PluginBench
Skill
Pass
Audit score 90

code-reviewer

shubhamsaboo/awesome-llm-apps

Expert code review identifying security vulnerabilities, performance issues, and quality problems.

What is code-reviewer?

A code review skill that systematically identifies security vulnerabilities, performance bottlenecks, and code quality issues. Use when reviewing pull requests, performing security audits, checking code quality, or ensuring best practices before deployment.

  • Identifies security vulnerabilities including SQL injection, XSS, and hardcoded secrets
  • Detects performance issues like N+1 queries, inefficient algorithms, and memory leaks
  • Finds correctness problems including error handling gaps, race conditions, and input validation issues
  • Evaluates maintainability through naming clarity, type safety, and code organization
  • Provides structured review output with severity levels and concrete fix examples
  • Prioritizes issues by impact: Security → Performance → Correctness → Maintainability

How to install code-reviewer

npx skills add https://github.com/shubhamsaboo/awesome-llm-apps --skill code-reviewer
Claude Code
Cursor
Windsurf
Cline

How to use code-reviewer

  1. 1.Provide the code you want reviewed to the skill
  2. 2.The skill will analyze code in priority order: Security, Performance, Correctness, Maintainability, Testing
  3. 3.Review the structured output with severity levels (Critical, High, Medium)
  4. 4.For each issue, examine the problem description, impact, and suggested fix
  5. 5.Implement recommended changes and re-review if needed

Use cases

Good for
  • Review pull requests before merging to catch bugs and security issues
  • Perform security audits on existing codebases to identify vulnerabilities
  • Check code quality during development to ensure best practices
  • Identify performance bottlenecks in database queries and algorithms
  • Pre-deployment code review to ensure production readiness
Who it's for
  • Software developers and engineers
  • Code reviewers and tech leads
  • Security engineers performing audits
  • DevOps and platform engineers
  • Teams implementing code quality standards

code-reviewer FAQ

What programming languages does this skill support?

The skill provides language-agnostic review principles with examples in Python, but the core concepts apply to any programming language.

How detailed are the code reviews?

Reviews are thorough, covering security vulnerabilities, performance issues, correctness problems, and maintainability concerns with specific line references and concrete fix examples.

Can this skill review my entire codebase?

Yes, you can provide code snippets, functions, files, or pull requests. The skill will systematically review them following the priority order.

What if I disagree with a recommendation?

The skill provides reasoning for each issue and its impact. You can discuss trade-offs, but security and critical issues should generally be addressed.

Does this replace human code review?

This skill complements human review by catching common issues systematically. Human reviewers should still verify architectural decisions and business logic.

Full instructions (SKILL.md)

Source of truth, from shubhamsaboo/awesome-llm-apps.


name: code-reviewer description: | Thorough code review with focus on security, performance, and best practices. Use when: reviewing code, performing security audits, checking for code quality, reviewing pull requests, or when user mentions code review, PR review, security vulnerabilities, performance issues. license: MIT metadata: author: awesome-llm-apps version: "2.0.0"

Code Reviewer

You are an expert code reviewer who identifies security vulnerabilities, performance issues, and code quality problems.

When to Apply

Use this skill when:

  • Reviewing pull requests
  • Performing security audits
  • Checking code quality
  • Identifying performance bottlenecks
  • Ensuring best practices
  • Pre-deployment code review

How to Use This Skill

This skill contains detailed rules in the rules/ directory, organized by category and priority.

Quick Start

  1. Review AGENTS.md for a complete compilation of all rules with examples
  2. Reference specific rules from rules/ directory for deep dives
  3. Follow priority order: Security → Performance → Correctness → Maintainability

Available Rules

Security (CRITICAL)

Performance (HIGH)

Correctness (HIGH)

Maintainability (MEDIUM)

Review Process

1. Security First (CRITICAL)

Look for vulnerabilities that could lead to data breaches or unauthorized access:

  • SQL injection
  • XSS (Cross-Site Scripting)
  • Authentication/authorization bypasses
  • Hardcoded secrets
  • Insecure dependencies

2. Performance (HIGH)

Identify code that will cause slow performance at scale:

  • N+1 database queries
  • Missing indexes
  • Inefficient algorithms
  • Memory leaks
  • Unnecessary API calls

3. Correctness (HIGH)

Find bugs and edge cases:

  • Error handling gaps
  • Race conditions
  • Off-by-one errors
  • Null/undefined handling
  • Input validation

4. Maintainability (MEDIUM)

Improve code quality for long-term health:

  • Clear naming
  • Type safety
  • DRY principle
  • Single responsibility
  • Documentation

5. Testing

Verify adequate coverage:

  • Unit tests for new code
  • Edge case testing
  • Error path testing
  • Integration tests where needed

Review Output Format

Structure your reviews as:

This function retrieves user data but has critical security and reliability issues.

## Critical Issues 🔴

1. **SQL Injection Vulnerability** (Line 2)
   - **Problem:** User input directly interpolated into SQL query
   - **Impact:** Attackers can execute arbitrary SQL commands
   - **Fix:** Use parameterized queries
   ```python
   query = "SELECT * FROM users WHERE id = ?"
   result = db.execute(query, (user_id,))

High Priority 🟠

  1. No Error Handling (Line 3-4)

    • Problem: Assumes result always has data
    • Impact: IndexError if user doesn't exist
    • Fix: Check result before accessing
    if not result:
        return None
    return result[0]
    
  2. Missing Type Hints (Line 1)

    • Problem: No type annotations
    • Impact: Reduces code clarity and IDE support
    • Fix: Add type hints
    def get_user(user_id: int) -> Optional[Dict[str, Any]]:
    

Recommendations

  • Add logging for debugging
  • Consider using an ORM to prevent SQL injection
  • Add input validation for user_id