# Ai Code Reviewer

> |

- **Type:** Skill
- **Install:** `agentstack add skill-latestaiagents-agent-skills-ai-code-reviewer`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [latestaiagents](https://agentstack.voostack.com/s/latestaiagents)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [latestaiagents](https://github.com/latestaiagents)
- **Source:** https://github.com/latestaiagents/agent-skills/tree/main/plugins/developer-toolkit/skills/code-intelligence/ai-code-reviewer
- **Website:** https://latestaiagents.com

## Install

```sh
agentstack add skill-latestaiagents-agent-skills-ai-code-reviewer
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# AI Code Reviewer

Systematically review AI-generated code to catch common mistakes before they hit production.

## When to Use

- After AI generates code you plan to use
- Before committing AI-assisted changes
- When AI code "looks right" but you want verification
- Reviewing PRs with significant AI-generated content

## The AI Code Review Checklist

### 1. Correctness Issues (Most Common)

AI often generates code that looks correct but has subtle bugs.

**Check for:**

- [ ] **Hallucinated APIs** - Methods/functions that don't exist
  ```javascript
  // AI might generate:
  array.findLast(x => x.id === id)  // Verify this exists in your target
  ```

- [ ] **Wrong library versions** - API changes between versions
  ```javascript
  // React 18 vs 19 differences
  // Node.js API differences
  ```

- [ ] **Off-by-one errors** - Loop bounds, array indices
  ```javascript
  for (let i = 0; i  {
    const posts = await getPosts(user.id)  // N queries!
  })

  // GOOD: Batch
  const posts = await getPostsForUsers(userIds)
  ```

- [ ] **Unnecessary Re-renders (React)**
  ```javascript
  // BAD: New object every render
  

  // GOOD: Stable reference
  const style = useMemo(() => ({ margin: 10 }), [])
  ```

- [ ] **Memory Leaks**
  ```javascript
  // BAD: Missing cleanup
  useEffect(() => {
    const interval = setInterval(fetch, 1000)
    // No cleanup!
  }, [])

  // GOOD: Cleanup
  useEffect(() => {
    const interval = setInterval(fetch, 1000)
    return () => clearInterval(interval)
  }, [])
  ```

- [ ] **Blocking Operations**
  ```javascript
  // BAD: Sync file operations
  const data = fs.readFileSync(path)

  // GOOD: Async
  const data = await fs.promises.readFile(path)
  ```

### 4. Maintainability Issues

AI generates "works now" code, not "maintainable" code.

**Check for:**

- [ ] **Magic Numbers/Strings**
  ```javascript
  // BAD
  if (status === 3) { ... }

  // GOOD
  if (status === OrderStatus.SHIPPED) { ... }
  ```

- [ ] **Inconsistent Patterns**
  ```javascript
  // AI might mix patterns
  const getUser = async () => {}  // Arrow function
  async function getPost() {}      // Function declaration
  ```

- [ ] **Missing Types (TypeScript)**
  ```typescript
  // BAD: AI uses 'any' when uncertain
  function process(data: any) { ... }

  // GOOD: Proper types
  function process(data: ProcessInput) { ... }
  ```

- [ ] **Dead Code**
  ```javascript
  // AI sometimes includes unused variables/imports
  import { unused } from './utils'
  const temp = calculate()  // Never used
  ```

### 5. Integration Issues

AI doesn't know your codebase deeply.

**Check for:**

- [ ] **Duplicate Logic** - Does similar code already exist?
- [ ] **Wrong Imports** - Using the right internal modules?
- [ ] **Naming Mismatches** - Following your conventions?
- [ ] **Missing Error Handling** - Using your error patterns?

## Review Workflow

### Step 1: Quick Scan (30 seconds)
```
- Does it compile/run?
- Any obvious red flags?
- Right general approach?
```

### Step 2: Security Review (1 minute)
```
- User input handling?
- Database queries?
- Authentication/authorization?
- Sensitive data exposure?
```

### Step 3: Logic Review (2-3 minutes)
```
- Edge cases handled?
- Null/undefined checks?
- Error scenarios?
- Loop bounds correct?
```

### Step 4: Integration Review (1-2 minutes)
```
- Follows project patterns?
- Uses existing utilities?
- Correct imports?
- Consistent naming?
```

### Step 5: Performance Review (1 minute)
```
- Obvious inefficiencies?
- Unnecessary operations?
- Memory management?
- Async patterns?
```

## Common AI Mistakes by Language

### JavaScript/TypeScript
- Missing `await` on async functions
- Wrong `this` context in callbacks
- Type assertions hiding real issues (`as any`)
- Mixing CommonJS and ESM imports

### Python
- Mutable default arguments
- Not closing file handles
- Missing `__init__.py` awareness
- Wrong exception handling scope

### React
- Missing dependency arrays in hooks
- Incorrect key props in lists
- State updates in render
- Missing cleanup in effects

### SQL
- Missing indexes awareness
- Cartesian products from bad joins
- Not using transactions
- Inefficient subqueries

## Quick Validation Commands

```bash
# TypeScript: Compile check
npx tsc --noEmit

# ESLint: Style and common errors
npx eslint src/new-file.ts

# Tests: Run affected tests
npm test -- --findRelatedTests src/new-file.ts

# Security: Quick scan
npx audit-ci --moderate
```

## When to Regenerate vs Fix

**Regenerate if:**
- Fundamental approach is wrong
- Would require 50%+ rewrite
- Security issue is systemic

**Fix manually if:**
- Small corrections needed
- Logic is sound, details wrong
- Integration issues only

## Documentation Template

When the review passes:

```markdown
## AI Code Review

**Generated by:** [Claude/GPT/etc]
**Reviewed by:** [Your name]
**Date:** [Date]

### Changes Made After Review
- Fixed null check on line 45
- Added input validation
- Replaced magic number with constant

### Verified
- [x] Security review passed
- [x] Tests added/passing
- [x] Follows project conventions
```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [latestaiagents](https://github.com/latestaiagents)
- **Source:** [latestaiagents/agent-skills](https://github.com/latestaiagents/agent-skills)
- **License:** MIT
- **Homepage:** https://latestaiagents.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** yes
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-latestaiagents-agent-skills-ai-code-reviewer
- Seller: https://agentstack.voostack.com/s/latestaiagents
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
