Token导航 LogoToken导航TokenDH.com
开发执行命令clawhub未标认证来源可访问clear审计通过

tk-code-reviewerTK 代码审查员

Agent Skill

tk-code-reviewer 用于记录任务执行中的错误、用户纠正、经验和能力缺口,适合在 OpenClaw 中希望让 Agent 持续沉淀问题、修正和最佳实践时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,938

周安装

120

GitHub Stars

公开资料未说明

下载量

941
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:tk-code-reviewer(TK 代码审查员)
来源仓库:https://github.com/tktk-ai/tk-code-reviewer
安装命令:
openclaw skills install tk-code-reviewer
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install tk-code-reviewer

简介

自动审查代码安全漏洞、性能问题与最佳实践差距。

  • 适用于 Python、JavaScript 等多语言项目质量保障。
  • 输出重构建议与文档补全提示,提升代码可维护性。
  • 不能直接作为最终结论,需人工复核关键问题。tk-code-reviewer 属于开发类 Skill,可作为该场景下的辅助能力补充。
  • 安装前应确认代码库访问权限与敏感信息脱敏策略。

SKILL.md

name
ai-code-reviewer
description
Automated code review — security vulnerabilities, performance issues, best practices, refactoring suggestions, and documentation gaps. Supports Python, JavaScript/TypeScript, Go, Rust, and more. PR-ready review comments.
metadata
version
1.0.0
author
TKDigital
category
Developer Tools
tags
[code review, security, performance, refactoring, best practices, pull request, developer tools]

AI Code Reviewer

Comprehensive automated code reviews — security, performance, best practices, and refactoring suggestions.

What It Does

  1. Security Scan — SQL injection, XSS, SSRF, secrets in code, insecure dependencies
  2. Performance Analysis — N+1 queries, memory leaks, inefficient loops, caching opportunities
  3. Best Practices — Code style, naming conventions, SOLID principles, DRY violations
  4. Refactoring Suggestions — Concrete before/after code improvements
  5. Documentation Gaps — Missing docstrings, unclear function names, no type hints
  6. Complexity Analysis — Cyclomatic complexity, function length, nesting depth
  7. PR-Ready Comments — Output formatted as pull request review comments

Usage

Full Code Review

Review this code for security, performance, and best practices:

Language: [Python/JavaScript/TypeScript/Go/Rust]
Context: [What does this code do?]
Priority: [Security first / Performance first / General review]

[Paste code or file path]

For each issue found:
1. Severity (critical/high/medium/low)
2. Category (security/performance/style/bug)
3. Line reference
4. What's wrong
5. How to fix (with corrected code)

Security-Focused Review

Security audit this code. I'm looking for:
- SQL injection vulnerabilities
- XSS attack vectors
- Authentication/authorization bypasses
- Secrets or credentials in code
- Insecure dependencies
- SSRF/CSRF vulnerabilities
- Input validation gaps

Language: [Language]
[Paste code]

Performance Review

Analyze this code for performance issues:
- Database query efficiency (N+1, missing indexes)
- Memory usage and potential leaks
- Algorithm complexity (can it be optimized?)
- Caching opportunities
- Async/concurrency improvements

Context: This handles [X requests/second] and processes [Y data]
[Paste code]

Refactoring Guide

Suggest refactoring improvements for this code:
- Reduce complexity
- Improve readability
- Apply design patterns where beneficial
- Remove duplication
- Improve testability

Show before/after for each suggestion.
[Paste code]

PR Review Format

Review this pull request diff:

[Paste diff or describe changes]

Output as PR comments:
- File: [filename]
- Line: [number]
- Comment: [review comment]
- Suggestion: [code suggestion if applicable]

Output Format

# Code Review Report

**Files Reviewed**: [count]
**Language**: [language]
**Overall Score**: [X/100]

## 🔴 Critical Issues ([count])

### Issue 1: [Title]
- **Severity**: Critical
- **Category**: Security
- **Location**: [file:line]
- **Problem**: [Description]
- **Impact**: [What could happen]
- **Fix**:

// Before (vulnerable) [old code]

// After (fixed) [new code]


## 🟡 Warnings ([count])
[Medium-severity issues]

## 🔵 Suggestions ([count])
[Low-severity improvements]

## 🟢 Positive Observations
[What's already good about the code]

## Summary
- Critical: [X] (must fix before merge)
- Warnings: [X] (should fix soon)
- Suggestions: [X] (nice to have)
- Score: [X/100]

Supported Languages

  • Python (3.8+)
  • JavaScript / TypeScript
  • Go
  • Rust
  • Ruby
  • PHP
  • Java / Kotlin
  • C / C++
  • Shell / Bash

Best Practices

  • Provide context about what the code does — better context = better review
  • Specify your priority (security vs performance vs general)
  • For large codebases, review one module/file at a time
  • Pair with security-auditor for infrastructure-level security checks
  • Use the PR format output to paste directly into GitHub/GitLab reviews

References

  • references/security-patterns.md — Common vulnerability patterns by language
  • references/performance-patterns.md — Common performance anti-patterns

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

81.67%
按下载量换算769

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install tk-code-reviewer 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills