How to Use the Code-Reviewer Agent in Everything-Claude-Code
Run /code-review in your workspace to automatically evaluate changed code for security vulnerabilities, quality issues, and best-practice violations before committing.
The code-reviewer agent is a built-in Claude agent in the WorldFlowAI/everything-claude-code repository that performs automated static analysis on modified files. It acts as a mandatory quality gate, ensuring that only vetted code progresses to pull requests.
What the Code-Reviewer Agent Does
The agent evaluates code against a three-tier review checklist defined in agents/code-reviewer.md. Each finding includes file location, description, and a concrete fix example.
| Severity | Focus Areas |
|---|---|
| CRITICAL | Security flaws: hard-coded secrets, SQL injection, XSS, missing input validation, vulnerable dependencies, path traversal, CSRF, authentication bypasses |
| HIGH | Code quality: functions exceeding 50 lines, files exceeding 800 lines, deep nesting, missing error handling, stray console.log, duplicated code |
| MEDIUM | Best practices: mutable patterns, emoji usage in code, missing tests, accessibility concerns |
Critical and high-severity issues automatically block commits according to the workflow rules in rules/git-workflow.md.
Triggering the Code-Reviewer
Basic Usage
Execute the command wrapper defined in commands/code-review.md:
/code-review
This triggers the following execution flow:
- Diff collection — Runs
git diff --name-only HEADto identify changed files - File-by-file inspection — Applies checklist rules using
Read,Grep,Glob, andBashtools - Report generation — Groups issues by severity with actionable fixes
- Feedback delivery — Provides concrete code examples for each finding
Example Output
[CRITICAL] Hardcoded API key
File: src/api/client.ts:42
Issue: API key exposed in source code
Fix: Move to environment variable
const apiKey = "sk-abc123"; // ❌ Bad
const apiKey = process.env.API_KEY; // ✓ Good
Integrating into Your Development Workflow
Git Hook Automation
Add a pre-commit hook to enforce the agent on every commit, mirroring the repository's mandated workflow:
# .git/hooks/pre-commit
#!/bin/sh
# Run code-reviewer before any commit
/code-review || exit 1
This ensures the code-reviewer runs automatically before git commit completes, preventing violations from entering the repository.
CLI and UI Invocation
The /code-review command is available in both CLI and UI contexts. The agent operates locally without external CI dependencies, using only repository-contained tools per the security rules.
Key Source Files and Architecture
| Component | Path | Purpose |
|---|---|---|
| Agent definition | agents/code-reviewer.md |
Declares agent name, description, required tools, and full review checklist |
| Command wrapper | commands/code-review.md |
User-facing /code-review command with step outline and blocking logic |
| Workflow enforcement | rules/git-workflow.md |
Mandates code-reviewer execution before committing |
| Agent registry | rules/agents.md |
Lists code-reviewer among project agents and maps to "Code review" capability |
| Project docs | README.md |
Summarizes agent purpose in the development lifecycle |
The agent's static analysis respects the repository's security constraint: no external commands are executed beyond what exists in the workspace.
Customizing the Review Checklist
Project-specific guidelines can be appended to the "Project-Specific Guidelines" section of agents/code-reviewer.md. This extensibility allows teams to enforce domain-specific standards while retaining the base security and quality rules.
Summary
- Run
/code-reviewto trigger automated analysis of changed files - Critical security issues block commits — fix before proceeding
- Local execution requires no external CI for initial review
- Customize rules by editing
agents/code-reviewer.md - Enforce universally via git hooks or the mandated workflow in
rules/git-workflow.md
Frequently Asked Questions
What tools does the code-reviewer agent use?
The agent uses Read, Grep, Glob, and Bash tools to analyze code statically without execution. This toolset is declared in agents/code-reviewer.md and enables safe inspection of repository contents.
Can I bypass the code-reviewer if I'm in a hurry?
No. The rules/git-workflow.md file explicitly mandates that every code change must run the code-reviewer before committing. Critical findings block progression regardless of urgency.
How do I add custom rules for my project?
Open agents/code-reviewer.md and append guidelines to the "Project-Specific Guidelines" section. These augment the base checklist covering critical, high, and medium severity issues without modifying core security rules.
Does the code-reviewer work with any programming language?
Yes. The agent operates on file content and pattern matching rather than language-specific parsers. However, fix examples in the checklist emphasize JavaScript/TypeScript conventions; adapt these to your target language as needed.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →