code-reviewer
Reviews your code for bugs, security vulnerabilities, logic errors, performance issues, and style violations. Organizes findings by severity and suggests fixes with code examples.
Give your AI agent the ability to perform thorough code reviews, identify anti-patterns, suggest refactors, and enforce coding standards automatically across your codebase.
📖 Related guide: Best Code Review Skills for Claude Code →
81 skills
Reviews your code for bugs, security vulnerabilities, logic errors, performance issues, and style violations. Organizes findings by severity and suggests fixes with code examples.
Writes clear pull request descriptions by analyzing your branch diff. Covers what changed, why, how, and what to test. Works with GitHub, GitLab, and Bitbucket.
Turn your AI agent into a senior engineer with strict task classification and verification-driven coding protocols.
Expert Java code auditor for SE 8–24, flagging performance leaks, threading risks, and modernization gaps.
Technical Heilmeier-style analysis and critical review of academic papers from PDFs, arXiv links, or DOIs.
Expert risk analysis and revision suggestions for software sales, SaaS, and custom development contracts.
Audit and auto-fix agent skills to remove platform lock-in and ensure cross-platform compatibility.
Master the Agensi open standard to build, structure, and document reliable reusable skills for AI coding agents.
A multi-stage, evidence-grounded academic review agent modeled on the AAAI-26 AI Review Pilot research.

Best way to steer your agents, effortlessly.
Audit your codebase for technical debt and generate a prioritized, actionable remediation report.
A systematic framework to diagnose, refine, and harden existing AI agent skills based on real-world performance.
Transform technical debt into a prioritized roadmap with professional-grade refactoring reports.

Transforms vague coding requests into precise, scoped, testable, AI-ready prompts for Cursor, Claude Code, Codex CLI, Replit, and other coding agents.
Research comparable real projects before choosing, fixing, or shipping your project architecture.
Catches dangerous database migrations before they hit production. Reviews schema changes for locking hazards, data loss, missing rollbacks, and index issues across PostgreSQL, MySQL, and SQLite.
微信与支付宝小程序全栈开发助手。覆盖项目初始化、页面开发、组件编写、Bug检测与自动修复、支付收款集成、支付安全扫描、用户反馈收集与自动更新。

Creates safe modernization roadmaps for old, messy, undocumented, or fragile codebases, including risk audits, refactor phases, dependency reviews, testing plans, migration steps, and AI coding prompts.

Master Red-Green-Refactor with an opinionated TDD mentor that guides coding, reviews PRs, and secures legacy systems.
Enforce senior-level coding standards (Surgical, Simple, Goal-Driven) on every AI-generated code change.

Designs and upgrades business automation systems into modular, reliable, observable, secure, low-maintenance, enterprise-grade workflows.

Supercharge repo exploration and refactoring with semantic call-graph tracing and structural AST pattern matching.

Reviews contracts and DPAs for GDPR-related triage issues, extracts obligations, flags missing clauses, creates risk tables, and generates legal-review checklists.

Audit, score, and improve your AI agent skills for higher quality, lower token costs, better reliability, and marketplace success. Get actionable recommendations for prompts, instructions, tool usage, error handling, and user experience.

Analyze German legal contracts for risks, missing clauses, and compliance issues using AI.
Audit web pages against 13 technical SEO factors to generate structured compliance reports and prioritized code fixes.
A rigorous security auditor that scans code for OWASP Top 10 vulnerabilities with severity ratings and concrete fixes.
Audit applications against 12-Factor methodology to identify architectural risks and generate cloud-native fix plans.

Structured, severity-aware code reviews focusing on security, bugs, and performance across all major languages.

A pre-publish audit gate to extract claims, verify facts, and flag compliance risks in public-facing content.

Catch the dangerous migration before it locks or wrecks your production database. Scans SQL migration files for destructive and risky operations: DROP and TRUNCATE, drops without IF EXISTS, lossy column-type changes, NOT NULL added without a default, DELETE or UPDATE with no WHERE, non-concurrent index builds, dropped constraints, renames, and data backfills mixed into schema changes. Each finding is ranked by severity with a safer rewrite. Postgres, MySQL, and SQLite.

Architect safe, staged code migrations with zero-downtime patterns and automated rollback gates.
Expert guidance for native Kotlin Android development, architecture, Jetpack Compose, and Play Store readiness.

Lint your AGENTS.md (or CLAUDE.md and .cursorrules) for the problems that make a coding agent misbehave. Flags contradictory rules, references to files and commands that no longer exist, overly broad or unsafe instructions, missing sections (build, test, run, conventions), duplicate rules, and the case where you have competing rule files that should be consolidated into one AGENTS.md.
Automated risk classification and regression checking to stop AI agents from breaking your codebase.

Audit, verify, and format academic citations across AMA, APA, and Vancouver styles to eliminate AI hallucinations.
Scan multi-language codebases for unused variables, orphaned functions, and unreachable code with severity ranking.

Supercharge your agent with semantic code intelligence for safer refactors, precise navigation, and zero-error edits.

Automate information security assessments and drafting for procurement contracts, RFPs, and supplier agreements.
Idiomatic code translation between Python, TypeScript, and Go that preserves logic and adapts language-specific patterns.

Find and remove commented-out dead code across 8 languages (JS, TS, Python, Java, Go, Rust, HTML, CSS) while preserving TODOs, FIXMEs, license headers, disabled tests, and real documentation. Previews every change first and writes .bak backups before it touches a file.
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.

Systematically refactor large codebases, eliminate circular dependencies, and define clean module boundaries.
Production-grade 3-layer agent orchestration with dual-blind verification and automated model routing.
Rapid legal screening and risk assessment for NDAs with traffic-light scoring and counter-proposals.

Teaches AI coding agents to make software engineering decisions before coding, including layer placement, complexity control, refactor timing, and framework-change assessment.

Check a desired handle against every platform's username rules and find the form that works everywhere. Flags handles that break a platform's length limits, use a disallowed character (like a period on YouTube or TikTok), or start with a disallowed character, and recommends the safe consistent form (4 to 15 lowercase alphanumeric). Covers X, Instagram, TikTok, YouTube, Twitch, GitHub, and Bluesky. It checks the rules, not availability.

Reconstruct architecture and map risks in inherited legacy codebases with evidence-based auditing and migration plans.
Automated, high-precision code reviews that detect bugs, security flaws, and performance bottlenecks in your PRs.
A complete Manifest V3 Chrome extension to detect and highlight manipulative UI dark patterns on any website.
A rigorous, safety-first framework for planning and executing code changes in complex or production environments.
Benchmark your DevOps performance against DORA standards and generate a prioritized 90-day improvement roadmap.

Map any repo into an interactive D3 dependency graph plus a Markdown onboarding guide: entry points, module relationships, circular dependencies, and dead-code candidates, with refactor suggestions. Parses TypeScript, Python, Java, Go, and Rust imports, exports, and calls. Self-contained HTML, no source changes.
Professional audit tool to detect and fix React hooks anti-patterns, stale closures, and performance bottlenecks.
Reviewer left comments and your PR is stuck? Find the #1 blocking comment and get a finished reply — acknowledge, the fix, what to test — written to move the reviewer to approve.
Three-pass automated code review that catches error handling gaps, structural issues, and naming problems — then auto-fixes everything before code reaches the user.
Generate meaningful, maintainable tests that actually protect your code — not just inflate coverage numbers.
A professional framework for designing consistent, observable, and resilient error handling architectures.

Hold your bios, footers, and profiles to one brand spec. Flags brand-name spelling and casing that does not match your canonical form, off-spec taglines, links that are not on your official list, leftover placeholders (Lorem, TODO, "your tagline here"), and handles that differ from one surface to the next. You define the spec once and it enforces it everywhere.
Audit SQL and ORM queries for security vulnerabilities, N+1 performance issues, and indexing anti-patterns.

Transform raw 360-degree feedback and performance reviews into a prioritized leadership development roadmap.
Protect Java desktop apps by migrating sensitive logic and API keys to a secure, Cloudflare-backed thin-client architecture.
Transform your agent into a Senior Engineer that analyzes architecture and reuses code before writing a single line.

Audits AI agent failures and converts recurring mistakes into durable rules, anti-patterns, regression tests, memory candidates, and improved SKILL.md sections.
Master the Grok Build CLI with professional workflows, safety protocols, and structured plan-mode discipline.
Audit codebases for structural debt, TODOs, and dependency rot to generate prioritized remediation reports.

Professional-grade legal contract analysis with automated redlining and playbook-aligned risk assessment.
Enforce senior-level coding standards with a focus on verification, minimal diffs, and evidence-based bug fixing.

Lint a prompt template for the issues that cause injection and flaky output. Flags untrusted variables interpolated straight into the instructions (the injection surface), placeholders that are never provided or never used, contradictory instructions, a missing output-format spec where the result is parsed, unbounded context interpolation, and leftover placeholders. It detects problems; it does not write prompts.

An adversarial senior engineer review gate that audits AI-written code for security gaps and logic errors before shipping.

A senior-level code reviewer that uses Socratic questioning to identify architectural flaws and teach better patterns.
Professional-grade git diff auditor that identifies security vulnerabilities and code smells before you merge.

One-line summary description Stop your agent from claiming "done" before it's proven. A verification gate that classifies each change by risk (payment, auth, database, user-facing), picks the tests that actually cover it, demands evidence, maps regression risk, and outputs an honest pass/fail report. Turns "looks good to me" into "here's what I ran, and here's what's still unverified."

An adversarial self-review gate that hunts your agent's weakest claim, overclaims, and missing limitations before a human sees the output.

Orchestrate independent reviews, adversarial audits, and multimodal analysis via secondary models and external tools.

Expert accessibility auditing that prioritizes user impact and provides production-ready code fixes for WCAG compliance.
A disciplined, safety-first framework for refactoring legacy codebases using incremental modernization patterns.

Rigorous academic and internal research verification to score idea novelty and identify prior work.

First-pass screener that flags AI-generated, paper-mill, and fabricated scholarship using tortured-phrase, citation, statistical, and template detectors.
Detect and fix the 9 most expensive PySpark anti-patterns to slash your Spark compute costs.

An adversarial gate that audits any chart, data summary, or statistic for misleading visuals and unsound inference, then returns one PASS/REVISE/FAIL verdict.