code-review-checklist
tranhieutt/software_development_department/.claude/skills/code-review-checklist/SKILL.md
Output: checklist score (X/Y passing) + blocking items with file:line refs + verdict
Skill71 starsChanged 5 months ago
- Reads credentials
What's in it
- Code Review Checklist
- Pre-review (always start here)
- Functionality
- Security (block if any fail)
- Performance
- Code quality
- Tests
- Documentation
- Review comment format
- Verdict
---
name: code-review-checklist
type: workflow
description: "Provides a comprehensive code review checklist for pull requests covering security, performance, maintainability, and testing. Use as a reference during code reviews or when the user asks for a review checklist."
allowed-tools: Read, Glob, Grep, Bash
argument-hint: "[file path or PR number]"
user-invocable: true
effort: 3
when_to_use: "Quick self-check before committing, when a full review is not needed"
---
# Code Review Checklist
## Pre-review (always start here)
- [ ] Read PR description and linked issue — understand the *why*
- [ ] Check CI passes before spending time on review
- [ ] Pull branch locally if logic is complex
## Functionality
- [ ] Solves stated problem and meets acceptance criteria
- [ ] Edge cases: null/empty inputs, concurrent calls, network failure
- [ ] Error handling: errors caught, message doesn't expose internals
- [ ] No off-by-one, loop termination, or race conditions
## Security (block if any fail)
- [ ] No SQL injection — use parameterized queries, not string concat
- [ ] No XSS — escape all user-controlled output in DOM
- [ ] No hardcoded secrets — use environment variables
- [ ] Authentication required on all protected routes
- [ ] Authorization checks presence AND ownership (not just auth)
- [ ] File uploads validated: type, size, content
```javascript
// ❌ SQL injection
const q = `SELECT * FROM users WHERE email = '${email}'`;
// ✅ Parameterized
db.query("SELECT * FROM users WHERE email = $1", [email]);
// ❌ Hardcoded secret
const KEY = "sk_live_abc123";
// ✅ Env variable
const KEY = process.env.API_KEY;
if (!KEY) throw new Error("API_KEY is required");
```
## Performance
- [ ] No N+1 queries — check ORM calls inside loops
- [ ] Database queries use indexes for filter/sort columns
- [ ] No unbounded queries — always paginate or limit
- [ ] No blocking main thread with sync I/O (Node.js)
- [ ] Caching used for repeated expensive operations
## Code quality
- [ ] Names describe intent (`calculateTotalPrice` not `calc`)
- [ ] Functions have single responsibility (< ~30 lines is a signal)
- [ ] No dead code or commented-out blocks
- [ ] DRY — no copy-paste of more than 3 lines
- [ ] Follows existing project conventions and patterns
- [ ] Abstractions are deep enough to justify themselves; thin pass-through wrappers fail the deletion test
## Tests
- [ ] New behavior has test coverage
- [ ] Happy path + at least 1 failure/edge case tested
- [ ] Tests use real assertions, not just "doesn't throw"
- [ ] No brittle tests that break on unrelated changes
## Documentation
- [ ] Complex logic has `// why` comment (not `// what`)
- [ ] Public API changes documented
- [ ] Breaking changes documented in CHANGELOG or PR body
## Review comment format
```markdown
**Issue:** [What's wrong]
**Current:** `problematic code`
**Suggested:** `improved code`
**Why:** [reason]
```
## Verdict
- **APPROVED** — all sections pass
- **APPROVED WITH CONDITIONS** — minor items, non-blocking
- **CHANGES REQUIRED** — blocking security, correctness, or test coverage issues
Output: checklist score (X/Y passing) + blocking items with file:line refs + verdict
More agent context in tranhieutt/software_development_department
117 other files this repository gives its agents, the first 60 shown.
AGENTS.md
CLAUDE.md
Skill
- agent-health.claude/skills/agent-health/SKILL.md
- agent-style.claude/skills/agent-style/SKILL.md
- angular-best-practices.claude/skills/angular-best-practices/SKILL.md
- annotate.claude/skills/annotate/SKILL.md
- api-design.claude/skills/api-design/SKILL.md
- architecture-decision-records.claude/skills/architecture-decision-records/SKILL.md
- aws-serverless.claude/skills/aws-serverless/SKILL.md
- backend-architect.claude/skills/backend-architect/SKILL.md
- backend-patterns.claude/skills/backend-patterns/SKILL.md
- brainstorm.claude/skills/brainstorm/SKILL.md
- bug-report.claude/skills/bug-report/SKILL.md
- changelog.claude/skills/changelog/SKILL.md
- claude-api.claude/skills/claude-api/SKILL.md
- cloud-architect.claude/skills/cloud-architect/SKILL.md
- cloud-run-puppeteer.claude/skills/cloud-run-puppeteer/SKILL.md
- code-review.claude/skills/code-review/SKILL.md
- code-simplification.claude/skills/code-simplification/SKILL.md
- codex-sdd.claude/skills/codex-sdd/SKILL.md
- commit.claude/skills/commit/SKILL.md
- context-engineering.claude/skills/context-engineering/SKILL.md
- database-architect.claude/skills/database-architect/SKILL.md
- db-review.claude/skills/db-review/SKILL.md
- deep-interview.claude/skills/deep-interview/SKILL.md
- design-review.claude/skills/design-review/SKILL.md
- design-system.claude/skills/design-system/SKILL.md
- devops-deploy.claude/skills/devops-deploy/SKILL.md
- diagnose.claude/skills/diagnose/SKILL.md
- django-patterns.claude/skills/django-patterns/SKILL.md
- docker-patterns.claude/skills/docker-patterns/SKILL.md
- dotnet-backend-patterns.claude/skills/dotnet-backend-patterns/SKILL.md
- dream.claude/skills/dream/SKILL.md
- drizzle-orm-expert.claude/skills/drizzle-orm-expert/SKILL.md
- estimate.claude/skills/estimate/SKILL.md
- event-sourcing-architect.claude/skills/event-sourcing-architect/SKILL.md
- fastapi-pro.claude/skills/fastapi-pro/SKILL.md
- fork-join.claude/skills/fork-join/SKILL.md
- freeze.claude/skills/freeze/SKILL.md
- frontend-design.claude/skills/frontend-design/SKILL.md
- frontend-patterns.claude/skills/frontend-patterns/SKILL.md
- frontend-ui-dark-ts.claude/skills/frontend-ui-dark-ts/SKILL.md
- gate-check.claude/skills/gate-check/SKILL.md
- gemini-api-integration.claude/skills/gemini-api-integration/SKILL.md
- gitlab-ci-patterns.claude/skills/gitlab-ci-patterns/SKILL.md
- guard.claude/skills/guard/SKILL.md
- handoff.claude/skills/handoff/SKILL.md
- hotfix.claude/skills/hotfix/SKILL.md
- hybrid-cloud-architect.claude/skills/hybrid-cloud-architect/SKILL.md
- kubernetes-architect.claude/skills/kubernetes-architect/SKILL.md
- laravel-patterns.claude/skills/laravel-patterns/SKILL.md
- launch-checklist.claude/skills/launch-checklist/SKILL.md
- learner.claude/skills/learner/SKILL.md
- llm-app-patterns.claude/skills/llm-app-patterns/SKILL.md
- localize.claude/skills/localize/SKILL.md
- map-systems.claude/skills/map-systems/SKILL.md
- map-workflow.claude/skills/map-workflow/SKILL.md
- markdown-injection-scanner.claude/skills/markdown-injection-scanner/SKILL.md
- microservices-patterns.claude/skills/microservices-patterns/SKILL.md
- milestone-review.claude/skills/milestone-review/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

