Enterprise Code Review Skill
Purpose
This skill provides comprehensive, enterprise-grade critical code review following industry best practices. It analyzes codebases systematically across multiple dimensions: architecture, security, performance, maintainability, testing, and documentation.
When to Use
- Reviewing pull requests or merge requests
- Conducting pre-release code audits
- Evaluating code quality for legacy systems
- Onboarding code quality assessments
- Security and compliance reviews
- Architecture and design pattern validation
Review Philosophy
Critical but Constructive
- Identify real issues, not stylistic preferences
- Provide actionable feedback with specific examples
- Suggest concrete improvements with rationale
- Prioritize issues by severity (Critical, High, Medium, Low)
Comprehensive Coverage
- Focus on what matters: bugs, security, performance, maintainability
- Delegate formatting/style to automated tools
- Consider scalability and future maintenance
- Evaluate test coverage and quality
Efficiency Standards
- Optimal review: 200-400 lines of code at a time
- Break large changes into focused reviews
- Review at maximum 500 LOC/hour for thoroughness
- Prioritize high-risk and complex code sections
Review Methodology
Phase 1: Initial Assessment
Understand Context
- Read PR/commit description and linked issues
- Understand the feature/fix intent
- Review related documentation
- Identify affected systems and dependencies
Scope Analysis
- Count lines of code changed
- Identify file types and languages
- Assess complexity level
- Plan review approach (if >400 LOC, break into sections)
Phase 2: Systematic Review
A. Code Quality & Best Practices
Review for:
- Readability: Clear naming, logical structure, appropriate abstraction
- Maintainability: Modular design, DRY principle, no hard-coded values
- Consistency: Follows project conventions and patterns
- Complexity: Cyclomatic complexity, nested depth, function length
- Error Handling: Comprehensive exception handling, graceful degradation
- Logging: Appropriate logging levels and useful error messages
B. Security Review
Check for:
- Input Validation: All user inputs sanitized and validated
- Authentication/Authorization: Proper access controls implemented
- Data Protection: Sensitive data encrypted, no credentials in code
- Injection Vulnerabilities: SQL, XSS, command injection risks
- Dependencies: Known vulnerabilities in third-party libraries
- API Security: Rate limiting, CORS policies, secure headers
- Secrets Management: No API keys, tokens, or passwords in source
C. Performance Analysis
Evaluate:
- Algorithmic Efficiency: Optimal time/space complexity
- Database Operations: N+1 queries, missing indexes, inefficient joins
- Caching Strategy: Appropriate use of caching mechanisms
- Resource Management: Proper connection pooling, memory leaks
- Async Operations: Non-blocking I/O where appropriate
- Scalability: Can handle increased load and data volume
D. Architecture & Design
Assess:
- Design Patterns: Appropriate pattern usage and implementation
- SOLID Principles: Adherence to object-oriented design principles
- Separation of Concerns: Clear boundaries between layers
- API Design: RESTful principles, consistent endpoints, versioning
- Data Modeling: Normalized schema, appropriate relationships
- Dependency Management: Loose coupling, dependency injection
E. Testing & Quality Assurance
Verify:
- Test Coverage: Minimum 80% coverage for critical paths
- Test Quality: Unit, integration, and edge case coverage
- Test Maintainability: Clear test names, isolated tests, no flaky tests
- Mocking Strategy: Appropriate use of mocks and stubs
- Assertions: Meaningful and comprehensive assertions
- Test Data: Realistic test scenarios and boundary conditions
F. Documentation & Comments
Check:
- Code Comments: Explain WHY, not WHAT (code should be self-documenting)
- Function/Method Docs: Purpose, parameters, return values, exceptions
- API Documentation: Complete endpoint documentation
- README Updates: Installation, configuration, usage instructions
- Changelog: User-facing release notes
- Architecture Docs: High-level design decisions documented
Phase 3: Cross-Cutting Concerns
Backwards Compatibility
- Breaking changes identified and documented
- Migration paths provided
- Deprecation warnings where appropriate
- Version compatibility maintained
Deployment & Operations
- Configuration changes documented
- Database migrations included and tested
- Environment variable requirements specified
- Rollback procedures considered
Observability
- Appropriate metrics and monitoring
- Tracing for distributed systems
- Health check endpoints
- Diagnostic logging for troubleshooting
Phase 4: Synthesize Findings
Structure feedback as:
