code-review-pipeline

SkillSecurity

code-review-pipeline adds multi-dimensional code review to your AI. Once it is added, your AI can examine code for correctness bugs, security issues, performance problems, and maintainability concerns, then suggest fixes. It reports the findings it is confident about and can run follow-up passes to work through remediation.

Available today. Use it from your connected AI after setup.

Add the skill, then ask your AI to review a file or a set of code changes. It will return the issues it finds along with suggested fixes.

Then ask your AI: use the code-review-pipeline skill

What your AI can do with it

  • Review code for correctness bugs
  • Flag security issues in your code
  • Spot performance problems
  • Assess how maintainable the code is
  • Suggest fixes for the issues it finds
  • Run follow-up review passes until reported issues are remediated

What this skill tells your AI

The instructions your AI receives, as published by a5c-ai/babysitter in library/methodologies/everything-claude-code/skills/code-review-pipeline/SKILL.md and read by ahel’s review.

  • Logic errors and off-by-one mistakes
  • Edge case handling (null, undefined, empty, boundary)
  • Type safety (no implicit any, proper narrowing)
  • Error handling completeness
  • Floating promise detection
  • Race condition analysis

Dimension 2: Security

  • Injection vectors (SQL, XSS, command, template)
  • Authentication and authorization gaps
  • Data exposure (PII, credentials, internal state)
  • Dependency vulnerabilities (known CVEs)
  • Input validation completeness

Dimension 3: Performance

  • Algorithmic complexity (O(n^2) detection)
  • Memory leaks (event listeners, closures, caches)
  • Unnecessary allocations in hot paths
  • Database query optimization (N+1, missing indexes)
  • Bundle size impact

Dimension 4: Maintainability

  • Naming clarity and consistency
  • Documentation completeness (JSDoc, inline comments)
  • Test coverage adequacy
  • Coupling analysis (afferent/efferent)
  • File organization compliance

Confidence Gating

  • Score each issue 0-100 on confidence
  • Only report issues >= 80% confidence
  • Prevents false positive noise
  • Higher confidence for clear patterns, lower for heuristic matches

Remediation Loop

  • Prioritize: critical > high > medium > low
  • Apply fixes via refactor-cleaner agent
  • Re-review after remediation
  • Maximum 2 remediation cycles
  • Exit when no critical/high issues remain

When to Use

  • Post-implementation review
  • Pre-merge PR review
  • Security audit
  • Technical debt assessment

Agents Used

  • code-reviewer (primary)
  • refactor-cleaner (remediation)

Signals

GitHub stars
2k
Forks
106
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
code-review-pipeline
Source
github.com/a5c-ai/babysitter