code-review 2026

    1

    A multi-dimensional code review engine that enforces quality gates across correctness, security, and architecture.

    Free

    2 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    code-review 2026

    Example session with this skill installed

    Review this Python function for a new API endpoint:

    def get_user_data(user_id):
        query = "SELECT * FROM users WHERE id = " + user_id
        res = db.execute(query)
        return res.fetchall()
    
    • Read your context and instructions
    • Compiled the code-review 2026

    I have reviewed the get_user_data function against the five-axis quality standard. The implementation has significant security and correctness issues.

    Review: User Data API Endpoint

    Correctness

    • Change matches spec
    • Edge cases handled
    • Error paths handled
    • Tests adequate

    Security

    • No secrets in code
    • Input validated
    • No injection vulnerabilities
    • Auth checks
    • External data treated as untrusted

    Findings

    Critical: SQL Injection vulnerability. The user_id is concatenated directly into the query string. Use parameterized queries instead.
    Required: Input validation is missing. There is no check to ensure user_id is a valid format or exists before execution.
    Required: Error handling is missing. If the database connection fails or the query returns no results, the application may crash or return an unhandled exception.
    Nit: Use a more descriptive variable name than res to improve readability (e.g., user_records).

    Implementation Suggestion

    def get_user_data(user_id: str):
        try:
            # Use parameterized query to prevent SQL injection
            query = "SELECT id, username, email FROM users WHERE id = ?"
            cursor = db.execute(query, (user_id,))
            record = cursor.fetchone()
            
            if not record:
                return None
            return record
        except DatabaseError as e:
            logger.error(f"Failed to fetch user {user_id}: {e}")
            raise APIError("Internal Database Error")
    

    Verdict

    • Approve
    • Request changes — The SQL injection vulnerability must be fixed before this code is merged.

    Next steps

    1. Implement parameterized queries for all database interactions.
    2. Add a global error handler or local try-except block for database exceptions.
    3. Add a unit test specifically targeting the SQL injection vector.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The problem

    Manual code reviews are inconsistent, time-consuming, and prone to missing security flaws or architectural debt. Developers often struggle to distinguish between critical blockers and minor stylistic suggestions, leading to friction and delayed merges.

    What it does

    • Evaluates changes across five core axes: Correctness, Readability, Architecture, Security, and Performance.
    • Categorizes findings with clear severity labels like Critical, Required, Optional, and Nit.
    • Identifies structural regressions such as N+1 queries, leaked logic, and unnecessary complexity.
    • Performs automated security scans for secrets, injection vulnerabilities, and dependency risks.
    • Analyzes change sizing to prevent bloated, unreviewable pull requests.

    Why this beats prompting it yourself

    General-purpose prompts often miss subtle architectural smells or fail to enforce a consistent quality gate. This skill uses a structured multi-dimensional framework that forces deep inspection of edge cases, security boundaries, and code hygiene that typical chat interactions overlook.

    Use cases

    • Reviewing feature implementations before merging to the main branch.
    • Auditing AI-generated code to ensure it meets project standards and security requirements.
    • Identifying dead code and orphaned modules after a major refactor.
    • Enforcing consistent naming conventions and architectural patterns across a distributed team.

    Known limitations

    Automated security scans for dependencies require local package managers (npm, pip, go) to be installed. The skill evaluates code quality but cannot replace a full runtime integration test suite.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    2 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 18 days ago

    • Free to download with an account

    Needs access to

    Stackoverflow
    Web
    Postgresql
    Hpbn
    Owasp
    Mitre

    Listed18 days ago

    What's inside

    Frequently Asked Questions