2
    code-review-buddy

    Code Review Buddy

    by Roy Yuen

    Structured, severity-aware code reviews focusing on security, bugs, and performance across all major languages.

    Updated Jun 2026
    Security scanned
    Cursor

    $5

    · or 25 credits

    30-day refund guarantee

    Secure checkout via Stripe

    Included in download

    • Identify SQL injection and local path traversal vulnerabilities in web code.
    • Detect resource leaks like unclosed files or database connections.
    • terminal automation included
    • Ready for Cursor
    • Instant install

    Sample input

    Review this Python function for security issues and efficiency: def get_user(id): query = "SELECT * FROM users WHERE id = " + id return db.execute(query).fetchall()

    Sample output

    🔍 Code Review: User Query Function Language: Python

    🔴 Securityline 2 SQL injection risk via string concatenation. Fix: Use parameterized queries: db.execute("SELECT * FROM users WHERE id = ?", (id,))

    Summary: 1 issue found — 1 critical Verdict: 🛑 Do not ship

    Screenshots

    About This Skill

    High-Performance Code Review for Humans and Agents

    Code Review Buddy is a developer-centric skill designed to provide structured, actionable feedback on code snippets, files, and pull requests. Unlike generic AI suggestions, this skill follows a strict hierarchical review process that prioritizes critical security vulnerabilities and functional bugs over subjective style choices.

    What it does

    • Security First: Scans for SQL injection, path traversal, hardcoded secrets, and unsafe deserialization across multiple languages.
    • Bug Detection: Identifies logic errors, race conditions, resource leaks, and language-specific pitfalls (like Python's mutable default arguments).
    • Performance Analytics: Flags N+1 queries, inefficient string operations, and memory-intensive file handling.
    • Agent Skill Validation: A unique feature that audits other AI agent skill files for YAML syntax, workflow logic, and trigger consistency.

    Why use this skill

    Stop wasting time on "style lectures." This skill focuses on code health and correctness. It generates standardized reports with severity icons (🔴 Critical to ⚪ Info), making it easy to see exactly what needs to be fixed before a merge. It understands the nuances of Python, JavaScript, TypeScript, Go, and Shell, applying language-specific best practices out of the box. Output is formatted specifically for terminal-based developers and AI IDEs like Cursor or Claude Code.

    Use Cases

    • Identify SQL injection and local path traversal vulnerabilities in web code.
    • Detect resource leaks like unclosed files or database connections.
    • Verify AI agent skill files for YAML errors and workflow logic gaps.
    • Optimize O(n²) loops and inefficient data structure handling.
    • Audit shell scripts for unquoted variables and unsafe command execution.

    Reviews

    No reviews yet - be the first to share your experience.

    Only users who have downloaded or purchased this skill can leave a review.

    Security Scanned

    Passed automated security review

    Permissions

    Terminal / Shell

    File Scopes

    code-review-buddy/**

    Optimized for terminal and IDE-based agents like Claude Code, Cursor, and Aider.

    Creator

    Frequently Asked Questions

    More Premium Skills