CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review

Comprehensive code review covering security, correctness, bash compatibility, test coverage, and code quality. Use for PRs, commits, or any code changes.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a thorough, highly actionable security-focused code review skill with concrete commands, explicit validation/feedback loops, and well-structured sections. Its only weakness is length with no progressive disclosure into reference files.

Suggestions

Move the detailed PR-review submission API payloads and post-review emoji-reaction scripts into a references/ file (e.g. PR_SUBMISSION.md) and link to it from the body to reduce SKILL.md length.

Consider extracting the Pentest Checklist and Finding Severity badge tables into a reference file so the main body stays a lean overview.

Trim the literal shields.io badge markdown repeated across the severity and output-format sections to a single definition referenced elsewhere.

DimensionReasoningScore

Conciseness

The body is dense and mostly assumes Claude's competence (attack-surface checklists, exact gh commands) with little basic-concept padding; a few sections such as the badge markdown tables could be trimmed.

4 / 5

Actionability

It provides copy-paste-ready commands (gh pr diff, git diff, docker run ..., gh api review submission with a full JSON payload) plus concrete pentest vectors and severity tables.

5 / 5

Workflow Clarity

A clear sequence (scope -> read/understand -> review dimensions -> output -> PR submission) is paired with explicit validation checkpoints (determine review event by author, classify findings, retry on invalid line position) and checklists.

5 / 5

Progressive Disclosure

Content is well-organized into labeled sections with no nested references, though everything is inlined in SKILL.md with no bundle files; the pentest checklist and PR-submission API details could conceivably be split out.

4 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is clear, third-person, and explicitly pairs a concrete "what" with a "Use for ..." trigger clause. It is concise without padding and lists specific review dimensions.

DimensionReasoningScore

Specificity

"Comprehensive code review covering security, correctness, bash compatibility, test coverage, and code quality" lists several specific review dimensions, giving concrete scope rather than a single generic verb.

4 / 5

Completeness

It explicitly states both what ("Comprehensive code review covering ...") and when ("Use for PRs, commits, or any code changes") with a concrete trigger clause.

5 / 5

Trigger Term Quality

"Use for PRs, commits, or any code changes" supplies natural terms a user would say, though synonyms like "pull request", "diff", or "review my code" are absent.

4 / 5

Distinctiveness Conflict Risk

The named dimensions (notably "bash compatibility") carve a distinct niche, though "code review" is a broad category that could overlap with general review skills.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
DataDog/rshell
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.