CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review

Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.

60

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./engineering/skills/code-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized and gives concrete review dimensions plus a clear output format, but the decorative ASCII box and duplicated dimension lists waste tokens, and the actual review workflow is never laid out as an explicit sequence. No bundle files exist, so structure rests entirely on this single document.

Suggestions

Remove the ASCII 'How It Works' box or merge it with the Review Dimensions section to eliminate the duplicated security/performance/correctness lists.

Replace the implicit workflow with an explicit numbered sequence (obtain diff -> review per dimension -> verify findings -> emit the output template with verdict).

Make the connector guidance concrete (e.g., the actual command or API call to fetch a PR diff) instead of 'Pull the PR diff automatically'.

DimensionReasoningScore

Conciseness

The ASCII "How It Works" box largely duplicates the Review Dimensions section (security, performance, correctness listed twice) and adds decorative padding, so the body could be tightened noticeably.

3 / 5

Actionability

Provides a concrete, copy-paste-ready output template and specific checklists (SQL injection, XSS, CSRF, N+1 queries, race conditions), though connector steps like "Pull the PR diff automatically" lack concrete commands.

4 / 5

Workflow Clarity

A rough sequence exists (take input, review across dimensions, emit structured output, give verdict) but it is implicit and scattered across sections, with no validation checkpoints for confirming findings.

3 / 5

Progressive Disclosure

A single-file skill with no bundle files, cleanly sectioned, and one clearly signaled one-level-deep reference (CONNECTORS.md); slightly long at ~114 body lines with duplicated dimension content that could be consolidated or split out.

4 / 5

Total

14

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with explicit what/when structure, third-person voice, and genuinely natural trigger phrases. Its main weakness is incomplete synonym coverage for common invocation terms like "pull request" and "code review".

DimensionReasoningScore

Specificity

The description names the domain and enumerates specific review concerns ("security, performance, and correctness", "N+1 queries, injection risks, missing edge cases, or error handling gaps"), giving several concrete capability areas with minor gaps.

4 / 5

Completeness

Explicitly answers what ("Review code changes for security, performance, and correctness") and when ("Trigger with a PR URL or diff... or when checking a change for N+1 queries...") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural user phrases like "review this before I merge", "is this code safe?", and "PR URL or diff", but omits common synonyms such as "pull request", "code review", or "audit".

4 / 5

Distinctiveness Conflict Risk

A clear niche (structured code review) with distinct triggers, though phrases like "is this code safe?" and the security dimension carry minor overlap risk with dedicated security-audit skills.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
anthropics/knowledge-work-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.