CtrlK
BlogDocsLog inGet started
Tessl Logo

code-review-web

Review web application code for bugs, security issues, performance problems, and stack-specific anti-patterns. Use this skill whenever the user wants to review code, debug a production issue, investigate a build failure, audit security, or check a PR before merging. Triggers on code review, review my code, debug, build error, broken, not working, why is X failing, check this code, security check, PR review, audit code, refactor. Also triggers when investigating 4xx or 5xx errors, deploy failures, environment variable issues, and CMS integration problems.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-structured, mostly lean review framework with concrete checklists, two clear workflows, and clean progressive disclosure into real reference files. Its main weakness is minor redundancy and the absence of explicit validation feedback loops in the workflows.

Suggestions

De-duplicate the N+1 query guidance so it lives in one place (either the Performance dimension or the bug-patterns section) and cross-references the other.

Add an explicit validate->fix->retry loop to the debugging workflow (e.g., 'after the minimal fix, re-run the failing case locally before deploying') to reach the top workflow_clarity anchor.

Trim the 'Failure patterns' section, which partly restates guidance already implied by the five dimensions.

DimensionReasoningScore

Conciseness

The body avoids explaining concepts Claude already knows and mostly earns its tokens, but the ~205 lines include minor redundancy (e.g., N+1 appears in both the Performance dimension and the bug-patterns section).

4 / 5

Actionability

Concrete bullet checklists (e.g., 'Session cookies have Secure, HttpOnly, SameSite attributes set', 'No literal 60000 in code') and specific commands ('git log --oneline') give mostly executable guidance with minor gaps.

4 / 5

Workflow Clarity

Two clearly sequenced workflows are present, and the debugging workflow includes verification checkpoints ('Reproduce locally', 'Verify in production'), but neither has an explicit validate->fix->re-validate loop, leaving minor validation gaps.

4 / 5

Progressive Disclosure

The body is a well-organized overview that signals three one-level-deep references (review-template, nextjs-patterns, wordpress-headless-patterns) with descriptive markdown links, all of which exist; stack-specific detail is correctly offloaded.

5 / 5

Total

17

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities, gives comprehensive natural trigger terms, and explicitly covers both what and when. Its only weakness is slight overlap risk with adjacent review/audit skills that the body's 'When NOT to use' section later resolves.

Suggestions

Add a brief exclusion cue in the description (e.g., 'not for pre-launch QA or accessibility audits') to reduce overlap with sibling skills at the trigger layer.

Tighten the 'Triggers on... refactor' list, which is broad and could fire for non-review refactor requests.

DimensionReasoningScore

Specificity

Names the web-app domain plus several concrete actions ('bugs, security issues, performance problems, and stack-specific anti-patterns'), with only minor coverage gaps versus the comprehensive anchor.

4 / 5

Completeness

Explicitly answers both 'what' (review web app code for bugs/security/perf) and 'when' ('Use this skill whenever... Triggers on...') with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Comprehensive natural phrasings including synonyms ('review my code, debug, build error, broken, not working, why is X failing') plus concrete error classes (4xx/5xx, deploy failures), matching the comprehensive-synonyms anchor.

5 / 5

Distinctiveness Conflict Risk

Scoped to web application code with distinct triggers, but the description alone does not disambiguate from closely related perf/security-audit skills, so minor overlap risk remains.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
rampstackco/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.