Skip to content
afrexai-code-reviewer logo

Code Review Engine

afrexai-code-reviewer

Enterprise-grade code review agent. Reviews PRs, diffs, or code files for security vulnerabilities, performance issues, error handling gaps, architecture smells, and test coverage. Works with any language, any repo, no dependencies required.

simplefarmer69/ape-claw0installs2stars

SKILL.md

Full skill instructions

Code Review Engine

Enterprise-grade automated code review. Works on GitHub PRs, local diffs, pasted code, or entire files. No dependencies — pure agent intelligence.

Quick Start

Review a GitHub PR

Review PR #42 in owner/​repo

Review a local diff

Review the staged changes in this repo

Review a file

Review src/​auth/​login.ts for security issues

Review pasted code

Just paste code and say "review this"


Review Framework: SPEAR

Every review follows the SPEAR framework — 5 dimensions, each scored 1-10:

🔴 S — Security (Weight: 3x)

CheckSeverityExample
Hardcoded secretsCRITICALAPI keys, passwords, tokens in source
SQL injectionCRITICALString concatenation in queries
XSS vectorsHIGHUnsanitized user input in HTML/​DOM
Path traversalHIGHUser input in file paths without validation
Insecure deserializationHIGHeval(), pickle.loads(), JSON.parse on untrusted input
Auth bypassCRITICALMissing auth checks on endpoints
SSRFHIGHUser-controlled URLs in server requests
Timing attacksMEDIUMNon-constant-time string comparison for secrets
Dependency vulnerabilitiesMEDIUMKnown CVEs in imported packages
Sensitive data loggingMEDIUMPII, tokens, passwords in log output
Insecure randomnessMEDIUMMath.random() for security-sensitive values
Missing rate limitingMEDIUMAuth endpoints without throttling

🟡 P — Performance (Weight: 2x)

CheckSeverityExample
N+1 queriesHIGHDB call inside a loop
Unbounded queriesHIGHSELECT * without LIMIT on user-facing endpoints
Missing indexes (implied)MEDIUMFrequent WHERE/​ORDER on unindexed columns
Memory leaksHIGHEvent listeners never removed, growing caches
Blocking main threadHIGHSync I/​O in async context, CPU-heavy in event loop
Unnecessary re-rendersMEDIUMReact: missing memo, unstable refs in deps
Large bundle importsMEDIUMimport _ from 'lodash' vs import get from 'lodash/​get'
Missing paginationMEDIUMReturning all records to client
Redundant computationLOWSame expensive calc repeated without caching
Connection pool exhaustionHIGHNot releasing DB/​HTTP connections

🟠 E — Error Handling (Weight: 2x)

CheckSeverityExample
Swallowed errorsHIGHEmpty catch blocks, Go _ := on error
Missing error boundariesMEDIUMReact components without error boundaries
Unchecked null/​undefinedHIGHNo null checks before property access
Missing finally/​cleanupMEDIUMResources opened but not guaranteed closed
Generic error messagesLOWcatch(e) { throw new Error("something went wrong") }
Missing retry logicMEDIUMNetwork calls without retry on transient failures
Panic/​exit in library codeHIGHpanic(), os.Exit(), process.exit() in non-main
Unhandled promise rejectionsHIGHAsync calls without .catch() or try/​catch
Error type conflationMEDIUMAll errors treated the same (4xx vs 5xx, retriable vs fatal)

🔵 A — Architecture (Weight: 1.5x)

CheckSeverityExample
God functions (>50 lines)MEDIUMSingle function doing too many things
God files (>300 lines)MEDIUMMonolithic module
Tight couplingMEDIUMDirect DB calls in request handlers
Missing abstractionLOWRepeated patterns that should be extracted
Circular dependenciesHIGHA imports B imports A
Wrong layerMEDIUMBusiness logic in controllers, SQL in UI
Magic numbers/​stringsLOWHardcoded values without named constants
Missing typesMEDIUMany in TypeScript, missing type hints in Python
Dead codeLOWUnreachable branches, unused imports/​variables
Inconsistent patternsLOWDifferent error handling styles in same codebase

📊 R — Reliability (Weight: 1.5x)

CheckSeverityExample
Missing tests for changesHIGHNew logic without corresponding test
Test qualityMEDIUMTests that only check happy path
Missing edge casesMEDIUMNo handling for empty arrays, null, boundary values
Race conditionsHIGHShared mutable state without synchronization
Non-idempotent operationsMEDIUMRetrying could cause duplicates
Missing validationHIGHUser input accepted without schema validation
Brittle testsLOWTests depending on execution order or timing
Missing loggingMEDIUMError paths with no observability
Configuration driftMEDIUMHardcoded env-specific values
Missing migrationsHIGHSchema changes without migration files

Scoring System

Per-Finding Severity

CRITICAL  → -3 points from dimension score
HIGH      → -2 points
MEDIUM    → -1 point
LOW       → -0.5 points
INFO      → 0 (suggestion only)

