Skill

Elevate Code Quality and Security

Elite code reviewer persona spanning AI-assisted analysis, security, performance, config review, and team process.

Works with tragbitocodigagithub copilotsonarqube

90
Spark score
out of 100
Updated last month
Version 14.0.0

Add to Favorites

Why it matters

Ensure your codebase is secure, performant, and maintainable by leveraging AI-powered analysis and expert-driven code review practices.

Outcomes

What it gets done

01

Perform comprehensive code reviews using AI and static analysis tools.

02

Identify and mitigate security vulnerabilities, including OWASP Top 10.

03

Analyze code for performance bottlenecks and scalability issues.

04

Provide actionable feedback and best practices for code improvement.

Install

Add it to your toolbox

Run in your project directory:

curl -fsSL https://spark.entire.vc/get/ag-code-reviewer | bash

Overview

Code Reviewer

Elite code reviewer persona spanning AI-assisted code analysis, static analysis tooling, OWASP-based security review, performance/scalability analysis, infrastructure-as-code and CI/CD config review, and mentor-style team process guidance across JavaScript/Python/Java/Go/Rust/.NET/PHP ecosystems. Use when reviewing code, configuration, or infrastructure for quality, security, performance, and maintainability across a broad range of concerns.

What it does

This skill is an elite code review expert covering code quality, security, performance, and maintainability across ten capability areas, combining deep technical expertise with modern AI-assisted review processes. AI-powered code analysis covers integration with AI review tools (Trag, Bito, Codiga, GitHub Copilot), natural-language custom review rules, context-aware LLM analysis, automated PR comment generation, and real-time CLI/IDE feedback. Modern static analysis spans SonarQube/CodeQL/Semgrep for scanning, Snyk/Bandit/OWASP tools for security focus, profilers and complexity analyzers for performance, npm audit/pip-audit for dependency vulnerabilities, license compliance checking, and technical-debt/code-smell detection. Security code review covers OWASP Top 10 detection, input validation/sanitization, auth and authorization implementation, cryptographic and key-management review, SQL injection/XSS/CSRF prevention, secrets management, API security/rate limiting, and container/infrastructure security. Performance and scalability analysis covers N+1 query detection, memory-leak and resource-management analysis, caching strategy review, async pattern verification, load-testing integration, connection pooling, and cloud-native/microservices performance anti-patterns. Configuration and infrastructure review covers production config security, database connection-pool/timeout settings, Kubernetes manifest analysis, Infrastructure-as-Code (Terraform, CloudFormation) review, CI/CD pipeline security, and secrets/observability configuration. Modern development practices covers TDD/BDD and test coverage, contract testing and API compatibility, feature flags and rollback strategy, blue-green/canary deployment patterns, and error-handling/resilience review. Code quality and maintainability covers Clean Code/SOLID adherence, design-pattern consistency, duplication detection, naming conventions, technical-debt remediation planning, and legacy-code modernization. Team collaboration and process covers PR workflow optimization, review checklist enforcement, team coding standards, mentor-style feedback, review-automation tooling, and onboarding support. Language-specific expertise spans JavaScript/TypeScript (React/Vue patterns), Python (PEP 8, performance), Java (Spring), Go (concurrency), Rust (memory safety), C#/.NET Core, PHP, and cross-platform SQL/NoSQL query optimization. Integration and automation covers GitHub Actions/GitLab CI/Jenkins pipelines, Slack/Teams notification integration, VS Code/IntelliJ IDE integration, custom webhooks, quality gates, and metrics dashboards. Its behavioral traits emphasize a constructive, educational tone that teaches rather than just flags issues, balancing thoroughness with development velocity, prioritizing security and production reliability above all else, and staying current with emerging threats. Its ten-step response approach: analyze code context and scope, apply automated tools first, conduct manual review for logic/architecture/business fit, assess security implications, evaluate performance impact, review configuration changes with production-risk attention, provide severity-organized structured feedback, suggest improvements with concrete code examples, document rationale for complex decisions, and follow up on implementation.

When to use - and when NOT to

Use this skill when reviewing code for quality, security, performance, and maintainability across a wide range of concerns - APIs, database migrations, frontend components, Kubernetes configs, authentication implementations, caching strategies, or CI/CD pipelines. It is not a narrow, single-purpose linter - it's a broad reviewer persona meant to combine automated tooling with manual judgment across many domains at once, so for a highly specific automated-only AI-review pipeline with concrete orchestration code, a more narrowly-scoped review-automation skill may fit better.

Inputs and outputs

Input is code, configuration, or infrastructure changes to review (a PR, a migration, a component, a deployment manifest). Output is structured, severity-organized review feedback with concrete code examples, security/performance/architecture assessments, and mentor-style explanations of the reasoning behind each recommendation.

Integrations

Spans AI review tools (Trag, Bito, Codiga, GitHub Copilot), static analysis platforms (SonarQube, CodeQL, Semgrep, Snyk, Bandit), CI/CD systems (GitHub Actions, GitLab CI, Jenkins), IDEs (VS Code, IntelliJ), and communication tools (Slack, Teams), across JavaScript/TypeScript, Python, Java, Go, Rust, C#/.NET, and PHP ecosystems, with awareness of regulatory compliance requirements like SOC2, PCI DSS, and GDPR for security-sensitive reviews, informed by DevSecOps and shift-left security methodologies.

Who it's for

Engineers and teams who want a comprehensive, mentor-style code reviewer combining AI-assisted analysis, static analysis tooling, security/performance expertise, and team-process guidance across many languages and domains at once.

FAQ

Common questions

Discussion

Questions & comments ยท 0

Sign In Sign in to leave a comment.