Code Reviewing Skill — Quick Reference
This skill provides operational checklists and prompts for structured code
review across languages and stacks. Use it when the primary task is reviewing
existing code rather than designing new systems.
Quick Reference
| Review Type |
Focus Areas |
Key Checklist |
When to Use |
| Security Review |
Auth, input validation, secrets, OWASP Top 10 |
software-security-appsec |
Security-critical code, API endpoints |
| Supply Chain Review |
Dependencies, lockfiles, licenses, SBOM, CI policies |
dev-dependency-management |
Dependency bumps, build/CI changes |
| Performance Review |
N+1 queries, algorithms, caching, hot paths |
DB queries, loops, memory allocation |
High-traffic features, bottlenecks |
| Correctness Review |
Logic, edge cases, error handling, tests |
Boundary conditions, null checks, retries |
Business logic, data transformations |
| Maintainability Review |
Naming, complexity, duplication, readability |
Function length, naming clarity, DRY |
Complex modules, shared code |
| Test Review |
Coverage, edge cases, flakiness, assertions |
Test quality, missing scenarios |
New features, refactors |
| Frontend Review |
Accessibility, responsive design, performance |
frontend-review.md |
UI/UX changes |
| Backend Review |
API design, error handling, database patterns |
api-review.md |
API endpoints, services |
| Blockchain Review |
Reentrancy, access control, gas optimization |
crypto-review.md |
Smart contracts, DeFi protocols |
Specialized: .NET/EF Core Crypto Integration
Skip unless reviewing C#/.NET crypto/fintech services using Entity Framework
Core.
For C#/.NET crypto/fintech services using Entity Framework Core, see:
- references/dotnet-efcore-crypto-rules.md
— Complete review rules (correctness, security, async, EF Core, tests, MRs)
Key rules summary:
- Review only new/modified code in the MR
- Use
decimal for financial values, UTC for dates
- Follow
CC-SEC-03 (no secrets in code) and CC-OBS-02 (no sensitive data in
logs)
- Async for I/O, pass
CancellationToken, avoid .Result/.Wait() (see
CC-ERR-04, CC-FLOW-03)
- EF Core:
AsNoTracking for reads, avoid N+1, no dynamic SQL
Result<T> pattern for explicit success/fail
When to Use This Skill
Invoke this skill when the user asks to:
- Review a pull request or diff for issues
- Audit code for security vulnerabilities or injection risks
- Improve readability, structure, and maintainability
- Suggest targeted refactors without changing behavior
- Validate tests and edge-case coverage
When NOT to Use This Skill
Decision Tree: Selecting Review Mode
Code review task: [What to Focus On?]
├─ Security-critical changes?
│ ├─ Auth/access control → Security Review (OWASP, auth patterns)
│ ├─ User input handling → Input validation, XSS, SQL injection
│ └─ Smart contracts → Blockchain Review (reentrancy, access control)
│
├─ Performance concerns?
│ ├─ Database queries → Check for N+1, missing indexes
│ ├─ Loops/algorithms → Complexity analysis, caching
│ └─ API response times → Profiling, lazy loading
│
├─ Correctness issues?
│ ├─ Business logic → Edge cases, error handling, tests
│ ├─ Data transformations → Boundary conditions, null checks
│ └─ Integration points → Retry logic, timeouts, fallbacks
│
├─ Maintainability problems?
│ ├─ Complex code → Naming, function length, duplication
│ ├─ Hard to understand → Comments, abstractions, clarity
│ └─ Technical debt → Refactoring suggestions
│
├─ Test coverage gaps?
│ ├─ New features → Happy path + error cases
│ ├─ Refactors → Regression tests
│ └─ Bug fixes → Reproduction tests
│
└─ Stack-specific review?
├─ Frontend → [frontend-review.md](assets/web-frontend/frontend-review.md)
├─ Backend → [api-review.md](assets/backend-api/api-review.md)
├─ Mobile → [mobile-review.md](assets/mobile/mobile-review.md)
├─ Infrastructure → [infrastructure-review.md](assets/infrastructure/infrastructure-review.md)
└─ Blockchain → [crypto-review.md](assets/blockchain/crypto-review.md)
Multi-Mode Reviews:
For complex PRs, apply multiple review modes sequentially:
- Security first (P0/P1 issues)
- Correctness (logic, edge cases)
- Performance (if applicable)
- Maintainability (P2/P3 suggestions)
Async Review Workflows (2026)
Timezone-Friendly Reviews
| Practice |
Implementation |
| Review windows |
Define 4-hour overlap windows |
| Review rotation |
Assign reviewers across timezones |
| Async communication |
Use PR comments, not DMs |
| Review SLAs |
24-hour initial response, 48-hour completion |
Non-Blocking Reviews
PR Submitted -> Auto-checks (CI) -> Async Review -> Merge
| | |
Author continues If green, Reviewer comments
on other work queue for when available
review
Anti-patterns:
- Synchronous review meetings for routine PRs
- Blocking on reviewer availability for non-critical changes
- Single reviewer bottleneck
Review Prioritization Matrix
| Priority |
Criteria |
SLA |
| P0 |
Security fix, production incident |
4 hours |
| P1 |
Bug fix, blocking dependency |
24 hours |
| P2 |
Feature work, tech debt |
48 hours |
| P3 |
Documentation, refactoring |
72 hours |
Optional: AI/Automation Extensions
Note: AI-assisted review tools. Human review remains authoritative.
AI Review Assistants
| Tool |
Use Case |
Limitation |
| GitHub Copilot PR |
Summary, suggestions |
May miss context |
| CodeRabbit |
Automated PR review comments |
Requires human validation |
| Qodo |
Test generation + review, 15+ workflows |
Enterprise pricing |
| OpenAI Codex |
System-level codebase context |
API integration required |
| AWS Security Agent |
OWASP Top 10, policy violations |
Preview only (2026) |
| Endor Labs AI SAST |
AI-assisted SAST |
Security-focused |
| Graphite |
PR stacking, stack-aware merge queue |
Process, not content |
AI assistant rules:
- AI suggestions are advisory only
- Human reviewer approves/rejects
- AI cannot bypass security review
- AI findings require manual verification
AI Review Checklist
Simplicity and Complexity Control
- Prefer existing, battle-tested libraries over bespoke implementations when
behavior is identical.
- Flag avoidable complexity early: remove dead/commented-out code, collapse
duplication, and extract single-responsibility helpers.
- Call out premature optimization; favor clarity and measured, evidence-based
tuning.
- Encourage incremental refactors alongside reviews to keep modules small,
predictable, and aligned to standards.
Operational Playbooks
Shared Foundation
Code Review Specific
- references/operational-playbook.md —
Review scope rules, severity ratings (P0-P3), checklists, modes, and PR
workflow patterns
Default Review Output (Agent-Facing)
When producing a review, default to:
- Short summary of intent + risk
- Findings grouped by
P0/P1/P2/P3 (mark REQUIRED vs OPTIONAL)
- Concrete suggestions (minimal diffs or test cases)
- Follow-up questions when requirements or constraints are unclear
Use
assets/core/review-comment-guidelines.md
for comment style and labeling.
Navigation
Resources
- references/operational-playbook.md
- references/review-checklist-comprehensive.md
- references/implementing-effective-code-reviews-checklist.md
- references/looks-good-to-me-checklist.md
- references/automation-tools.md
- references/dotnet-efcore-crypto-rules.md
- references/psychological-safety-guide.md
Templates
- assets/core/pull-request-description-template.md
- assets/core/review-checklist-judgment.md
- assets/core/review-comment-guidelines.md
- assets/backend-api/api-review.md
- assets/web-frontend/frontend-review.md
- assets/mobile/mobile-review.md
- assets/infrastructure/infrastructure-review.md
- assets/blockchain/crypto-review.md
- assets/data-ml/data-pipeline-review.md
- assets/data-ml/experiment-tracking-review.md
- assets/data-ml/ml-model-review.md
- assets/data-ml/ml-deployment-review.md
Data
Trend Awareness Protocol
IMPORTANT: When users ask recommendation questions about code review tools,
practices, or automation, you MUST use WebSearch to check current trends before
answering.
Trigger Conditions
- "What's the best code review tool?"
- "What should I use for [automated code review/PR automation]?"
- "What's the latest in code review practices?"
- "Current best practices for [code review/PR workflow]?"
- "Is [GitHub Copilot PR/CodeRabbit] still relevant in 2026?"
- "[CodeRabbit] vs [Graphite] vs [other]?"
- "Best AI code review assistant?"