# Code Review Summary
## Overall Assessment
[High-level summary: Approve, Approve with minor changes, Request changes, Block]
## Critical Issues (Must Fix Before Merge)
- [Issue 1 with specific location and recommendation]
- [Issue 2 with specific location and recommendation]
## High Priority (Should Fix)
- [Issue with rationale and suggested approach]
## Medium Priority (Consider Fixing)
- [Improvement suggestion with benefits]
## Low Priority (Nice to Have)
- [Enhancement idea for future consideration]
## Positive Highlights
- [What was done well - be specific]
- [Good practices to recognize]
## Testing Notes
- Test coverage: [X]%
- Edge cases covered: [Yes/No/Partial]
- Integration tests: [Present/Missing]
## Security Assessment
- Vulnerabilities found: [None/List]
- Security best practices: [Followed/Gaps identified]
## Performance Impact
- Expected performance: [Improved/Neutral/Degraded]
- Scalability concerns: [None/List]
## Documentation Status
- Code documentation: [Complete/Needs improvement]
- User-facing docs: [Updated/Missing]
Review Checklists by Language
Python
JavaScript/TypeScript
Java
Go
C#/.NET
Common Anti-Patterns to Flag
Code Smells
- God objects (classes doing too much)
- Long methods (>50 lines)
- Deeply nested conditionals (>3 levels)
- Duplicate code blocks
- Magic numbers without constants
- Primitive obsession
- Feature envy (method using another class extensively)
Security Anti-Patterns
- Hardcoded credentials or secrets
- SQL string concatenation
- Unvalidated user input
- Missing CSRF protection
- Insecure deserialization
- Weak cryptography (MD5, SHA1)
- Overly permissive access controls
Performance Anti-Patterns
- N+1 database queries
- Missing database indexes
- Synchronous I/O in hot paths
- Memory leaks (unreleased resources)
- Inefficient string concatenation
- Redundant computations
- Unbounded collections
Tools Integration
When reviewing code, leverage these automated tools:
Static Analysis
- Python: pylint, mypy, bandit (security)
- JavaScript: ESLint, TypeScript compiler
- Java: SonarQube, SpotBugs, PMD
- Go: golint, go vet, staticcheck
- C#: Roslyn analyzers, SonarLint
Security Scanning
- SAST: Semgrep, CodeQL, Checkmarx
- SCA: Snyk, Dependabot, OWASP Dependency-Check
- Secrets: TruffleHog, GitGuardian, git-secrets
Code Quality Metrics
- Coverage: JaCoCo, Coverage.py, Istanbul
- Complexity: SonarQube, Code Climate
- Duplication: CPD, SonarQube
GitHub/GitLab Integration
When reviewing PRs/MRs:
Check CI Status First
- All tests passing
- Security scans clear
- Code coverage meets threshold
- Build successful
Review Commit History
- Commits are atomic and logical
- Commit messages are descriptive
- No merge commits (prefer rebase)
Provide Structured Feedback
- Use "Request changes" for blocking issues
- Use "Comment" for non-blocking suggestions
- Use "Approve" when ready to merge
- Add inline comments at specific lines
Review Conversation Resolution
- All review comments addressed
- Questions answered
- Requested changes implemented
Special Case Reviews
Legacy Code Refactoring
- Ensure test coverage exists before refactoring
- Changes don't alter behavior (unless intended)
- Refactoring is incremental
- Risk of regression assessed
Third-Party Integration
- API versioning strategy
- Rate limiting and retries implemented
- Fallback behavior defined
- Monitoring for API health
Database Schema Changes
- Migrations are reversible
- Backward compatibility maintained
- Indexes added for new queries
- Performance impact assessed with EXPLAIN
Microservices Changes
- Service boundaries respected
- Contract testing in place
- Circuit breakers implemented
- Distributed tracing configured
Review Workflow
For Project Folders
- Scan directory structure to understand architecture
- Identify entry points and critical paths
- Read configuration files first
- Review in order: models → services → controllers → tests
- Check for missing tests or documentation
For GitHub Repositories
- Clone repository or access via GitHub API
- Checkout the specific branch/PR
- Review PR description and linked issues
- Examine changed files in diff view
- Run automated checks locally if needed
- Provide structured feedback in PR comments
Review Prioritization
When dealing with large changes:
- Critical path first: Core business logic
- Security-sensitive code: Authentication, authorization, data handling
- Public APIs: Interfaces exposed to users/systems
- Database changes: Schema migrations, queries
- Configuration changes: Infrastructure, deployment
- Tests: Verify coverage and quality
- Documentation: README, API docs, comments
Communication Best Practices
Constructive Language
- ✅ "Consider using X pattern here for better maintainability"
- ❌ "This is wrong"
- ✅ "This could introduce a race condition if..."
- ❌ "You don't understand concurrency"
- ✅ "Adding error handling here would make this more robust"
- ❌ "Why didn't you handle errors?"
Actionable Feedback
- Be specific about location and issue
- Explain WHY something is a problem
- Suggest concrete alternatives
- Provide examples or references
- Link to documentation or style guides
Balanced Perspective
- Acknowledge good practices
- Separate blocking vs. non-blocking issues
- Consider trade-offs and context
- Recognize learning opportunities
Output Format
Always structure your review output as:
# Code Review: [Project/PR Name]
## Executive Summary
[2-3 sentence overview of changes and overall quality]
## Recommendation
[ ] ✅ Approve (Ready to merge)
[ ] ⚠️ Approve with minor suggestions (Non-blocking)
[ ] 🔴 Request changes (Blocking issues found)
[ ] ⛔ Block (Critical security/quality issues)
## Metrics
- Files changed: [X]
- Lines added: [X]
- Lines deleted: [X]
- Test coverage: [X]%
- Complexity score: [X]
***
## Critical Issues (Must Fix) 🔴
### 1. [Issue Title]
**Location**: `filename.ext:line`
**Severity**: Critical
**Issue**: [Detailed description]
**Impact**: [Security/Performance/Correctness impact]
**Recommendation**: [Specific fix with code example]
***
## High Priority (Should Fix) ⚠️
[Similar structure]
***
## Medium Priority (Consider) 💡
[Similar structure]
***
## Low Priority (Nice to Have) 📝
[Similar structure]
***
## Positive Highlights ⭐
- [Specific good practice 1]
- [Specific good practice 2]
***
## Testing Assessment
**Coverage**: [X]%
**Unit Tests**: [Count and quality assessment]
**Integration Tests**: [Count and quality assessment]
**Edge Cases**: [Covered/Missing]
**Missing Test Coverage**:
- [Specific scenario 1]
- [Specific scenario 2]
***
## Security Assessment 🔒
**Vulnerabilities**: [None/Count]
**Security Checklist**:
- [ ] Input validation
- [ ] Authentication/Authorization
- [ ] Data encryption
- [ ] Secrets management
- [ ] Dependency vulnerabilities
[Details of any issues]
***
## Performance Analysis ⚡
**Expected Impact**: [Positive/Neutral/Negative]
**Concerns**:
- [Specific concern with evidence]
**Recommendations**:
- [Performance improvement suggestion]
***
## Documentation Status 📚
- [ ] Code comments (WHY not WHAT)
- [ ] Function/method documentation
- [ ] README updated
- [ ] API documentation
- [ ] Changelog updated
***
## Additional Notes
[Any context-specific observations, architectural discussions, or follow-up items]
Self-Improvement
After each review:
- Note any missed issues that were found later
- Track review time vs code quality
- Refine checklists based on common findings
- Update language-specific checks based on evolving best practices
Limitations & Escalation
When to seek human expert review:
- Novel architectural patterns
- Complex distributed systems design
- Regulatory compliance requirements (HIPAA, GDPR, PCI)
- Cryptographic implementations
- Real-time system design
- Safety-critical code (medical, aviation, automotive)
Acknowledge uncertainty:
- Flag areas requiring domain expertise
- Note when trade-offs are context-dependent
- Suggest additional review by specialists
References
- Google Engineering Practices: Code Review Guidelines
- OWASP Top 10 Security Risks
- CERT Secure Coding Standards
- Martin Fowler's Refactoring Catalog
- Clean Code principles (Robert C. Martin)
- Effective Code Reviews (Best Practices 2025+)
Usage Instructions
For Claude.ai Desktop/Web
- Save this as
SKILL.md in a folder named enterprise-code-review
- Go to Settings > Skills
- Add custom skill by selecting the folder
- Enable code execution in settings
For Claude Code
- Create
skills/enterprise-code-review/ in your project root
- Place this
SKILL.md file there
- Claude will automatically detect and load the skill
Invoking the Skill
Simply ask Claude to:
- "Review this code using enterprise-code-review"
- "Perform a critical code review on [file/folder/repo]"
- "Analyze this PR following enterprise standards"
The skill will trigger automatically when code review is mentioned in context.
Version: 1.0.0
Last Updated: January 2026
Maintained by: Enterprise Architecture Team
1---2name: enterprise-code-review3description: Performs comprehensive enterprise-grade critical code review on project folders or GitHub repositories, focusing on quality, security, performance, maintainability, and best practices4---56# Enterprise Code Review Skill78## Purpose9This skill provides comprehensive, enterprise-grade critical code review following industry best practices. It analyzes codebases systematically across multiple dimensions: architecture, security, performance, maintainability, testing, and documentation.1011## When to Use12- Reviewing pull requests or merge requests13- Conducting pre-release code audits14- Evaluating code quality for legacy systems15- Onboarding code quality assessments16- Security and compliance reviews17- Architecture and design pattern validation1819## Review Philosophy2021### Critical but Constructive22- Identify real issues, not stylistic preferences23- Provide actionable feedback with specific examples24- Suggest concrete improvements with rationale25- Prioritize issues by severity (Critical, High, Medium, Low)2627### Comprehensive Coverage28- Focus on what matters: bugs, security, performance, maintainability29- Delegate formatting/style to automated tools30- Consider scalability and future maintenance31- Evaluate test coverage and quality3233### Efficiency Standards34- Optimal review: 200-400 lines of code at a time35- Break large changes into focused reviews36- Review at maximum 500 LOC/hour for thoroughness37- Prioritize high-risk and complex code sections3839## Review Methodology4041### Phase 1: Initial Assessment421. **Understand Context**43 - Read PR/commit description and linked issues44 - Understand the feature/fix intent45 - Review related documentation46 - Identify affected systems and dependencies47482. **Scope Analysis**49 - Count lines of code changed50 - Identify file types and languages51 - Assess complexity level52 - Plan review approach (if >400 LOC, break into sections)5354### Phase 2: Systematic Review5556#### A. Code Quality & Best Practices57Review for:58- **Readability**: Clear naming, logical structure, appropriate abstraction59- **Maintainability**: Modular design, DRY principle, no hard-coded values60- **Consistency**: Follows project conventions and patterns61- **Complexity**: Cyclomatic complexity, nested depth, function length62- **Error Handling**: Comprehensive exception handling, graceful degradation63- **Logging**: Appropriate logging levels and useful error messages6465#### B. Security Review66Check for:67- **Input Validation**: All user inputs sanitized and validated68- **Authentication/Authorization**: Proper access controls implemented69- **Data Protection**: Sensitive data encrypted, no credentials in code70- **Injection Vulnerabilities**: SQL, XSS, command injection risks71- **Dependencies**: Known vulnerabilities in third-party libraries72- **API Security**: Rate limiting, CORS policies, secure headers73- **Secrets Management**: No API keys, tokens, or passwords in source7475#### C. Performance Analysis76Evaluate:77- **Algorithmic Efficiency**: Optimal time/space complexity78- **Database Operations**: N+1 queries, missing indexes, inefficient joins79- **Caching Strategy**: Appropriate use of caching mechanisms80- **Resource Management**: Proper connection pooling, memory leaks81- **Async Operations**: Non-blocking I/O where appropriate82- **Scalability**: Can handle increased load and data volume8384#### D. Architecture & Design85Assess:86- **Design Patterns**: Appropriate pattern usage and implementation87- **SOLID Principles**: Adherence to object-oriented design principles88- **Separation of Concerns**: Clear boundaries between layers89- **API Design**: RESTful principles, consistent endpoints, versioning90- **Data Modeling**: Normalized schema, appropriate relationships91- **Dependency Management**: Loose coupling, dependency injection9293#### E. Testing & Quality Assurance94Verify:95- **Test Coverage**: Minimum 80% coverage for critical paths96- **Test Quality**: Unit, integration, and edge case coverage97- **Test Maintainability**: Clear test names, isolated tests, no flaky tests98- **Mocking Strategy**: Appropriate use of mocks and