smithery/coder

code-review

Reviews code changes for bugs, security issues, and quality problems

Installation

$ npx skills add smithery/coder --skill code-review

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/coder.

npx skills add smithery/coder

Browse all from smithery/coder

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,300 B
  • docs SUMMARY.md 87 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Code Review Skill

Review code changes in coder/coder and identify bugs, security issues, and quality problems.

Workflow

  1. Get the code changes - Use the method provided in the prompt, or if none

specified: - For a PR: gh pr diff <PR_NUMBER> --repo coder/coder - For local changes: git diff main or git diff --staged

  1. Read full files and related code before commenting - verify issues exist

and consider how similar code is implemented elsewhere in the codebase

  1. Analyze for issues - Focus on what could break production
  1. Report findings - Use the method provided in the prompt, or summarize

directly

Severity Levels

  • 🔴 CRITICAL: Security vulnerabilities, auth bypass, data corruption,

crashes

  • 🟡 IMPORTANT: Logic bugs, race conditions, resource leaks, unhandled

errors

  • 🔵 NITPICK: Minor improvements, style issues, portability concerns

What to Look For

  • Security: Auth bypass, injection, data exposure, improper access control
  • Correctness: Logic errors, off-by-one, nil/null handling, error paths
  • Concurrency: Race conditions, deadlocks, missing synchronization
  • Resources: Leaks, unclosed handles, missing cleanup
  • Error handling: Swallowed errors, missing validation, panic paths
  • Frontend (site/src/): audit against the FE rule IDs in

[Frontend Patterns](../../docs/FRONTEND_PATTERNS.md) and cite the rule ID in findings (for example, "FE7: re-typed query key")

What NOT to Comment On

  • Style that matches existing Coder patterns (check AGENTS.md first)
  • Code that already exists unchanged
  • Theoretical issues without concrete impact
  • Changes unrelated to the PR's purpose

Coder-Specific Patterns

Authorization Context

// Public endpoints needing system access
dbauthz.AsSystemRestricted(ctx)

// Authenticated endpoints with user context - just use ctx
api.Database.GetResource(ctx, id)

Error Handling

// OAuth2 endpoints use RFC-compliant errors
writeOAuth2Error(ctx, rw, http.StatusBadRequest, "invalid_grant", "description")

// Regular endpoints use httpapi
httpapi.Write(ctx, rw, http.StatusBadRequest, codersdk.Response{...})

Shell Scripts

set -u only catches UNDEFINED variables, not empty strings:

unset VAR; echo ${VAR}         # ERROR with set -u
VAR=""; echo ${VAR}            # OK with set -u (empty is fine)
VAR="${INPUT:-}"; echo ${VAR}  # OK - always defined

GitHub Actions context variables (github., inputs.) are always defined.

Review Quality

  • Explain impact ("causes crash when X" not "could be better")
  • Make observations actionable with specific fixes
  • Read the full context before commenting on a line
  • Check AGENTS.md for project conventions before flagging style

Comment Standards

  • Only comment when confident - If you're not 80%+ sure it's a real issue,

don't comment. Verify claims before posting.

  • No speculation - Avoid "might", "could", "consider". State facts or skip.
  • Verify technical claims - Check documentation or code before asserting how

something works. Don't guess at API behavior or syntax rules.