Required Searches
- Search:
"code review best practices 2026"
- Search:
"[specific tool] vs alternatives 2026"
- Search:
"AI code review tools January 2026"
- Search:
"PR automation trends 2026"
What to Report
After searching, provide:
- Current landscape: What code review tools/practices are popular NOW
- Emerging trends: New AI assistants, PR tools, or review patterns gaining
traction
- Deprecated/declining: Tools/approaches losing relevance or support
- Recommendation: Based on fresh data, not just static knowledge
Example Topics (verify with fresh search)
- AI code review (GitHub Copilot PR, CodeRabbit, Cursor)
- PR automation (Graphite, Stacked PRs, merge queues)
- Code review platforms (GitHub, GitLab, Bitbucket)
- Review bots and automation
- Async review practices for distributed teams
- Review metrics and analytics tools
1---2name: software-code-review3description: Use when reviewing code, pull requests, or diffs. Provides patterns, checklists, and templates for systematic code review with a focus on correctness, security, readability, performance, and maintainability.4---56# Code Reviewing Skill — Quick Reference78This skill provides operational checklists and prompts for structured code9review across languages and stacks. Use it when the primary task is reviewing10existing code rather than designing new systems.1112## Quick Reference1314| Review Type | Focus Areas | Key Checklist | When to Use |15| ---------------------- | ---------------------------------------------------- | ------------------------------------------------------------------ | ------------------------------------- |16| Security Review | Auth, input validation, secrets, OWASP Top 10 | [software-security-appsec](../software-security-appsec/SKILL.md) | Security-critical code, API endpoints |17| Supply Chain Review | Dependencies, lockfiles, licenses, SBOM, CI policies | [dev-dependency-management](../dev-dependency-management/SKILL.md) | Dependency bumps, build/CI changes |18| Performance Review | N+1 queries, algorithms, caching, hot paths | DB queries, loops, memory allocation | High-traffic features, bottlenecks |19| Correctness Review | Logic, edge cases, error handling, tests | Boundary conditions, null checks, retries | Business logic, data transformations |20| Maintainability Review | Naming, complexity, duplication, readability | Function length, naming clarity, DRY | Complex modules, shared code |21| Test Review | Coverage, edge cases, flakiness, assertions | Test quality, missing scenarios | New features, refactors |22| Frontend Review | Accessibility, responsive design, performance | [frontend-review.md](assets/web-frontend/frontend-review.md) | UI/UX changes |23| Backend Review | API design, error handling, database patterns | [api-review.md](assets/backend-api/api-review.md) | API endpoints, services |24| Blockchain Review | Reentrancy, access control, gas optimization | [crypto-review.md](assets/blockchain/crypto-review.md) | Smart contracts, DeFi protocols |2526---2728## Specialized: .NET/EF Core Crypto Integration2930Skip unless reviewing C#/.NET crypto/fintech services using Entity Framework31Core.3233For C#/.NET crypto/fintech services using Entity Framework Core, see:3435- [references/dotnet-efcore-crypto-rules.md](references/dotnet-efcore-crypto-rules.md)36 — Complete review rules (correctness, security, async, EF Core, tests, MRs)3738**Key rules summary:**3940- Review only new/modified code in the MR41- Use `decimal` for financial values, UTC for dates42- Follow `CC-SEC-03` (no secrets in code) and `CC-OBS-02` (no sensitive data in43 logs)44- Async for I/O, pass `CancellationToken`, avoid `.Result`/`.Wait()` (see45 `CC-ERR-04`, `CC-FLOW-03`)46- EF Core: `AsNoTracking` for reads, avoid N+1, no dynamic SQL47- `Result<T>` pattern for explicit success/fail4849---5051## When to Use This Skill5253Invoke this skill when the user asks to:5455- Review a pull request or diff for issues56- Audit code for security vulnerabilities or injection risks57- Improve readability, structure, and maintainability58- Suggest targeted refactors without changing behavior59- Validate tests and edge-case coverage6061## When NOT to Use This Skill6263- **System design or architecture**: Use64 [software-architecture-design](../software-architecture-design/SKILL.md) for65 greenfield architecture decisions66- **Writing new code from scratch**: This skill reviews existing code, not67 authoring new features68- **Deep security audits**: For penetration testing or comprehensive security69 assessments, use70 [software-security-appsec](../software-security-appsec/SKILL.md)71- **Deep performance investigations**: For profiling/observability, use72 [qa-observability](../qa-observability/SKILL.md) and for SQL/query tuning use73 [data-sql-optimization](../data-sql-optimization/SKILL.md)7475## Decision Tree: Selecting Review Mode7677```text78Code review task: [What to Focus On?]79 ├─ Security-critical changes?80 │ ├─ Auth/access control → Security Review (OWASP, auth patterns)81 │ ├─ User input handling → Input validation, XSS, SQL injection82 │ └─ Smart contracts → Blockchain Review (reentrancy, access control)83 │84 ├─ Performance concerns?85 │ ├─ Database queries → Check for N+1, missing indexes86 │ ├─ Loops/algorithms → Complexity analysis, caching87 │ └─ API response times → Profiling, lazy loading88 │89 ├─ Correctness issues?90 │ ├─ Business logic → Edge cases, error handling, tests91 │ ├─ Data transformations → Boundary conditions, null checks92 │ └─ Integration points → Retry logic, timeouts, fallbacks93 │94 ├─ Maintainability problems?95 │ ├─ Complex code → Naming, function length, duplication96 │ ├─ Hard to understand → Comments, abstractions, clarity97 │ └─ Technical debt → Refactoring suggestions98 │99 ├─ Test coverage gaps?100 │ ├─ New features → Happy path + error cases101 │ ├─ Refactors → Regression tests102 │ └─ Bug fixes → Reproduction tests103 │104 └─ Stack-specific review?105 ├─ Frontend → [frontend-review.md](assets/web-frontend/frontend-review.md)106 ├─ Backend → [api-review.md](assets/backend-api/api-review.md)107 ├─ Mobile → [mobile-review.md](assets/mobile/mobile-review.md)108 ├─ Infrastructure → [infrastructure-review.md](assets/infrastructure/infrastructure-review.md)109 └─ Blockchain → [crypto-review.md](assets/blockchain/crypto-review.md)110```111112**Multi-Mode Reviews:**113114For complex PRs, apply multiple review modes sequentially:1151161. **Security first** (P0/P1 issues)1172. **Correctness** (logic, edge cases)1183. **Performance** (if applicable)1194. **Maintainability** (P2/P3 suggestions)120121---122123## Async Review Workflows (2026)124125### Timezone-Friendly Reviews126127| Practice | Implementation |128| ------------------- | -------------------------------------------- |129| Review windows | Define 4-hour overlap windows |130| Review rotation | Assign reviewers across timezones |131| Async communication | Use PR comments, not DMs |132| Review SLAs | 24-hour initial response, 48-hour completion |133134### Non-Blocking Reviews135136```text137PR Submitted -> Auto-checks (CI) -> Async Review -> Merge138 | | |139 Author continues If green, Reviewer comments140 on other work queue for when available141 review142```143144**Anti-patterns:**145146- Synchronous review meetings for routine PRs147- Blocking on reviewer availability for non-critical changes148- Single reviewer bottleneck149150### Review Prioritization Matrix151152| Priority | Criteria | SLA |153| -------- | --------------------------------- | -------- |154| P0 | Security fix, production incident | 4 hours |155| P1 | Bug fix, blocking dependency | 24 hours |156| P2 | Feature work, tech debt | 48 hours |157| P3 | Documentation, refactoring | 72 hours |158159---160161### Optional: AI/Automation Extensions162163> **Note**: AI-assisted review tools. Human review remains authoritative.164165#### AI Review Assistants166167| Tool | Use Case | Limitation |168| ------------------ | --------------------------------------- | ------------------------- |169| GitHub Copilot PR | Summary, suggestions | May miss context |170| CodeRabbit | Automated PR review comments | Requires human validation |171| Qodo | Test generation + review, 15+ workflows | Enterprise pricing |172| OpenAI Codex | System-level codebase context | API integration required |173| AWS Security Agent | OWASP Top 10, policy violations | Preview only (2026) |174| Endor Labs AI SAST | AI-assisted SAST | Security-focused |175| Graphite | PR stacking, stack-aware merge queue | Process, not content |176177**AI assistant rules:**178179- AI suggestions are advisory only180- Human reviewer approves/rejects181- AI cannot bypass security review182- AI findings require manual verification183184#### AI Review Checklist185186- [ ] AI suggestions validated against codebase patterns187- [ ] AI-flagged issues manually confirmed188- [ ] False positives documented for tool improvement189- [ ] Human reviewer explicitly approved190191---192193## Simplicity and Complexity Control194195- Prefer existing, battle-tested libraries over bespoke implementations when196 behavior is identical.197- Flag avoidable complexity early: remove dead/commented-out code, collapse198 duplication, and extract single-responsibility helpers.199- Call out premature optimization; favor clarity and measured, evidence-based200 tuning.201- Encourage incremental refactors alongside reviews to keep modules small,202 predictable, and aligned to standards.203204---205206## Operational Playbooks207208**Shared