Code Review & Quality Agent Plugins

Code Review & Quality is the 7th-largest category in agentpluginsdirectory.com's verified index: 121 of the 2,790 distinct Agent Plugins verified on 2026-09-23, or 4% of the directory. It covers plugins that read existing code and judge it: code review, refactoring guidance, linting and static analysis, debugging assistance, performance profiling, and codebase auditing. Of these 121, 108 ship at least one Agent Skill and 27 declare MCP servers.

Analysing or improving code that already exists. Writing new tests for it belongs to Testing; scanning it for vulnerabilities belongs to Security. Agent Plugins 1.0.0 defines no category field, so this grouping is editorial, not read from the manifest — the verification claim covers the plugin, not the category.

Plugin directory

48 of 48 plugins on this page · click a row to expand · 121 total

PluginStars
  1. chrome-devtools1.10.0Reliable Chrome automation, debugging, and performance analysis for AI agents.ChromeDevTools7 skills1 mcp52,507
  2. agentic-bundle-oss-maintainer18.2.0Portable skills-only "OSS Maintainer" plugin from Agentic Awesome Skills.sickn3310 skills46,814
  3. diffusersConventions and task skills for contributing to diffusershuggingface4 skills34,588
  4. megalinter1.0.11Set up, run and fix MegaLinter on any repository: 100+ linters for 69+ languages, 23+ formats and 21+ tooling formats, from CI or locally.oxsecurity4 skills2,599
  5. code-craftsmanship1.8.0Code quality and software design skills including Clean Code (Robert C. Martin), Refactoring patterns (Martin Fowler), A Philosophy of Software Design (John Ousterhout), The Pragmatic Programmer (Hunt & Thomas), Domain-Driven Design (Eric Evans), Working Effectively with Legacy Code (Michael Feathers), and Google's Developer Documentation Style Guide (technical-documentation)wondelai7 skills2,245
  6. swift-concurrency2.3.0Expert guidance on Swift Concurrency best practices, patterns, and implementation. Covers async/await, actors, tasks, Sendable conformance, data race prevention, and Swift 6 migration strategies.AvdLee1 skills1,660
  7. java-agent-skills1.0.0Agent Skills for Java development: code review, testing, architecture, Spring Boot, JPA, concurrency, security and release workflows.decebals18 skills744
  8. squirrelscan0.0.98Website QA tool built for coding agents (Claude Code, Cursor). 260+ rules across SEO, performance, security, accessibility & agent experience: audit from the CLI, fix findings in code, publish reports, and connect over MCP.squirrelscan2 skills1 mcp267
  9. aws-well-architected6.4.0Well-Architected skills and steering for AI coding agents: full and pillar-scoped Well-Architected reviews, guardrails, migration readiness, and guided build assistance across all 6 pillars.aws-samples6 skills262
  10. lattice2.1.0Composable AI skills framework covering the full software delivery lifecycle, design, architecture, implementation, testing, and review.techygarg27 skills193
  11. trace-mcp3.31.3Framework-aware code intelligence MCP server: 88 framework integrations, 81 languages, 72.7% fewer input tokens to review a pull request, comprehension at paritynikolai-vysotskyi4 skills1 mcp180
  12. rstack0.1.0Agent Skills for debugging, tracing, upgrading, and analyzing Rstack projects.rstackjs22 skills95
  13. qodo2.0.11Qodo setup, code intelligence, and review workflows.qodo-ai4 skills54
  14. php-modernization1.23.4PHP 8.x modernization patterns with type safety and PHPStannetresearch1 skills47
  15. vinv0.0.5Give your agent runtime evidence: semantic code search, dead-code detection, and fault localization over real runs, zero code changes (Python).VinvAI1 mcp46
  16. file-search1.8.1Fast codebase search with ripgrep for text patterns, ast-grep for structural code search, plus fd, rga, tokei, and sccnetresearch1 skills38
  17. q-knowledge0.1.1kdb+/q language support: idiomatic q, qsql, IPC, kdb+ workflows, and KX qlint integration via /qlint-snippetKxSystems2 skills1 mcp20
  18. agent-toolkit-craft1.32.1Writing quality and change-safety toolkit: cut AI tells (unslop), remove code slop (deslop), and prove blast radius before shipping.ulises-jeremias3 skills18
  19. search-first0.1.0Enforce a search-before-edit workflow: locate relevant files, symbols, call sites, and surrounding context before proposing or making code changes.MiniMax-AI1 skills18
  20. vastlint0.13.9Validate VAST, VMAP, and DAAST ad tags against IAB Tech Lab specs. Hosted MCP at https://vastlint.org/mcp. Auth none for public tools.aleksUIX2 skills1 mcp18
  21. unified-code-review1.4.10Risk-first PR/branch review: blast radius, agent-authored checks, call-graph pincer, structure.dancingteeth1 skills17
  22. architecture1.0.0Opinionated guidance for maintainable software architecture, code design, and testing.BastiDood4 skills14
