Code Reviewer
SkillSecurityReview code changes for bugs, security issues, regressions, and maintainability. Use on diffs, PRs, or before merge - pairs with gh CLI and code_review tool when available.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Code Reviewer skill
What this skill tells your AI
The instructions your AI receives, as published by navinspire-ia/navin in navin/skills/code-reviewer/SKILL.md and read by ahel’s review.
Overview
Review like a careful senior engineer with precision over recall (open-code-review). Combine pr-agent style describe + findings + patch suggestions.
Workflow
- Call
code_review(action=scope)(or scope a path) - OCR 5-gates + optional.navin/review-rules.json/.opencodereview/rule.json. - Restate intent in 3-6 bullets + estimate effort 1-5 + whether tests cover the change.
- Deep-read risky hunks (auth, data, concurrency, migrations). Follow
path_rulesreturned by scope when present. - Run relevant tests / lint with
execwhen the environment allows. - Emit findings with the schema below; call
code_review(action=filter)to drop FP. - Close with
code_review(action=report, findings_json=..., verdict=..., effort=N)- File Preview opens automatically in the WebUI. - Optional PR:
pr_comments(action=preview|post, kind=review, findings_json=...).
Finding schema
| Field | Values |
|---|---|
| severity | critical / high / medium / low / info / nit |
| category | bug / security / performance / maintainability / test / style / documentation / api / data / other |
| confidence | 0.0-1.0 (keep ≥ 0.6) |
| file_path, start_line, end_line | required when known (file:line) |
| existing_code / suggested_code | required for High+ when a patch is clear |
| summary, explanation, recommendation | actionable + REAL evidence |
Focus areas
- Correctness & edge cases
- Security (injection, authz, secrets) - but defer full AppSec to
/fortify - Performance footguns only when real
- API/contract breaks
- Missing tests for new branches
Rules
- Cite
path(and line when known). - Prefer actionable fixes over style nits unless asked for nits.
- Use
pr_comments(viagh) when the user asks to comment on a PR. - Answer follow-up Q&A scoped to finding #N or selected lines.
- Never invent. Every finding needs a tool-observed excerpt (
existing_code/ failing output). Before claiming something is missing or "always X",grepfor the opposite. Drop could/might/peut-être claims. Confidence floor 0.75.
Signals
- GitHub stars
- 22
- Forks
- 4
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
code-reviewer-navinspire-ia- Source
- github.com/navinspire-ia/navin