code-reviewer

by Jeffallan 11k MIT Updated Aug 7, 2026
code-reviewer skill by Jeffallan
Social preview for Jeffallan/claude-skills

code-reviewer is an open-source security skill for Claude Code and compatible agents, published by Jeffallan. Its author describes it as: “Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured…”. The project has 11k stars on GitHub and is available under the MIT license. Add it to your setup with `/plugin marketplace add Jeffallan/claude-skills`.

What code-reviewer does

Senior engineer conducting thorough, constructive code reviews that improve quality and share knowledge.

Installation

Add code-reviewer to your agent with:

/plugin marketplace add Jeffallan/claude-skills

Always review a skill's source before installing it. This command comes from the skill's public repository; the linked repo is the source of truth for exact setup steps.

What's inside

The SKILL.md for code-reviewer is organised into these sections:

  • When to Use This Skill
  • Core Workflow
  • Reference Guide
  • Review Patterns (Quick Reference)
  • N+1 Query — Bad vs Good
  • Magic Number — Bad vs Good
  • Security: SQL Injection — Bad vs Good
  • Constraints
  • MUST DO
  • MUST NOT DO
  • Output Template
  • Knowledge Reference

When to use it

Reach for code-reviewer when you want security help from your agent without writing the same instructions every session. Load the skill and the agent picks it up automatically for relevant tasks.

Strengths

  • Clear MIT license — safe to read and adapt
  • Ships in Jeffallan/claude-skills, an established project with 11,060 GitHub stars
  • Actively maintained (recent commits)

Topics

ai-agentsclaudeclaude-codeclaude-marketplaceclaude-skills

Frequently asked questions

What does code-reviewer do?
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
How do I install code-reviewer?
Run /plugin marketplace add Jeffallan/claude-skills in your agent, then reload your skills. Review the source at https://github.com/Jeffallan/claude-skills before installing.
Is code-reviewer free to use?
Yes. code-reviewer is free and open source under the MIT license, so you can read, run, and adapt it within that license's terms.
Where does code-reviewer come from?
code-reviewer ships inside Jeffallan/claude-skills, a repository that contains 41 catalogued skills in total. The repository's 11,060 GitHub stars apply to that whole collection, not to this skill on its own.

Related skills

More Security →

State-of-the-Art (2026) AI/LLM engineering skills/agents for building and auditing software — 40+ domain & language skills, BUILD/AUDIT modes, audit checklists.

8 martinholovsky CC-BY-4.0

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

39k wshobson MIT

Meta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ TPR, <1% FPR. Fast (<2ms GPU). Multilingual (8 languages). Deploy with HuggingFace or batch processing for RAG security.

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.

3.2k elementalsouls Other

Whole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.

105k DietrichGebert MIT