ai-code-review
Review AI-authored code for its characteristic failure modes — plausible-but-wrong logic, hallucinated APIs, over-engineering, dead scaffolding, and silent security shortcuts
Install / Use
npx skills add mohitagw15856/pm-claude-skills --skill ai-code-reviewInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of ai-code-review
ai-code-review scores 82/100 on our quality scale, 831st of 1,088 Security skills we index.
Its SKILL.md is 5.6 KB long, well organised into 8 sections and no code examples: a solid amount of guidance for an agent.
With 1,396 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 8 days ago, so ai-code-review is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ai-code-review compared with similar skills
All 4 of these similar skills score higher than ai-code-review; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ai-code-review (this skill)by mohitagw15856 | 82 | 1.4k | 8d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 88.6k | 17d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.3k | 2d ago | MCP Server |
| crawl4aiby unclecode | 100 | 84.7k | 7d ago | MCP Server |
Frequently asked questions
- How do I install ai-code-review?
- Run
npx skills add mohitagw15856/pm-claude-skills --skill ai-code-review. The install tabs above show the steps for each supported agent. - Which AI agents does ai-code-review work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ai-code-review safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ai-code-review still maintained?
- The repository was last updated 8 days ago, so ai-code-review is actively maintained.
Skill content
View source on GitHubname: ai-code-review description: "Review AI-authored code for its characteristic failure modes — plausible-but-wrong logic, hallucinated APIs, over-engineering, dead scaffolding, and silent security shortcuts. Use when reviewing an AI-generated or heavily AI-assisted PR, when AI-written code keeps shipping subtle bugs, or when setting review standards for a team using coding agents. Produces a focused review with AI-specific findings, verification steps per risk class, and a team checklist for AI-authored changes. For general PR review use code-review-checklist — this skill covers what that one assumes a human wouldn't do."
AI Code Review Skill
Human code fails where the human got tired or didn't know; AI code fails where plausibility diverged from correctness — and it fails fluently, with confident naming, clean formatting, and tests that pass without testing anything. Reviewing it with human-code instincts ("looks careful, probably is careful") is how the new bug class ships. This skill reviews for the failure modes that are characteristically AI.
What This Skill Produces
- A review of the change organised by AI-characteristic risk, each finding with file/line and severity
- Verification steps the reviewer must actually run (not read) per risk class
- A team checklist for AI-authored PRs, calibrated to this codebase
Required Inputs
Ask for (if not already provided):
- The diff or PR (or the files changed)
- Provenance honestly: fully agent-written, human-piloted, or mixed — and whether the author reviewed it themselves before requesting review
- The codebase context: existing conventions/utilities the AI may not have known, and what the change claims to do
- Test infrastructure: what CI actually runs (the AI may have written tests CI never executes)
The AI-Characteristic Failure Modes
Review in this order — most damaging first:
- Plausible-but-wrong logic. The code reads correctly and does something subtly different: inverted edge conditions, off-by-one on boundaries the prompt never mentioned, the right algorithm for a slightly different problem. Verification: trace 2-3 concrete inputs through the changed logic by hand — the fluency of the code is not evidence; it's the camouflage.
- Hallucinated or misused APIs. Methods that don't exist in this version, config keys from a different library, plausible-sounding parameters silently ignored. Verification: for every external API call touched, check the actual dependency version's docs — not memory, not the AI's comment.
- Tests that test nothing. Asserting mocks return what they were mocked to return; happy-path-only suites with confident names; tests copied from the implementation (tautological). Verification: mentally break the implementation — would any test fail? If not, the coverage number is decoration.
- Reinvention and drift. A new utility duplicating an existing one (the AI didn't know your
utils/), a new pattern where the codebase has a convention, a second source of truth. Verification: for each new helper/abstraction, grep for the existing equivalent. - Over-engineering as default. Speculative generality: interfaces with one implementer, config for things that never vary, error hierarchies for a script. AI pads scope because scope was ambiguous. Finding, not felony — but it's yours to maintain forever.
- Dead scaffolding. Unused imports/variables, TODO stubs presented as done, commented-out alternatives, leftover debug logging. Cheap to catch, and its presence predicts the deeper failures — a diff with scaffolding wasn't self-reviewed.
- Silent security shortcuts. Broad exception swallowing, disabled TLS verification "for now", string-built SQL, secrets in examples that became code, permissive CORS. AI reproduces the internet's average security posture unless told otherwise. Verification: run the security linters even for a "trivial" change; the shortcut is rarely where the feature is.
Output Format
AI Code Review: [PR/change] — provenance: [stated]
Verdict: ✅ approve / 🟡 approve with required fixes / 🔴 request changes — [one line]
Findings | # | Failure mode | Location | Severity | Finding + fix | |---|---|---|---|---|
Verified by running: [the hand-traces, API checks, and break-the-test exercises actually performed — a review that only read the diff says so]
Debt accepted knowingly: [over-engineering/style items merged anyway, listed so they're chosen]
Team checklist for AI-authored PRs: [the 7 modes as a calibrated checklist + the house rule: AI-assisted PRs declare provenance, and the author self-reviews before requesting review]
Quality Checks
- [ ] At least one concrete input was hand-traced through the changed logic
- [ ] Every touched external API was verified against the actual dependency version
- [ ] Each test was assessed by "what breakage would this catch?"
- [ ] New helpers were grepped against existing utilities
- [ ] The verdict distinguishes required fixes from accepted debt
Anti-Patterns
- [ ] Do not extend human-code trust heuristics ("clean and well-named, so probably correct") — fluency is the failure mode's costume
- [ ] Do not approve on green CI without checking whether the tests can fail
- [ ] Do not review the description instead of the diff — AI PR descriptions are confident summaries of intent, not of behaviour
- [ ] Do not reject code for being AI-written — review the code; provenance calibrates scrutiny, not verdicts
- [ ] Do not skip security linting because the change is small — the shortcut hides in the periphery
- [ ] Do not accept "the agent tested it" as verification — demand the evidence in the PR
Related Skills
Agent-Reach
88.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.3kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.3k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.7kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
