
Peer Review Specialist
Deliver rigorous peer reviews with structured feedback and actionable insights
What You Can Do
This skill provides a comprehensive framework for conducting structured peer reviews that balance technical rigor with constructive feedback. It systematically evaluates code quality, architecture decisions, testing, security, and documentation while delivering specific, prioritized recommendations. You'll ensure consistent, professional review standards across your team and help developers grow through clear, actionable guidance.
Features
Examines functionality, code quality, design patterns, performance, security, testing, and documentation in a structured sequence
Combines technical rigor with constructive guidance, highlighting strengths before addressing areas for improvement
Categorizes issues as critical, major, minor, or style to help prioritize fixes and guide implementation urgency
Transforms observations into specific, implementable improvements with code examples and rationale when applicable
Assesses test coverage, test quality, edge case handling, and verification strategies for implementation
Identifies potential vulnerabilities, unsafe patterns, and violations of security best practices
Evaluates code comments, type hints, docstrings, function documentation, and architectural notes
Examines computational complexity, resource usage, and optimization opportunities relevant to context
Example Output
Peer Review: UserAuthenticationService
Summary
Solid implementation of JWT-based authentication with good error handling. Code is well-structured and documented. Primary opportunities: strengthen password validation, add rate limiting, and expand unit test coverage.
Strengths
✓ Clean separation of concerns — Token generation, validation, and refresh logic are properly isolated ✓ Comprehensive error handling — Specific error messages for debugging without exposing sensitive info ✓ Good inline documentation — Comments explain complex token claims and validation logic
Critical Issues (must address before merge)
- Missing rate limiting on login endpoint — Vulnerable to brute force attacks. Recommend: Redis-backed rate limiter (e.g.,
express-rate-limit)
Major Issues
- Password validation could be stronger — Currently requires 8 chars; consider NIST guidelines (min 12, no composition rules)
- Test coverage at 62% — Should reach 80%+ for security-critical code
Recommendations
- Implement exponential backoff rate limiting on
/auth/login - Upgrade password validation to follow NIST 800-63B guidelines
- Add integration tests for token refresh flow with expired tokens
- Document token claim structure in README
Testing & Coverage
- Current: 62% | Target: 80%+
- Missing: Edge cases around token expiry, concurrent refresh requests
- Good: Error path coverage, null input handling
Ready to merge? No — requires critical issues fixed first
What's Included
- Review framework template: Pre-built structure guiding you through systematic evaluation: Summary, Strengths, Issues, Recommendations, Testing, Security
- Severity classification guide: Clear definitions for critical, major, minor, and style issues with examples to calibrate your assessment
- Feedback patterns library: Pre-written constructive communication patterns for common issues (inconsistent naming, missing tests, etc.)
- Multi-layer evaluation checklist: Comprehensive checklist covering code quality, architecture, testing, security, documentation, and performance
- Example reviews: Full-length peer review examples showing proper structure, tone, and recommendation specificity across different domains
Who It's For
- Software engineers and developers
- Team leads and engineering managers
- Open source maintainers
- Senior architects and tech leads
- QA and code quality specialists
Best For
- Code reviews for feature pull requests
- Architecture and design pattern evaluation
- Security and performance audits
- Mentoring and learning-oriented feedback
- Refactoring and technical debt reviews






