Code quality skillCommunity

Code Review Skill

Matt Pocock's code review skill checks your branch twice, once against the repo's standards and once against the issue it was meant to solve.

Works in
  • Claude Code
  • Codex

By Matt Pocock · mattpocock/skills · MIT

Last updated

Install

Run

npx skills add mattpocock/skills --skill code-review

This installs the repo's latest version. We reviewed commit c55ee46; use the Manual tab to install exactly that.

What it can touch

Runs scripts
No. Instructions only.
Needs network
No.
allowed-tools
Not set. It asks for no extra tool permissions; your tool's usual prompts apply.
Licence
MIT
Last reviewed
How we check a skill is safe
Check it yourself

Agent skills checklist

0 of 10 checked

Who made it

Before reading a line of it, know whose code you are about to run.

What's inside

The part people skip. Read what your agent will read.

What it can reach

Give it the least access that still does the job.

Keeping it that way

What you checked today is only what runs tomorrow if you pin it.

Your ticks are saved in this browser only.

Ask an AI agent to review your branch and you usually get a mixed list: a naming nit, a missing test, a question about whether the feature is what was asked for, all in one ranking. Matt Pocock's code review skill splits that into two separate reviews. One checks the code against your repo's standards. The other checks it against the issue or spec it was meant to implement. You get both reports side by side.

What it does

You give it a starting point (a branch, a commit, main), and it:

  1. Pins the diff. Runs git diff <start>...HEAD and lists the commits, and stops early if the ref is wrong or the diff is empty.
  2. Finds the spec. Issue numbers in the commit messages first, then a path you pass, then a matching file under docs/, specs/ or .scratch/. If there isn't one, it asks.
  3. Finds the standards. Files like CONTRIBUTING.md or CODING_STANDARDS.md, plus a fixed list of twelve code smells from Martin Fowler's Refactoring (Duplicated Code, Feature Envy, Shotgun Surgery and so on). Your repo's rules override the smells.
  4. Runs two sub-agents in parallel, one per axis, each limited to about 400 words.
  5. Reports them separately under Standards and Spec, without merging or re-ranking.

It explains the split this way:

Code that follows every standard but implements the wrong thing → Standards pass, Spec fail.

From SKILL.md by Matt Pocock, MIT.

An example

You say: "Review since main." The branch's commits mention #42, which asked for CSV export with a date filter. The Spec review reports that the date filter is missing and that a JSON export was added that nobody asked for. The Standards review separately flags a possible Data Clump (from, to and timezone passed together through three functions) as a judgement call, and notes the new file breaks the repo's documented naming rule.

When to use it, and when not to

Use it before you open a pull request, or when reviewing someone else's, and especially when there's a written issue to check against. It's a good way to learn the classic code smells too, because each finding names one.

It's not a security review and doesn't run your tests. For a one-line change, reading the diff yourself is quicker.

What we checked

We read every file in the folder at the commit linked above: SKILL.md and agents/openai.yaml (a display name for Codex). There are no scripts and no allowed-tools. It runs git commands in your repo and reads files in it. If you've set up an issue tracker file with Matt Pocock's setup skill, it follows that file to fetch the issue, which can go over the network with your tracker's own command-line tool; without it, nothing leaves your machine. The repo is MIT licensed. Our full checklist is in the guide to checking a skill before you install it.

To settle the plan before you build, and have a spec to review against, try the grill me skill.

FAQ

What are the two axes?

Standards: does the code follow the rules this repo documents, plus a baseline of common code smells? Spec: does it do what the issue or spec asked, no more and no less? They're reviewed separately so a pass on one can't hide a fail on the other.

It told me to run /setup-matt-pocock-skills. Do I have to?

No. That setup skill writes a file describing your issue tracker, which the review uses to fetch the issue behind your commits. Without it, the review still looks for a spec in your commit messages, in a path you give it, or under docs/ or specs/, and asks you if it finds nothing.

Does it fix what it finds?

No. It reports findings under two headings and a one-line summary. What to fix, and whether a code smell is worth fixing, is left to you.

Does it need sub-agents?

It's written to run the two reviews as parallel sub-agents, which Claude Code and Codex both support. That keeps each review's context separate, which is part of the point.

See all skills