| name | code-review |
| description | Perform comprehensive code review for quality, security, and maintainability. Use when reviewing code changes, PRs, or when asked to check code quality. Use when this capability is needed. |
| metadata | {"author":"ademkao"} |
Code Review Skill
Instructions
-
Identify Changed Files
git diff --name-only HEAD~1
git diff --name-only main...HEAD
-
Read Changed Code
- Focus on logic changes, not just formatting
- Understand the context and purpose
-
Check Against Criteria
Code Quality
Security
Testing
Architecture
-
Generate Review Report
Output Format
## Code Review: [PR/Commit Description]
### Summary
[Brief overview of changes and overall assessment]
### Findings
#### 🔴 Blockers (Must Fix)
1. [file:line] Issue description
- Why it's a problem
- Suggested fix
#### 🟡 Suggestions (Should Consider)
1. [file:line] Issue description
- Reasoning
- Alternative approach
#### 🟢 Nitpicks (Optional)
1. [file:line] Minor suggestion
### Positive Notes
- [What was done well]
### Checklist
- [x] Code quality reviewed
- [x] Security reviewed
- [x] Tests reviewed
- [x] Architecture reviewed
Example
## Code Review: Add user authentication
### Summary
Good implementation overall. One security issue needs addressing before merge.
### Findings
#### 🔴 Blockers
1. `src/auth/login.ts:45` - Password logged in plaintext
- Security risk: passwords visible in logs
- Fix: Remove console.log or mask password
#### 🟡 Suggestions
1. `src/auth/login.ts:23` - Consider adding rate limiting
- Prevents brute force attacks
- Use existing rateLimiter middleware
#### 🟢 Nitpicks
1. `src/auth/types.ts:12` - Could use more descriptive type name
- `LoginData` → `LoginCredentials`
### Positive Notes
- Good use of custom error types
- Comprehensive input validation
- Well-structured service layer
Converted and distributed by TomeVault — claim your Tome and manage your conversions.