How to Use the Code-Reviewer Agent in Everything-Claude-Code

Run /code-review in your workspace to automatically evaluate changed code for security vulnerabilities, quality issues, and best-practice violations before committing.

The code-reviewer agent is a built-in Claude agent in the WorldFlowAI/everything-claude-code repository that performs automated static analysis on modified files. It acts as a mandatory quality gate, ensuring that only vetted code progresses to pull requests.

What the Code-Reviewer Agent Does

The agent evaluates code against a three-tier review checklist defined in agents/code-reviewer.md. Each finding includes file location, description, and a concrete fix example.

Severity Focus Areas
CRITICAL Security flaws: hard-coded secrets, SQL injection, XSS, missing input validation, vulnerable dependencies, path traversal, CSRF, authentication bypasses
HIGH Code quality: functions exceeding 50 lines, files exceeding 800 lines, deep nesting, missing error handling, stray console.log, duplicated code
MEDIUM Best practices: mutable patterns, emoji usage in code, missing tests, accessibility concerns

Critical and high-severity issues automatically block commits according to the workflow rules in rules/git-workflow.md.

Triggering the Code-Reviewer

Basic Usage

Execute the command wrapper defined in commands/code-review.md:

/code-review

This triggers the following execution flow:

  1. Diff collection — Runs git diff --name-only HEAD to identify changed files
  2. File-by-file inspection — Applies checklist rules using Read, Grep, Glob, and Bash tools
  3. Report generation — Groups issues by severity with actionable fixes
  4. Feedback delivery — Provides concrete code examples for each finding

Example Output


[CRITICAL] Hardcoded API key
File: src/api/client.ts:42
Issue: API key exposed in source code
Fix: Move to environment variable

const apiKey = "sk-abc123";   // ❌ Bad
const apiKey = process.env.API_KEY; // ✓ Good

Integrating into Your Development Workflow

Git Hook Automation

Add a pre-commit hook to enforce the agent on every commit, mirroring the repository's mandated workflow:


# .git/hooks/pre-commit

#!/bin/sh

# Run code-reviewer before any commit

/code-review || exit 1

This ensures the code-reviewer runs automatically before git commit completes, preventing violations from entering the repository.

CLI and UI Invocation

The /code-review command is available in both CLI and UI contexts. The agent operates locally without external CI dependencies, using only repository-contained tools per the security rules.

Key Source Files and Architecture

Component Path Purpose
Agent definition agents/code-reviewer.md Declares agent name, description, required tools, and full review checklist
Command wrapper commands/code-review.md User-facing /code-review command with step outline and blocking logic
Workflow enforcement rules/git-workflow.md Mandates code-reviewer execution before committing
Agent registry rules/agents.md Lists code-reviewer among project agents and maps to "Code review" capability
Project docs README.md Summarizes agent purpose in the development lifecycle

The agent's static analysis respects the repository's security constraint: no external commands are executed beyond what exists in the workspace.

Customizing the Review Checklist

Project-specific guidelines can be appended to the "Project-Specific Guidelines" section of agents/code-reviewer.md. This extensibility allows teams to enforce domain-specific standards while retaining the base security and quality rules.

Summary

  • Run /code-review to trigger automated analysis of changed files
  • Critical security issues block commits — fix before proceeding
  • Local execution requires no external CI for initial review
  • Customize rules by editing agents/code-reviewer.md
  • Enforce universally via git hooks or the mandated workflow in rules/git-workflow.md

Frequently Asked Questions

What tools does the code-reviewer agent use?

The agent uses Read, Grep, Glob, and Bash tools to analyze code statically without execution. This toolset is declared in agents/code-reviewer.md and enables safe inspection of repository contents.

Can I bypass the code-reviewer if I'm in a hurry?

No. The rules/git-workflow.md file explicitly mandates that every code change must run the code-reviewer before committing. Critical findings block progression regardless of urgency.

How do I add custom rules for my project?

Open agents/code-reviewer.md and append guidelines to the "Project-Specific Guidelines" section. These augment the base checklist covering critical, high, and medium severity issues without modifying core security rules.

Does the code-reviewer work with any programming language?

Yes. The agent operates on file content and pattern matching rather than language-specific parsers. However, fix examples in the checklist emphasize JavaScript/TypeScript conventions; adapt these to your target language as needed.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →