# Code Review

> Review code changes for correctness, regressions, security, test gaps, and operational risk. Use when reviewing a local diff, pull request, recently merged change, or requested implementation before release.

- **Type:** Skill
- **Install:** `agentstack add skill-ravisingh11-agent-safe-engineering-code-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [ravisingh11](https://agentstack.voostack.com/s/ravisingh11)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [ravisingh11](https://github.com/ravisingh11)
- **Source:** https://github.com/ravisingh11/agent-safe-engineering/tree/main/skills/assurance/code-review

## Install

```sh
agentstack add skill-ravisingh11-agent-safe-engineering-code-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Code Review

Use this skill when reviewing a local diff, pull request, recently merged change, or requested implementation before release.

## Focus

- Correctness bugs and behavioral regressions.
- Security, privacy, auth, permission, and data-exposure risks.
- API, schema, serialization, and client compatibility drift.
- Migration and rollback safety.
- Missing or weak tests for changed behavior.
- Operational gaps: logging, deploy safety, smoke tests, and rollback.

## Method

1. Inspect the changed files and surrounding code.
2. Trace user-visible behavior and data flow.
3. Check whether tests cover the risky paths.
4. Prefer concrete file/line findings over broad commentary.
5. Do not suggest cosmetic rewrites unless they hide a real risk.

## Decision Rules

- Findings must be evidence-backed and tied to file or behavior references.
- Do not promote speculative concerns unless the failure mode is concrete.
- Separate real defects from verification gaps.
- Preserve unrelated user changes in dirty worktrees.

## Verification

- Prefer running focused tests for changed code when feasible.
- If tests are unavailable, explain the static evidence and residual risk.
- Record commands not run when they would materially affect confidence.

## Output

Findings first, ordered by severity:

```text
Findings
- severity: file:line - issue and impact

Questions
- assumptions that affect correctness

Verification Gaps
- checks not run or coverage missing
```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ravisingh11](https://github.com/ravisingh11)
- **Source:** [ravisingh11/agent-safe-engineering](https://github.com/ravisingh11/agent-safe-engineering)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-ravisingh11-agent-safe-engineering-code-review
- Seller: https://agentstack.voostack.com/s/ravisingh11
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
