Install
$ agentstack add skill-canarslandev-claude-code-setup-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Code Review Skill
Perform a comprehensive code review on the specified files, directory, or recent changes.
Usage
/review # Review all uncommitted changes
/review src/api/ # Review all files in a directory
/review src/auth/login.ts # Review a specific file
/review --last-commit # Review the last commit
Steps
- Determine what to review
- If a path is provided, review those files
- If
--last-commitflag, reviewgit diff HEAD~1 - If no arguments, review
git diff(all uncommitted changes)
- Read and analyze the code
For each file, check:
### Correctness
- Logic errors or bugs
- Off-by-one errors
- Null/undefined handling
- Race conditions
- Edge cases not handled
### Security
- SQL injection vulnerabilities
- XSS vulnerabilities
- Hardcoded secrets or credentials
- Improper input validation
- Authentication/authorization issues
### Performance
- N+1 query problems
- Unnecessary re-renders (React)
- Missing indexes (if DB queries visible)
- Memory leaks
- Expensive operations in loops
### Code Quality
- Naming clarity
- Function length and complexity
- Code duplication
- Proper error handling
- Type safety (TypeScript)
### Testing
- Are new features tested?
- Are edge cases covered?
- Are tests meaningful (not just checking happy path)?
- Generate the review
Output a structured review with:
- Summary (1-2 sentences)
- Findings grouped by severity:
- Critical — must fix before merge
- Warning — should fix, potential issues
- Suggestion — nice to have improvements
- Praise — good patterns worth noting
- Each finding should include:
- File and line reference
- Description of the issue
- Suggested fix (with code if applicable)
Output Format
## Code Review Summary
[Brief overview]
### Critical (X issues)
- **[file:line]** — [description]
Suggested fix: [solution]
### Warnings (X issues)
- **[file:line]** — [description]
### Suggestions (X items)
- **[file:line]** — [description]
### Highlights
- **[file:line]** — [what's good about it]
Rules
- Be constructive, not harsh
- Provide actionable suggestions with code examples
- Don't nitpick formatting if there's a formatter configured
- Focus on logic and architecture over style
- Always mention good patterns too — reviews shouldn't be only negative
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: CanArslanDev
- Source: CanArslanDev/claude-code-setup
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.