跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 code-review-expert

Code Review Expert

专家代码审查当前用高级工程师镜头进行git修改. 侦测SOLID违规情况、安全风险,并提出可采取行动的改进措施.

13074 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

专家代码审查当前用高级工程师镜头进行git修改. 侦测SOLID违规情况、安全风险,并提出可采取行动的改进措施.

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Code Review Expert、Overview、Severity Levels、Workflow、1) Preflight context、2) SOLID + architecture smells。 其中含规范建议的小节:分步指令。

文件分析

文件分析:除 SKILL.md 外,正文引用了 references/solid-checklist.md、references/removal-plan.md、references/security-checklist.md、references/code-quality-checklist.md,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.

Code Review ExpertOverviewSeverity LevelsWorkflow1) Preflight context2) SOLID + architecture smells3) Removal candidates + iteration plan4) Security and reliability scan5) Code quality scan6) Output formatCode Review SummaryFindings

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
code-review-expert
description
Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 4
  • references/solid-checklist.md
  • references/removal-plan.md
  • references/security-checklist.md
  • references/code-quality-checklist.md

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「code-review-expert」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-8aec857694a79d1f-Code-Review-Expert.html
请存为 .cursor/skills/code-review-expert/SKILL.md 或 .claude/skills/code-review-expert/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/sanyuan0704/sanyuan-skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/sanyuan0704/sanyuan-skills' --list

npx skills add 'https://github.com/sanyuan0704/sanyuan-skills' --skill 'code-review-expert'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版

name: code-review-expert description: "Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements."

Code Review Expert

Overview

Perform a structured review of the current git changes with focus on SOLID, architecture, removal candidates, and security risks. Default to review-only output unless the user asks to implement changes.

Severity Levels

| Level | Name | Description | Action | |-------|------|-------------|--------| | P0 | Critical | Security vulnerability, data loss risk, correctness bug | Must block merge | | P1 | High | Logic error, significant SOLID violation, performance regression | Should fix before merge | | P2 | Medium | Code smell, maintainability concern, minor SOLID violation | Fix in this PR or create follow-up | | P3 | Low | Style, naming, minor suggestion | Optional improvement |

Workflow

1) Preflight context

  • Use git status -sb, git diff --stat, and git diff to scope changes.
  • If needed, use rg or grep to find related modules, usages, and contracts.
  • Identify entry points, ownership boundaries, and critical paths (auth, payments, data writes, network).

Edge cases:

  • No changes: If git diff is empty, inform user and ask if they want to review staged changes or a specific commit range.
  • Large diff (>500 lines): Summarize by file first, then review in batches by module/feature area.
  • Mixed concerns: Group findings by logical feature, not just file order.

2) SOLID + architecture smells

  • Load references/solid-checklist.md for specific prompts.
  • Look for:
    • SRP: Overloaded modules with unrelated responsibilities.
    • OCP: Frequent edits to add behavior instead of extension points.
    • LSP: Subclasses that break expectations or require type checks.
    • ISP: Wide interfaces with unused methods.
    • DIP: High-level logic tied to low-level implementations.
  • When you propose a refactor, explain why it improves cohesion/coupling and outline a minimal, safe split.
  • If refactor is non-trivial, propose an incremental plan instead of a large rewrite.

3) Removal candidates + iteration plan

  • Load references/removal-plan.md for template.
  • Identify code that is unused, redundant, or feature-flagged off.
  • Distinguish safe delete now vs defer with plan.
  • Provide a follow-up plan with concrete steps and checkpoints (tests/metrics).

4) Security and reliability scan

  • Load references/security-checklist.md for coverage.
  • Check for:
    • XSS, injection (SQL/NoSQL/command), SSRF, path traversal
    • AuthZ/AuthN gaps, missing tenancy checks
    • Secret leakage or API keys in logs/env/files
    • Rate limits, unbounded loops, CPU/memory hotspots
    • Unsafe deserialization, weak crypto, insecure defaults
    • Race conditions: concurrent access, check-then-act, TOCTOU, missing locks
  • Call out both exploitability and impact.

5) Code quality scan

  • Load references/code-quality-checklist.md for coverage.
  • Check for:
    • Error handling: swallowed exceptions, overly broad catch, missing error handling, async errors
    • Performance: N+1 queries, CPU-intensive ops in hot paths, missing cache, unbounded memory
    • Boundary conditions: null/undefined handling, empty collections, numeric boundaries, off-by-one
  • Flag issues that may cause silent failures or production incidents.

6) Output format

Structure your review as follows:

## Code Review Summary

**Files reviewed**: X files, Y lines changed
**Overall assessment**: [APPROVE / REQUEST_CHANGES / COMMENT]

---

## Findings

### P0 - Critical
(none or list)

### P1 - High
1. **[file:line]** Brief title
  - Description of issue
  - Suggested fix

### P2 - Medium
2. (continue numbering across sections)
  - ...

### P3 - Low
...

---

## Removal/Iteration Plan
(if applicable)

## Additional Suggestions
(optional improvements, not blocking)

Inline comments: Use this format for file-specific findings:

::code-comment{file="path/to/file.ts" line="42" severity="P1"}
Description of the issue and suggested fix.
::

Clean review: If no issues found, explicitly state:

  • What was checked
  • Any areas not covered (e.g., "Did not verify database migrations")
  • Residual risks or recommended follow-up tests

7) Next steps confirmation

After presenting findings, ask user how to proceed:

---

## Next Steps

I found X issues (P0: _, P1: _, P2: _, P3: _).

**How would you like to proceed?**

1. **Fix all** - I'll implement all suggested fixes
2. **Fix P0/P1 only** - Address critical and high priority issues
3. **Fix specific items** - Tell me which issues to fix
4. **No changes** - Review complete, no implementation needed

Please choose an option or provide specific instructions.

Important: Do NOT implement any changes until user explicitly confirms. This is a review-first workflow.

Resources

references/

| File | Purpose | |------|---------| | solid-checklist.md | SOLID smell prompts and refactor heuristics | | security-checklist.md | Web/app security and runtime risk checklist | | code-quality-checklist.md | Error handling, performance, boundary conditions | | removal-plan.md | Template for deletion candidates and follow-up plan |

相关技能

安全测试

Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .