Multi-Dimensional Code Review
Paste the following prompt into your AI chat to install this skill:
Install @user_13d278dd/slug according to https://skillhub.cn/install/skillhub.md.
About this skill
What It Addresses
Code reviews can drift into style nitpicks or generic feedback. This skill constrains the review to five dimensions: code quality, security, performance, maintainability, and architecture & design, making it easier to catch security risks, hidden performance costs, and maintainability issues before merge. It is useful for reviewing a branch, a directory such as src/, or a single file.
How It Works
The skill is invoked through /code-review commands:
- /code-review: review all changes on the current branch
- /code-review src/: review a directory
- /code-review src/main.ts: review a file
The review checks naming, duplication, single responsibility, exception handling, dead code, and magic values. It also looks for SQL/NoSQL injection, XSS, SSRF, hardcoded secrets, dependency vulnerabilities, N+1 queries, resource leaks, event-loop blocking, missing tests, weak logging, and unclear module boundaries. Findings should include the language, a suggested code example, and severity: 🔴 high must be fixed, 🟡 medium should be fixed, and 🟢 low is optional.
Boundaries
It works from the provided source and visible context, so it does not replace runtime tests, dynamic analysis, or production incident diagnosis. For large repositories, narrow the scope by directory or file. Conclusions about security and performance still need validation against project constraints, deployment environment, and actual behavior.
Use Cases
- Review branch changes before PR merge.
- Review src/ for N+1 queries and secrets.
- Check one core file before release.
- Recheck fixes for cache and blocking.
Best For
- Backend engineer needing pre-merge checks for injection, hardcoded secrets, and swallowed exceptions.
- Legacy maintainer needing DRY, SRP, and SOLID maintainability reviews.
- Performance engineer hunting N+1 queries, resource leaks, and event-loop blocking.
- Tech lead reviewing coupling, interface design, and extensibility.
Related Skills
A one-shot coding agent built on Claude Code CLI that runs non-interactively, supports a specified workdir, and can be monitored in the foreground or background.
Preview and confirm file sorting by extension, with recursive cleanup, ignore rules, and transactional rollback.
An engineering assistant for static HTML/CSS/JS pages, design-token extraction, IE8-compatible review, and structured delivery.
An engineering workflow for requirement analysis, scenario modeling, risk planning, quality gates, testing, and knowledge capture, with lightweight, standard, and full modes.