Code Review
Review a PR or diff for style, correctness, security, and tests. Severity-tagged findings with a pass/fail verdict.
.skills/code-review/SKILL.md2650 charsagentreviewci
.skills/code-review/SKILL.md
---
name: code-review
description: >
Review a pull request or diff for style, correctness, security, and test
coverage. Produces a structured report with severity-tagged findings, a
pass/fail verdict, and a concrete list of blocking issues. Use when an
author wants automated pre-merge review, when a reviewer needs a draft
comment, or when a CI gate needs a machine-readable verdict.
when-to-use:
- Reviewing a PR before merge
- Drafting reviewer comments
- Auditing a diff for security or correctness regressions
- Enforcing a style or convention across many PRs
---
# Code Review
Run this skill on any pull request or local diff to get an evidence-backed
review with actionable findings.
## Overview
The skill inspects a diff (unified format or PR URL), groups hunks by file,
and evaluates each one against four lenses:
1. **Correctness** — bugs, off-by-one, type errors, missing null checks, race conditions.
2. **Security** — injection, auth bypass, secret leakage, SSRF, unsafe deserialization.
3. **Style** — naming, structure, dead code, duplication, idiomatic patterns.
4. **Tests** — coverage of new branches, edge cases, regression tests.
Each finding is tagged `blocker | major | minor | nit` and includes file,
line, the offending snippet, and a one-line fix suggestion.
## Usage examples
```bash
# Review the diff of the current branch vs main
npx skills run code-review --base main
# Review a PR by URL (GitHub, GitLab, or Bitbucket)
npx skills run code-review --pr https://github.com/org/repo/pull/42
# Review a unified diff piped from git
git diff main..HEAD | npx skills run code-review --stdin
```
## Parameters
| Name | Type | Default | Description |
|---|---|---|---|
| `diff` | string \| stdin | — | Unified diff text or `--stdin` flag. |
| `base` | string | `main` | Git base ref when reading from a checkout. |
| `pr` | string | — | PR URL; mutually exclusive with `diff`/`base`. |
| `ruleset` | string | `default` | `default`, `strict`, `security-only`, or a path to a YAML ruleset. |
| `max_findings` | int | `50` | Cap on the number of reported findings. |
| `fail_on` | enum | `major` | `blocker`, `major`, `minor`, `never`. |
## Expected output
JSON or Markdown report with:
- `verdict`: `pass | fail | warn`
- `summary`: 1–2 sentence overall assessment
- `findings`: array of `{ severity, file, line, rule, message, suggestion }`
- `metrics`: counts per severity, files changed, lines added/removed
- `next_steps`: ordered list of the top 3–5 fixes the author should ship
The skill exits non-zero when `verdict == fail` so it can drop straight into
a CI pipeline as a required check.
How to use this skill
These files live in the .skills/ directory of the aidimension UI repo. Open Design–compatible agents (Claude Code, Cursor, Cline, etc.) auto-detect them. You can also reference them directly:
# in your agent's config - name: aidimension-ui source: https://github.com/javashn/aidimension-ui/tree/main/.skills