Overall SPEAR Score Calculation

Raw Score = (S×3 + P×2 + E×2 + A×1.5 + R×1.5) / 10
Final Score = Raw Score × 10  (scale 0-100)

Verdict Thresholds

ScoreVerdictAction
90-100✅ EXCELLENTShip it
75-89🟢 GOODMinor suggestions, approve
60-74🟡 NEEDS WORKAddress findings before merge
40-59🟠 SIGNIFICANT ISSUESMajor rework needed
0-39🔴 BLOCKCritical issues, do not merge

Review Output Template

Use this structure for every review:

# Code Review: [PR title or file name]

## Summary
[1-2 sentence overview of what this code does and overall quality]

## SPEAR Score: [X]/​100 — [VERDICT]

| Dimension | Score | Key Finding |
|-----------|-------|-------------|
| 🔴 Security | X/​10 | [worst finding or "Clean"] |
| 🟡 Performance | X/​10 | [worst finding or "Clean"] |
| 🟠 Error Handling | X/​10 | [worst finding or "Clean"] |
| 🔵 Architecture | X/​10 | [worst finding or "Clean"] |
| 📊 Reliability | X/​10 | [worst finding or "Clean"] |

## Findings

### [CRITICAL/​HIGH] 🔴 [Title]
**File:** `path/​to/​file.ts:42`
**Category:** Security
**Issue:** [What's wrong]
**Impact:** [What could happen]
**Fix:**
```[lang]
// suggested fix

[MEDIUM] 🟡 [Title]

...

What's Done Well

  • [Genuinely good patterns worth calling out]

Recommendations

  1. [Prioritized action items]

---

## Language-Specific Patterns

### TypeScript / JavaScript
- `any` type usage → Architecture finding
- `as` type assertions → potential runtime error
- `console.log` in production code → Style
- `==` instead of `===` → Reliability
- Missing `async/​await` error handling
- `useEffect` missing cleanup return
- Index signatures without validation

### Python
- Bare `except:` or `except Exception:` → Error Handling
- `eval()` / `exec()` → Security CRITICAL
- Mutable default arguments → Reliability
- `import *` → Architecture
- Missing `__init__.py` type hints
- f-strings with user input → potential injection

### Go
- `_ :=` discarding errors → Error Handling HIGH
- `panic()` in library code → Reliability HIGH
- Missing `defer` for resource cleanup
- Exported functions without doc comments
- `interface{}` / `any` overuse

### Java
- Catching `Exception` or `Throwable` → Error Handling
- Missing `@Override` annotations
- Mutable static fields → thread safety
- `System.out.println` in production
- Missing null checks (pre-Optional code)

### SQL
- String concatenation in queries → Security CRITICAL
- `SELECT *` → Performance
- Missing WHERE on UPDATE/​DELETE → Security CRITICAL
- No LIMIT on user-facing queries → Performance
- Missing indexes for JOIN columns

---

## Advanced Techniques

### Reviewing for Business Logic
Beyond code quality, check:
- Does the code match the PR description / ticket requirements?
- Are there edge cases the spec didn't mention?
- Could this break existing functionality?
- Is there a simpler way to achieve the same result?

### Reviewing for Operability
- Can this be debugged in production? (logging, error messages)
- Can this be rolled back safely?
- Are feature flags needed?
- What monitoring should accompany this change?

### Reviewing Database Changes
- Is the migration reversible?
- Will it lock tables during migration?
- Are there indexes for new query patterns?
- Is there a data backfill needed?

### Security Review Depth Levels
| Level | When | What |
|-------|------|------|
| Quick | Internal tool, trusted input | OWASP Top 10 patterns only |
| Standard | User-facing feature | + auth, input validation, output encoding |
| Deep | Payment, auth, PII handling | + crypto review, session management, audit logging |
| Threat Model | New service/​API surface | + attack surface mapping, trust boundaries |

---

## Integration Patterns

### GitHub PR Review
```bash
# Get PR diff
gh pr diff 42 --repo owner/​repo

# Get PR details
gh pr view 42 --repo owner/​repo --json title,body,files,commits

# Post review comment
gh pr review 42 --repo owner/​repo --comment --body "review content"

Local Git Review

# Review staged changes
git diff --cached

# Review branch vs main
git diff main..HEAD

# Review last N commits
git log -5 --oneline && git diff HEAD~5..HEAD

Heartbeat / Cron Integration

Check for open PRs in [repo] that I haven't reviewed yet.
For each, run a SPEAR review and post the results as a PR comment.

Edge Cases & Gotchas

  • Large PRs (>500 lines): Break into logical chunks. Review file-by-file. Flag the PR size itself as a finding (Architecture: "PR too large — consider splitting").
  • Generated code: Skip generated files (proto, swagger, migrations from ORMs). Note that you skipped them.
  • Dependency updates: Focus on breaking changes in changelogs, not the lockfile diff.
  • Merge conflicts markers: Flag immediately as CRITICAL — <<<<<<< in code means broken merge.
  • Binary files: Note presence, can't review content.
  • Config changes: Extra scrutiny — wrong env var = production outage.
  • Refactors: Verify behavior preservation. Check if tests still pass conceptually.

Review Checklist (Quick Mode)

For fast reviews when full SPEAR isn't needed:

  • No hardcoded secrets or credentials
  • No SQL injection / XSS / path traversal
  • All errors handled (no empty catch, no discarded errors)
  • No N+1 queries or unbounded operations
  • Tests exist for new/​changed logic
  • No console.log / print / fmt.Print left in
  • Functions under 50 lines, files under 300 lines
  • Types are specific (no any / interface{})
  • PR description matches the actual changes
  • No TODOs without linked issues

More skills from simplefarmer69

content-gap-analysis logo
simplefarmer69/ape-claw

content-gap-analysis

Use when the user asks to "find content gaps", "what am I missing", "topics to cover", "content opportunities", "what do competitors write about that I do not", "what topics am I missing", "topics my competitors cover that I lack", or "where are my content blind spots". Identifies content opportu...

2 0
View
afrexai-api-architect logo
simplefarmer69/ape-claw

afrexai-api-architect

Design, build, test, document, and secure production-grade APIs. Covers the full lifecycle from schema design through deployment, monitoring, and versioning. Use when designing new APIs, reviewing existing ones, generating OpenAPI specs, building test suites, or debugging production issues.

2 0
View
things-mac logo
simplefarmer69/ape-claw

things-mac

Manage Things 3 via the `things` CLI on macOS (add/update projects+todos via URL scheme; read/search/list from the local Things database). Use when a user asks OpenClaw to add a task to Things, list inbox/today/upcoming, search tasks, or inspect projects/areas/tags.

2 0
View
wacli logo
simplefarmer69/ape-claw

wacli

Send WhatsApp messages to other people or search/sync WhatsApp history via the wacli CLI (not for normal user chats).

2 0
View
coding-agent logo
simplefarmer69/ape-claw

coding-agent

Delegate coding tasks to Codex, Claude Code, or Pi agents via background process. Use when: (1) building/creating new features or apps, (2) reviewing PRs (spawn in temp dir), (3) refactoring large codebases, (4) iterative coding that needs file exploration. NOT for: simple one-liner fixes (just e...

2 0
View
yahoo-finance logo
simplefarmer69/ape-claw

yahoo-finance

Get stock prices, quotes, fundamentals, earnings, options, dividends, and analyst ratings using Yahoo Finance. Uses yfinance library - no API key required.

2 0
View
internal-linking-optimizer logo
simplefarmer69/ape-claw

internal-linking-optimizer

Use when the user asks to "fix internal links", "improve site architecture", "link structure", "distribute page authority", "internal linking strategy", "orphan pages", "site architecture is messy", or "pages have no links pointing to them". Analyzes and optimizes internal link structure to impro...

2 0
View
coda logo
simplefarmer69/ape-claw

coda

General-purpose Coda document manager via REST API v1. Supports listing/creating/updating/deleting docs, managing tables/rows/pages, triggering automations, and exploring doc structure. Requires CODA_API_TOKEN environment variable. Delete operations require explicit confirmation; publishing and p...

2 0
View
backlink-analyzer logo
simplefarmer69/ape-claw

backlink-analyzer

Use when the user asks to "analyze backlinks", "check link profile", "find toxic links", "link building opportunities", "off-page SEO", "who links to me", "I have spammy links", "how do I get more backlinks", or "disavow links". Analyzes backlink profiles to understand link authority, identify to...

2 0
View
obsidian-sync logo
simplefarmer69/ape-claw

obsidian-sync

Sync files between Clawdbot workspace and Obsidian. Run the sync server to enable two-way file synchronization with the OpenClaw Obsidian plugin.

2 0
View
food-order logo
simplefarmer69/ape-claw

food-order

Reorder Foodora orders + track ETA/status with ordercli. Never confirm without explicit user approval. Triggers: order food, reorder, track ETA.

2 0
View
Canvas Skill logo
simplefarmer69/ape-claw

Canvas Skill

Display HTML content on connected OpenClaw nodes (Mac app, iOS, Android).

2 0
View

Popular AI tools

Kaiber logo
Video

Kaiber

Generate, edit, and beat-sync AI video with leading models in one workspace.

Paid
View
Vimcal logo
Productivity

Vimcal

The world's fastest calendar for remote work

Free
View

Transform Your Design with AI Designer by ImgCreator.ai

Freemium
View
Akool AI logo
Content & writing

Akool AI

Revolutionizing Video Production with AI-Powered Creativity

Paid
View

Extend an image past the frame and let AI fill the new aspect ratio.

Freemium
View
StarByFace logo
Security

StarByFace

Discover your celebrity doppelgänger with StarByFace!

Free
View
C

ChainClarity explains 700+ crypto whitepapers in plain English, with layered summaries, comparisons, research tools, alerts, and a $4.99 Pro plan.

Freemium
View
Opus Clip logo
Coding & apps

Opus Clip

Opus.ai: Revolutionize Your Web Experience

Free
View