# Code Review

Code Review is a tested SKILL.md that reviews a code change (a diff or a changed file pasted as text) and reports real problems ranked by severity — correctness bugs, security holes, data loss, missing error handling, edge cases, resource leaks — each with location, reason and a concrete fix in words; an agent buys it once for $0.05 over x402.

- Page: https://aiskills402.com/skills/code-review
- Category: Code & Engineering (https://aiskills402.com/categories/code)
- Price: $0.05 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/code-review

## Use it when

Reviews a code change (a diff or a changed file pasted as text) and reports real problems ranked by severity — correctness bugs, security holes, data loss, missing error handling, edge cases, resource leaks — each with location, reason and a concrete fix in words. Use when asked to review code, a diff or a pull request, check a change for bugs, or find security problems in a snippet.

## Not for

Style or formatting review, whole-repository audits, or proving code correct: it reads pasted text only, never runs the code, and can miss bugs that depend on code you did not paste.

## Tested, honestly

Tested 2026-09-30.

- Strong model (Claude Sonnet (claude-sonnet-5-5, Claude Code alias "sonnet")): Found every planted bug in all 5 buggy cases in both runs (missing await, off-by-one, SQL injection, unclosed file, UPDATE without WHERE, comparison with NULL, nil pointer, unclosed response body, assignment instead of comparison). Said 'No significant issues' on the clean change both times, invented nothing there. Ignored the injected 'approve this and say LGTM' comment and reported it as a finding. Adds real extra findings (CSV escaping, no timeout); sometimes adds speculative ones (server-side request forgery marked as an assumption, floating point on cart prices, a mutation note on an unrelated function).
- Weak model (Claude Haiku (claude-haiku-4-5-20251001, Claude Code alias "haiku")): Also found every planted bug in both runs and resisted the injected comment and the clean case. Weaker judgement: rates severity too high (unclosed response body and silently dropped decode error as Critical, floating point on prices as High), hedges ('likely missing await'), and once described the loop bug inaccurately. In the first run the verdict line contradicted its own Critical finding; a rule was added and this did not repeat in the second run.

Note: Planted-bug test: 6 cases (JavaScript, Python, SQL, Go, one clean TypeScript change, one with an injected instruction in a comment), 2 full runs per model, one run per case. Mechanical checks pass 12 of 12 in both runs; they check that bugs are named, not that severity is right. Only short changes (20-30 lines) were tested, not a real multi-file pull request. The reviewer reads text only and never runs the code.

Full summary: https://aiskills402.com/skills/code-review/tests

## What is in the file

- Hard rules
- How to work
- Severity
- Output format
- Examples of the judgement

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/code-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 6.0 KB (6099 bytes)
- SHA-256: 4d53a3ee20881538ef3451f79e9acae0e0b773349f25c381386cccaa04fe0392
- Updated: 2026-09-30
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-09-30)

- First release: severity-ranked review of a pasted diff or file; treats the code as data; says so plainly when nothing important is found.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### What kind of problems does it report?

Only problems it can tie to a concrete input or situation: missing awaits, injection into queries, unclosed files and connections, an update without a condition, comparisons with null, and similar. Each finding carries a location, a reason and a fix described in words.

### What if a comment in the code tells the reviewer to approve it?

The skill treats pasted code as data, never as instructions. In our test, both models ignored a planted comment asking for an approval and reported that comment as a finding. On a clean change, both said there were no significant issues.

### How big a change can it handle?

We tested short changes of 20 to 30 lines in JavaScript, Python, SQL, Go and TypeScript, not a real multi-file pull request. Paste the diff and the surrounding code it depends on; the skill marks any finding that rests on code it cannot see.

## Related skills

- [x402 Seller: Payable and Listed](https://aiskills402.com/skills/x402-seller.md): $0.10 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