Foundation**209210- [../software-clean-code-standard/references/clean-code-standard.md](../software-clean-code-standard/references/clean-code-standard.md) -211 Canonical clean code rules (`CC-*`) for citation in reviews212- Legacy playbook:213 [../software-clean-code-standard/references/code-quality-operational-playbook.md](../software-clean-code-standard/references/code-quality-operational-playbook.md) -214 `RULE-01`–`RULE-13`, refactoring decision trees, and design patterns215216**Code Review Specific**217218- [references/operational-playbook.md](references/operational-playbook.md) —219 Review scope rules, severity ratings (P0-P3), checklists, modes, and PR220 workflow patterns221222## Default Review Output (Agent-Facing)223224When producing a review, default to:225226- Short summary of intent + risk227- Findings grouped by `P0`/`P1`/`P2`/`P3` (mark REQUIRED vs OPTIONAL)228- Concrete suggestions (minimal diffs or test cases)229- Follow-up questions when requirements or constraints are unclear230231Use232[assets/core/review-comment-guidelines.md](assets/core/review-comment-guidelines.md)233for comment style and labeling.234235## Navigation236237**Resources**238239- [references/operational-playbook.md](references/operational-playbook.md)240- [references/review-checklist-comprehensive.md](references/review-checklist-comprehensive.md)241- [references/implementing-effective-code-reviews-checklist.md](references/implementing-effective-code-reviews-checklist.md)242- [references/looks-good-to-me-checklist.md](references/looks-good-to-me-checklist.md)243- [references/automation-tools.md](references/automation-tools.md)244- [references/dotnet-efcore-crypto-rules.md](references/dotnet-efcore-crypto-rules.md)245- [references/psychological-safety-guide.md](references/psychological-safety-guide.md)246247**Templates**248249- [assets/core/pull-request-description-template.md](assets/core/pull-request-description-template.md)250- [assets/core/review-checklist-judgment.md](assets/core/review-checklist-judgment.md)251- [assets/core/review-comment-guidelines.md](assets/core/review-comment-guidelines.md)252- [assets/backend-api/api-review.md](assets/backend-api/api-review.md)253- [assets/web-frontend/frontend-review.md](assets/web-frontend/frontend-review.md)254- [assets/mobile/mobile-review.md](assets/mobile/mobile-review.md)255- [assets/infrastructure/infrastructure-review.md](assets/infrastructure/infrastructure-review.md)256- [assets/blockchain/crypto-review.md](assets/blockchain/crypto-review.md)257- [assets/data-ml/data-pipeline-review.md](assets/data-ml/data-pipeline-review.md)258- [assets/data-ml/experiment-tracking-review.md](assets/data-ml/experiment-tracking-review.md)259- [assets/data-ml/ml-model-review.md](assets/data-ml/ml-model-review.md)260- [assets/data-ml/ml-deployment-review.md](assets/data-ml/ml-deployment-review.md)261262**Data**263264- [data/sources.json](data/sources.json) — Curated external references265- Shared checklists:266 [../software-clean-code-standard/assets/checklists/secure-code-review-checklist.md](../software-clean-code-standard/assets/checklists/secure-code-review-checklist.md),267 [../software-clean-code-standard/assets/checklists/backend-api-review-checklist.md](../software-clean-code-standard/assets/checklists/backend-api-review-checklist.md)268269---270271## Trend Awareness Protocol272273**IMPORTANT**: When users ask recommendation questions about code review tools,274practices, or automation, you MUST use WebSearch to check current trends before275answering.276277### Trigger Conditions278279- "What's the best code review tool?"280- "What should I use for [automated code review/PR automation]?"281- "What's the latest in code review practices?"282- "Current best practices for [code review/PR workflow]?"283- "Is [GitHub Copilot PR/CodeRabbit] still relevant in 2026?"284- "[CodeRabbit] vs [Graphite] vs [other]?"285- "Best AI code review assistant?"286287### Required Searches2882891. Search: `"code review best practices 2026"`2902. Search: `"[specific tool] vs alternatives 2026"`2913. Search: `"AI code review tools January 2026"`2924. Search: `"PR automation trends 2026"`293294### What to Report295296After searching, provide:297298- **Current landscape**: What code review tools/practices are popular NOW299- **Emerging trends**: New AI assistants, PR tools, or review patterns gaining300 traction301- **Deprecated/declining**: Tools/approaches losing relevance or support302- **Recommendation**: Based on fresh data, not just static knowledge303304### Example Topics (verify with fresh search)305306- AI code review (GitHub Copilot PR, CodeRabbit, Cursor)307- PR automation (Graphite, Stacked PRs, merge queues)308- Code review platforms (GitHub, GitLab, Bitbucket)309- Review bots and automation310- Async review practices for distributed teams311- Review metrics and analytics tools