when-reviewing-code-comprehensively-use-code-review-assistant
Run Comprehensive Code Reviews
Large pull requests are hard to review consistently across security, performance, tests, and documentation. This skill coordinates specialized review agents and produces merge readiness feedback.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "when-reviewing-code-comprehensively-use-code-review-assistant" from https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant.md and its manifest at https://skillstore.io/api/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
GET /skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant.md Signed manifest GET /api/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/manifest Signed lockfile GET /api/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/lockfileTest it
Using "when-reviewing-code-comprehensively-use-code-review-assistant". Review pull request 123 for all quality dimensions.
Expected outcome:
A score summary, blocking issues, recommended fixes, and a clear merge readiness decision.
Using "when-reviewing-code-comprehensively-use-code-review-assistant". Focus on security and dependency risk.
Expected outcome:
A prioritized security review covering critical vulnerabilities, dependency findings, secrets risk, and authentication concerns.
Using "when-reviewing-code-comprehensively-use-code-review-assistant". Assess whether the release branch can merge.
Expected outcome:
A release-oriented review with pass or fail status, unresolved blockers, and the work needed before approval.
Security Audit
High RiskMost static findings were false positives caused by Markdown fences, example tables, and review criteria. I confirmed the generated auto-fix shell script risk and added semantic findings for npx-based package execution and repository-modifying auto-fixes. No prompt injection text was found.
Confirmed security concerns (2)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Filesystem access (4)
๐ Env variables (8)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
DNYoussef. (2026). when-reviewing-code-comprehensively-use-code-review-assistant security audit report (audit version 10) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/audits/10BibTeX citation
@techreport{dnyoussef-dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant-2026,
author = {DNYoussef},
title = {when-reviewing-code-comprehensively-use-code-review-assistant security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/audits/10},
note = {Author version 1.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "when-reviewing-code-comprehensively-use-code-review-assistant security audit report (audit version 10)"
version: "1.0.0"
type: report
authors:
- name: "DNYoussef"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant/audits/10"
identifiers:
- type: other
value: "skillstore:dnyoussef-when-reviewing-code-comprehensively-use-code-review-assistant:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review a Feature Pull Request
Run a broad review before requesting approval from maintainers.
Check Security and Dependency Risk
Focus review effort on OWASP issues, secrets, authentication, and vulnerable dependencies.
Set Merge Readiness Gates
Use scoring thresholds to decide whether a pull request should proceed.
Try These Prompts
Review pull request 123 across security, performance, style, tests, and documentation. Summarize blockers and recommended next actions.
Review this pull request for authentication, authorization, secrets, dependency risk, and missing tests. Report only issues that should block merge.
Assess merge readiness for this pull request. Score each review dimension and explain the changes required to reach approval.
Audit the review workflow and auto-fix process. Identify unsafe commands, missing validation, weak thresholds, and CI improvements.
Best Practices
- Run the review in a clean branch with source control enabled.
- Review command execution and generated scripts before allowing file changes.
- Tune thresholds to project risk, compliance needs, and CI requirements.
Avoid
- Running auto-fix scripts against production branches without review.
- Treating the score as final approval without human judgment.
- Using the skill without required security, test, and lint tools installed.
Frequently Asked Questions
Does this skill replace human code review?
Which tools does it expect?
Can it modify files?
Is it suitable for CI?
What review dimensions are covered?
Does it need project configuration?
Developer Details
Author
DNYoussefLicense
MIT
Author version
v1.0.0
Skillstore revision
r1
Ref
0519034dad657fb1f7706e0550e962beeda73fdf
Maintenance freshness
7/20/2026
Usage
5 downloads ยท 191 views
File structure