Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问clear审计异常

code-reviewer代码审查员

Agent Skill

code-reviewer 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

212

周安装

9

GitHub Stars

17

下载量

74
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:code-reviewer(代码审查员)
来源仓库:https://github.com/nguyenthienthanh/aura-frog
仓库路径:skills/code-reviewer
安装命令:
npx skills add https://github.com/nguyenthienthanh/aura-frog --skill code-reviewer
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/nguyenthienthanh/aura-frog --skill code-reviewer

简介

用于查找、检索和筛选相关信息,适合快速定位候选结果。

  • 适用于关键词搜索、任务场景匹配和来源线索筛选。
  • 可结合仓库路径和原始 README 核验具体用法。
  • 安装方式:通过 GitHub 仓库安装,使用前确认权限与维护状态。
  • 注意是否会触发联网、命令执行或文件读写操作。code-reviewer 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Aura Frog Code Reviewer — 6-Aspect Analysis

Priority: HIGH — Use before merging code


When to Use

  • After implementation, before merge
  • During Phase 4 (Refactor + Review)
  • When explicitly requested

Review Process

Step 1: Get Changed Files

git diff --name-only main...HEAD
# Or: files modified in current workflow

Step 2: Run 6-Aspect Review

MANDATORY: All 6 aspects must be covered. Do not skip any.

Aspect 1: 🔒 Security

  • Hardcoded secrets (API keys, passwords, tokens)
  • SQL injection, XSS, command injection vectors
  • Auth/authz gaps (missing middleware, privilege escalation)
  • CSRF, CORS misconfigurations
  • Insecure crypto (MD5, SHA1, Math.random for tokens)

Aspect 2: 🏷️ Type Safety

  • Missing type annotations on public functions
  • any type usage (suggest specific types)
  • Inconsistent return types
  • Null/undefined handling gaps
  • Generic types that could be narrower

Aspect 3: ⚠️ Error Handling

  • Unhandled promise rejections
  • Empty catch blocks without justification
  • Missing error boundaries (React) / error middleware (Express)
  • Silent failures (errors swallowed without logging)
  • Missing retry logic on external calls

Aspect 4: 🧪 Test Gaps

  • Untested critical paths
  • Missing edge case tests
  • Test quality (testing behavior vs implementation)
  • Mock quality (over-mocking, missing integration tests)
  • Gaps on modified files

Aspect 5: 📐 Code Quality

  • KISS violations (over-engineering, premature abstraction)
  • DRY violations (duplicated logic)
  • Naming clarity (functions, variables, files)
  • Single Responsibility violations
  • Dead code, unused imports

Aspect 6: ♻️ Simplification Opportunities

  • Complex conditionals that could be simplified
  • Deep nesting that could be flattened (early returns)
  • Long functions that should be split
  • Verbose patterns with simpler alternatives
  • Redundant null checks or type guards

Step 3: Generate Report

review[6]{aspect,icon,status,findings}:
  Security,🔒,✅|⚠️|❌,{count} findings
  Types,🏷️,✅|⚠️|❌,{count} findings
  Errors,⚠️,✅|⚠️|❌,{count} findings
  Tests,🧪,✅|⚠️|❌,{count} findings
  Quality,📐,✅|⚠️|❌,{count} findings
  Simplify,♻️,✅|⚠️|❌,{count} findings

Detail each finding:

[ASPECT] [SEVERITY] file:line — description
  → Fix: recommendation

Severity: 🔴 CRITICAL (block merge) | 🟡 WARNING (should fix) | 🔵 INFO (nice to have)

Step 4: Decision

  • ✅ APPROVED — 0 critical, ≤3 warnings
  • ⚠️ APPROVED WITH COMMENTS — 0 critical, >3 warnings
  • ❌ CHANGES REQUESTED — Any critical finding

Step 5: Summary Line

Review: 🔒✅ 🏷️✅ ⚠️⚠️ 🧪✅ 📐✅ ♻️✅ — APPROVED WITH COMMENTS (1 error handling warning)

Critical (Block Merge)

  • Hardcoded secrets
  • SQL injection / XSS / command injection
  • Missing auth on protected routes
  • Breaking changes without migration

Remember: Review improves code quality. Be constructive.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenCode

29.48%
按下载量换算22

Claude Code

21.67%
按下载量换算16

windsurf

15.3%
按下载量换算11

cline

12.69%
按下载量换算9

weavefox

7.06%
按下载量换算5

Codex

3.16%
按下载量换算2

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

未通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills