Code Review: /review & /ultrareview
/review runs in 30 seconds; /ultrareview fans out five specialized agents in parallel and synthesizes a unified report. Gating every PR on an automated review before a human ever sees it is the highest-leverage automation in the dev cycle.After this lesson, you will be able to:
- Run `/review` for a fast quality pass on uncommitted changes — bugs, security, performance, missing tests
- Run `/ultrareview` (cloud, multi-agent) for production-grade reviews of full PRs or branches
- Customize review depth and focus via `REVIEW.md` and prompt arguments
- Wire Claude Code reviews into GitHub Actions / GitLab CI for automated PR feedback
Before You Start
#/review vs /ultrareview
| Command | Speed | Depth | Cost | Best For |
|---|---|---|---|---|
/review | ~30s | Single-agent pass | Local model tokens | Pre-commit sanity check on uncommitted changes |
/ultrareview | 2–5 min | Multi-agent fanout (security, perf, tests, style) | Billed cloud run | Pre-PR or pre-merge — production-grade |
/review constantly (cheap, fast). Use /ultrareview at PR boundaries.#/review: Fast Local Pass
> /review
git diff). Output:🟡 src/api/auth.py:42 — SQL string concatenation; use parameterized query
🟢 src/api/auth.py:68 — Magic constant 86400; consider TOKEN_TTL_SECONDS
🟢 tests/auth.py — Missing test for expired-token path
No critical issues. 3 suggestions.
Variants:
> /review --staged # only review staged changes
> /review src/auth/ # only review files in src/auth/
> /review --since main # review everything since branching from main
> /review --focus security # focus on security issues only
#/ultrareview: Multi-Agent Cloud Review
> /ultrareview # review current branch vs main (local bundle)
> /ultrareview 142 # review GitHub PR #142
> /ultrareview --base develop # custom base branch
/ultrareview does:1. Bundle the diff (current branch vs base, OR fetch PR #N)
2. Spawn parallel cloud agents:
- security-reviewer (auth, secrets, injection, OWASP)
- performance-reviewer (N+1, big-O, blocking I/O, allocations)
- test-reviewer (coverage, edge cases, missing assertions)
- style-reviewer (project conventions, CLAUDE.md compliance)
- architecture-reviewer (layering, module boundaries, abstractions)
4. Each agent reads relevant files for context (not just the diff)
5. Synthesizer agent merges findings, dedupes, ranks by severity
6. Outputs unified report + (optional) GitHub PR comment
Sample output:
ULTRAREVIEW — feat/auth-google (12 files, +487 -128)
🔴 CRITICAL (2)
src/api/auth.py:42 — SQL injection: f-string in WHERE clause
src/api/auth.py:101 — JWT verified without checking expiry
🟡 MAJOR (4)
src/api/auth.py:68 — Token TTL hardcoded; use config
src/api/auth.py:155 — Missing rate limit on /callback endpoint
tests/auth.py:23 — No test for expired-token branch
src/db/users.py:12 — N+1: get_user_with_roles loops queries
🟢 MINOR (7)
... (style, naming, doc improvements)
OVERALL: 2 blockers, 4 should-fix, 7 nits.
Recommendation: BLOCK merge until critical issues resolved.
#Customizing Review Behavior
REVIEW.md to your repo root:# Code Review Guidelines
## Severity Bar
- CRITICAL: blocks merge — security, data loss, public API breakage
- MAJOR: should fix — bugs, missing tests, performance regressions
- MINOR: nits — naming, comments, formatting
## Project-Specific Rules
- All API endpoints must have rate limiting (use @rate_limit decorator)
- Database queries must use parameterized statements (no f-strings in SQL)
- React components must handle prefers-reduced-motion
- TypeScript strict mode — no `any`
- All public functions need JSDoc
## Skip
- Don't flag prettier formatting (CI handles it)
- Don't suggest renaming variables to match a different convention
- Don't recommend abstraction unless the duplication exceeds 3 places
## Tests
- Coverage minimum: 80% on new code
- Every new endpoint needs at least: happy path, auth failure, validation failure
REVIEW.md automatically when running /review or /ultrareview.#Review Slash Command Recipes
> /review --since main --focus security
↳ security-only review of full branch
> /ultrareview --skip style
↳ skip the style agent (saves cloud cost on draft PRs)
> /ultrareview 142 --post-comment
↳ post the synthesized review as a GitHub PR comment
> /review --diff-only
↳ skip context fetching; only look at diff (fastest, less accurate)
#CI/CD Integration: GitHub Actions
Auto-review every PR on open:
# .github/workflows/claude-review.yml
name: Claude Code Review
on:
pull_request:
types: [opened, synchronize]
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install Claude Code
run: npm install -g @anthropic-ai/claude-code
- name: Run ultrareview on PR
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
claude --headless \
--permission-mode dontAsk \
--prompt "/ultrareview ${{ github.event.pull_request.number }} --post-comment"
What this does:
- Triggers on every PR open or push to PR branch
- Runs
/ultrareviewagainst the PR diff - Posts the synthesized review as a PR comment
- Engineers see the review automatically before human reviewer arrives
#CI Integration: GitLab CI
# .gitlab-ci.yml
claude-review:
stage: review
image: node:20
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
script:
- npm install -g @anthropic-ai/claude-code
- claude --headless --permission-mode dontAsk \
--prompt "/ultrareview --base $CI_MERGE_REQUEST_TARGET_BRANCH_NAME"
#Pair /ultrareview with Hooks
/review on every commit:{
"hooks": [
{
"event": "PostToolUse",
"matcher": { "tool": "Bash", "pattern": "git commit" },
"command": "claude --headless --prompt '/review --since HEAD~1' >> .claude/review-log.md"
}
]
}
.claude/review-log.md. Catch issues before push.#Reviewing AI-Generated Code
Special case: when Claude wrote the code, you still want a review pass, but a different angle.
> /review --persona skeptic
↳ assume the code is wrong; look for hallucinated APIs, made-up function signatures, plausible-but-broken patterns
Common AI-code failure modes to catch:
- Hallucinated library functions (especially less-popular packages)
- Wrong API version (Claude trained on older docs)
- Plausible but subtly broken async patterns
- Missing error handling on network calls
- Tests that pass but don't actually verify the behavior
#Key Takeaways
/reviewis fast and cheap — run it constantly, especially before commits/ultrareviewis multi-agent and thorough — run it at PR boundaries, after which humans review- Customize via
REVIEW.md— severity bar, project rules, skip-list - CI integration via GitHub Actions / GitLab CI auto-posts review comments on every PR
/ultrareviewon AI-generated code with--persona skepticcatches hallucinated APIs
#Quick Check
You opened a PR with 8 commits across 14 files. Best review approach?
Pick the cleanest way to plug Claude Code review into a 30-engineer team's PR flow.