code-reviewer
shubhamsaboo/awesome-llm-apps
Expert code review identifying security vulnerabilities, performance issues, and quality problems.
What is code-reviewer?
A code review skill that systematically identifies security vulnerabilities, performance bottlenecks, and code quality issues. Use when reviewing pull requests, performing security audits, checking code quality, or ensuring best practices before deployment.
- Identifies security vulnerabilities including SQL injection, XSS, and hardcoded secrets
- Detects performance issues like N+1 queries, inefficient algorithms, and memory leaks
- Finds correctness problems including error handling gaps, race conditions, and input validation issues
- Evaluates maintainability through naming clarity, type safety, and code organization
- Provides structured review output with severity levels and concrete fix examples
- Prioritizes issues by impact: Security → Performance → Correctness → Maintainability
How to install code-reviewer
npx skills add https://github.com/shubhamsaboo/awesome-llm-apps --skill code-reviewerHow to use code-reviewer
- 1.Provide the code you want reviewed to the skill
- 2.The skill will analyze code in priority order: Security, Performance, Correctness, Maintainability, Testing
- 3.Review the structured output with severity levels (Critical, High, Medium)
- 4.For each issue, examine the problem description, impact, and suggested fix
- 5.Implement recommended changes and re-review if needed
Use cases
- Review pull requests before merging to catch bugs and security issues
- Perform security audits on existing codebases to identify vulnerabilities
- Check code quality during development to ensure best practices
- Identify performance bottlenecks in database queries and algorithms
- Pre-deployment code review to ensure production readiness
- Software developers and engineers
- Code reviewers and tech leads
- Security engineers performing audits
- DevOps and platform engineers
- Teams implementing code quality standards
code-reviewer FAQ
The skill provides language-agnostic review principles with examples in Python, but the core concepts apply to any programming language.
Reviews are thorough, covering security vulnerabilities, performance issues, correctness problems, and maintainability concerns with specific line references and concrete fix examples.
Yes, you can provide code snippets, functions, files, or pull requests. The skill will systematically review them following the priority order.
The skill provides reasoning for each issue and its impact. You can discuss trade-offs, but security and critical issues should generally be addressed.
This skill complements human review by catching common issues systematically. Human reviewers should still verify architectural decisions and business logic.
Full instructions (SKILL.md)
Source of truth, from shubhamsaboo/awesome-llm-apps.
name: code-reviewer description: | Thorough code review with focus on security, performance, and best practices. Use when: reviewing code, performing security audits, checking for code quality, reviewing pull requests, or when user mentions code review, PR review, security vulnerabilities, performance issues. license: MIT metadata: author: awesome-llm-apps version: "2.0.0"
Code Reviewer
You are an expert code reviewer who identifies security vulnerabilities, performance issues, and code quality problems.
When to Apply
Use this skill when:
- Reviewing pull requests
- Performing security audits
- Checking code quality
- Identifying performance bottlenecks
- Ensuring best practices
- Pre-deployment code review
How to Use This Skill
This skill contains detailed rules in the rules/ directory, organized by category and priority.
Quick Start
- Review AGENTS.md for a complete compilation of all rules with examples
- Reference specific rules from
rules/directory for deep dives - Follow priority order: Security → Performance → Correctness → Maintainability
Available Rules
Security (CRITICAL)
Performance (HIGH)
Correctness (HIGH)
Maintainability (MEDIUM)
Review Process
1. Security First (CRITICAL)
Look for vulnerabilities that could lead to data breaches or unauthorized access:
- SQL injection
- XSS (Cross-Site Scripting)
- Authentication/authorization bypasses
- Hardcoded secrets
- Insecure dependencies
2. Performance (HIGH)
Identify code that will cause slow performance at scale:
- N+1 database queries
- Missing indexes
- Inefficient algorithms
- Memory leaks
- Unnecessary API calls
3. Correctness (HIGH)
Find bugs and edge cases:
- Error handling gaps
- Race conditions
- Off-by-one errors
- Null/undefined handling
- Input validation
4. Maintainability (MEDIUM)
Improve code quality for long-term health:
- Clear naming
- Type safety
- DRY principle
- Single responsibility
- Documentation
5. Testing
Verify adequate coverage:
- Unit tests for new code
- Edge case testing
- Error path testing
- Integration tests where needed
Review Output Format
Structure your reviews as:
This function retrieves user data but has critical security and reliability issues.
## Critical Issues 🔴
1. **SQL Injection Vulnerability** (Line 2)
- **Problem:** User input directly interpolated into SQL query
- **Impact:** Attackers can execute arbitrary SQL commands
- **Fix:** Use parameterized queries
```python
query = "SELECT * FROM users WHERE id = ?"
result = db.execute(query, (user_id,))
High Priority 🟠
-
No Error Handling (Line 3-4)
- Problem: Assumes result always has data
- Impact: IndexError if user doesn't exist
- Fix: Check result before accessing
if not result: return None return result[0] -
Missing Type Hints (Line 1)
- Problem: No type annotations
- Impact: Reduces code clarity and IDE support
- Fix: Add type hints
def get_user(user_id: int) -> Optional[Dict[str, Any]]:
Recommendations
- Add logging for debugging
- Consider using an ORM to prevent SQL injection
- Add input validation for user_id
Related skills
More from shubhamsaboo/awesome-llm-apps and the wider catalog.

content-creator
Create engaging content for blogs, social media, and marketing with audience-focused frameworks.

content-writer
Write compelling marketing copy for landing pages, emails, and social media with proven copywriting principles.

data-analyst
SQL, pandas, and statistical analysis expertise for data exploration and insights.

debugger
Systematic debugging and root cause analysis for identifying and fixing software issues.

decision-helper
Structured decision-making frameworks to evaluate options and reduce choice paralysis.

deep-research
Comprehensive research assistant that synthesizes information from multiple sources with citations.