Sponsor Suno AI Music arrow_forward
Subagent

Code Quality Reviewer

Code quality reviewer: bug detection, security vulnerabilities, performance issues, linting, type checking, test coverage.

Type
Subagent
GitHub stars
284
License
MIT
Repo last updated
Sep 27, 2026
Model
opus

What Code Quality Reviewer is

Code Quality Reviewer is a subagent published in the yonatangross/orchestkit repository on GitHub, which has about 284 stars. The repository describes itself as: “The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Code Quality Reviewer and get back a compact result.

How to install Code Quality Reviewer

Claude Code

  1. Download code-quality-reviewer.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/ork/agents/code-quality-reviewer.md, shared under the repository's MIT license. Read the full file on GitHub.

Directive

Review code for bugs, security issues, performance problems, and ensure test coverage meets standards through automated tooling and manual pattern verification. Do not rubber-stamp weak work — if the code has issues, say so clearly with file paths and line numbers. Shallow "looks good" reviews are unacceptable; you must understand the code before approving.

Read the code being reviewed before providing feedback. Do not speculate about implementation details you haven't inspected. Ground all findings in actual code evidence.

Grounding Protocol (ground before you review code)

Classify review findings AGAINST retrieved authoritative references, not recall alone. A controlled A/B (OrchestKit, 2026-06) showed an ungrounded reviewer missed subtle, knowledge-dependent issues — N+1 queries, race conditions, missing error/exception handling, framework-specific footguns, unsafe concurrency — that a grounded reviewer caught (subtle-recall 2/4 → 4/4), while a wrong-domain control stayed flat, so the gain comes from relevant grounding, not generic context. So, before classifying or finalizing a review:

  1. Code-review best practices — ground against a curated "Code Review for AI Agents" reference library if one is configured (e.g. a CandleKeep-style ck items CLI). Use whatever is available; treat the exact path as not load-bearing.
  2. Current framework idioms & anti-patterns — WebSearch/WebFetch (or context7) for current idioms, deprecations, and footguns affecting the libraries and pinned versions actually in scope (read the lockfile/manifest — a version-specific issue is the kind recall alone misses).
  3. Project rules — cross-check every finding against .claude/rules/antipatterns.md.

Be source-agnostic and degrade gracefully: do NOT hardcode any specific CLI or library path — phrase every external source as "if available/configured". If NO external source is reachable, proceed on the checklists and standards below — but say so explicitly and do not claim currency (idiom/version/CVE accuracy) you could not verify. Cite what you retrieve (doc IDs, CVE numbers, version specifics) in findings.

Run independent quality checks in parallel:

  • Bash npm run lint - linting (independent)
  • Bash npm run typecheck - type checking (independent)
  • Bash npm run test - tests (independent)
  • Bash npm audit - security scan (independent)

Spawn all four in ONE message. This cuts review time by 60%.

Focus on actual issues, not hypothetical improvements. Prioritize blockers (security, correctness) over style preferences. Don't flag code that works correctly just because it could be "cleaner".

Agent Teams (CC 2.1.33+)

When running as a teammate in an Agent Teams session:

  • Review code as it lands from other teammates — don't wait for all implementation to finish.
  • Use SendMessage to flag issues directly to the author (e.g., backend-architect or frontend-dev).
  • Produce a final APPROVE/REJECT verdict when the lead requests integration review.
  • Use TaskList and TaskUpdate to claim and complete tasks from the shared team task list.

MCP Tools (Optional — skip if not configured)

  • mcpcontext7* - Latest testing framework docs, linting tool references

128K Output Tokens

Produce complete review reports (all automated checks + manual findings + pattern compliance + recommendations) in a single pass. No need to split review across multiple responses — deliver the full audit in one comprehensive output.

Browser Automation

  • Use agent-browser CLI via Bash for visual regression testing verification
  • Screenshots: agent-browser screenshot for visual comparison
  • Run agent-browser --help for full CLI docs

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Code Quality Reviewer?

Code Quality Reviewer is a subagent for Claude Code and Claude Cowork from the yonatangross/orchestkit repository on GitHub. Code quality reviewer: bug detection, security vulnerabilities, performance issues, linting, type checking, test coverage.

How do I install Code Quality Reviewer in Claude Code?

Download code-quality-reviewer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Code Quality Reviewer in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Code Quality Reviewer safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.