CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review-ai-ai-review

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. Leverage AI tools (GitHub Copilot, Qodo, GPT-5, C

24

Quality

13%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/code-review-ai-ai-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

27%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is an extensive but bloated reference document that tries to cover too many topics (security, performance, architecture, CI/CD, model selection, OWASP) in a single file. It explains many concepts Claude already knows (SOLID principles, OWASP Top 10, common anti-patterns) and provides illustrative but not fully executable code examples. The content would benefit enormously from aggressive trimming and splitting into focused sub-files.

Suggestions

Reduce content by 60-70%: remove explanations of SOLID principles, OWASP Top 10 descriptions, and common anti-pattern definitions that Claude already knows. Focus only on the specific workflow and configuration details unique to this skill.

Split into multiple files: move security analysis, performance review, architecture analysis, and CI/CD integration into separate referenced files, keeping SKILL.md as a concise overview with clear navigation links.

Make the Python orchestrator example fully executable by implementing all referenced methods (get_pr_diff, to_github_comment) or explicitly mark incomplete sections, and add validation/error handling steps.

Add explicit validation checkpoints: what to verify after static analysis completes, how to handle AI hallucinations in review comments, and a feedback loop for when the quality gate fails.

DimensionReasoningScore

Conciseness

Extremely verbose at ~400+ lines. Explains concepts Claude already knows (OWASP Top 10 list, SOLID principles, what N+1 queries are). Includes multiple large code blocks that are illustrative rather than executable, and extensive lists of well-known anti-patterns and scalability red flags that add no novel information.

1 / 3

Actionability

Contains concrete code examples (Python orchestrator, GitHub Actions YAML, TypeScript interfaces), but many are pseudocode-like illustrations rather than truly executable (e.g., `detect_n_plus_1_queries` references undefined functions, `ReviewIssue` missing `to_github_comment()` method, `get_pr_diff()` never defined). The review prompt templates are useful but the overall guidance is more of a reference catalog than step-by-step executable instructions.

2 / 3

Workflow Clarity

The 'Automated Code Review Workflow' section provides a reasonable sequence (triage → static analysis → AI review → routing), and the CI/CD pipeline has a quality gate. However, there are no explicit validation checkpoints or error recovery loops between steps. The workflow lacks guidance on what to do when tools fail, when AI produces hallucinated findings, or how to verify results before posting comments.

2 / 3

Progressive Disclosure

Monolithic wall of text with everything inline. References `resources/implementation-playbook.md` but no bundle files exist. The massive amount of content (architecture analysis, security detection, performance review, CI/CD integration, complete examples) should be split across multiple files but is all crammed into a single document with no clear navigation hierarchy.

1 / 3

Total

6

/

12

Passed

Description

0%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This description is truncated mid-sentence, rendering it fundamentally incomplete. Even the visible portion relies heavily on buzzwords and tool name-dropping ('GitHub Copilot, Qodo, GPT-5') rather than describing concrete capabilities. It also uses second-person framing ('You are an expert') which is inappropriate for a skill description — it reads like a system prompt rather than a selection-oriented description.

Suggestions

Complete the description and restructure it to list specific concrete actions (e.g., 'Reviews pull requests for bugs, security vulnerabilities, and style issues. Performs static analysis and suggests code improvements.').

Add an explicit 'Use when...' clause with natural trigger terms like 'code review', 'pull request', 'PR review', 'review my code', 'check for bugs'.

Remove the system-prompt-style 'You are an expert' framing and tool name-dropping; instead use third-person voice describing what the skill does (e.g., 'Performs automated code reviews...').

DimensionReasoningScore

Specificity

The description mentions 'automated static analysis, intelligent pattern recognition, and modern DevOps practices' but these are abstract buzzwords rather than concrete actions. No specific actions like 'review pull requests', 'detect bugs', or 'suggest fixes' are listed. The description also appears truncated.

1 / 3

Completeness

The description is truncated and incomplete — it never finishes its sentence. There is no 'Use when...' clause or any explicit trigger guidance. The 'what' is vaguely implied through buzzwords but never concretely stated, and the 'when' is entirely absent.

1 / 3

Trigger Term Quality

The description uses technical jargon like 'static analysis', 'intelligent pattern recognition', and 'DevOps practices' rather than natural terms users would say. While 'code review' is a good trigger term, the rest is filled with tool names (GitHub Copilot, Qodo, GPT-5) that are unlikely user triggers. The description is also truncated, cutting off mid-sentence.

1 / 3

Distinctiveness Conflict Risk

The description is so vague and broad ('code review specialist', 'modern DevOps practices') that it could easily conflict with any coding, CI/CD, linting, or development workflow skill. There are no distinct triggers that would differentiate it from other development-related skills.

1 / 3

Total

4

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.