Instructions that tell a model what to look for in a diff, what to ignore and how to report it. Saved as a skill, it runs the same way every time.
How to write a code review skill for Claude Code or Codex
A code review skill is a prompt file a coding agent loads when you ask it to review. In Claude Code it is .claude/skills/<name>/SKILL.md, with a name and a description at the top; you run it with /<name>, or Claude picks it when your request matches the description.[1] Codex reads the same SKILL.md format from .agents/skills, and you call a skill with $ or /skills.[2]
IonWarp's 16 reviewers are skills of this shape, measured on benchmark pull requests and on production reviews. Three paired experiments on production reviews in September 2026 shaped them. With tools to read the whole repository, about half of the significant findings rested on code the pull request never touched. Turning the model's reasoning off (142 reviews each way) cut cost by 31% but more than doubled false findings. Halving the turn budget (45 paired reviews) found 28% fewer real issues and twice as many false ones.
What goes in a code review skill
What counts, and what does not
One sentence that defines a finding for this review, then short lists of findings to post and findings to skip. Examples teach more than rules: a retry that charges an order twice is a finding; a variable name you would have chosen differently is not.
A sweep of every changed file
The patterns a scan can see: an empty catch, input reaching a query or shell unescaped, a missing auth check, an await inside a loop, a secret in code.
A trace of every changed function
For each function that holds or passes state, walk the real cases: first call and repeat call, success, error and timeout, a value present or missing, events in either order. Check units where a value crosses a boundary, such as cents and dollars. Follow deleted code: what does that job now?
For security, who gains what
For each route the diff changes: who is calling, which ids they control, what check binds them to that scope, and what they can reach. No named attacker and no gain, no finding.
Evidence before a finding
Each finding quotes the line it rests on. A claim about a schema, a type or a function it calls needs that definition read first; no definition, no finding.
One output format
A severity, the file and line, a title that names the consequence, and a suggested fix. Severity follows the consequence: blocks the merge, should be fixed, or a note.
Run it in Claude Code or Codex
Save the skill
Claude Code reads .claude/skills/pr-review/SKILL.md and Codex reads .agents/skills/pr-review/SKILL.md. Pick a name other than code-review: Claude Code ships its own /code-review command.[1]
Describe when to use it
The description is what the agent reads to decide when to load the skill, for example: Review the current branch's diff for defects. Use when asked to review a pull request or a diff.
Run it on the diff
Type /pr-review in Claude Code or $pr-review in Codex on the branch you want reviewed.
Check, fix, run again
Treat each finding as a claim: read the line it quotes, fix what holds up, and run the skill again on the new diff.
Starter is free for 3 seats. Pro is $49 a month with 5 seats, and Max is $149 a month with 10 seats. Compare plans
Frequently asked questions
Yes. Claude Code ships /code-review, also available as /review, and /security-review for security. A project skill lets you set your own rules for what counts as a finding.
Ask for evidence: each finding quotes the line it rests on, and a claim about a schema or a function needs its definition read first. In IonWarp's CI/CD reviewer, 14 of 28 false findings were claims about how GitHub or a CI vendor behaves, which no repository shows. Tell the reviewer to file only what the repository shows.
It depends on the review. On IonWarp's benchmarks, Muse Spark 1.3 led code review, GLM 5.3 Flash led security and DeepSeek v4 Pro led CI/CD. Our guide to the best LLM for code review has the numbers.
A skill runs when you run it, on your machine. A review app such as IonWarp runs on every pull request, posts its findings on GitHub and tracks each one across pushes until it is fixed or declined.
Sources
- Claude Code: Skills — Anthropic, read 2026-10-03.
- Build skills — OpenAI, read 2026-10-03.
- Pricing — CodeRabbit, read 2026-10-02.
Get a review on your next pull request
Install IonWarp on GitHub. Starter is free for 3 people, with 15,000 credits to start.
Try for free