Code Review

codewithmukesh/dotnet-claude-kit/skills/code-review

by codewithmukesh23300897f4d1No license754 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 2 months ago

MCP-powered multi-dimensional code review for .NET projects. Uses Roslyn analysis tools for antipatterns, diagnostics, references, and dependency graphs combined with structured manual review. Prioritizes effort with blast-radius scoring — data access, security, concurrency, and integration boundaries before style — and produces severity-categorized findings with actionable fixes. Use when: "review", "code review", "PR review", "review this", "review my code", "check code quality", "review changes", "what should I review", "review priorities", "blast radius", "critical path".

AI-generated overview

Reviews .NET code changes using Roslyn MCP analysis and manual review, prioritizing high-risk areas and reporting severity-categorized findings.

What it does
Performs a multi-dimensional code review of .NET projects by combining Roslyn MCP analysis (antipatterns, diagnostics, references, dependency graphs) with structured manual review. It scores each change by blast radius to set review depth, then checks data access, security, concurrency, integration boundaries, correctness, and test coverage. It produces a markdown review with a summary, critical/warning/suggestion findings, architecture compliance, test coverage notes, and positive observations.
When to use it
Use it before merging a pull request, after a major refactor to check for regressions or design drift, when deciding where to focus review effort on a large change, or when assessing unfamiliar code. It is intended for .NET codebases.
Requirements
Requires a .NET project and access to the Roslyn MCP analysis tools (detect_antipatterns, get_diagnostics, find_references, get_dependency_graph, get_project_graph, detect_circular_dependencies) plus git for diffing. It ships no scripts; it is instructions only.

/code-review — MCP-Powered Code Review

What

Performs a multi-dimensional code review combining Roslyn MCP analysis with structured manual review. Effort follows the 80/20 rule: the 20% of code that causes 80% of incidents (data access, security, concurrency, integration boundaries) gets thorough review; style and formatting are left to tooling.

Review dimensions: Correctness (logic, edge cases, null handling, async pitfalls), Security (auth gaps, injection, secrets, CORS), Performance (N+1, allocations, missing cancellation), Architecture compliance (layer violations, boundary breaches), Test coverage (behavior tests for changed types).

When

  • "Review this", "code review", "PR review", before merging a pull request
  • After a major refactor to verify no regressions or design drift
  • "What should I review?" — deciding where review effort goes on a large change
  • Onboarding to unfamiliar code and wanting a quality assessment

How

Step 1: Scope and Score Blast Radius

Identify changed files (git diff main...HEAD, specified files, or module). Score each change to set review depth — blast radius determines depth, not line count. A one-line middleware change outranks a 300-line rename.

Blast RadiusExamplesDepth
CriticalMiddleware, auth, DB migrations, shared kernel, CI/CDThorough — every code path
HighPublic API changes, message consumers, EF configuration, new moduleFocused — consumers + behavior
MediumNew feature following existing patterns, bug fix, new endpointStandard — checklist pass
LowDocs, formatting, renames, logging statementsGlance — build + tests pass

Step 2: MCP Analysis (before reading any file)

detect_antipatterns(projectFilter: "affected-project")   → async void, DateTime.Now, new HttpClient(), broad catchget_diagnostics(scope: "project", path: "affected-project") → new warnings, nullability issues

Distinguish newly introduced findings from pre-existing ones — focus on new.

Step 3: Blast Radius Verification

For each modified public API:

find_references(symbolName: "ModifiedType")              → count consumers; high count = high riskget_dependency_graph(symbolName: "ModifiedMethod", depth: 2) → ripple effects

Check whether callers handle changed return types and new error cases.

Step 4: Architecture Compliance

Verify dependency direction (Domain → nothing; Infrastructure → Application → Domain) via get_project_graph and detect_circular_dependencies. Per architecture: VSA features don't cross-reference; Clean Architecture domain has zero project references; Modular Monolith modules communicate only via integration events — find_references on a module's DbContext should resolve only inside that module.

Step 5: Manual Review — Priority Order

Review what tools can't catch, highest-risk areas first:

PriorityAreaCheck
1Data accessN+1 (missing Include/projection), raw SQL with user input, missing CancellationToken
2SecurityEvery endpoint has explicit [Authorize]/[AllowAnonymous], input validated, no secrets in code, no PII in logs
3ConcurrencyToken propagated end-to-end, no .Result/.Wait(), thread-safe shared state
4IntegrationRetry/timeout on external calls, consumer idempotency, no swallowed exceptions
5CorrectnessBusiness logic, edge cases (empty/null/concurrent), entities mapped to DTOs at the boundary
6TestsBehavior tested (not implementation); happy path + main error case covered
—Style/namingMention only after the above; formatters and analyzers own this

Step 6: Produce the Review

Every finding states what's wrong, why it matters, and how to fix it. Never bury a security bug under naming nits.

markdown
## Code Review: [Scope]
### Summary[1-3 sentences: scope, risk level, recommendation]
### Critical (must fix before merge)- **[Title]** — [file:line] [What's wrong. Why it matters. How to fix.]
### Warnings (should fix, creates tech debt)- **[Title]** — [file:line] [...]
### Suggestions (nice to have)- **[Title]** — [file:line] [...]
### Architecture Compliance[PASS/WARN with boundary-violation notes]
### Test Coverage[Which changed types have tests; specific scenarios to add]
### What's Good- [Always include — reinforce good patterns]

Quick review (1-2 files, low blast radius): run detect_antipatterns + get_diagnostics, read for correctness, output Summary + Issues + What's Good.

Example

User: /code-review the changes in this PR
Claude: 7 changed files across 3 projects. CreateOrder touches data accessand a public endpoint — High blast radius. Running MCP analysis...
## Code Review: Order Processing Feature
### SummaryAdds CreateOrder/GetOrder endpoints with EF Core persistence. Well-structuredVSA feature. Two issues need attention before merge.
### Critical (must fix before merge)- **Missing CancellationToken propagation** — CreateOrder.cs:38  SaveChangesAsync() called without the token. Client disconnects keep  burning server resources. Pass `ct` from the handler parameter.
### Warnings (should fix, creates tech debt)- **N+1 query in GetOrder** — GetOrder.cs:25  Order loaded without `.Include(o => o.Items)`; one lazy load per item  during serialization. Eager-load or use a projection.
### Suggestions (nice to have)- **Seal the handler** — CreateOrderHandler.cs:10  Not designed for inheritance; `sealed` enables devirtualization.
### Architecture CompliancePASS — all changes within Features/Orders/, no layer violations.
### Test CoverageHappy path covered. Add tests for validation failure and not-found.
### What's Good- Clean command/query separation; FluentValidation covers edge cases- Response DTOs are records, no entity leaks

Related

  • /de-sloppify — Cleanup pass for the style/formatting issues review skips
  • /verify — Automated verification pipeline (complements manual review)
  • /health-check — Broader project health assessment beyond a single PR

Source and attribution

Source:codewithmukesh/dotnet-claude-kitinskills/code-reviewat commit2330089

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from codewithmukesh/dotnet-claude-kit

Wrap Up

codewithmukesh

Captures end-of-session work, pending tasks and learnings into a handoff file, and reloads it at session start.

Productivity & Workflow754updated 2 months ago

Workflow Mastery

codewithmukesh

Claude Code workflow mastery for .NET developers. Covers parallel execution with git worktrees, plan mode strategy, verification loops, auto-formatting hooks, permission setup for dotnet CLI, prompting techniques, subagent patterns, and context discipline — token budget management, MCP-first navigation, lazy loading, and subagent isolation — all adapted for the .NET ecosystem. Load this skill when setting up Claude Code for a .NET project, optimizing workflows, running parallel sessions, when context is running low or sessions feel sluggish, when exploring a large codebase efficiently, or when the user mentions "productivity", "workflow", "parallel", "worktree", "plan mode", "permissions", "hooks", "10x", "setup Claude Code", "speed up development", "context", "tokens", "budget", "running out of context", "too many files", or "large codebase". Inspired by tips from Boris Cherny (creator of Claude Code) and the Anthropic team.

Awaiting classification754updated 2 months ago

Vertical Slice

codewithmukesh

Guides .NET developers in structuring applications with Vertical Slice Architecture, covering feature folders, endpoint grouping and handler patterns.

Software Development754updated 2 months ago

Testing

codewithmukesh

Testing strategy for .NET 10 applications. Covers xUnit v3, WebApplicationFactory for integration tests, Testcontainers for real database testing, Verify for snapshot testing, and the AAA pattern. Load this skill when writing tests, setting up test infrastructure, reviewing test coverage, or when the user mentions "test", "xUnit", "WebApplicationFactory", "Testcontainers", "integration test", "unit test", "bUnit", "snapshot test", "Verify", "test coverage", "AAA pattern", "WireMock", or "FakeTimeProvider".

Awaiting classification754updated 2 months ago

Tdd

codewithmukesh

Guided test-driven development workflow for .NET 10 using xUnit v3, WebApplicationFactory, Testcontainers, and Verify snapshots. Follows the strict red-green-refactor cycle. Use when: "TDD", "test-driven", "let's TDD this", "red green refactor", "write the test first", or when building a feature with clear acceptance criteria.

Awaiting classification754updated 2 months ago

Spec

codewithmukesh

Turns a vague feature idea into an agreed, persisted specification file through structured questioning rounds.

Productivity & Workflow754updated 2 months ago