled (`User | null`)
- [ ] Strict mode enabled
- [ ] Enums or union types instead of magic strings

## 3. Error Handling

- [ ] Try/catch around async operations
- [ ] Errors logged with context (not swallowed)
- [ ] User-facing errors are helpful (not stack traces)
- [ ] Unhandled promise rejections caught

## 4. Performance

- [ ] No N+1 database queries
- [ ] Proper pagination on list endpoints
- [ ] No memory leaks (event listeners cleaned up)
- [ ] Database indexes for common queries
- [ ] No unnecessary re-renders (React)

## 5. Testing

- [ ] New code has corresponding tests
- [ ] Tests have explicit assertions (not just "page loads")
- [ ] Edge cases covered (empty, null, max values)
- [ ] Mocks are realistic

## 6. Architecture

- [ ] Database access through StrictDB only
- [ ] API versioning (/api/v1/) followed
- [ ] Service separation respected
- [ ] No business logic in route handlers

## Output Format

For each issue:
- **Severity**: πŸ”΄ Critical | 🟑 Warning | πŸ”΅ Suggestion
- **Location**: file:line
- **Issue**: What's wrong
- **Fix**: How to fix it
- **Why**: Why this matters

## RuleCatch Report

After completing the review, check RuleCatch for automated violations:

- If the RuleCatch MCP server is available: query for violations on the reviewed files
- Include results in a dedicated "RuleCatch Violations" section
- This catches pattern-based violations the manual review might miss
- If no MCP: suggest β€” "Install RuleCatch MCP for automated violation monitoring"

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…