- Home
- Skills
- Code Quality & Review
- code review excellence
Works with the AI tools you already use
code review excellence
Structured code and PR reviews with severity-based findings, security checks, and test quality audits.
$8
code review excellence
Example session with this skill installed
Review this diff for a Node.js API endpoint. It adds a new GET /user/:id route. I've attached the code and the test file. Business objective: fast retrieval for the profile page.
- Read your context and instructions
- Compiled the code review excellence
- Generated the document
I have reviewed the changes for the GET /user/:id endpoint. The review focuses on security, performance, and test quality based on the provided diff and test suite.
Code Review Report: User Profile API
| Severity | Category | File:Line | Finding | Rationale |
|---|---|---|---|---|
| BLOCKING | Security | routes/user.js:14 | Potential NoSQL Injection | The id param is passed directly to the find() query without validation. |
| IMPORTANT | Performance | services/userService.js:22 | Missing Projection | The query fetches the entire user object, including password_hash, when only profile data is needed. |
| SUGGESTION | Maintainability | tests/user.test.js:45 | Hardcoded ID | The test uses a static UUID. Using a factory or dynamic ID improves test isolation. |
| PRAISE | Correctness | middleware/auth.js:5 | Robust Auth | Good use of early returns for unauthorized tokens. |
Detailed Findings
[BLOCKING] NoSQL Injection Risk
- Evidence:
db.users.find({ _id: req.params.id })
Rationale: Untrusted input from the URL segment is used in a database query. Attackers could pass query operators to bypass filters.
- Suggested Change:
const userId = String(req.params.id);
if (!isValidObjectId(userId)) return res.status(400).send('Invalid ID');
db.users.find({ _id: userId });
[IMPORTANT] Data Over-fetching
- Evidence: The current implementation returns all fields.
- Rationale: Minimizing payload size improves response times and prevents accidental PII leaks.
- Suggested Change: Add
.select('username email bio avatar')to the Mongoose query.
Verdict
REQUEST CHANGES
The injection vulnerability must be addressed before this is merged.
Next steps
- Sanitize the
req.params.idinput. - Add a projection to the database query to limit returned fields.
- Update the test suite to include a case for invalid ID formats.
code-review-excellence.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Manual code reviews often miss critical security flaws or architectural debt because reviewers get bogged down in syntax nits. Teams struggle with inconsistent feedback quality and lack a structured way to prioritize blocking issues over minor suggestions.
What it does
- Analyzes pull requests and diffs to identify logic errors, security risks, and maintenance debt.
- Categorizes findings by severity: blocking issues, important suggestions, questions, and praise.
- Evaluates test coverage and quality to ensure changes are verified before approval.
- Provides actionable recommendations with clear rationales and validation steps.
Why this beats prompting it yourself
Generic prompts often result in "LGTM" or shallow formatting critiques. This skill enforces a rigorous severity classification system and prevents the AI from fabricating test results or ignoring missing context, ensuring every finding is backed by evidence from your specific files.
Use cases
- Reviewing complex pull requests for architectural alignment and security risks.
- Auditing test quality and coverage for mission-critical features.
- Standardizing review comments across a large engineering team.
- Summarizing technical decisions and risks for stakeholders during a release cycle.
Known limitations
Does not execute code or run actual CI/CD pipelines. It cannot replace formal security assurance or automated linting tools for style enforcement.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install