# How to Use the Code-Reviewer Agent in Everything-Claude-Code

> Learn how to use the code-reviewer agent in Everything-Claude-Code. Run /code-review to scan for security, quality, and best-practice issues before committing your changes.

- Repository: [WorldFlowAI/everything-claude-code](https://github.com/WorldFlowAI/everything-claude-code)
- Tags: how-to-guide
- Published: 2026-09-07

---

**Run `/code-review` in your workspace to automatically evaluate changed code for security vulnerabilities, quality issues, and best-practice violations before committing.**

The **code-reviewer agent** is a built-in Claude agent in the `WorldFlowAI/everything-claude-code` repository that performs automated static analysis on modified files. It acts as a mandatory quality gate, ensuring that only vetted code progresses to pull requests.

## What the Code-Reviewer Agent Does

The agent evaluates code against a three-tier **review checklist** defined in [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md). Each finding includes file location, description, and a concrete fix example.

| Severity | Focus Areas |
|----------|-------------|
| **CRITICAL** | Security flaws: hard-coded secrets, SQL injection, XSS, missing input validation, vulnerable dependencies, path traversal, CSRF, authentication bypasses |
| **HIGH** | Code quality: functions exceeding 50 lines, files exceeding 800 lines, deep nesting, missing error handling, stray `console.log`, duplicated code |
| **MEDIUM** | Best practices: mutable patterns, emoji usage in code, missing tests, accessibility concerns |

Critical and high-severity issues automatically **block commits** according to the workflow rules in [`rules/git-workflow.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/git-workflow.md).

## Triggering the Code-Reviewer

### Basic Usage

Execute the command wrapper defined in [`commands/code-review.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/code-review.md):

```bash
/code-review

```

This triggers the following execution flow:

1. **Diff collection** — Runs `git diff --name-only HEAD` to identify changed files
2. **File-by-file inspection** — Applies checklist rules using `Read`, `Grep`, `Glob`, and `Bash` tools
3. **Report generation** — Groups issues by severity with actionable fixes
4. **Feedback delivery** — Provides concrete code examples for each finding

### Example Output

```

[CRITICAL] Hardcoded API key
File: src/api/client.ts:42
Issue: API key exposed in source code
Fix: Move to environment variable

const apiKey = "sk-abc123";   // ❌ Bad
const apiKey = process.env.API_KEY; // ✓ Good

```

## Integrating into Your Development Workflow

### Git Hook Automation

Add a pre-commit hook to enforce the agent on every commit, mirroring the repository's mandated workflow:

```bash

# .git/hooks/pre-commit

#!/bin/sh

# Run code-reviewer before any commit

/code-review || exit 1

```

This ensures the code-reviewer runs automatically before `git commit` completes, preventing violations from entering the repository.

### CLI and UI Invocation

The `/code-review` command is available in both CLI and UI contexts. The agent operates **locally** without external CI dependencies, using only repository-contained tools per the security rules.

## Key Source Files and Architecture

| Component | Path | Purpose |
|-----------|------|---------|
| Agent definition | [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md) | Declares agent name, description, required tools, and full review checklist |
| Command wrapper | [`commands/code-review.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/code-review.md) | User-facing `/code-review` command with step outline and blocking logic |
| Workflow enforcement | [`rules/git-workflow.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/git-workflow.md) | Mandates code-reviewer execution before committing |
| Agent registry | [`rules/agents.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/agents.md) | Lists code-reviewer among project agents and maps to "Code review" capability |
| Project docs | [`README.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/README.md) | Summarizes agent purpose in the development lifecycle |

The agent's static analysis respects the repository's security constraint: **no external commands** are executed beyond what exists in the workspace.

## Customizing the Review Checklist

Project-specific guidelines can be appended to the "Project-Specific Guidelines" section of [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md). This extensibility allows teams to enforce domain-specific standards while retaining the base security and quality rules.

## Summary

- **Run `/code-review`** to trigger automated analysis of changed files
- **Critical security issues block commits** — fix before proceeding
- **Local execution** requires no external CI for initial review
- **Customize rules** by editing [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md)
- **Enforce universally** via git hooks or the mandated workflow in [`rules/git-workflow.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/git-workflow.md)

## Frequently Asked Questions

### What tools does the code-reviewer agent use?

The agent uses `Read`, `Grep`, `Glob`, and `Bash` tools to analyze code statically without execution. This toolset is declared in [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md) and enables safe inspection of repository contents.

### Can I bypass the code-reviewer if I'm in a hurry?

No. The [`rules/git-workflow.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/git-workflow.md) file explicitly mandates that every code change must run the code-reviewer before committing. Critical findings block progression regardless of urgency.

### How do I add custom rules for my project?

Open [`agents/code-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/code-reviewer.md) and append guidelines to the "Project-Specific Guidelines" section. These augment the base checklist covering critical, high, and medium severity issues without modifying core security rules.

### Does the code-reviewer work with any programming language?

Yes. The agent operates on file content and pattern matching rather than language-specific parsers. However, fix examples in the checklist emphasize JavaScript/TypeScript conventions; adapt these to your target language as needed.