
Code Review Checklist
Systematically audit code for security, performance, maintainability, and architectural issues
What You Can Do
This skill performs multi-dimensional code audits that go beyond surface-level feedback. You submit code in any major language (Python, JavaScript, Java, Go, Rust, etc.), and Claude systematically examines it against structured criteria: security vulnerabilities, performance anti-patterns, maintainability issues, test coverage gaps, naming conventions, and architectural pattern compliance. Each finding includes severity levels, remediation steps, and corrected code examples.
Features
identifies OWASP top 10 risks, injection flaws, authentication weaknesses, and data exposure patterns
flags algorithmic inefficiencies, memory leaks, database query problems, and hot-path bottlenecks
evaluates code complexity, readability, DRY violations, and refactoring opportunities
identifies untested paths, missing edge case coverage, and suggests test scenarios
checks variable/function naming conventions, consistency, and adherence to team standards
ensures SOLID principles, design pattern usage, and system cohesion
categorizes issues as critical, high, medium, or low with estimated remediation effort
works with Python, JavaScript, Java, Go, Rust, C#, TypeScript, and other major languages
Example Output
Critical: SQL injection vulnerability in user search function
- Issue: Direct string concatenation in database query:
query = f"SELECT * FROM users WHERE name = '{user_input}'" - Risk: Attacker can execute arbitrary SQL commands
- Fix: Use parameterized queries:
cursor.execute("SELECT * FROM users WHERE name = ?", (user_input,))
High: Missing error handling in async operation
- Issue: Promise chain in
fetchUserData()lacks.catch()block - Impact: Unhandled rejection crashes application
- Fix: Add
.catch(error => logger.error('Fetch failed:', error))
Medium: Naming convention violation
- Issue: Variable
usrDtaviolates camelCase convention and lacks clarity - Fix: Rename to
userData
What's Included
- SKILL.md: Core instruction file with review methodology and severity framework
- Security checklist: OWASP vulnerabilities, authentication, encryption, and data protection criteria
- Performance audit template: Algorithm complexity, database query patterns, memory usage checks
- Maintainability framework: Code complexity metrics, SOLID principles, technical debt assessment
- Test coverage template: Test gap identification, edge case scenarios, coverage targets
Who It's For
- Software engineers & developers — submitting code for peer review on pull requests
- Tech leads & engineering managers — auditing team code quality and identifying training needs
- Security engineers — reviewing code in security-sensitive areas (auth, payments, healthcare)
- QA/test engineers — identifying test coverage gaps and suggesting test scenarios
- Architects — validating architectural compliance and design pattern usage
Best For
- Pull request reviews before merge — catching issues before they reach production
- Legacy code refactoring — identifying technical debt and modernization priorities
- Security-critical features — auth systems, payment processing, data handling code
- Performance optimization reviews — database queries, algorithms, hot-path code
- Team onboarding — educating new developers on code standards through structured feedback
- Architectural validation — ensuring SOLID principles and design pattern compliance