  23. bifrost0.11.5Bifrost by Brokk: multi-language code intelligence and MCP workflows.BrokkAi4 skills1 mcp12
  24. go-development1.16.0Production-grade Go development patterns for resilient servicesnetresearch1 skills12
  25. search-first0.1.0Enforce a search-before-edit workflow: locate relevant files, symbols, call sites, and surrounding context before proposing or making code changes.hetaoBackend1 skills12
  26. typo3-extension-upgrade3.13.0Systematic TYPO3 extension upgrades with planning agents and commandsnetresearch1 skills10
  27. gophers0.1.0Production-grade Go programming skills for AI coding agents.muratmirgun26 skills9
  28. rootloom4.4.0Portable Rootloom Agent Skills for inspectable code changes and evidence-backed review with bounded project and artifact context.qingye-lab3 skills9
  29. baseline0.5.0The portable minimum for disciplined, proportional software engineeringwoliveiras18 skills6
  30. kotlin-quality1.13.0Risk-based Kotlin review agents for READMEs, tests, architecture, domain behavior, concurrency, API and data compatibility, security, builds, performance, resilience, and platform runtimesHeapy2 skills6
  31. typo3-conformance2.19.5Evaluate TYPO3 extensions for conformance to v12/v13/v14 standards (v14.3 LTS is the default/gold standard)netresearch1 skills6
  32. wcode0.8.3Portable wcode engineering control-plane skill with explicit safe MCP connection profiles.francis-du1 skills6
  33. git-slop0.16.1Agent guidance for the deterministic git-slop repository token-defragmenter.coreycoto4 skills5
  34. loops0.0.3Autonomous loops that shepherd work to completion, such as driving a PR to a mergeable statestbenjam1 skills5
  35. novus0.5.0Novus skills for coding agents: UX review and evidence-backed next-work and portfolio investment decisions, powered by Pendo product analytics.pendo-io6 skills1 mcp5
  36. dotnet-modernization1.0.1Convert legacy.NET project files to modern SDK-style format.PlagueHO4
  37. fresh-eyes0.2.0Look at a module with fresh eyes and keep the simplest redesigns that survive its constraintsstaticaland1 skills4
  38. minottobot2.5.1Use whenever the user asks about QA, testing strategy, CI/CD health, team processes, developer experience, code review practices, test coverage, flaky tests, monitoring, or any audit of an engineering team's quality practices.EmanueleMinotto8 skills4
  39. ngautopilot-angular-21-to-220.9.0Bounded Angular 21 to 22 upgrade preflight, execution, compatibility, and validation guidance.janpereira-dev19 skills4
  40. paireto0.10.0Pair-programming with Paireto in VS Code.Nick-Lucas2 skills1 mcp4
  41. pioneer0.3.5Delegate Pi code reviews with native sandboxing on macOS and Linux.rock3r1 skills4
  42. smrt-dev-mcpDevelopment MCP server and SMRT code-review skill.happyvertical1 skills1 mcp4
  43. agent-code-navigator0.1.0Route code discovery across exact search, semantic search, LSP navigation, and call-graph analysis.777genius4 skills3
  44. audits0.3.1Scheduled findings that open PRs/issues, deliberately capped and conservative: audit-architecture (tech-debt sweep), audit-tests (test-suite health), audit-security (vulnerable deps, committed secrets incl. git history, permissive defaults: code patterns are left to Claude Code's built-in /security-review), audit-deps (dependency health: outdated, deprecated, unused, lockfile drift, licenses), audit-design-docs (validate design docs against code), and audit-product-docs (validate user-facing docs against code). Detection rules and invariants come from the repo's.claude/maintainerd.json and guidelines files.Vycari6 skills3
  45. codex-skills0.19.0Agent skills for research, App Store readiness, Codex model routing, repository and Swift review, PR feedback triage, and safe branch cleanup.coryparrry8 skills3
  46. git-subtrees0.1.0Blocks unsafe git subtree invocations: URL fetch, missing --squash, missing -S/--gpg-sign, and subtree push.systemfsoftware3
  47. verify-catalog-conformance0.0.1Repo-local policy (this repo only, never published): run the fast deterministic catalog checks at commit time, registry labels, README counts, quoted console output, workflow-trigger safety, so a mismatch fails in seconds under the committer's hands instead of minutes later in CI. Each of these caught a real error from CI on 2026-08-16. CI remains the authority: it re-runs the same tools on the pinned engine plus everything too slow for a hook (evals, transcripts, the staged adopter). Skips with a warning when python is absent, because the backstop is what makes that honest.open-coder-ai1 skills3
  48. calm-craft0.3.1Specs as the source of truth, a chunked delivery loop, and decided-and-enforced code conventions, as portable agent skills.calmtechltd31 skills2

Verified on 2026-09-23