5 passes. 0 bugs merged.
The code review that catches what you miss. A structured 5-pass review protocol for Claude Code — correctness, security, performance, maintainability, and test coverage.
Your PR reviews are missing critical bugs
You ask Claude Code to “review my PR.” It says “looks clean, maybe add some tests.” You merge. Something breaks at 2am.
# "Review my PR" ✓ Code looks clean ✓ Consider adding some tests ✓ Minor: rename `data` to something descriptive # Meanwhile, in production... 💥 SQL injection in search endpoint 💥 XSS via user-supplied HTML 💥 N+1 query taking down the DB
## PR Review: Add search endpoint Verdict: REQUEST_CHANGES [SECURITY] critical — search.ts:28 User input interpolated into SQL Fix: Use parameterized query [SECURITY] critical — render.tsx:15 dangerouslySetInnerHTML on user data Fix: Sanitize with DOMPurify [PERFORMANCE] high — search.ts:42 N+1 query in results loop Fix: Batch with IN clause
5 focused passes. Every PR.
Senior engineers don't review code in a single sweep. They check correctness, then security, then performance — each as a focused pass. Deep PR Review does the same.
Correctness
Logic errors, edge cases, race conditions, type safety
Security
SQL injection, XSS, missing auth, data exposure (OWASP)
Performance
N+1 queries, missing indexes, unbounded ops, memory leaks
Maintainability
Naming, complexity, dead code, codebase consistency
Test Coverage
Specific missing test scenarios — not generic 'add tests'
Real bugs caught
These passed a quick “review this” prompt. They wouldn't pass Deep PR Review.
SQL injection — in a "simple" 45-line search endpoint
XSS — via dangerouslySetInnerHTML on user-supplied data
IDOR — letting any user view another user's analytics
Stale closure — from a missing useEffect dependency
Full table scan — on every search request (leading wildcard LIKE)
Install in 30 seconds
One file. Drop it in. Every PR gets a senior-level review.
# After purchase, unzip and copy mkdir -p .claude/skills cp deep-pr-review.md .claude/skills/ # That's it. Now ask Claude: "Review my PR"
Who this is for
Solo devs
A second pair of eyes before every merge. No team required.
Team leads
Consistent review quality across the team. No more “LGTM” rubber stamps.
Startups
Ship fast without a dedicated security reviewer. Every PR gets OWASP-aligned checks.
What the output looks like
Structured, severity-rated, actionable. Every finding has a file, line number, and fix.
## PR Review: Add user authentication middleware Verdict: REQUEST_CHANGES Summary: Adds JWT-based auth middleware. Core implementation is solid, but critical security issue with token validation. ### Critical Issues [SECURITY] critical — auth.ts:28 JWT secret fallback to "secret" string. In production, all tokens signed with known value if env var missing. Fix: Remove fallback. Throw on startup. ### Recommendations [CORRECTNESS] high — auth.ts:45 Token expiry uses < instead of <= Fix: Use jwt.verify built-in expiry [TESTING] high No test for expired token rejection. Suggested: assert 401 for exp = now - 1
One file. Five passes. Zero bugs merged.
Stop merging bugs. Start shipping confidence. $19 one-time — works with any language, any project.
Instant download · Works with Claude Code · MIT License