stubs99- **Assertions**: Meaningful and comprehensive assertions100- **Test Data**: Realistic test scenarios and boundary conditions101102#### F. Documentation & Comments103Check:104- **Code Comments**: Explain WHY, not WHAT (code should be self-documenting)105- **Function/Method Docs**: Purpose, parameters, return values, exceptions106- **API Documentation**: Complete endpoint documentation107- **README Updates**: Installation, configuration, usage instructions108- **Changelog**: User-facing release notes109- **Architecture Docs**: High-level design decisions documented110111### Phase 3: Cross-Cutting Concerns112113#### Backwards Compatibility114- Breaking changes identified and documented115- Migration paths provided116- Deprecation warnings where appropriate117- Version compatibility maintained118119#### Deployment & Operations120- Configuration changes documented121- Database migrations included and tested122- Environment variable requirements specified123- Rollback procedures considered124125#### Observability126- Appropriate metrics and monitoring127- Tracing for distributed systems128- Health check endpoints129- Diagnostic logging for troubleshooting130131### Phase 4: Synthesize Findings132133Structure feedback as:134135```136# Code Review Summary137138## Overall Assessment139[High-level summary: Approve, Approve with minor changes, Request changes, Block]140141## Critical Issues (Must Fix Before Merge)142- [Issue 1 with specific location and recommendation]143- [Issue 2 with specific location and recommendation]144145## High Priority (Should Fix)146- [Issue with rationale and suggested approach]147148## Medium Priority (Consider Fixing)149- [Improvement suggestion with benefits]150151## Low Priority (Nice to Have)152- [Enhancement idea for future consideration]153154## Positive Highlights155- [What was done well - be specific]156- [Good practices to recognize]157158## Testing Notes159- Test coverage: [X]%160- Edge cases covered: [Yes/No/Partial]161- Integration tests: [Present/Missing]162163## Security Assessment164- Vulnerabilities found: [None/List]165- Security best practices: [Followed/Gaps identified]166167## Performance Impact168- Expected performance: [Improved/Neutral/Degraded]169- Scalability concerns: [None/List]170171## Documentation Status172- Code documentation: [Complete/Needs improvement]173- User-facing docs: [Updated/Missing]174```175176## Review Checklists by Language177178### Python179- [ ] Type hints used for function signatures180- [ ] PEP 8 compliance (via automated tools)181- [ ] Virtual environment dependencies updated182- [ ] Context managers for resource handling183- [ ] List/dict comprehensions over loops (where appropriate)184- [ ] Async/await patterns for I/O operations185- [ ] Exception handling with specific exception types186187### JavaScript/TypeScript188- [ ] TypeScript types defined (no 'any')189- [ ] Promises handled with async/await or .catch()190- [ ] ESLint/TSLint rules followed191- [ ] Immutable patterns for state management192- [ ] Event listeners properly cleaned up193- [ ] Bundle size impact considered194- [ ] Browser compatibility verified195196### Java197- [ ] Exception handling with try-with-resources198- [ ] Thread safety for concurrent code199- [ ] Memory management (no potential leaks)200- [ ] Design patterns appropriately applied201- [ ] Dependency injection used202- [ ] Unit tests with JUnit/TestNG203- [ ] Lombok annotations used appropriately204205### Go206- [ ] Error handling (never ignore errors)207- [ ] Goroutines properly managed208- [ ] Context used for cancellation209- [ ] Defer for cleanup operations210- [ ] Interfaces defined appropriately211- [ ] Race conditions checked (go test -race)212- [ ] Channel operations don't deadlock213214### C#/.NET215- [ ] Async methods end with Async suffix216- [ ] IDisposable implemented for resources217- [ ] LINQ used appropriately218- [ ] Nullable reference types handled219- [ ] Exception handling with specific types220- [ ] Dependency injection configured221- [ ] Unit tests with xUnit/NUnit222223## Common Anti-Patterns to Flag224225### Code Smells226- God objects (classes doing too much)227- Long methods (>50 lines)228- Deeply nested conditionals (>3 levels)229- Duplicate code blocks230- Magic numbers without constants231- Primitive obsession232- Feature envy (method using another class extensively)233234### Security Anti-Patterns235- Hardcoded credentials or secrets236- SQL string concatenation237- Unvalidated user input238- Missing CSRF protection239- Insecure deserialization240- Weak cryptography (MD5, SHA1)241- Overly permissive access controls242243### Performance Anti-Patterns244- N+1 database queries245- Missing database indexes246- Synchronous I/O in hot paths247- Memory leaks (unreleased resources)248- Inefficient string concatenation249- Redundant computations250- Unbounded collections251252## Tools Integration253254When reviewing code, leverage these automated tools:255256### Static Analysis257- **Python**: pylint, mypy, bandit (security)258- **JavaScript**: ESLint, TypeScript compiler259- **Java**: SonarQube, SpotBugs, PMD260- **Go**: golint, go vet, staticcheck261- **C#**: Roslyn analyzers, SonarLint262263### Security Scanning264- **SAST**: Semgrep, CodeQL, Checkmarx265- **SCA**: Snyk, Dependabot, OWASP Dependency-Check266- **Secrets**: TruffleHog, GitGuardian, git-secrets267268### Code Quality Metrics269- **Coverage**: JaCoCo, Coverage.py, Istanbul270- **Complexity**: SonarQube, Code Climate271- **Duplication**: CPD, SonarQube272273## GitHub/GitLab Integration274275When reviewing PRs/MRs:2762771. **Check CI Status First**278 - All tests passing279 - Security scans clear280 - Code coverage meets threshold281 - Build successful2822832. **Review Commit History**284 - Commits are atomic and logical285 - Commit messages are descriptive286 - No merge commits (prefer rebase)2872883. **Provide Structured Feedback**289 - Use "Request changes" for blocking issues290 - Use "Comment" for non-blocking suggestions291 - Use "Approve" when ready to merge292 - Add inline comments at specific lines2932944. **Review Conversation Resolution**295 - All review comments addressed296 - Questions answered297 - Requested changes implemented298299## Special Case Reviews300301### Legacy Code Refactoring302- Ensure test coverage exists before refactoring303- Changes don't alter behavior (unless intended)304- Refactoring is incremental305- Risk of regression assessed306307### Third-Party Integration308- API versioning strategy309- Rate limiting and retries implemented310- Fallback behavior defined311- Monitoring for API health312313### Database Schema Changes314- Migrations are reversible315- Backward compatibility maintained316- Indexes added for new queries317- Performance impact assessed with EXPLAIN318319### Microservices Changes320- Service boundaries respected321- Contract testing in place322- Circuit breakers implemented323- Distributed tracing configured324325## Review Workflow326327### For Project Folders3281. Scan directory structure to understand architecture3292. Identify entry points and critical paths3303. Read configuration files first3314. Review in order: models → services → controllers → tests3325. Check for missing tests or documentation333334### For GitHub Repositories3351. Clone repository or access via GitHub API3362. Checkout the specific branch/PR3373. Review PR description and linked issues3384. Examine changed files in diff view3395. Run automated checks locally if needed3406. Provide structured feedback in PR comments341342### Review Prioritization343When dealing with large changes:3441. **Critical path first**: Core business logic3452. **Security-sensitive code**: Authentication, authorization, data handling3463. **Public APIs**: Interfaces exposed to users/systems3474. **Database changes**: Schema migrations, queries3485. **Configuration changes**: Infrastructure, deployment3496. **Tests**: Verify coverage and quality3507. **Documentation**: README, API docs, comments351352## Communication Best Practices353354### Constructive Language355- ✅ "Consider using X pattern here for better maintainability"356- ❌ "This is wrong"357- ✅ "This could introduce a race condition if..."358- ❌ "You don't understand concurrency"359- ✅ "Adding error handling here would make this more robust"360- ❌ "Why didn't you handle errors?"361362### Actionable Feedback363- Be specific about location and issue364- Explain WHY something is a problem365- Suggest concrete alternatives366- Provide examples or references367- Link to documentation or style guides368369### Balanced Perspective370- Acknowledge good practices371- Separate blocking vs. non-blocking issues372- Consider trade-offs and context373- Recognize learning opportunities374375## Output Format376377Always structure your review output as:378379```markdown380# Code Review: [Project/PR Name]381382## Executive Summary383[2-3 sentence overview of changes and overall quality]384385## Recommendation386[ ] ✅ Approve (Ready to merge)387[ ] ⚠️ Approve with minor suggestions (Non-blocking)388[ ] 🔴 Request changes (Blocking issues found)389[ ] ⛔ Block (Critical security/quality issues)390391## Metrics392- Files changed: [X]393- Lines added: [X]394- Lines deleted: [X]395- Test coverage: [X]%396- Complexity score: [X]397398***399400## Critical Issues (Must Fix) 🔴401402### 1. [Issue Title]403**Location**: `filename.ext:line`404**Severity**: Critical405**Issue**: [Detailed description]406**Impact**: [Security/Performance/Correctness impact]407**Recommendation**: [Specific fix with code example]408409***410411## High Priority (Should Fix) ⚠️412413[Similar structure]414415***416417## Medium Priority (Consider) 💡418419[Similar structure]420421***422423## Low Priority (Nice to Have) 📝424425[Similar structure]426427***428429## Positive Highlights ⭐430431- [Specific good practice 1]432- [Specific good practice 2]433434***435436## Testing Assessment437438**Coverage**: [X]%439**Unit Tests**: [Count and quality assessment]440**Integration Tests**: [Count and quality assessment]441**Edge Cases**: [Covered/Missing]442443**Missing Test Coverage**:444- [Specific scenario 1]445- [Specific scenario 2]446447***448449## Security Assessment 🔒450451**Vulnerabilities**: [None/Count]452**Security Checklist**:453- [ ] Input validation454- [ ] Authentication/Authorization455- [ ] Data encryption456- [ ] Secrets management457- [ ] Dependency vulnerabilities458459[Details of any issues]460461***462463## Performance Analysis ⚡464465**Expected Impact**: [Positive/Neutral/Negative]466**Concerns**:467- [Specific concern with evidence]468469**Recommendations**:470- [Performance improvement suggestion]471472***473474## Documentation Status 📚475476- [ ] Code comments (WHY not WHAT)477- [ ] Function/method documentation478- [ ] README updated479- [ ] API documentation480- [ ] Changelog updated481482***483484## Additional Notes485486[Any context-specific observations, architectural discussions, or follow-up items]487```488489## Self-Improvement490491After each review:492- Note any missed issues that were found later493- Track review time vs code quality494- Refine checklists based on common findings495- Update language-specific checks based on evolving best practices496497## Limitations & Escalation498499**When to seek human expert review**:500- Novel architectural patterns501- Complex distributed systems design502- Regulatory compliance requirements (HIPAA, GDPR, PCI)503- Cryptographic implementations504- Real-time system design505- Safety-critical code (medical, aviation, automotive)506507**Acknowledge uncertainty**:508- Flag areas requiring domain expertise509- Note when trade-offs are context-dependent510- Suggest additional review by specialists511512## References513514- Google Engineering Practices: Code Review Guidelines515- OWASP Top 10 Security Risks516- CERT Secure Coding Standards517- Martin Fowler's Refactoring Catalog518- Clean Code principles (Robert C. Martin)519- Effective Code Reviews (Best Practices 2025+)520521---522523## Usage Instructions524525### For Claude.ai Desktop/Web5261. Save this as `SKILL.md` in a folder named `enterprise-code-review`5272. Go to Settings > Skills5283. Add custom skill by selecting the folder5294. Enable code execution in settings530531### For Claude Code5321. Create `skills/enterprise-code-review/` in your project root5332. Place this `SKILL.md` file there5343. Claude will automatically detect and load the skill535536### Invoking the Skill537Simply ask Claude to:538- "Review this code using enterprise-code-review"539- "Perform a critical code review on [file/folder/repo]"540- "Analyze this PR following enterprise standards"541542The skill will trigger automatically when code review is mentioned in context.543544---545546**Version**: 1.0.0547**Last Updated**: January 2026548**Maintained by**: Enterprise Architecture Team