Token导航 LogoToken导航TokenDH.com
研究检索执行命令clawhub未标认证来源可访问clear审计通过

qf-code-reviewQF 代码审查

Agent Skill

qf-code-review 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

4,504

周安装

184

GitHub Stars

1

下载量

1,457
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:qf-code-review(QF 代码审查)
来源仓库:https://github.com/371166758-qq/qf-code-review
安装命令:
openclaw skills install qf-code-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install qf-code-review

简介

提供有关多种主要编程语言的安全性、性能、正确性和可维护性问题的详细、优先的代码审查反馈。

SKILL.md

AI Code Review

Systematic code review framework covering security vulnerabilities, performance bottlenecks, maintainability issues, and best practices across major programming languages.

Description

This skill provides a structured approach to reviewing code like a senior engineer. It produces actionable, prioritized feedback organized by severity (Critical / Warning / Suggestion) and category (Security / Performance / Maintainability / Correctness / Style). Works across Python, JavaScript/TypeScript, Go, Rust, Java, and other common languages.

When to Use

  • Reviewing a pull request or code submission
  • Auditing code for security vulnerabilities before deployment
  • Identifying performance issues in hot paths
  • Onboarding new developers with consistent review standards
  • Reviewing AI-generated code for production readiness

Instructions

Review Process

Phase 1: Quick Scan (30 seconds)

Before deep analysis:

  1. Understand intent: What does this code do? Read commit message or PR description.
  2. Check scope: Is the change focused, or does it touch unrelated files?
  3. Assess risk: Does this modify auth, payment, data persistence, or external APIs? Flag as high-risk.

Phase 2: Category-by-Category Review

Security (🔴 Critical if found)

Check for these common vulnerabilities:

VulnerabilityPattern to Look For
SQL InjectionString concatenation in queries, raw SQL without parameterization
XSSUnescaped user input rendered in HTML, innerHTML with user data
Path TraversalUser-controlled file paths, ../ not sanitized
Hardcoded SecretsAPI keys, passwords, tokens in source code
Insecure Deserializationeval(), pickle.loads(), JSON.parse on untrusted data
IDORMissing authorization checks on resource access endpoints
Command Injectionos.system(), exec(), subprocess with user input
Broken AuthWeak password hashing, missing rate limiting, JWT without validation

For each finding, specify:

  • The vulnerable code location
  • Attack scenario
  • Recommended fix with code example

Performance (🟡 Warning if found)

Check for:

  • N+1 queries: Database calls inside loops
  • Unbounded operations: Loops without limits on user-controlled data size
  • Memory leaks: Unclosed connections, unbounded caches, event listeners not removed
  • Inefficient algorithms: O(n²) where O(n) suffices, unnecessary copies
  • Synchronous blocking: File I/O or HTTP calls on the main thread/event loop
  • Missing pagination: Loading full datasets instead of paginated results
  • Redundant computations: Repeated calculations that could be cached

Correctness (🔴 Critical if found)

Check for:

  • Off-by-one errors: Loop bounds, index calculations, substring operations
  • Null/undefined handling: Missing null checks before dereferencing
  • Race conditions: Shared mutable state without synchronization
  • Error handling: Swallowed exceptions, missing error cases, overly broad catch
  • Edge cases: Empty inputs, negative numbers, zero, max values, Unicode
  • Type mismatches: Comparing different types, implicit coercions

Maintainability (🟢 Suggestion if found)

Check for:

  • Function length: Functions over 30 lines should be considered for splitting
  • Complexity: Deep nesting (>3 levels), long parameter lists (>5 params)
  • Naming: Single-letter variables (except loop indices), ambiguous names, inconsistency
  • Duplication: Repeated logic that should be extracted
  • Dead code: Unused imports, unreachable branches, commented-out code
  • Magic numbers: Unexplained numeric literals

Phase 3: Output Format

Organize findings as:

## Code Review Summary

**Overall Assessment**: [Ready to merge / Needs changes / Request changes]

### 🔴 Critical (must fix)
1. [Category] **Title**: Description + Location + Fix suggestion

### 🟡 Warning (should fix)
1. [Category] **Title**: Description + Location + Fix suggestion

### 🟢 Suggestion (nice to have)
1. [Category] **Title**: Description + Location + Fix suggestion

### ✅ Highlights
- Things done well (positive reinforcement)

Language-Specific Rules

Python:

  • Use type hints for public functions
  • Prefer pathlib.Path over os.path
  • Use context managers for resources
  • Follow PEP 8 line length (88 chars for Black, 79 for flake8)

JavaScript/TypeScript:

  • Use const by default, let only when reassignment needed
  • Prefer interface over type for object shapes in TypeScript
  • Avoid any — use unknown and narrow with type guards
  • Use optional chaining (?.) and nullish coalescing (??) over manual checks

Go:

  • Handle errors explicitly — never use _ = err
  • Keep functions under 50 lines
  • Use table-driven tests
  • Accept interfaces, return structs

Examples

Finding Example:

🔴 Critical [Security] SQL Injection in user lookup
Location: src/auth/login.py:42
The `username` parameter is directly interpolated into the SQL query:
  cursor.execute(f"SELECT * FROM users WHERE username='{username}'")
Fix: Use parameterized queries:
  cursor.execute("SELECT * FROM users WHERE username = %s", (username,))

Suggestion Example:

🟢 Suggestion [Maintainability] Extract magic number
Location: src/utils/cache.py:18
The value 86400 appears without explanation. It represents seconds in a day.
Fix: Define as a named constant:
  CACHE_TTL_SECONDS = 86_400  # 24 hours

Tips

  • Review the diff, not the full file — focus on what changed
  • Always check the test coverage for changed code
  • Use automated tools (linter, type checker, security scanner) first — human review should catch what tools miss
  • When suggesting changes, provide the fixed code, not just the description
  • Be specific about severity — calling everything "critical" dilutes real critical issues

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

89.07%
按下载量换算1,298

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install qf-code-review 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills