Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计通过

code-review代码审查

Agent Skill

code-review 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

528

周安装

22

GitHub Stars

23

下载量

176
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:code-review(代码审查)
来源仓库:https://github.com/akaszubski/autonomous-dev
仓库路径:skills/code-review
安装命令:
npx skills add https://github.com/akaszubski/autonomous-dev --skill code-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/akaszubski/autonomous-dev --skill code-review

简介

确保代码审查全面且可执行,提供 10 项必查清单覆盖正确性与测试覆盖。

  • 适用于新代码评审、边缘情况检查和异常处理验证。
  • 使用时需逐项评估,禁止跳过任何检查项。
  • 安装命令:npx skills add https://github.com/akaszubski/autonomous-dev --skill code-review
  • 建议结合 CI 结果和测试日志进行交叉验证。

SKILL.md

Code Review Enforcement Skill

Ensures every code review is thorough, consistent, and produces actionable feedback. Used by the reviewer agent.

10-Point Review Checklist

Every review MUST evaluate all 10 items. No shortcuts.

1. Correctness

  • Does the code do what the ticket/plan requires?
  • Are edge cases handled (empty input, None, boundary values)?
  • Are return types consistent with declarations?

2. Test Coverage

  • Do tests exist for new/changed code?
  • Do ALL tests pass (100%, not "most")?
  • Are edge cases and error paths tested?

3. Error Handling

  • Are exceptions specific (not bare except:)?
  • Do error messages include context (what failed, what was expected)?
  • Is there graceful degradation where appropriate?

4. Type Hints on Public APIs

  • All public functions have parameter and return type annotations?
  • Complex types use Optional, Union, List, Dict correctly?

5. Naming Conventions

  • Variables/functions: snake_case
  • Classes: PascalCase
  • Constants: UPPER_SNAKE_CASE
  • Names are descriptive (no single-letter except loop vars)

6. Security

  • No hardcoded secrets, API keys, or passwords
  • No bare except: that swallows errors silently
  • SQL queries use parameterized statements
  • User input is validated before use

7. Style Compliance

  • Code is formatted with black (100 char line length)
  • Imports sorted with isort
  • No unused imports or variables

8. Documentation

  • Public APIs have Google-style docstrings
  • Complex logic has inline comments
  • Examples provided for non-obvious usage

9. No Stubs or Placeholders

  • No NotImplementedError in shipped code
  • No pass as the sole body of a function
  • No TODO without a linked issue number

10. No Unnecessary Complexity

  • No premature abstraction
  • No dead code paths
  • Functions do one thing
  • Nesting depth <= 3 levels

Severity Levels

BLOCKING (must fix before approval)

  • Failing tests
  • Security vulnerabilities (hardcoded secrets, SQL injection)
  • Missing error handling on external calls
  • Stubbed/placeholder code
  • Incorrect logic or data loss risk

ADVISORY (prefix with "Nit:")

  • Style preferences beyond black/isort
  • Alternative naming suggestions
  • Minor documentation improvements
  • Performance micro-optimizations

HARD GATE: Required Output

Every review MUST conclude with exactly one of:

  • APPROVED — all 10 checklist items pass, no BLOCKING issues
  • REQUEST_CHANGES — at least one BLOCKING issue found

FORBIDDEN:

  • Saying "looks good" without running the full checklist
  • Approving code with failing tests
  • Approving stubbed or placeholder code
  • Approving without checking security items (checklist #6)
  • Mixing BLOCKING and ADVISORY without clear labels
  • Rubber-stamping: approving in under 30 seconds of analysis

REQUIRED:

  • Per-file summary with specific line references for each finding
  • Explicit pass/fail on each of the 10 checklist items
  • Test results included from STEP 8 artifact provided in context — do NOT re-run pytest
  • Security checklist explicitly addressed
  • BLOCKING vs ADVISORY clearly labeled on every finding

Required Output Format

## Review: [file or PR title]

### Checklist
1. Correctness: PASS/FAIL — [details]
2. Test Coverage: PASS/FAIL — [details]
3. Error Handling: PASS/FAIL — [details]
4. Type Hints: PASS/FAIL — [details]
5. Naming: PASS/FAIL — [details]
6. Security: PASS/FAIL — [details]
7. Style: PASS/FAIL — [details]
8. Documentation: PASS/FAIL — [details]
9. No Stubs: PASS/FAIL — [details]
10. Complexity: PASS/FAIL — [details]

### Findings
- [BLOCKING] file.py:42 — description
- [Nit:] file.py:88 — suggestion

### Test Results
[from STEP 8 artifact provided in context — do NOT re-run pytest]

### Verdict: APPROVED / REQUEST_CHANGES

Anti-Patterns

BAD: Rubber-stamp approval

"Looks good to me, ship it!"

Missing: checklist, line references, test results, security review.

GOOD: Structured review

## Review: lib/auth.py

### Checklist
1. Correctness: PASS — token validation logic matches RFC 7519
2. Test Coverage: PASS — 12 tests, all pass, covers expiry edge case
...
6. Security: FAIL — API key on line 34 is hardcoded

### Findings
- [BLOCKING] auth.py:34 — Hardcoded API key, move to env var

### Verdict: REQUEST_CHANGES

BAD: Nitpicking style, missing logic bugs

Spending 10 comments on variable naming while an off-by-one error goes unnoticed.

BAD: "Will fix later" acceptance

Approving with known BLOCKING issues and a verbal promise to fix. If it is BLOCKING, it blocks.


Cross-References

  • python-standards: Style and type hint requirements
  • testing-guide: Test coverage expectations
  • security-patterns: Security checklist details

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

37.01%
按下载量换算65

Claude

31.1%
按下载量换算55

Cursor

20.9%
按下载量换算37

Gemini CLI

8.75%
按下载量换算15

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills