Install
$ agentstack add skill-latestaiagents-agent-skills-ai-code-reviewer ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
AI Code Reviewer
Systematically review AI-generated code to catch common mistakes before they hit production.
When to Use
- After AI generates code you plan to use
- Before committing AI-assisted changes
- When AI code "looks right" but you want verification
- Reviewing PRs with significant AI-generated content
The AI Code Review Checklist
1. Correctness Issues (Most Common)
AI often generates code that looks correct but has subtle bugs.
Check for:
- [ ] Hallucinated APIs - Methods/functions that don't exist
``javascript // AI might generate: array.findLast(x => x.id === id) // Verify this exists in your target ``
- [ ] Wrong library versions - API changes between versions
``javascript // React 18 vs 19 differences // Node.js API differences ``
- [ ] Off-by-one errors - Loop bounds, array indices
```javascript for (let i = 0; i { const posts = await getPosts(user.id) // N queries! })
// GOOD: Batch const posts = await getPostsForUsers(userIds) ```
- [ ] Unnecessary Re-renders (React)
```javascript // BAD: New object every render
// GOOD: Stable reference const style = useMemo(() => ({ margin: 10 }), []) ```
- [ ] Memory Leaks
```javascript // BAD: Missing cleanup useEffect(() => { const interval = setInterval(fetch, 1000) // No cleanup! }, [])
// GOOD: Cleanup useEffect(() => { const interval = setInterval(fetch, 1000) return () => clearInterval(interval) }, []) ```
- [ ] Blocking Operations
```javascript // BAD: Sync file operations const data = fs.readFileSync(path)
// GOOD: Async const data = await fs.promises.readFile(path) ```
4. Maintainability Issues
AI generates "works now" code, not "maintainable" code.
Check for:
- [ ] Magic Numbers/Strings
```javascript // BAD if (status === 3) { ... }
// GOOD if (status === OrderStatus.SHIPPED) { ... } ```
- [ ] Inconsistent Patterns
``javascript // AI might mix patterns const getUser = async () => {} // Arrow function async function getPost() {} // Function declaration ``
- [ ] Missing Types (TypeScript)
```typescript // BAD: AI uses 'any' when uncertain function process(data: any) { ... }
// GOOD: Proper types function process(data: ProcessInput) { ... } ```
- [ ] Dead Code
``javascript // AI sometimes includes unused variables/imports import { unused } from './utils' const temp = calculate() // Never used ``
5. Integration Issues
AI doesn't know your codebase deeply.
Check for:
- [ ] Duplicate Logic - Does similar code already exist?
- [ ] Wrong Imports - Using the right internal modules?
- [ ] Naming Mismatches - Following your conventions?
- [ ] Missing Error Handling - Using your error patterns?
Review Workflow
Step 1: Quick Scan (30 seconds)
- Does it compile/run?
- Any obvious red flags?
- Right general approach?
Step 2: Security Review (1 minute)
- User input handling?
- Database queries?
- Authentication/authorization?
- Sensitive data exposure?
Step 3: Logic Review (2-3 minutes)
- Edge cases handled?
- Null/undefined checks?
- Error scenarios?
- Loop bounds correct?
Step 4: Integration Review (1-2 minutes)
- Follows project patterns?
- Uses existing utilities?
- Correct imports?
- Consistent naming?
Step 5: Performance Review (1 minute)
- Obvious inefficiencies?
- Unnecessary operations?
- Memory management?
- Async patterns?
Common AI Mistakes by Language
JavaScript/TypeScript
- Missing
awaiton async functions - Wrong
thiscontext in callbacks - Type assertions hiding real issues (
as any) - Mixing CommonJS and ESM imports
Python
- Mutable default arguments
- Not closing file handles
- Missing
__init__.pyawareness - Wrong exception handling scope
React
- Missing dependency arrays in hooks
- Incorrect key props in lists
- State updates in render
- Missing cleanup in effects
SQL
- Missing indexes awareness
- Cartesian products from bad joins
- Not using transactions
- Inefficient subqueries
Quick Validation Commands
# TypeScript: Compile check
npx tsc --noEmit
# ESLint: Style and common errors
npx eslint src/new-file.ts
# Tests: Run affected tests
npm test -- --findRelatedTests src/new-file.ts
# Security: Quick scan
npx audit-ci --moderate
When to Regenerate vs Fix
Regenerate if:
- Fundamental approach is wrong
- Would require 50%+ rewrite
- Security issue is systemic
Fix manually if:
- Small corrections needed
- Logic is sound, details wrong
- Integration issues only
Documentation Template
When the review passes:
## AI Code Review
**Generated by:** [Claude/GPT/etc]
**Reviewed by:** [Your name]
**Date:** [Date]
### Changes Made After Review
- Fixed null check on line 45
- Added input validation
- Replaced magic number with constant
### Verified
- [x] Security review passed
- [x] Tests added/passing
- [x] Follows project conventions
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: latestaiagents
- Source: latestaiagents/agent-skills
- License: MIT
- Homepage: https://latestaiagents.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.