Code Review

作者 anthropicsae1513ea94dc无许可证27K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.

精选仅含说明Software Development
AI 生成的概览

审查代码变更的安全性、性能、正确性与可维护性,并输出带结论的结构化报告。

功能
针对提供的 diff、拉取请求链接或文件路径,从四个维度进行审查:安全性(注入、认证缺陷、密钥泄露、SSRF)、性能(N+1 查询、复杂度、资源泄漏)、正确性(边界情况、竞态条件、错误处理)以及可维护性(命名、重复、测试)。输出 markdown 报告,包含摘要、严重问题表格、建议表格、优点观察以及批准、要求修改或需要讨论的结论。建议力求可执行,并附代码示例。
适用场景
适用于合并前检查变更、判断代码是否安全,或需要针对 N+1 查询、注入风险、缺失的边界情况和错误处理缺口审查 diff 的场景。也适合需要带严重级别和合并结论的结构化审查报告时使用。
运行要求
无需脚本,仅为指令。可独立使用,接受粘贴的 diff、PR 链接或文件路径。可选连接器(源代码管理、项目跟踪、知识库)可自动拉取 diff、关联工单并对照团队编码规范检查。

/code-review

If you see unfamiliar placeholders or need to check which tools are connected, see CONNECTORS.md.

Review code changes with a structured lens on security, performance, correctness, and maintainability.

Usage

/code-review <PR URL or file path>

Review the provided code changes: @$1

If no specific file or URL is provided, ask what to review.

How It Works

┌─────────────────────────────────────────────────────────────────┐│                      CODE REVIEW                                   │├─────────────────────────────────────────────────────────────────┤│  STANDALONE (always works)                                       ││  ✓ Paste a diff, PR URL, or point to files                      ││  ✓ Security audit (OWASP top 10, injection, auth)               ││  ✓ Performance review (N+1, memory leaks, complexity)           ││  ✓ Correctness (edge cases, error handling, race conditions)    ││  ✓ Style (naming, structure, readability)                        ││  ✓ Actionable suggestions with code examples                    │├─────────────────────────────────────────────────────────────────┤│  SUPERCHARGED (when you connect your tools)                      ││  + Source control: Pull PR diff automatically                    ││  + Project tracker: Link findings to tickets                     ││  + Knowledge base: Check against team coding standards           │└─────────────────────────────────────────────────────────────────┘

Review Dimensions

Security

  • SQL injection, XSS, CSRF
  • Authentication and authorization flaws
  • Secrets or credentials in code
  • Insecure deserialization
  • Path traversal
  • SSRF

Performance

  • N+1 queries
  • Unnecessary memory allocations
  • Algorithmic complexity (O(n²) in hot paths)
  • Missing database indexes
  • Unbounded queries or loops
  • Resource leaks

Correctness

  • Edge cases (empty input, null, overflow)
  • Race conditions and concurrency issues
  • Error handling and propagation
  • Off-by-one errors
  • Type safety

Maintainability

  • Naming clarity
  • Single responsibility
  • Duplication
  • Test coverage
  • Documentation for non-obvious logic

Output

markdown
## Code Review: [PR title or file]
### Summary[1-2 sentence overview of the changes and overall quality]
### Critical Issues| # | File | Line | Issue | Severity ||---|------|------|-------|----------|| 1 | [file] | [line] | [description] | 🔴 Critical |
### Suggestions| # | File | Line | Suggestion | Category ||---|------|------|------------|----------|| 1 | [file] | [line] | [description] | Performance |
### What Looks Good- [Positive observations]
### Verdict[Approve / Request Changes / Needs Discussion]

If Connectors Available

If ~~source control is connected:

  • Pull the PR diff automatically from the URL
  • Check CI status and test results

If ~~project tracker is connected:

  • Link findings to related tickets
  • Verify the PR addresses the stated requirements

If ~~knowledge base is connected:

  • Check changes against team coding standards and style guides

Tips

  1. Provide context — "This is a hot path" or "This handles PII" helps me focus.
  2. Specify concerns — "Focus on security" narrows the review.
  3. Include tests — I'll check test coverage and quality too.

来源与署名

来源:anthropics/knowledge-work-plugins位于engineering/skills/code-review提交ae1513e

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 anthropics/knowledge-work-plugins 的技能

Ticket Deflector

anthropics

精选

Reads a forwarded customer email or ticket, pulls order and refund status from a payments connector (PayPal, Square, or Stripe) or Shopify, account history from the CRM, and open tickets from a support desk (Zoho Desk), drafts a tone-matched reply in the owner's writing voice, and can issue a refund through the payments connector with explicit owner approval. With Shopify connected it also runs a proactive order-triage mode that surfaces orders needing attention — unfulfilled past the promised window, payment problems, pending refunds, stuck shipments — and drafts the next action for each before the customer has to ask. Use when the user says "draft a response," "answer this customer," "where's my order," "I want a refund," "check my orders," or "anything about to blow up."

待分类27K今天更新

Tax Season Organizer

anthropics

精选

Prepares tax-season materials for the owner's accountant, not tax advice. US federal tax; a non-US business gets its closed-books packet instead. Two modes: (1) quarterly estimated tax from YTD net income in the ledger (MYOB, NetSuite, QuickBooks, Xero, or Zoho Books); (2) year-end 1099 prep, scanning the ledger, PayPal, and Stripe for contractors paid over USD 600 into a 1099-NEC list with missing W-9 flags. Any tax request routes first to /tax-prep, which confirms the books are closed and reconciled before running this skill. Use this skill directly only when the owner says the period's books are already closed: "books are closed, now do the 1099s," "run the quarterly estimate off the closed numbers," or "just the contractor W-9 list."

待分类27K今天更新

Tax Prep

anthropics

精选

基于已结账的账目准备税务材料:季度预估缴税明细,或年终 1099-NEC 清单与会计师资料包。

Business & Finance27K今天更新

Smb Onboard

anthropics

精选

引导小微企业主完成首次设置:连接工具、运行一次体现价值的配方、记录业务背景并设定每周检查节奏。

Productivity & Workflow27K今天更新

Smb Router

anthropics

精选

将小企业主的需求转接到合适的插件技能或命令,并说明可用功能。

Productivity & Workflow27K今天更新

Month End Prep

anthropics

精选

Reconciles the accounting ledger (MYOB, NetSuite, QuickBooks, Xero, or Zoho Books) against PayPal, Shopify, Square, and Stripe settlements, flags transactions that need attention, suspicious duplicates, and missing receipts, then writes a plain-English P&L narrative and exports a close packet (xlsx + one-page PDF). This is the first link of the /close-month command; a request to close the month or the books routes there, and the command runs this skill before refreshing the forecast and distributing the packet. Use this skill directly only when the owner wants the reconciliation alone, with no forecast refresh and no distribution: "just reconcile, no packet," "what's missing from the books," "flag the duplicates and missing receipts," or "write the P&L narrative for this month."

待分类27K今天更新