Wave 11·Skills.sh · part of AI Dimensie·Why Skills.sh? →·⌘K jump
aidimension UI built-in skill

Code Review

Review a PR or diff for style, correctness, security, and tests. Severity-tagged findings with a pass/fail verdict.

.skills/code-review/SKILL.md2650 charsagentreviewci
.skills/code-review/SKILL.md
GitHub
---
name: code-review
description: >
  Review a pull request or diff for style, correctness, security, and test
  coverage. Produces a structured report with severity-tagged findings, a
  pass/fail verdict, and a concrete list of blocking issues. Use when an
  author wants automated pre-merge review, when a reviewer needs a draft
  comment, or when a CI gate needs a machine-readable verdict.
when-to-use:
  - Reviewing a PR before merge
  - Drafting reviewer comments
  - Auditing a diff for security or correctness regressions
  - Enforcing a style or convention across many PRs
---

# Code Review

Run this skill on any pull request or local diff to get an evidence-backed
review with actionable findings.

## Overview

The skill inspects a diff (unified format or PR URL), groups hunks by file,
and evaluates each one against four lenses:

1. **Correctness** — bugs, off-by-one, type errors, missing null checks, race conditions.
2. **Security** — injection, auth bypass, secret leakage, SSRF, unsafe deserialization.
3. **Style** — naming, structure, dead code, duplication, idiomatic patterns.
4. **Tests** — coverage of new branches, edge cases, regression tests.

Each finding is tagged `blocker | major | minor | nit` and includes file,
line, the offending snippet, and a one-line fix suggestion.

## Usage examples

```bash
# Review the diff of the current branch vs main
npx skills run code-review --base main

# Review a PR by URL (GitHub, GitLab, or Bitbucket)
npx skills run code-review --pr https://github.com/org/repo/pull/42

# Review a unified diff piped from git
git diff main..HEAD | npx skills run code-review --stdin
```

## Parameters

| Name | Type | Default | Description |
|---|---|---|---|
| `diff` | string \| stdin | — | Unified diff text or `--stdin` flag. |
| `base` | string | `main` | Git base ref when reading from a checkout. |
| `pr` | string | — | PR URL; mutually exclusive with `diff`/`base`. |
| `ruleset` | string | `default` | `default`, `strict`, `security-only`, or a path to a YAML ruleset. |
| `max_findings` | int | `50` | Cap on the number of reported findings. |
| `fail_on` | enum | `major` | `blocker`, `major`, `minor`, `never`. |

## Expected output

JSON or Markdown report with:

- `verdict`: `pass | fail | warn`
- `summary`: 1–2 sentence overall assessment
- `findings`: array of `{ severity, file, line, rule, message, suggestion }`
- `metrics`: counts per severity, files changed, lines added/removed
- `next_steps`: ordered list of the top 3–5 fixes the author should ship

The skill exits non-zero when `verdict == fail` so it can drop straight into
a CI pipeline as a required check.

How to use this skill

These files live in the .skills/ directory of the aidimension UI repo. Open Design–compatible agents (Claude Code, Cursor, Cline, etc.) auto-detect them. You can also reference them directly:

# in your agent's config
- name: aidimension-ui
  source: https://github.com/javashn/aidimension-ui/tree/main/.skills