Browse / Security Testing / Code Review

Code Review

Automates comprehensive code quality analysis, security vulnerability scanning, and architectural compliance checks to ensure production-grade standards.

SkillSecurity TestingCode ReviewVulnerabilityCompliance

The source repository doesn't declare a license. Check its terms before reusing the code.

Key features

  • Architectural compliance verification against ADRs and design specifications
  • Automated security scanning for OWASP vulnerabilities and hardcoded secrets
  • Automated fix suggestions for formatting, imports, and common refactorings
  • Multi-tool static analysis for linting, type safety, and complexity metrics
  • Performance analysis to identify inefficient algorithms and database query patterns

Use cases

  • Verifying that new implementations strictly adhere to established architectural decisions
  • Performing pre-merge quality gates to ensure code meets security and style standards
  • Auditing legacy codebases for complexity, technical debt, and missing documentation

FAQ

How does it help with architectural compliance?

The skill verifies your code against Architectural Decision Records (ADRs) and design specifications, ensuring your implementation follows project-specific patterns, layering rules, and API contracts.

What specific security risks can this skill identify?

It scans for OWASP Top 10 vulnerabilities like SQL injection and XSS, detects hardcoded secrets and API keys, and identifies dependency vulnerabilities using tools like bandit and semgrep.

What is the Claude Code Review skill?

The Code Review skill is a specialized capability for Claude Code that automates comprehensive code quality analysis, security vulnerability scanning, and compliance checks to maintain production-grade coding standards.

Can it automatically fix the issues it discovers?

Yes, it provides automated fix suggestions for common issues such as PEP 8 formatting, import organization, and simple refactorings, allowing you to resolve many quality flags with a single command.

When should I use this skill in my development process?

You should use this skill during the active development phase, specifically before submitting pull requests or when refactoring complex modules, to identify security risks and technical debt before code reaches production.