Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计通过

code-review代码审查

Agent Skill

用于辅助文档、README、Markdown、说明文和内容稿件的整理与改写。它适合让 Agent 提炼结构、补齐章节、统一术语、检查链接或把零散材料整理成可读文档。使用时应保留项目已有事实、命令和路径,不要把未确认的信息写成确定结论;涉及对外文案时,还需要控制语气,避免过度营销或夸大能力。

总安装

2,493

周安装

106

GitHub Stars

4,668

下载量

873
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:code-review(代码审查)
来源仓库:https://github.com/cloudflare/cloudflare-docs
仓库路径:skills/code-review
安装命令:
npx skills add https://github.com/cloudflare/cloudflare-docs --skill code-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/cloudflare/cloudflare-docs --skill code-review

简介

code-review 针对 Cloudflare Workers 代码提供审查建议和技术校验。

  • 依赖本地 node_modules 中的类型定义和 Wrangler 配置模式。
  • 优先调用 cloudflare-docs search 工具获取最新 API 用法示例。
  • 不得自行打包或安装依赖包来更新类型声明文件。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Your knowledge of Cloudflare Workers APIs, types, and wrangler configuration may be outdated. Prefer retrieval over pre-training for any Workers code review task.

Reference Sources

Use the repo's local copies — do not run npm pack or install packages to fetch types.

SourceWhere to find itUse for
Wrangler config schemanode_modules/wrangler/config-schema.jsonConfig fields, binding shapes, allowed values
Workers typesnode_modules/@cloudflare/workers-types/index.d.tsAPI usage, handler signatures, binding types
Cloudflare docs searchUse the cloudflare-docs search tool or read files in this repoAPI reference, compatibility dates/flags, binding docs

Read these files directly when you need to verify a type, config field, or API signature. The reference guides in references/ describe what to validate — not how to fetch packages.

Review Process

1. Build Context

Read full files, not just diffs or isolated snippets. Code that looks wrong in isolation may be correct given surrounding logic.

  • Identify the purpose of the code: is it a complete Worker, a snippet, a configuration example?
  • Check git history for context: git log --oneline -5 -- <file>
  • Understand which bindings, types, and patterns the code depends on

2. Categorize the Code

Every code block falls into one of three categories. Review in the context of its category.

CategoryDefinitionExpectations
IllustrativeDemonstrates a concept; uses comments for most logicCorrect API names, realistic signatures
DemonstrativeFunctional but incomplete; would work if placed in the right contextSyntactically valid, correct APIs and binding access
ExecutableStandalone and complete; runs without modificationCompiles, runs, includes imports and config

3. Validate with Tools

Run type-checking and linting. Tool output is evidence, not opinion.

npx tsc --noEmit                    # TypeScript errors
npx eslint <files>                  # Lint issues

For config files, validate against the latest wrangler config schema (see references/wrangler-config.md for retrieval) and check that all fields, binding types, and values conform.

4. Check Against Rules

See references/workers-types.md for type system rules, references/wrangler-config.md for config validation, and references/common-patterns.md for correct API patterns.

Quick-reference rules:

RuleDetail
Binding accessenv.X in module export handlers; this.env.X in classes extending platform base classes. See references/common-patterns.md.
No anyNever use any for binding types, handler params, or API responses. Use proper generics.
No type-system cheatsFlag as unknown as T, unjustified @ts-ignore, unsafe assertions. See references/workers-types.md.
Config-code consistencyBinding names in wrangler config must match env.X usage in code. See references/wrangler-config.md.
Required config fieldsVerify against the wrangler config schema — do not assume which fields are required.
Concise examplesExamples should focus on core logic. Minimize boilerplate that distracts from what the code teaches.
Floating promisesEvery Promise must be awaited, returned, voided, or passed to ctx.waitUntil(). See references/common-patterns.md.
SerializationData crossing Queue, Workflow step, or DO storage boundaries must be structured-clone serializable. See references/common-patterns.md.
StreamingLarge/unknown payloads must stream, not buffer. Flag await response.text() on unbounded data.
Error handlingMinimal but present — null checks on nullable returns, basic fetch error handling. Do not distract with verbose try/catch.

5. Assess Risk

RiskTriggers
HIGHAuth, crypto, external calls, value transfer, validation removal, access control, binding misconfiguration
MEDIUMBusiness logic, state changes, new public APIs, error handling, config changes
LOWComments, logging, formatting, minor style

Focus deeper analysis on HIGH risk. For critical paths, check blast radius: how many other files reference this code?

Security logic escalation: for crypto, auth, and timing-sensitive code, do not stop at verifying API calls are correct. Examine the surrounding logic for flaws that undermine the security property (e.g., correct timingSafeEqual call but early return on length mismatch). See references/common-patterns.md Security section.

Anti-patterns to Flag

Anti-patternWhy it matters
any on Env or handler paramsDefeats type safety for every binding access downstream
as unknown as T double-castHides real type incompatibilities — fix the underlying design
@ts-ignore / @ts-expect-error without explanationMasks errors silently; require a comment justifying each suppression
Buffering unbounded data (await res.text(), await res.json() on streams)Memory exhaustion on large payloads; use streaming
Hardcoded secrets or API keysUse env bindings and wrangler secret
blockConcurrencyWhile on every requestOnly for initialization; blocks all concurrent requests
Single global Durable ObjectCreates a bottleneck; shard by coordination atom
In-memory-only state in DOsLost on eviction; persist to SQLite storage
Missing DO migrations in configNew DO classes require migration entries or deployment fails
Floating promises (step.do(), fetch() without await)Silent bugs — drops results, breaks Workflow durability, ignores errors
Non-serializable values across boundaries (Response, Error in step/queue)Compiles but fails at runtime; extract plain data before crossing boundary
implements instead of extends on platform base classesLegacy pattern — loses this.ctx, this.env access from base class

What NOT to Flag

  • Style not enforced by linters
  • "Could be cleaner" when code is correct and clear
  • Theoretical performance concerns without evidence
  • Missing features not in scope of the example
  • Pre-existing issues in unchanged code
  • TOML config in existing docs (only flag for new content)

Output Format

**[SEVERITY]** Brief description
`file.ts:42` — explanation with evidence (tool output, type error, config mismatch)
Suggested fix: `code` (if applicable)

Severity: CRITICAL (security, data loss, crash) | HIGH (type error, wrong API, broken config) | MEDIUM (missing validation, edge case, outdated pattern) | LOW (style, minor improvement)

End with a summary count by severity. If no issues found, say so directly.

Principles

  • Be certain. Investigate before flagging. If you cannot confirm an API, binding pattern, or config field, retrieve the docs or schema first.
  • Provide evidence. Reference line numbers, tool output, schema fields, or type definitions.
  • Correctness over completeness. A concise example that works is better than a comprehensive one with errors.
  • Respect existing patterns. Do not flag conventions already established in the codebase unless actively harmful.
  • Focus on what developers will copy. Code in documentation gets pasted into production. Treat it accordingly.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.66%
按下载量换算294

Claude

31.07%
按下载量换算271

Cursor

16.54%
按下载量换算144

Gemini CLI

9.56%
按下载量换算83

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills