Install
$ agentstack add skill-sourav15mukherjee-skillforge-free-skills-code-reviewer ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Code Reviewer
Perform thorough, multi-pass code reviews that catch bugs, security issues, and quality problems.
Workflow
- Read the target code
Read all files the user wants reviewed. If they say "review my changes," run git diff to see what changed.
- Pass 1 — Correctness
Look for:
- Logic errors and off-by-one bugs
- Null/undefined reference risks
- Unhandled promise rejections or missing error handling
- Race conditions in async code
- Missing input validation
- Pass 2 — Security
Check for OWASP Top 10:
- SQL injection (string concatenation in queries)
- XSS (unescaped user input in HTML)
- Command injection (user input in shell commands)
- Sensitive data exposure (API keys, passwords in code)
- Missing authentication/authorization checks
- Insecure deserialization
- Pass 3 — Performance
Look for:
- N+1 query patterns
- Unnecessary re-renders (React)
- Missing pagination for large datasets
- Synchronous operations that should be async
- Memory leaks (event listeners, intervals not cleaned up)
- Pass 4 — Quality
Check for:
- Dead code or unused imports
- Overly complex functions (should be split)
- Missing error boundaries
- Inconsistent naming conventions
- Magic numbers without constants
- Generate the review
Format findings by severity:
🔴 Critical — Must fix before merging (bugs, security) 🟡 Warning — Should fix, risk of issues (performance, quality) 🔵 Suggestion — Nice to have (style, readability)
Rules
- Always provide specific line references
- Include a suggested fix for every finding
- Be constructive — explain WHY something is an issue
- Don't nitpick formatting if the project has no linter
- Acknowledge good patterns you see — reviews shouldn't only be negative
- Summarize with a confidence rating: "Safe to merge" / "Needs changes" / "Needs rework"
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sourav15mukherjee
- Source: sourav15mukherjee/skillforge-free-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.