CtrlK
BlogDocsLog inGet started
Tessl Logo

code-reviewer

Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with 2024/2025 best practices. Use PROACTIVELY for code quality assurance.

41

Quality

41%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/v19.7/configuration/agent/skills_external/antigravity-awesome-skills-main/skills/code-reviewer/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

25%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a persona/role prompt, not an operational skill: it exhaustively enumerates capabilities and traits Claude already possesses while providing no commands, code, concrete review procedures, or working references. Almost every token could be deleted without reducing what Claude can actually do, and the one promise of deeper detail points to a nonexistent file.

Suggestions

Replace the Capabilities/Behavioral Traits/Knowledge Base catalogs with a small set of concrete, executable review procedures — e.g., actual Semgrep/CodeQL commands to run, a severity-ranked findings checklist, and a worked example of review feedback with code.

Fix or remove the dangling reference to `resources/implementation-playbook.md`; either create that file with the detailed playbooks and checklists, or inline the genuinely useful subset and cut the rest.

Rewrite the 'Response Approach' as a real workflow with validation checkpoints (e.g., 'run scanner → triage findings by severity → verify each claim against the diff before reporting') so the sequence has gates and an error-recovery loop instead of abstract labels.

DimensionReasoningScore

Conciseness

The body is ~150 lines of padded persona content — 'Elite code review expert', 'Capabilities' lists of 100+ bullets (SonarQube, OWASP Top 10, N+1 detection, SOLID principles), 'Behavioral Traits', and a 'Knowledge Base' section — nearly all of which restates domain knowledge Claude already has. Individual bullets are terse, so it is not the worst-case explanatory prose of anchor 1, but the volume of zero-marginal-value content is severe: nothing here is knowledge Claude lacks.

2 / 5

Actionability

Concrete tool names appear (SonarQube, CodeQL, Semgrep, npm audit, pip-audit), which is slightly more than minimal, but there is not a single command, code snippet, checklist, or specific step — instructions like 'Apply relevant best practices and validate outcomes' and 'Apply automated tools for initial analysis' are pure high-level hints with no executable path, and the only concrete pointer ('open resources/implementation-playbook.md') targets a file that does not exist in the bundle.

2 / 5

Workflow Clarity

The 'Response Approach' offers a rough 10-step sequence ('Analyze code context', 'Apply automated tools', 'Conduct manual review'), but the steps are abstract labels with no commands or criteria, no validation checkpoints, and no error-recovery loop — matching anchor 2's 'rough sequence present but many gaps; validation absent' rather than anchor 3, whose steps are concrete and executable.

2 / 5

Progressive Disclosure

Section headers exist, but the entire skill is one monolithic SKILL.md with no bundle files (no references/, scripts/, or assets/), and its single cross-file pointer, 'open `resources/implementation-playbook.md`', is dangling — the referenced file is absent, so navigation fails. That lands between anchor 2 (inlined content that belongs in separate files, broken/buried references) and anchor 3, and is noticeably below the midpoint.

2 / 5

Total

8

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a recognizable domain (code review spanning security, performance, and configuration) and does include an explicit use clause, so it is functional. But it is padded with persona fluff ('Elite', 'Masters', '2024/2025 best practices'), its trigger guidance is abstract rather than phrased the way users actually ask, and its broad scope creates overlap risk with adjacent skills.

Suggestions

Strip the persona fluff ('Elite', 'Masters', '2024/2025 best practices') and state plain concrete actions, e.g., 'Reviews code for security vulnerabilities, performance issues, and configuration risks using static analysis tools such as Semgrep and CodeQL.'

Rewrite the trigger in user language: 'Use when the user asks to review code, a pull request, or a diff, or mentions security vulnerabilities, code quality, or production readiness.'

Narrow the claimed scope (or name a distinguishing focus, such as production-readiness review of PRs) so it does not collide with generic security-review or code-quality skills.

DimensionReasoningScore

Specificity

The description names the domain and several review areas — 'AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability' plus 'static analysis tools, security scanning, and configuration review' — but the actions are generic ('analysis', 'scanning', 'review') and wrapped in fluff ('Elite', 'Masters', '2024/2025 best practices') that the guidelines explicitly penalize. It is above anchor 2 (which has only minimal actions) but lacks the several concrete, distinct actions of anchor 4.

3 / 5

Completeness

Both parts are present: the 'what' (code analysis, security, performance, configuration review) is reasonably clear, and an explicit use clause exists ('Use PROACTIVELY for code quality assurance'), so the missing-trigger cap of 3 does not apply. However the 'when' names no concrete triggering situation or artifact — compare anchor 5's 'when the user mentions PDFs, forms, or document extraction' — matching anchor 4's 'when could be more explicit or specific'.

4 / 5

Trigger Term Quality

'code review' and 'security' are natural terms users would say, but the description leans on jargon ('static analysis', 'AI-powered code analysis', 'production reliability') and the only trigger phrase, 'Use PROACTIVELY for code quality assurance', is not a phrase a user would naturally utter. Relevant keywords exist but common variations (review my code, PR review, find bugs/vulnerabilities) are missing — anchor 3.

3 / 5

Distinctiveness Conflict Risk

'Code review expert' with security, performance, and configuration review is somewhat specific but the stated scope is very broad — it would claim trigger space overlapping generic code-quality, security-review, testing, and DevOps skills. This sits squarely on anchor 3 ('could still overlap with similar skills'), not anchor 4's 'minor overlap risk with closely related skills'.

3 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
duclm1x1/Dive-Ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.