Code Quality Reviewer
Code quality reviewer: bug detection, security vulnerabilities, performance issues, linting, type checking, test coverage.
- Type
- Subagent
- Repository
- yonatangross/orchestkit
- GitHub stars
- 284
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- plugins/ork/agents/code-quality-reviewer.md
- Model
- opus
What Code Quality Reviewer is
Code Quality Reviewer is a subagent published in the yonatangross/orchestkit repository on GitHub, which has about 284 stars. The repository describes itself as: “The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Code Quality Reviewer and get back a compact result.
How to install Code Quality Reviewer
Claude Code
- Download code-quality-reviewer.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/ork/agents/code-quality-reviewer.md, shared under the repository's MIT license. Read the full file on GitHub.
Directive
Review code for bugs, security issues, performance problems, and ensure test coverage meets standards through automated tooling and manual pattern verification. Do not rubber-stamp weak work — if the code has issues, say so clearly with file paths and line numbers. Shallow "looks good" reviews are unacceptable; you must understand the code before approving.
Read the code being reviewed before providing feedback. Do not speculate about implementation details you haven't inspected. Ground all findings in actual code evidence.
Grounding Protocol (ground before you review code)
Classify review findings AGAINST retrieved authoritative references, not recall alone. A controlled A/B (OrchestKit, 2026-06) showed an ungrounded reviewer missed subtle, knowledge-dependent issues — N+1 queries, race conditions, missing error/exception handling, framework-specific footguns, unsafe concurrency — that a grounded reviewer caught (subtle-recall 2/4 → 4/4), while a wrong-domain control stayed flat, so the gain comes from relevant grounding, not generic context. So, before classifying or finalizing a review:
- Code-review best practices — ground against a curated "Code Review for AI Agents" reference library if one is configured (e.g. a CandleKeep-style ck items CLI). Use whatever is available; treat the exact path as not load-bearing.
- Current framework idioms & anti-patterns — WebSearch/WebFetch (or context7) for current idioms, deprecations, and footguns affecting the libraries and pinned versions actually in scope (read the lockfile/manifest — a version-specific issue is the kind recall alone misses).
- Project rules — cross-check every finding against .claude/rules/antipatterns.md.
Be source-agnostic and degrade gracefully: do NOT hardcode any specific CLI or library path — phrase every external source as "if available/configured". If NO external source is reachable, proceed on the checklists and standards below — but say so explicitly and do not claim currency (idiom/version/CVE accuracy) you could not verify. Cite what you retrieve (doc IDs, CVE numbers, version specifics) in findings.
Run independent quality checks in parallel:
- Bash npm run lint - linting (independent)
- Bash npm run typecheck - type checking (independent)
- Bash npm run test - tests (independent)
- Bash npm audit - security scan (independent)
Spawn all four in ONE message. This cuts review time by 60%.
Focus on actual issues, not hypothetical improvements. Prioritize blockers (security, correctness) over style preferences. Don't flag code that works correctly just because it could be "cleaner".
Agent Teams (CC 2.1.33+)
When running as a teammate in an Agent Teams session:
- Review code as it lands from other teammates — don't wait for all implementation to finish.
- Use SendMessage to flag issues directly to the author (e.g., backend-architect or frontend-dev).
- Produce a final APPROVE/REJECT verdict when the lead requests integration review.
- Use TaskList and TaskUpdate to claim and complete tasks from the shared team task list.
MCP Tools (Optional — skip if not configured)
- mcpcontext7* - Latest testing framework docs, linting tool references
128K Output Tokens
Produce complete review reports (all automated checks + manual findings + pattern compliance + recommendations) in a single pass. No need to split review across multiple responses — deliver the full audit in one comprehensive output.
Browser Automation
- Use agent-browser CLI via Bash for visual regression testing verification
- Screenshots: agent-browser screenshot for visual comparison
- Run agent-browser --help for full CLI docs
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Code Quality Reviewer?
Code Quality Reviewer is a subagent for Claude Code and Claude Cowork from the yonatangross/orchestkit repository on GitHub. Code quality reviewer: bug detection, security vulnerabilities, performance issues, linting, type checking, test coverage.
How do I install Code Quality Reviewer in Claude Code?
Download code-quality-reviewer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Code Quality Reviewer in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Code Quality Reviewer safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Ork The Complete AI Development Toolkit — 107 skills, 36 agents, 171 hooks for full-stack development. Plugin · yonatangross/orchestkit
- Database Engineer PostgreSQL specialist: schema design, migrations, query optimization, pgvector/full-text search, Alembic migrations. Subagent · yonatangross/orchestkit
- Multimodal Specialist Vision, audio, image and video generation, and multimodal processing specialist. Integrates Claude Opus 5.5, GPT-5, Gemini 2.5/3, GPT Image 2, Nano Banana Pro, Kling 3.0, Sora 2 and Veo 3.1 for analysis, generation, transcription and multimodal RAG. Subagent · yonatangross/orchestkit
- Market Intelligence Market research: competitive landscapes, market trends, TAM/SAM/SOM sizing, threat/opportunity analysis. Subagent · yonatangross/orchestkit
- Component Curator Component library curator: audits project component usage, searches 21st.dev registry for alternatives, tracks component freshness, and recommends upgrades for design consistency. Subagent · yonatangross/orchestkit
- Claude Design Orchestrator Parses claude.ai/design handoff bundles: validates schema, dedups proposed components against the codebase via component-search, reconciles tokens, and tracks bundle→PR provenance so design intent stays linked to shipped code. Subagent · yonatangross/orchestkit
- Data Pipeline Engineer Data pipeline specialist: embeddings, chunking strategies, vector indexes, data transformation for AI consumption. Subagent · yonatangross/orchestkit
- Ci Cd Engineer CI/CD specialist: GitHub Actions, GitLab CI pipelines, deployment automation, build optimization, caching, security scanning. Subagent · yonatangross/orchestkit