SkillsLib.ai

Code Review Checklist

Systematically audit code for security, performance, maintainability, and architectural issues

4.6(50 reviews)
500+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

This skill performs multi-dimensional code audits that go beyond surface-level feedback. You submit code in any major language (Python, JavaScript, Java, Go, Rust, etc.), and Claude systematically examines it against structured criteria: security vulnerabilities, performance anti-patterns, maintainability issues, test coverage gaps, naming conventions, and architectural pattern compliance. Each finding includes severity levels, remediation steps, and corrected code examples.

Features

Security vulnerability scanning

identifies OWASP top 10 risks, injection flaws, authentication weaknesses, and data exposure patterns

Performance anti-pattern detection

flags algorithmic inefficiencies, memory leaks, database query problems, and hot-path bottlenecks

Maintainability assessment

evaluates code complexity, readability, DRY violations, and refactoring opportunities

Test coverage analysis

identifies untested paths, missing edge case coverage, and suggests test scenarios

Naming and style compliance

checks variable/function naming conventions, consistency, and adherence to team standards

Architectural pattern validation

ensures SOLID principles, design pattern usage, and system cohesion

Severity-ranked findings

categorizes issues as critical, high, medium, or low with estimated remediation effort

Multi-language support

works with Python, JavaScript, Java, Go, Rust, C#, TypeScript, and other major languages

Example Output

Critical: SQL injection vulnerability in user search function

  • Issue: Direct string concatenation in database query: query = f"SELECT * FROM users WHERE name = '{user_input}'"
  • Risk: Attacker can execute arbitrary SQL commands
  • Fix: Use parameterized queries: cursor.execute("SELECT * FROM users WHERE name = ?", (user_input,))

High: Missing error handling in async operation

  • Issue: Promise chain in fetchUserData() lacks .catch() block
  • Impact: Unhandled rejection crashes application
  • Fix: Add .catch(error => logger.error('Fetch failed:', error))

Medium: Naming convention violation

  • Issue: Variable usrDta violates camelCase convention and lacks clarity
  • Fix: Rename to userData

What's Included

  • SKILL.md: Core instruction file with review methodology and severity framework
  • Security checklist: OWASP vulnerabilities, authentication, encryption, and data protection criteria
  • Performance audit template: Algorithm complexity, database query patterns, memory usage checks
  • Maintainability framework: Code complexity metrics, SOLID principles, technical debt assessment
  • Test coverage template: Test gap identification, edge case scenarios, coverage targets

Who It's For

  • Software engineers & developers — submitting code for peer review on pull requests
  • Tech leads & engineering managers — auditing team code quality and identifying training needs
  • Security engineers — reviewing code in security-sensitive areas (auth, payments, healthcare)
  • QA/test engineers — identifying test coverage gaps and suggesting test scenarios
  • Architects — validating architectural compliance and design pattern usage

Best For

  • Pull request reviews before merge — catching issues before they reach production
  • Legacy code refactoring — identifying technical debt and modernization priorities
  • Security-critical features — auth systems, payment processing, data handling code
  • Performance optimization reviews — database queries, algorithms, hot-path code
  • Team onboarding — educating new developers on code standards through structured feedback
  • Architectural validation — ensuring SOLID principles and design pattern compliance

You might also like

Site Monitoring Compliance & Deviation Auditor
$45
Site Monitoring Compliance & Deviation Auditor

This skill enables you to automatically audit your websites against compliance standards and detect deviations from expected baselines. You can track regulatory requirements, identify policy violations, and generate compliance reports with actionable remediation steps. Monitor multiple sites simultaneously and maintain detailed audit trails for compliance documentation.

Chemical Process Safety Analyzer
$40
Chemical Process Safety Analyzer

Analyze chemical processes systematically to identify hazards, assess risks, and generate safety recommendations. You can perform HAZOP analyses, evaluate compliance with industry standards, conduct root-cause analysis of incidents, and develop emergency response procedures. The skill guides you through structured safety reviews that reduce the likelihood of accidents and regulatory violations.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

$50
Integration Architecture Assessor

This skill helps you systematically assess integration needs across your systems, design architecture patterns that scale with your organization, and identify technical and operational risks before implementation. You'll receive architecture recommendations aligned to your business constraints, clear integration roadmaps, and risk mitigation strategies that reduce deployment surprises. Get structured decision records suitable for architecture review boards and engineering teams.

Chemical Process Hazard Analysis and Control Design
$30
Chemical Process Hazard Analysis and Control Design

You can conduct comprehensive hazard analyses for chemical processes using industry-standard methodologies like HAZOP and LOPA. The skill helps you assess risks quantitatively, identify control gaps, design engineered safeguards, and generate formal documentation for regulatory compliance and process safety management.

Git Commit Message Writer
$45
CI/CD4.3(47)
Git Commit Message Writer

Claude analyzes your code diffs and generates standardized commit messages that follow the Conventional Commits specification. The skill automatically determines the correct commit type, scope, and description based on the changes you've made, ensuring your messages are parseable by automation tools while remaining human-readable for code reviewers.

Structured NLP Analysis and Annotation with Claude
$35
NLP3.3(6)
Structured NLP Analysis and Annotation with Claude

You can transform raw text into structured, labeled datasets for machine learning, analysis, and research. This skill performs named entity recognition, sentiment classification, part-of-speech tagging, and dependency parsing—generating consistent, validated annotations at scale. Use it to prepare corpora, extract entities, classify documents, or perform linguistic analysis without manual annotation.

IoT Firmware Analysis & Device Debugger
$40
IoT Firmware Analysis & Device Debugger

Rapidly analyze firmware logs and diagnose hardware issues that cause device failures, connectivity problems, and performance degradation. You'll identify root causes from stack traces, crash dumps, and sensor data, then generate specific optimization recommendations. This skill transforms raw device logs into actionable debugging plans that reduce time-to-resolution from hours to minutes.

$30.00