Code Review SpecialistSAFE
A visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Overview
A visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
fb009cc72f7fOBSERVED · 2026-09-30Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: code-review-specialist description: Comprehensive code review with security, performance, and quality analysis. Use when users ask to review code, analyze code quality, evaluate pull requests, or mention code review, security analysis, or performance optimization. --- # Code Review Skill This skill provides comprehensive code review capabilities focusing on: 1. **Security Analysis** - Authentication/authorization issues - Data exposure risks - Injection vulnerabilities - Cryptographic weaknesses - Sensitive data logging 2. **Performance Review** - Algorithm efficiency (Big O analysis) - Memory optimization - Database query optimization - Caching opportunities - Concurrency issues 3. **Code Quality** - SOLID principles - Design patterns - Naming conventions - Documentation - Test coverage 4. **Maintainability** - Code readability - Function size (should be < 50 lines) - Cyclomatic complexity - Dependency management - Type safety ## Reference Files This skill includes supporting files that you should read when performing reviews: - **`templates/review-checklist.md`** — Structured checklist covering security, performance, quality, and testing. Read this file and use it as a guide to ensure no category is missed during review. - **`templates/finding-template.md`** — Standard template for documenting individual findings with severity, location, code examples, and impact analysis. Read this file and use its format when reporting issues. - **`scripts/analyze-metrics.py`** — Python script that calculates code metrics (function count, class count, average line length, complexity score). Run this on the file under review to gather quantitative data. - **`scripts/compare-complexity.py`** — Python script that compares cyclomatic and cognitive complexity between two versions of a file. Run this with the before and after versions when reviewing refactoring changes. ## Review Template For each piece of code reviewed, provide: ### Summary - Overall quality assessment (1-5) - Key findings count - Recommended priority areas ### Critical Issues (if any) - **Issue**: Clear description - **Location**: File and line number - **Impact**: Why this matters - **Severity**: Critical/High/Medium - **Fix**: Code example ### Findings by Category #### Security (if issues found) List security vulnerabilities with examples #### Performance (if issues found) List performance problems with complexity analysis #### Quality (if issues found) List code quality issues with refactoring suggestions #### Maintainability (if issues found) List maintainability problems with improvements ## Version History - v1.0.0 (2024-12-10): Initial release with security, performance, quality, and maintainability analysis --- **Last Updated**: August 4, 2026 **Claude Code Version**: 2.1.220 **Sources**: - https://code.claude.com/docs/en/skills **Compatible Models**: Claude Fable 5, Claude Opus 5, Claude Sonnet 5, Claude Sonnet 4.6, Claude Opus 4.8, Claude Haiku 4.5
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
fb009cc72f7ffull audit observations/trust-audit/skill/luongnv89__code-review-specialist.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | fb009cc72f7f | SAFE | B | 89 | first audit |
Questions
What does the Code Review Specialist skill do?
A visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Is Code Review Specialist safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Code Review Specialist access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Code Review Specialist work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (fb009cc72f7f), read on 2026-09-30. The repository is watched, and a new audit runs when it changes — this is the first audit.