跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 review

审查

通过管理任务、建筑、执行、工艺、安保和业绩通行证审查变化情况,然后将其权衡成判决.

237 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

通过管理任务、建筑、执行、工艺、安保和业绩通行证审查变化情况,然后将其权衡成判决.

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Review、Scope、Step 0 — Find the project's reference material、Passes、Reporting。 其中含规范建议的小节:分步指令。

文件分析

文件分析:这是一份仅含 SKILL.md 的指令型技能,代理激活后整份正文进入上下文。

官方 description(原文)

Reviews a change by running the mission, architecture, implementation, craft, security, and performance passes, then weighing them into a verdict.

ReviewScopeStep 0 — Find the project's reference materialPassesReporting

· 许可:MIT

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
review
description
Reviews a change by running the mission, architecture, implementation, craft, security, and performance passes, then weighing them into a verdict.
许可
MIT
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「review」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-7e1d07a14244fa0a-%E5%AE%A1%E6%9F%A5.html
请存为 .cursor/skills/review/SKILL.md 或 .claude/skills/review/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/elliottlawson/open-review' --list

npx skills add 'https://github.com/elliottlawson/open-review' --skill 'review'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: review description: Reviews a change by running the mission, architecture, implementation, craft, security, and performance passes, then weighing them into a verdict. license: MIT metadata: version: "4" --- # Review Review the change against the passes, then weigh them into a verdict. If a referenced skill isn't available locally, fetch it from the open-review repo at runtime — the whole directory, subdirectories included. Use `npx skills use elliottlawson/open-review@` if npx is available; otherwise fetch the directory from GitHub. ## Scope The change is the diff against the merge-base with the base branch (`git diff origin/main...HEAD`, or the base/range the caller gives). Confirm the ref resolves; if the diff is empty, say so and stop. Skip generated and vendored files. ## Step 0 — Find the project's reference material Find the project's standards and stack with `/infer-conventions`; use what it loads throughout the passes. If the project has no documented standards, say so in the verdict instead of inventing any. ## Passes Run in order: mission → architecture → implementation → craft → security → performance. Then weigh them into a verdict: - **Approve** — mission met, no blocking findings. - **Changes needed** — real issues found; name them. - **Hold** — mission unclear, or an architectural concern needs discussion first. **Depth calibration.** Match depth to scope — a 2-file bugfix is brief; a 30-file feature gets deep coverage. **Verify before you flag.** A finding must point at a concrete line and a concrete consequence. If you can't verify it, ask a question instead. ## Reporting Report your findings in prose — severity (critical / warning / info), the pass that found it, the file and line, and why it matters. - **Judge the change, not the codebase.** Blocking findings only on new or meaningfully changed code; a pre-existing violation is advisory at most. - **Cite the standard, state the target pattern.** When the project has documented standards, name the doc a finding violates and the pattern to follow instead. - **Report repeated issues once.** The same issue across multiple files is one finding — note that it applies broadly. Under CI, `/review-as-json` wraps this review and shapes the output as JSON.

相关技能

安全测试

技能维特Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

护身符Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

安保审计员Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

技能维特Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .