CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review-checklist

Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability

34

Quality

30%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/code-review-checklist/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

27%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is a comprehensive but excessively verbose code review checklist that repeats itself significantly and explains many concepts Claude already understands. While the concrete good/bad code examples add value, the overall content is roughly 3-4x longer than necessary, with checklist items duplicated across sections. The lack of bundle files means all content is crammed into a single monolithic document with no progressive disclosure.

Suggestions

Reduce content by 60-70%: eliminate the 'How It Works' steps 1-6 (which duplicate the Complete Review Checklist), remove the 'When to Use' section, and cut obvious advice from Best Practices and Common Pitfalls.

Extract the detailed category checklists (Security, Functionality, Code Quality, Performance) into separate bundle files and reference them from a concise SKILL.md overview.

Remove explanations of basic concepts (what SQL injection is, what edge cases are) and keep only the checklist items and code examples as actionable reference material.

Add a decision-point workflow: e.g., 'If security issues found → block merge; if style-only issues → approve with comments' to create actual validation checkpoints.

DimensionReasoningScore

Conciseness

Extremely verbose at ~350+ lines. Extensively explains concepts Claude already knows (what code review is, what edge cases are, what SQL injection is). The 'When to Use This Skill' section, 'How It Works' steps, 'Best Practices' do/don't lists, and 'Common Pitfalls' sections are all padded with obvious information. The same checklist items are repeated multiple times (e.g., the step-by-step review appears, then again in examples, then again in the 'Complete Review Checklist').

1 / 3

Actionability

The checklists with checkboxes are somewhat actionable, and the code examples showing good vs. bad patterns are concrete and useful. However, much of the content is generic advice rather than executable guidance—it reads more like a tutorial than a skill that tells Claude exactly what to do. The review comment templates are a nice touch but still fairly generic.

2 / 3

Workflow Clarity

Steps are listed (Step 1-6) and the 'Complete Review Checklist' provides a sequence, but there are no validation checkpoints or feedback loops. For a review process that could miss critical security or functionality issues, there's no mechanism for verifying completeness or iterating on findings. The workflow is more of a flat checklist than a sequenced process with decision points.

2 / 3

Progressive Disclosure

Monolithic wall of text with no bundle files to offload detailed content. The security checklist, code quality checklist, and functionality checklist could each be separate referenced files. Instead, everything is inlined, making the skill extremely long. References to external URLs and 'Related Skills' exist but don't help with internal content organization.

1 / 3

Total

6

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies its domain (code reviews) and lists high-level categories but reads more like a document title than a skill description. It lacks concrete actions, explicit trigger guidance ('Use when...'), and natural keyword variations that would help Claude reliably select it from a large skill set.

Suggestions

Add an explicit 'Use when...' clause with trigger terms like 'review my code', 'PR review', 'pull request', 'code quality check', or 'review checklist'.

Replace the high-level category list with specific concrete actions, e.g., 'Checks for security vulnerabilities, identifies performance bottlenecks, flags error handling gaps, and verifies test coverage in code changes'.

Reframe from a noun phrase ('Comprehensive checklist for...') to active verb phrases describing what the skill does, e.g., 'Conducts thorough code reviews by evaluating...'.

DimensionReasoningScore

Specificity

Names the domain (code reviews) and lists categories (functionality, security, performance, maintainability), but doesn't describe concrete actions like 'check for SQL injection', 'verify error handling', or 'flag N+1 queries'. The categories are high-level rather than specific actions.

2 / 3

Completeness

Describes what it is (a checklist for code reviews) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per the rubric, a missing 'Use when...' clause caps completeness at 2, and the 'what' itself is also weak (it's a noun phrase describing a thing rather than actions), warranting a 1.

1 / 3

Trigger Term Quality

Includes 'code review' which is a natural trigger term users would say, plus related terms like 'security' and 'performance'. However, it misses common variations like 'PR review', 'pull request', 'review checklist', 'code quality', or 'review my code'.

2 / 3

Distinctiveness Conflict Risk

The 'code review checklist' framing is somewhat specific, but terms like 'security', 'performance', and 'maintainability' could overlap with dedicated security auditing skills, performance optimization skills, or general code quality skills.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.