CCM
/Skills
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
onewave-ai avatar

Code Review Pro

onewave-ai/claude-skills
2.5k installs244 stars
Summary

This is your systematic code reviewer that catches what you miss in pull requests. It prioritizes security first (SQL injection, XSS, auth holes), then moves through performance bottlenecks like N+1 queries and memory leaks, code quality issues, and best practice violations. Every finding comes with before/after code snippets and severity ratings from critical to low priority. The output format is solid: grouped by urgency, includes a quick wins section for high impact fixes, and actually acknowledges what you did right. Use it when you need a thorough audit beyond linter warnings, especially on unfamiliar codebases or before production deploys.

Install to Claude Code

npx -y skills add onewave-ai/claude-skills --skill code-review-pro --agent claude-code

Installs into .claude/skills of the current project.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Lid closed, agents working
Lid closed, agents working
Keeps your Mac awake while Claude Code, Codex or Cursor works. Lets it sleep when they are done.
Try free for 7 days →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Open Steps
Open Steps
Free an open-source skills that make AI coding agents easier to understand, verify, and control.
Download for free →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Lid closed, agents working
Lid closed, agents working
Keeps your Mac awake while Claude Code, Codex or Cursor works. Lets it sleep when they are done.
Try free for 7 days →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Open Steps
Open Steps
Free an open-source skills that make AI coding agents easier to understand, verify, and control.
Download for free →
Files
SKILL.mdView on GitHub

Code Review Pro

Find the problems that matter, prove each one, and show the fix. A short list of real issues beats a long list of maybes.

Workflow

  1. Set the scope. Decide what is under review: a pasted snippet, specific files, the working-tree diff (git diff, git diff --staged), or a branch against its base (git diff main...HEAD). For a diff, review the changed lines but read enough surrounding code to know how they are called.

  2. Learn the context before judging. Identify language, framework and version (check package.json, pyproject.toml, go.mod, and so on), how the code is reached (HTTP handler, job, CLI, library), what input is untrusted, and any repo conventions (linters, CLAUDE.md, existing patterns). A pattern that is a bug in one framework can be safe in another; for example, React escapes JSX text, so XSS lives in dangerouslySetInnerHTML, href values, and raw HTML sinks.

  3. Review in priority order, using references/checklist.md:

    1. Security
    2. Correctness and edge cases
    3. Performance
    4. Maintainability and conventions
  4. Verify every finding before reporting it. For each candidate, trace the data flow: where does the input come from, can an attacker or real user control it, and does anything upstream already validate or escape it? Check whether a test covers it. If you can run code, reproduce the bug with a small test or script. Drop findings you cannot support; mark the rest with a confidence level.

  5. Rank and write the report in the format below. Lead with the highest severity. Group repeated instances of one problem into a single finding with all locations.

Severity

  • Critical - exploitable now or causes data loss/corruption: injection with user input, auth bypass, secrets in code, broken access control on real data.
  • High - likely bug or vulnerability under realistic conditions: race on shared state, missing authorization check, unbounded query on a user-facing path, swallowed errors that hide failures.
  • Medium - correct today but fragile: missing input validation behind a trusted caller, N+1 queries on small data, confusing ownership of state.
  • Low - style, naming, small simplifications. Report at most a handful; skip anything a linter or formatter already enforces.

Output format

# Code Review: [scope]

**Verdict**: [Ship / Ship after fixes / Do not ship] - [one sentence why]
**Findings**: [n] critical, [n] high, [n] medium, [n] low

## Critical

### 1. SQL injection in user search (`src/api/users.ts:42`)
**Category**: A05:2025 Injection | **Confidence**: High
**Evidence**: `q` comes from `req.query` and is interpolated into the SQL string; no validation upstream.
**Impact**: Any caller can read or modify arbitrary tables.

Current:
```ts
const rows = await db.query(`SELECT * FROM users WHERE name LIKE '%${q}%'`);
```

Fix:
```ts
const rows = await db.query("SELECT * FROM users WHERE name LIKE $1", [`%${q}%`]);
```

## High
...

## Medium
...

## Low
- `utils/date.ts:10` - [one line]

## What is solid
[Two or three specific things done well, so the author knows what to keep.]

## Not reviewed
[Files, paths, or concerns outside scope or that could not be verified.]

Traps that cause bad reviews

  • Reporting without reading the caller. "Missing validation" is often validated one layer up. Look before flagging.
  • Generic advice. "Consider adding error handling" is not a finding. Name the failure: which call throws, what the user sees, what state is left behind.
  • Style as severity. Line length, bracket placement, or personal preference never rank above Low.
  • Outdated rules. Check against the version in use: useMemo/useCallback advice changes when the React Compiler is enabled, and many Node APIs now ship built-ins (fetch, crypto.randomUUID, node:test).
  • Fixes that do not compile. Every "Fix" block must be valid for the language and version in the repo. If unsure, say so.
  • Flooding. More than about 15 findings buries the critical ones. Summarize the long tail in one line.
Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Lid closed, agents working
Lid closed, agents working
Keeps your Mac awake while Claude Code, Codex or Cursor works. Lets it sleep when they are done.
Try free for 7 days →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Open Steps
Open Steps
Free an open-source skills that make AI coding agents easier to understand, verify, and control.
Download for free →
Categories
SecurityGit & Pull RequestsCode Review & QualityDebugging
View on GitHub

More from onewave-ai/claude-skills

All 108 skills →
  • Csv Excel Merger1.1k
  • Technical Writer946
  • Screenshot To Code925
  • Social Media Content Repurposer744
  • Css Animation Creator694
  • Sports Betting Analyzer616
  • Knowledge Base Builder612
  • Job Application Optimizer574
  • Workout Program Designer528
  • Color Palette Extractor505
  • Stock Photo Finder501
  • Presentation Design Enhancer485
  • Itinerary Optimizer470
  • Font Pairing Suggester464
  • Seo Content Optimizer456
  • Cold Email Sequence Generator446
  • Reddit Thread Analyzer434
  • Linkedin Sales Navigator Alt429
  • Quiz Maker425
  • Portfolio Analyzer408
  • Competitor Price Tracker400
  • Financial Document Parser381
  • Contact Hunter373
  • Email Template Generator372

Recommended

More Security →
google avatar
google-cloud-recipe-foundation-builder

google/skills

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).
2.5k
17k
mindrally avatar
chrome-extension-development

mindrally/skills

Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices. Use when building browser extensions, creating popup UIs, implementing content scripts, working with Chrome APIs, managing extension permissions, or publishing to Chrome Web Store.
2.5k
223
starchild-ai-agent avatar
chatgpt-codex-onboarding

starchild-ai-agent/official-skills

Connect a ChatGPT or Codex subscription via OAuth device-code login. Use when the user wants to sign in with their ChatGPT Plus, Pro, or Team account (e.g. "use my Codex subscription", "log in with ChatGPT").
2.4k
22
coinbase avatar
authenticate-wallet

coinbase/agentic-wallet-skills

Sign in to the wallet. Use when you or the user want to log in, sign in, connect, or set up the wallet, or when any wallet operation fails with authentication or "not signed in" errors. This skill is a prerequisite before sending, trading, or funding.
2.4k
125
assistant-ui avatar
react-mcp

assistant-ui/skills

Lets end users add, authenticate, and manage MCP servers from the browser in assistant-ui apps with @assistant-ui/react-mcp. Use when building user-managed MCP server UIs: mounting McpManagerResource via useAui({ mcp }), declaring presets with defineConnector, dropping in McpConfigDialog, or composing McpManagerPrimitive (Root, Connectors, CustomServers, AddCustomTrigger), McpServerPrimitive (Root, Name, Icon, Status, ConnectButton, DisconnectButton, OAuthLink, RemoveButton, Error, Tools, ToolName), McpAddFormPrimitive (NameField, UrlField, AuthSelect, AuthFields, Submit, Cancel), and McpElicitationPrimitive (Root, Message, Fields, Items, Accept, Decline, Cancel, Error) for server-initiated input requests. Covers auth modes none/bearer/oauth, the OAuth flow with McpOAuthCallback and useMcpOAuthCallback, connection states, storage via McpLocalStorage/McpMemoryStorage/McpCustomStorage, reading state with useAuiState (s.mcp, s.mcpServer) and useMcpElicitation/useMcpElicitationField/useMcp
2.4k
20
coinbase avatar
agentic-wallet

coinbase/agentic-wallet-skills

Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API calls, monetize an API, or query onchain data. Use whenever the user mentions signing in, login, authentication, wallet status, balance, address, sending money, paying someone, transferring tokens, ENS names, swapping/trading/converting tokens, funding/topping up/onramp, USDC, ETH, POL, SOL, the x402 bazaar, paid APIs, monetizing an endpoint, or querying onchain data on Base.
2.4k
125