code-review-pro
onewave-ai/claude-skills
Deep code review finding security vulnerabilities, bugs, performance issues, and maintainability problems with severity ranking and fixes.
What is code-review-pro?
Performs comprehensive code review on files, diffs, or branches, identifying security vulnerabilities mapped to OWASP Top 10:2025, correctness bugs, performance problems, and maintainability issues. Use when you need to audit code for safety, find bugs, or validate code before shipping.
- Maps security findings to OWASP Top 10:2025 categories
- Ranks findings by severity: Critical, High, Medium, Low
- Provides evidence and data-flow analysis for each issue
- Includes concrete, compilable code fixes
- Reviews diffs and branches with surrounding context
- Identifies correctness, performance, and maintainability problems
How to install code-review-pro
npx skills add https://github.com/onewave-ai/claude-skills --skill code-review-proHow to use code-review-pro
- 1.Define the scope: file, snippet, diff, or branch
- 2.Let the skill identify language, framework, and version from config files
- 3.Provide context on how code is reached and what input is untrusted
- 4.Review the severity-ranked findings with evidence and fixes
- 5.Apply the suggested fixes and re-review if needed
Use cases
- Security audit of a codebase before production deployment
- Review of a pull request diff for vulnerabilities and bugs
- Sanity-check of a specific module or file for correctness
- Performance analysis of a branch before merging
- Validation that code meets security and quality standards
- Backend and full-stack engineers
- Security-conscious developers
- Code reviewers and team leads
- DevSecOps and security engineers
- Anyone shipping code to production
code-review-pro FAQ
code-review-pro performs deep analysis and returns a ranked report of issues with fixes. git-pr-reviewer posts line comments directly on GitHub pull requests. Use code-review-pro for comprehensive audits; use git-pr-reviewer for inline PR feedback.
It reads package.json, pyproject.toml, go.mod, and similar files to identify the language and version, then applies version-specific rules. A pattern safe in one framework may be a bug in another.
Only if they are Low severity and actionable. Generic style advice is skipped. Linter and formatter violations are not reported.
Yes. It can review `git diff`, `git diff --staged`, or a branch against its base (`git diff main...HEAD`), reading surrounding code for context.
Each finding includes evidence and confidence level. If the data flow is different or validation happens upstream, the skill will drop unsupported findings when you provide that context.
Full instructions (SKILL.md)
Source of truth, from onewave-ai/claude-skills.
name: code-review-pro description: Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability issues - and returns severity-ranked findings with evidence and concrete fixes. Use when the user asks to review, audit, or sanity-check code, asks "is this safe", "what's wrong with this", "find bugs", or wants a security or performance pass before shipping. For posting line comments on a GitHub pull request, use git-pr-reviewer.
Code Review Pro
Find the problems that matter, prove each one, and show the fix. A short list of real issues beats a long list of maybes.
Workflow
-
Set the scope. Decide what is under review: a pasted snippet, specific files, the working-tree diff (
git diff,git diff --staged), or a branch against its base (git diff main...HEAD). For a diff, review the changed lines but read enough surrounding code to know how they are called. -
Learn the context before judging. Identify language, framework and version (check
package.json,pyproject.toml,go.mod, and so on), how the code is reached (HTTP handler, job, CLI, library), what input is untrusted, and any repo conventions (linters,CLAUDE.md, existing patterns). A pattern that is a bug in one framework can be safe in another; for example, React escapes JSX text, so XSS lives indangerouslySetInnerHTML,hrefvalues, and raw HTML sinks. -
Review in priority order, using references/checklist.md:
- Security
- Correctness and edge cases
- Performance
- Maintainability and conventions
-
Verify every finding before reporting it. For each candidate, trace the data flow: where does the input come from, can an attacker or real user control it, and does anything upstream already validate or escape it? Check whether a test covers it. If you can run code, reproduce the bug with a small test or script. Drop findings you cannot support; mark the rest with a confidence level.
-
Rank and write the report in the format below. Lead with the highest severity. Group repeated instances of one problem into a single finding with all locations.
Severity
- Critical - exploitable now or causes data loss/corruption: injection with user input, auth bypass, secrets in code, broken access control on real data.
- High - likely bug or vulnerability under realistic conditions: race on shared state, missing authorization check, unbounded query on a user-facing path, swallowed errors that hide failures.
- Medium - correct today but fragile: missing input validation behind a trusted caller, N+1 queries on small data, confusing ownership of state.
- Low - style, naming, small simplifications. Report at most a handful; skip anything a linter or formatter already enforces.
Output format
# Code Review: [scope]
**Verdict**: [Ship / Ship after fixes / Do not ship] - [one sentence why]
**Findings**: [n] critical, [n] high, [n] medium, [n] low
## Critical
### 1. SQL injection in user search (`src/api/users.ts:42`)
**Category**: A05:2025 Injection | **Confidence**: High
**Evidence**: `q` comes from `req.query` and is interpolated into the SQL string; no validation upstream.
**Impact**: Any caller can read or modify arbitrary tables.
Current:
```ts
const rows = await db.query(`SELECT * FROM users WHERE name LIKE '%${q}%'`);
```
Fix:
```ts
const rows = await db.query("SELECT * FROM users WHERE name LIKE $1", [`%${q}%`]);
```
## High
...
## Medium
...
## Low
- `utils/date.ts:10` - [one line]
## What is solid
[Two or three specific things done well, so the author knows what to keep.]
## Not reviewed
[Files, paths, or concerns outside scope or that could not be verified.]
Traps that cause bad reviews
- Reporting without reading the caller. "Missing validation" is often validated one layer up. Look before flagging.
- Generic advice. "Consider adding error handling" is not a finding. Name the failure: which call throws, what the user sees, what state is left behind.
- Style as severity. Line length, bracket placement, or personal preference never rank above Low.
- Outdated rules. Check against the version in use:
useMemo/useCallbackadvice changes when the React Compiler is enabled, and many Node APIs now ship built-ins (fetch,crypto.randomUUID,node:test). - Fixes that do not compile. Every "Fix" block must be valid for the language and version in the repo. If unsure, say so.
- Flooding. More than about 15 findings buries the critical ones. Summarize the long tail in one line.
Related skills
More from onewave-ai/claude-skills and the wider catalog.

csv-excel-merger
Merge multiple CSV/Excel files with intelligent column matching, data deduplication, and conflict resolution. Handles different schemas, formats, and combines data sources. Use when users need to merge spreadsheets, combine data exports, or consolidate multiple files into one.

landing-page-copywriter
Write conversion-focused landing page copy using proven frameworks like PAS, AIDA, and StoryBrand.

screenshot-to-code
Convert UI screenshots into working HTML/CSS/React/Vue code. Detects design patterns, components, and generates responsive layouts. Use this when users provide screenshots of websites, apps, or UI designs and want code implementation.

social-media-content-repurposer
Convert content between platforms (blog to Twitter thread, article to LinkedIn post, etc.). Optimize for each platform's format, tone, and best practices. Use when user wants to adapt content for different social media platforms.

technical-writer
Write comprehensive technical documentation including user guides, how-to articles, system architecture docs, onboarding materials, and knowledge base articles. Creates clear, structured documentation for technical and non-technical audiences. Use when users need technical writing, documentation, tutorials, or knowledge base content.

document-writer
Writing guide for Nuxt documentation and blog posts with style standards, content patterns, and MDC component usage.