# Code Review

> >

- **Type:** Skill
- **Install:** `agentstack add skill-karmaloopai-jiva-code-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [KarmaloopAI](https://agentstack.voostack.com/s/karmaloopai)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [KarmaloopAI](https://github.com/KarmaloopAI)
- **Source:** https://github.com/KarmaloopAI/Jiva/tree/main/examples/personas/code-reviewer/skills/code-review
- **Website:** https://www.karmaloop.ai

## Install

```sh
agentstack add skill-karmaloopai-jiva-code-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Code Review Skill

## Overview
Perform comprehensive code reviews analyzing bugs, style issues, performance bottlenecks, security vulnerabilities, and adherence to best practices.

## Workflow

### 1. Scan Code Structure
- Use `view` tool to read all relevant files in the codebase
- Identify file types, frameworks, and languages used
- Map dependencies and module relationships

### 2. Analyze Code Quality
Check for the following categories:

**Bugs & Logic Errors:**
- Null/undefined handling
- Off-by-one errors
- Race conditions
- Memory leaks
- Incorrect algorithm implementation

**Security Issues:**
- SQL injection vulnerabilities
- XSS vulnerabilities
- Authentication/authorization flaws
- Sensitive data exposure
- Unsafe dependencies

**Performance Problems:**
- Inefficient algorithms (O(n²) where O(n) possible)
- Unnecessary database queries
- Memory overuse
- Blocking operations
- Missing caching

**Code Style:**
- Naming conventions
- Code formatting inconsistencies
- Magic numbers/strings
- Dead code
- Overly complex functions

**Best Practices:**
- DRY (Don't Repeat Yourself) violations
- SOLID principles adherence
- Error handling patterns
- Testing coverage
- Documentation quality

### 3. Categorize Findings
Group issues by:
- **Critical**: Security vulnerabilities, data loss risks
- **High**: Bugs that cause crashes/errors
- **Medium**: Performance issues, maintainability problems
- **Low**: Style issues, minor improvements

### 4. Provide Solutions
For each issue:
- Explain WHY it's a problem
- Show the problematic code snippet
- Provide a SPECIFIC fix with code examples
- Explain the benefits of the fix

### 5. Generate Report
Structure the output as:

```
# Code Review Report

## Summary
- Total files reviewed: X
- Issues found: Y (Z critical, W high, V medium, U low)

## Critical Issues
[List critical issues with fixes]

## High Priority Issues
[List high priority issues with fixes]

## Medium Priority Issues
[List medium priority issues with fixes]

## Low Priority Issues
[List low priority issues with fixes]

## Strengths
[Mention good practices found in the code]

## Recommendations
[Overall suggestions for improvement]
```

## Resources

### When to Use References
- Read `references/security_checklist.md` when analyzing security
- Consult `references/performance_patterns.md` for performance optimization
- Check `references/language_guides/` for language-specific best practices

### Scripts (Future Enhancement)
- `scripts/run_linter.sh ` - Run automated linting
- `scripts/complexity_analysis.py ` - Calculate cyclomatic complexity
- `scripts/security_scan.py ` - Run security vulnerability scanner

## Example Usage

**User:** "Review this authentication code"

**Process:**
1. Read authentication-related files with `view` tool
2. Check for common auth vulnerabilities (password storage, session management, etc.)
3. Analyze token handling and encryption
4. Check for privilege escalation risks
5. Provide detailed report with fixes

## Tips for Effective Reviews

1. **Be Specific**: Don't just say "improve error handling" - show exactly how
2. **Prioritize**: Focus on critical/high issues first
3. **Be Constructive**: Acknowledge good code practices too
4. **Provide Context**: Explain the "why" behind each suggestion
5. **Code Examples**: Always show concrete before/after code
6. **Consider Trade-offs**: Mention any downsides to suggested changes

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [KarmaloopAI](https://github.com/KarmaloopAI)
- **Source:** [KarmaloopAI/Jiva](https://github.com/KarmaloopAI/Jiva)
- **License:** MIT
- **Homepage:** https://www.karmaloop.ai

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-karmaloopai-jiva-code-review
- Seller: https://agentstack.voostack.com/s/karmaloopai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
