SkillsLib.ai

Code Review Checklist

Systematically audit code for security, performance, maintainability, and architectural issues

4.6(50 reviews)
500+ downloads
Updated Oct 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

This skill performs multi-dimensional code audits that go beyond surface-level feedback. You submit code in any major language (Python, JavaScript, Java, Go, Rust, etc.), and Claude systematically examines it against structured criteria: security vulnerabilities, performance anti-patterns, maintainability issues, test coverage gaps, naming conventions, and architectural pattern compliance. Each finding includes severity levels, remediation steps, and corrected code examples.

Features

Security vulnerability scanning

identifies OWASP top 10 risks, injection flaws, authentication weaknesses, and data exposure patterns

Performance anti-pattern detection

flags algorithmic inefficiencies, memory leaks, database query problems, and hot-path bottlenecks

Maintainability assessment

evaluates code complexity, readability, DRY violations, and refactoring opportunities

Test coverage analysis

identifies untested paths, missing edge case coverage, and suggests test scenarios

Naming and style compliance

checks variable/function naming conventions, consistency, and adherence to team standards

Architectural pattern validation

ensures SOLID principles, design pattern usage, and system cohesion

Severity-ranked findings

categorizes issues as critical, high, medium, or low with estimated remediation effort

Multi-language support

works with Python, JavaScript, Java, Go, Rust, C#, TypeScript, and other major languages

Example Output

Critical: SQL injection vulnerability in user search function

  • Issue: Direct string concatenation in database query: query = f"SELECT * FROM users WHERE name = '{user_input}'"
  • Risk: Attacker can execute arbitrary SQL commands
  • Fix: Use parameterized queries: cursor.execute("SELECT * FROM users WHERE name = ?", (user_input,))

High: Missing error handling in async operation

  • Issue: Promise chain in fetchUserData() lacks .catch() block
  • Impact: Unhandled rejection crashes application
  • Fix: Add .catch(error => logger.error('Fetch failed:', error))

Medium: Naming convention violation

  • Issue: Variable usrDta violates camelCase convention and lacks clarity
  • Fix: Rename to userData

What's Included

  • SKILL.md: Core instruction file with review methodology and severity framework
  • Security checklist: OWASP vulnerabilities, authentication, encryption, and data protection criteria
  • Performance audit template: Algorithm complexity, database query patterns, memory usage checks
  • Maintainability framework: Code complexity metrics, SOLID principles, technical debt assessment
  • Test coverage template: Test gap identification, edge case scenarios, coverage targets

Who It's For

  • Software engineers & developers — submitting code for peer review on pull requests
  • Tech leads & engineering managers — auditing team code quality and identifying training needs
  • Security engineers — reviewing code in security-sensitive areas (auth, payments, healthcare)
  • QA/test engineers — identifying test coverage gaps and suggesting test scenarios
  • Architects — validating architectural compliance and design pattern usage

Best For

  • Pull request reviews before merge — catching issues before they reach production
  • Legacy code refactoring — identifying technical debt and modernization priorities
  • Security-critical features — auth systems, payment processing, data handling code
  • Performance optimization reviews — database queries, algorithms, hot-path code
  • Team onboarding — educating new developers on code standards through structured feedback
  • Architectural validation — ensuring SOLID principles and design pattern compliance

You might also like

Database Performance Tuning Analyzer
$45
Database Performance Tuning Analyzer

You can systematically diagnose database performance bottlenecks by sharing your schema, slow query logs, and execution plans with Claude. It identifies root causes—missing indexes, inefficient joins, lock contention—and provides prioritized recommendations with ready-to-implement SQL. Skip the manual log analysis and get tuning strategies tailored to your workload.

Database Performance Tuning Analyst
$30
Database Performance Tuning Analyst

Use Claude to systematically analyze your database queries, execution plans, and schema to identify performance bottlenecks. The skill generates actionable optimization recommendations with SQL rewrites, index strategies, and configuration tuning. You'll receive detailed before-and-after performance analysis to validate improvements and prioritize work by impact.

IRB Compliance Protocol Assessment and Documentation
$35
IRB Compliance Protocol Assessment and Documentation

This skill evaluates your research protocols against institutional review board requirements, identifies compliance gaps, and generates the documentation needed for IRB submission. You receive a detailed assessment report, risk analysis, and ready-to-use documentation templates tailored to your specific research design.

Cloud Architecture Design & Decision Framework
$30
Cloud Architecture Design & Decision Framework

You can systematically evaluate cloud platforms, document architectural decisions with tradeoffs, and validate designs against security and compliance requirements. This skill accelerates architecture reviews, ensures consistency across teams, and reduces the cycles needed to reach approval on complex infrastructure decisions.

Mobile Feature Architecture & Implementation
$40
Mobile Feature Architecture & Implementation

You'll design and implement mobile features with architectural rigor, cross-platform considerations, and edge-case handling built-in. This skill generates complete system designs, platform-specific implementation strategies, performance optimization approaches, and testing frameworks. The output is production-ready guidance spanning iOS and Android with security, offline resilience, and deployment strategies included.

Implement Task
$35
Full-Stack4.6(48)
Implement Task

You can deploy this agent to execute specific implementation tasks within a larger development plan. It operates independently with fresh context, follows test-driven development principles for every code change, and creates comprehensive handoff documentation that captures progress, decisions, and learnings for the next task executor. This ensures consistent code quality, prevents rework, and maintains continuity across distributed implementation efforts.

Injectable Formulation Development Assistant
$40
Injectable Formulation Development Assistant

Design and optimize injectable formulations by analyzing your active pharmaceutical ingredient (API), selecting compatible excipients, and predicting stability outcomes. You'll receive systematic workflows that guide you through API characterization, formulation architecture, and risk mitigation—enabling faster development cycles and regulatory-ready documentation.

Smart Contract Security Analysis & Code Review
$20
Smart Contract Security Analysis & Code Review

Analyze Solidity and other smart contract code for security vulnerabilities, gas inefficiencies, and best practice violations. Get detailed reports with risk scoring, remediation suggestions, and optimization recommendations. Whether you're auditing before deployment or reviewing third-party contracts, this skill identifies critical issues faster than manual review.

$30.00