mcpbeat Sign in

Code Review Pro Skill for Claude

Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.

1k tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
235
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/OneWave-AI/claude-skills --skill code-review-pro

The instruction itself

6 sections, as written by the author

Code Review Pro

Deep code analysis covering security, performance, maintainability, and best practices.

When to Use This Skill

Activate when the user:

  • Asks for a code review
  • Wants security vulnerability scanning
  • Needs performance analysis
  • Asks to "review this code" or "audit this code"
  • Mentions finding bugs or improvements
  • Wants refactoring suggestions
  • Requests best practice validation

Instructions

  • Security Analysis (Critical Priority)
  • SQL injection vulnerabilities
  • XSS (cross-site scripting) risks
  • Authentication/authorization issues
  • Secrets or credentials in code
  • Unsafe deserialization
  • Path traversal vulnerabilities
  • CSRF protection
  • Input validation gaps
  • Insecure cryptography
  • Dependency vulnerabilities
  • Performance Analysis
  • N+1 query problems
  • Inefficient algorithms (check Big O complexity)
  • Memory leaks
  • Unnecessary re-renders (React/Vue)
  • Missing indexes (database queries)
  • Blocking operations
  • Resource cleanup (file handles, connections)
  • Caching opportunities
  • Excessive network calls
  • Large bundle sizes
  • Code Quality & Maintainability
  • Code duplication (DRY violations)
  • Function/method length (should be <50 lines)
  • Cyclomatic complexity
  • Unclear naming
  • Missing error handling
  • Inconsistent style
  • Missing documentation
  • Hard-coded values that should be constants
  • God classes/functions
  • Tight coupling
  • Best Practices
  • Language-specific idioms
  • Framework conventions
  • SOLID principles
  • Design patterns usage
  • Testing approach
  • Logging and monitoring
  • Accessibility (for UI code)
  • Type safety
  • Null/undefined handling
  • Bugs and Edge Cases
  • Logic errors
  • Off-by-one errors
  • Race conditions
  • Null pointer exceptions
  • Unhandled edge cases
  • Timezone issues
  • Encoding problems
  • Floating point precision
  • Provide Actionable Fixes
  • Show specific code changes
  • Explain why change is needed
  • Include before/after examples
  • Prioritize by severity

Output Format

# Code Review Report

## Critical Issues (Fix Immediately)
### 1. SQL Injection Vulnerability (line X)
**Severity**: Critical
**Issue**: User input directly concatenated into SQL query
**Impact**: Database compromise, data theft

**Current Code:**

const query = SELECT * FROM users WHERE email = '${userEmail}';


**Fixed Code:**

const query = 'SELECT * FROM users WHERE email = ?';

db.query(query, [userEmail]);


**Explanation**: Always use parameterized queries to prevent SQL injection.

## High Priority Issues
### 2. Performance: N+1 Query Problem (line Y)
[Details...]

## Medium Priority Issues
### 3. Code Quality: Function Too Long (line Z)
[Details...]

## Low Priority / Nice to Have
### 4. Consider Using Const Instead of Let
[Details...]

## Summary
- **Total Issues**: 12
  - Critical: 2
  - High: 4
  - Medium: 4
  - Low: 2

## Quick Wins
Changes with high impact and low effort:
1. [Fix 1]
2. [Fix 2]

## Strengths
- Good error handling in X
- Clear naming conventions
- Well-structured modules

## Refactoring Opportunities
1. **Extract Method**: Lines X-Y could be extracted into `calculateDiscount()`
2. **Remove Duplication**: [specific code blocks]

## Resources
- [OWASP SQL Injection Guide](https://...)
- [Performance Best Practices](https://...)

Examples

User: "Review this authentication code"

Response: Analyze auth logic → Identify security issues (weak password hashing, no rate limiting) → Check token handling → Note missing CSRF protection → Provide specific fixes with code examples → Prioritize by severity

User: "Can you find performance issues in this React component?"

Response: Analyze component → Identify unnecessary re-renders → Find missing useMemo/useCallback → Note large state objects → Check for expensive operations in render → Provide optimized version with explanations

User: "Review this API endpoint"

Response: Check input validation → Analyze error handling → Test for SQL injection → Review authentication → Check rate limiting → Examine response structure → Suggest improvements with code samples

Best Practices

  • Always prioritize security issues first
  • Provide specific line numbers for issues
  • Include before/after code examples
  • Explain *why* something is a problem
  • Consider the language/framework context
  • Don't just criticize—acknowledge good code too
  • Suggest gradual improvements for large refactors
  • Link to documentation for recommendations
  • Consider project constraints (legacy code, deadlines)
  • Balance perfectionism with pragmatism
  • Focus on impactful changes
  • Group similar issues together
  • Make recommendations actionable

Other skills for the same job

different authors, same section of the catalogue
Receiving Code Review
by ZhanlinCui
×7

Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation

2k tokens
Requesting Code Review
by ZhanlinCui
×6

Use when completing tasks, implementing major features, or before merging to verify work meets requirements

2k tokens
Git Commit
by github
vendor ×3

Execute git commit with conventional commit message analysis, intelligent staging, and message generation. Use when user asks to commit changes, create a git commit, or mentions "/commit". Supports: (1) Auto-detecting type and scope from changes, (2) Generating conventional commit messages from diff, (3) Interactive commit with optional type/scope/description overrides, (4) Intelligent file staging for logical grouping

799 tokens
Github Code Review
by ComeOnOliver
×3

Comprehensive GitHub code review with AI-powered swarm coordination

13k tokens
Karpathy Guidelines
by hyyhf
×3

Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.

629 tokens
Code Reviewer
by google-gemini
vendor ×2

Use this skill to review code. It supports both local changes (staged or working tree) and remote Pull Requests (by ID or URL). It focuses on correctness, maintainability, and adherence to project standards.

795 tokens
Agent MD Refactor
by softaworks
×2

Refactor bloated AGENTS.md, CLAUDE.md, or similar agent instruction files to follow progressive disclosure principles. Splits monolithic files into organized, linked documentation.

4k tokens
Commit Work
by softaworks
×2

Create high-quality git commits: review/stage intended changes, split into logical commits, and write clear commit messages (including Conventional Commits). Use when the user asks to commit, craft a commit message, stage changes, or split work into multiple commits.

2k tokens

How to use it

Copy the folder

Take onewave-ai/code-review-pro from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.