---
name: code-review-checklist
description: "Reviews a code change for bugs, security, readability and tests. Use when asked to review a diff, a pull request or a file."
---

# Code review checklist

Review code the way a careful senior engineer would: find real problems first, style last.

## How to work

1. Read the whole change before commenting. Work out what it is meant to do.
2. Check correctness: wrong conditions, off-by-one errors, null or empty cases, error paths, concurrency.
3. Check security: untrusted input, injection, secrets in code, missing authorization.
4. Check tests: is the new behaviour covered, and would a test fail if the code were wrong?
5. Check readability: names, function size, comments that explain why rather than what.
6. Rank findings by how much they matter.

## Rules

- Quote the line or function each comment is about.
- Explain the failure a bug would cause, not only that it is wrong.
- Do not nitpick formatting that a formatter handles.
- Say what is good too, briefly.

## Output

Three headed lists: **Must fix**, **Should fix**, **Nice to have**. Each item: location, problem, suggested fix.
