SkillAgentSearch skills...

ai-code-review

Review AI-authored code for its characteristic failure modes — plausible-but-wrong logic, hallucinated APIs, over-engineering, dead scaffolding, and silent security shortcuts

Install / Use

npx skills add mohitagw15856/pm-claude-skills --skill ai-code-review

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

82/100

Category

Security

Supported Platforms

Universal

Our assessment of ai-code-review

ai-code-review scores 82/100 on our quality scale, 831st of 1,088 Security skills we index.

Its SKILL.md is 5.6 KB long, well organised into 8 sections and no code examples: a solid amount of guidance for an agent.

With 1,396 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 8 days ago, so ai-code-review is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

ai-code-review compared with similar skills

All 4 of these similar skills score higher than ai-code-review; compare them before choosing.

SkillScoreStarsUpdatedFormat
ai-code-review (this skill)by mohitagw15856821.4k8d agoSKILL.md
Agent-Reachby Panniantong10088.6k17d agoCLAUDE.md
headroomby headroomlabs-ai10074.3ktodayCLAUDE.md
Scraplingby D4Vinci10085.3k2d agoMCP Server
crawl4aiby unclecode10084.7k7d agoMCP Server

Frequently asked questions

How do I install ai-code-review?
Run npx skills add mohitagw15856/pm-claude-skills --skill ai-code-review. The install tabs above show the steps for each supported agent.
Which AI agents does ai-code-review work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is ai-code-review safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is ai-code-review still maintained?
The repository was last updated 8 days ago, so ai-code-review is actively maintained.

name: ai-code-review description: "Review AI-authored code for its characteristic failure modes — plausible-but-wrong logic, hallucinated APIs, over-engineering, dead scaffolding, and silent security shortcuts. Use when reviewing an AI-generated or heavily AI-assisted PR, when AI-written code keeps shipping subtle bugs, or when setting review standards for a team using coding agents. Produces a focused review with AI-specific findings, verification steps per risk class, and a team checklist for AI-authored changes. For general PR review use code-review-checklist — this skill covers what that one assumes a human wouldn't do."

AI Code Review Skill

Human code fails where the human got tired or didn't know; AI code fails where plausibility diverged from correctness — and it fails fluently, with confident naming, clean formatting, and tests that pass without testing anything. Reviewing it with human-code instincts ("looks careful, probably is careful") is how the new bug class ships. This skill reviews for the failure modes that are characteristically AI.

What This Skill Produces

  • A review of the change organised by AI-characteristic risk, each finding with file/line and severity
  • Verification steps the reviewer must actually run (not read) per risk class
  • A team checklist for AI-authored PRs, calibrated to this codebase

Required Inputs

Ask for (if not already provided):

  • The diff or PR (or the files changed)
  • Provenance honestly: fully agent-written, human-piloted, or mixed — and whether the author reviewed it themselves before requesting review
  • The codebase context: existing conventions/utilities the AI may not have known, and what the change claims to do
  • Test infrastructure: what CI actually runs (the AI may have written tests CI never executes)

The AI-Characteristic Failure Modes

Review in this order — most damaging first:

  1. Plausible-but-wrong logic. The code reads correctly and does something subtly different: inverted edge conditions, off-by-one on boundaries the prompt never mentioned, the right algorithm for a slightly different problem. Verification: trace 2-3 concrete inputs through the changed logic by hand — the fluency of the code is not evidence; it's the camouflage.
  2. Hallucinated or misused APIs. Methods that don't exist in this version, config keys from a different library, plausible-sounding parameters silently ignored. Verification: for every external API call touched, check the actual dependency version's docs — not memory, not the AI's comment.
  3. Tests that test nothing. Asserting mocks return what they were mocked to return; happy-path-only suites with confident names; tests copied from the implementation (tautological). Verification: mentally break the implementation — would any test fail? If not, the coverage number is decoration.
  4. Reinvention and drift. A new utility duplicating an existing one (the AI didn't know your utils/), a new pattern where the codebase has a convention, a second source of truth. Verification: for each new helper/abstraction, grep for the existing equivalent.
  5. Over-engineering as default. Speculative generality: interfaces with one implementer, config for things that never vary, error hierarchies for a script. AI pads scope because scope was ambiguous. Finding, not felony — but it's yours to maintain forever.
  6. Dead scaffolding. Unused imports/variables, TODO stubs presented as done, commented-out alternatives, leftover debug logging. Cheap to catch, and its presence predicts the deeper failures — a diff with scaffolding wasn't self-reviewed.
  7. Silent security shortcuts. Broad exception swallowing, disabled TLS verification "for now", string-built SQL, secrets in examples that became code, permissive CORS. AI reproduces the internet's average security posture unless told otherwise. Verification: run the security linters even for a "trivial" change; the shortcut is rarely where the feature is.

Output Format

AI Code Review: [PR/change] — provenance: [stated]

Verdict: ✅ approve / 🟡 approve with required fixes / 🔴 request changes — [one line]

Findings | # | Failure mode | Location | Severity | Finding + fix | |---|---|---|---|---|

Verified by running: [the hand-traces, API checks, and break-the-test exercises actually performed — a review that only read the diff says so]

Debt accepted knowingly: [over-engineering/style items merged anyway, listed so they're chosen]

Team checklist for AI-authored PRs: [the 7 modes as a calibrated checklist + the house rule: AI-assisted PRs declare provenance, and the author self-reviews before requesting review]

Quality Checks

  • [ ] At least one concrete input was hand-traced through the changed logic
  • [ ] Every touched external API was verified against the actual dependency version
  • [ ] Each test was assessed by "what breakage would this catch?"
  • [ ] New helpers were grepped against existing utilities
  • [ ] The verdict distinguishes required fixes from accepted debt

Anti-Patterns

  • [ ] Do not extend human-code trust heuristics ("clean and well-named, so probably correct") — fluency is the failure mode's costume
  • [ ] Do not approve on green CI without checking whether the tests can fail
  • [ ] Do not review the description instead of the diff — AI PR descriptions are confident summaries of intent, not of behaviour
  • [ ] Do not reject code for being AI-written — review the code; provenance calibrates scrutiny, not verdicts
  • [ ] Do not skip security linting because the change is small — the shortcut hides in the periphery
  • [ ] Do not accept "the agent tested it" as verification — demand the evidence in the PR

Related Skills

View on GitHub
GitHub Stars1.4k
CategorySecurity
Updated8d ago
Forks249

Languages

HTML

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions