Skills code-review-and-quality
๐Ÿ“ฆ

code-review-and-quality

Content revision r2 Safe โš™๏ธ External commands๐Ÿ“ Filesystem access๐Ÿ”‘ Env variables

Review Code Across Five Quality Axes

Code reviews often miss risks when they focus only on tests or style. This skill guides a consistent review of correctness, readability, architecture, security, and performance.

Supports: Claude Codex Code(CC)
๐Ÿฅ‰ 78 Bronze

This skill is part of a pack

Install the whole pack to get every skill the task needs, in one command.

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "code-review-and-quality" from https://skillstore.io/skills/addyosmani-code-review-and-quality.md and its manifest at https://skillstore.io/api/skills/addyosmani-code-review-and-quality/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "code-review-and-quality". Review a feature change that adds a list endpoint and updates its tests.

Expected outcome:

  • Required: Add pagination before accepting unbounded result sets.
  • Required: Add an error-path test for a failed data request.
  • Consider: Move filtering logic into the module that owns the query.

Using "code-review-and-quality". Review a dependency upgrade that changes the lockfile.

Expected outcome:

Review the changelog and lockfile diff, isolate the package change, run the full test suite, and verify that transitive updates are expected.

Using "code-review-and-quality". Review an AI-generated refactor with passing tests.

Expected outcome:

  • The tests pass, but the refactor preserves the same branching complexity.
  • Move feature-specific logic out of the shared module.
  • Add regression coverage for the changed boundary.

Security Audit

Safe
v4 โ€ข 9/19/2026 Open versioned report

All 37 static findings are false positives in documentation-only Markdown. The matches are inline backticks, fenced examples, relative links, or ordinary checklist language; no executable behavior, secret access, network activity, or prompt injection was found in SKILL.md.

1
Files scanned
397
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/addyosmani-code-review-and-quality/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/addyosmani-code-review-and-quality/security.svg)](https://skillstore.io/skills/addyosmani-code-review-and-quality?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/addyosmani-code-review-and-quality?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/addyosmani-code-review-and-quality/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/addyosmani-code-review-and-quality.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

addyosmani. (2026). code-review-and-quality security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/addyosmani-code-review-and-quality/audits/4

BibTeX citation

@techreport{addyosmani-addyosmani-code-review-and-quality-2026, author = {addyosmani}, title = {code-review-and-quality security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/addyosmani-code-review-and-quality/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "code-review-and-quality security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "addyosmani" date-released: "2026-09-19" url: "https://skillstore.io/skills/addyosmani-code-review-and-quality/audits/4" identifiers: - type: other value: "skillstore:addyosmani-code-review-and-quality:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: High
55
Architecture
85
Maintainability
87
Content
67
Community
83
Spec Compliance

What You Can Build

Review a Pull Request

Evaluate a proposed change before merge with prioritized findings across correctness, design, security, and performance.

Validate AI-Generated Code

Inspect code produced by an agent for hidden assumptions, weak tests, unsafe patterns, and unnecessary complexity.

Plan a Safer Refactor

Separate structural improvements from feature work and identify simpler designs before implementation begins.

Try These Prompts

Basic Change Review
Review this change for correctness, readability, architecture, security, and performance. List the most important issues first.
Test Coverage Review
Review this change and its tests. Identify missing edge cases, weak assertions, error paths, and regressions the tests would not catch.
Architecture Review
Assess this change for coupling, duplication, misplaced responsibilities, abstraction debt, and complexity that was relocated rather than removed.
Release Readiness Review
Perform a release-readiness review. Prioritize correctness and security risks, inspect dependency changes, assess verification evidence, and propose concrete remedies.

Best Practices

  • Understand the change intent and tests before inspecting implementation details.
  • Lead with high-impact correctness and security findings, then discuss structure and style.
  • Pair each structural concern with a concrete remedy and verification step.

Avoid

  • Approving a change because its tests pass while ignoring security or architecture.
  • Reporting a long list of cosmetic nits before one serious correctness issue.
  • Combining broad refactoring, feature work, and dependency upgrades without isolation.

Frequently Asked Questions

What does this skill review?
It reviews correctness, readability, architecture, security, and performance.
Can it review code from an AI assistant?
Yes. It is designed to examine code from humans, agents, and mixed teams.
Does it run tests or builds?
No. It evaluates supplied verification evidence and identifies missing checks.
How are findings prioritized?
Correctness and security come first, followed by structural risks, simplifications, and minor style concerns.
Can it review dependency upgrades?
Yes. It checks changelog review, package isolation, lockfile changes, vulnerabilities, and test evidence.
Is it a replacement for security review?
No. It provides practical review guidance, but sensitive changes still need qualified security review.

Developer Details

Author

addyosmani

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

5d5054f8a23586f9b500fece1cb613a9dffc787b

Maintenance freshness

9/19/2026

Usage

12 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from addyosmani

View all
View all