CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review-ai-ai-review

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. Leverage AI tools (GitHub Copilot, Qodo, GPT-5, C

43

Quality

43%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./docs/v19.7/configuration/agent/skills_external/antigravity-awesome-skills-main/skills/code-review-ai-ai-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

38%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill covers a lot of ground with real tooling and code, but it is padded with concepts Claude already knows, mixes runnable and illustrative/non-executable code, lacks validation feedback loops in a batch workflow, and references a missing file with no real bundle structure.

Suggestions

Cut the re-teaching of known concepts (OWASP Top 10 enumeration, SOLID, anti-pattern definitions) and keep only review-specific heuristics Claude would not already apply.

Add explicit validation checkpoints to the workflow (e.g. 'If static analysis fails, re-run with verbose flags before AI review; verify SARIF output is non-empty before posting comments') so the batch/destructive flow has feedback loops.

Move the large reference code (orchestrator, CI/CD YAML, review routing) into actual files under references/ or scripts/ and link to them one level deep, so SKILL.md is a lean overview; either create resources/implementation-playbook.md or remove the dead reference.

DimensionReasoningScore

Conciseness

The body is noticeably verbose: it re-explains concepts Claude already knows (OWASP Top 10 list, SOLID principles, Singleton/God-object anti-patterns) and carries multiple long illustrative code blocks plus model-version name-dropping ('GPT-5', 'Claude 4.5 Sonnet', 'claude-3-5-sonnet-20241022') that pad tokens without adding guidance.

2 / 5

Actionability

There is concrete, runnable guidance (semgrep/codeql/trufflehog/sonar-scanner commands and a full Python orchestrator), but several code blocks are conceptual and non-executable (a TypeScript ReviewRoutingStrategy interface with imaginary classes, a Go struct with unimplemented methods), leaving the guidance mixed rather than copy-paste ready.

3 / 5

Workflow Clarity

A rough workflow is sequenced (triage -> parallel static analysis -> AI review -> comment posting -> quality gate), but there are no validation checkpoints or feedback loops (validate-then-retry), and because this is a batch/destructive operation that auto-posts review comments, the missing validation caps workflow clarity at 3 per the rubric.

3 / 5

Progressive Disclosure

The body is monolithic with all code examples inlined rather than split into reference files, and the one referenced file ('resources/implementation-playbook.md') does not exist in the bundle, so navigation and structure are minimal.

2 / 5

Total

10

/

20

Passed

Description

48%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear niche but suffers from a truncated, buzzword-heavy phrasing, a second-person voice the rubric penalizes, and a complete absence of an explicit 'Use when...' trigger. It is above the floor but well short of the strong examples.

Suggestions

Rewrite in third person and finish the sentence: e.g. 'Performs AI-assisted code review by combining static analysis (CodeQL, Semgrep, SonarQube) with LLM contextual review to surface bugs, vulnerabilities, and performance issues across pull requests.'

Add an explicit trigger clause: 'Use when reviewing a pull request, auditing a diff for security/performance issues, or when the user asks for an automated or AI-assisted code review.'

Include natural user phrases and file/extension cues ('PR review', 'review my diff', 'review staged changes', '.diff') to improve trigger-term coverage.

DimensionReasoningScore

Specificity

The description names the domain and a few concrete actions ('automated static analysis, intelligent pattern recognition, and modern DevOps practices'), but the phrasing is buzzword-heavy and abstract rather than crisp verb-actions, and it is written in second-person role-play voice ('You are an expert...') which reduces specificity by one per the rubric.

2 / 5

Completeness

It gives a recognizable 'what' (AI-powered code review combining static analysis, pattern recognition, DevOps), but provides no 'when'/'Use when...' trigger clause at all, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

It includes some relevant natural keywords a user might say ('code review', 'static analysis') plus tool names (GitHub Copilot, Qodo, GPT-5), but it is truncated mid-word and misses common natural variations like 'review my PR/diff' or 'review pull request'.

3 / 5

Distinctiveness Conflict Risk

'AI-powered code review specialist' with named tools (Copilot, Qodo, CodeQL, SonarQube) carves a fairly distinct niche with only minor overlap risk against generic review skills.

4 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
duclm1x1/Dive-Ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.