Code Review

codewithmukesh/dotnet-claude-kit/skills/code-review

作者 codewithmukesh23300897f4d1无许可证754 个星标收录于 2026年10月8日更新于 2026年10月8日仓库2个月前更新

MCP-powered multi-dimensional code review for .NET projects. Uses Roslyn analysis tools for antipatterns, diagnostics, references, and dependency graphs combined with structured manual review. Prioritizes effort with blast-radius scoring — data access, security, concurrency, and integration boundaries before style — and produces severity-categorized findings with actionable fixes. Use when: "review", "code review", "PR review", "review this", "review my code", "check code quality", "review changes", "what should I review", "review priorities", "blast radius", "critical path".

AI 生成的概览

使用 Roslyn MCP 分析与人工审查对 .NET 代码变更进行评审,优先处理高风险区域并按严重程度归类问题。

功能
结合 Roslyn MCP 分析(反模式、诊断、引用、依赖图)与结构化人工审查,对 .NET 项目进行多维度代码评审。它按影响范围(blast radius)为每处变更评分以确定审查深度,然后检查数据访问、安全、并发、集成边界、正确性与测试覆盖。最终产出 Markdown 评审报告,包含摘要、严重/警告/建议三级问题、架构合规性、测试覆盖说明以及值得肯定的部分。
适用场景
适用于合并拉取请求之前、重大重构之后检查回归或设计偏移、在大型变更中决定审查重点,以及评估不熟悉的代码。该技能面向 .NET 代码库。
运行要求
需要 .NET 项目,并可使用 Roslyn MCP 分析工具(detect_antipatterns、get_diagnostics、find_references、get_dependency_graph、get_project_graph、detect_circular_dependencies),以及用于生成差异的 git。该技能不附带脚本,仅为指令。

/code-review — MCP-Powered Code Review

What

Performs a multi-dimensional code review combining Roslyn MCP analysis with structured manual review. Effort follows the 80/20 rule: the 20% of code that causes 80% of incidents (data access, security, concurrency, integration boundaries) gets thorough review; style and formatting are left to tooling.

Review dimensions: Correctness (logic, edge cases, null handling, async pitfalls), Security (auth gaps, injection, secrets, CORS), Performance (N+1, allocations, missing cancellation), Architecture compliance (layer violations, boundary breaches), Test coverage (behavior tests for changed types).

When

  • "Review this", "code review", "PR review", before merging a pull request
  • After a major refactor to verify no regressions or design drift
  • "What should I review?" — deciding where review effort goes on a large change
  • Onboarding to unfamiliar code and wanting a quality assessment

How

Step 1: Scope and Score Blast Radius

Identify changed files (git diff main...HEAD, specified files, or module). Score each change to set review depth — blast radius determines depth, not line count. A one-line middleware change outranks a 300-line rename.

Blast RadiusExamplesDepth
CriticalMiddleware, auth, DB migrations, shared kernel, CI/CDThorough — every code path
HighPublic API changes, message consumers, EF configuration, new moduleFocused — consumers + behavior
MediumNew feature following existing patterns, bug fix, new endpointStandard — checklist pass
LowDocs, formatting, renames, logging statementsGlance — build + tests pass

Step 2: MCP Analysis (before reading any file)

detect_antipatterns(projectFilter: "affected-project")   → async void, DateTime.Now, new HttpClient(), broad catchget_diagnostics(scope: "project", path: "affected-project") → new warnings, nullability issues

Distinguish newly introduced findings from pre-existing ones — focus on new.

Step 3: Blast Radius Verification

For each modified public API:

find_references(symbolName: "ModifiedType")              → count consumers; high count = high riskget_dependency_graph(symbolName: "ModifiedMethod", depth: 2) → ripple effects

Check whether callers handle changed return types and new error cases.

Step 4: Architecture Compliance

Verify dependency direction (Domain → nothing; Infrastructure → Application → Domain) via get_project_graph and detect_circular_dependencies. Per architecture: VSA features don't cross-reference; Clean Architecture domain has zero project references; Modular Monolith modules communicate only via integration events — find_references on a module's DbContext should resolve only inside that module.

Step 5: Manual Review — Priority Order

Review what tools can't catch, highest-risk areas first:

PriorityAreaCheck
1Data accessN+1 (missing Include/projection), raw SQL with user input, missing CancellationToken
2SecurityEvery endpoint has explicit [Authorize]/[AllowAnonymous], input validated, no secrets in code, no PII in logs
3ConcurrencyToken propagated end-to-end, no .Result/.Wait(), thread-safe shared state
4IntegrationRetry/timeout on external calls, consumer idempotency, no swallowed exceptions
5CorrectnessBusiness logic, edge cases (empty/null/concurrent), entities mapped to DTOs at the boundary
6TestsBehavior tested (not implementation); happy path + main error case covered
—Style/namingMention only after the above; formatters and analyzers own this

Step 6: Produce the Review

Every finding states what's wrong, why it matters, and how to fix it. Never bury a security bug under naming nits.

markdown
## Code Review: [Scope]
### Summary[1-3 sentences: scope, risk level, recommendation]
### Critical (must fix before merge)- **[Title]** — [file:line] [What's wrong. Why it matters. How to fix.]
### Warnings (should fix, creates tech debt)- **[Title]** — [file:line] [...]
### Suggestions (nice to have)- **[Title]** — [file:line] [...]
### Architecture Compliance[PASS/WARN with boundary-violation notes]
### Test Coverage[Which changed types have tests; specific scenarios to add]
### What's Good- [Always include — reinforce good patterns]

Quick review (1-2 files, low blast radius): run detect_antipatterns + get_diagnostics, read for correctness, output Summary + Issues + What's Good.

Example

User: /code-review the changes in this PR
Claude: 7 changed files across 3 projects. CreateOrder touches data accessand a public endpoint — High blast radius. Running MCP analysis...
## Code Review: Order Processing Feature
### SummaryAdds CreateOrder/GetOrder endpoints with EF Core persistence. Well-structuredVSA feature. Two issues need attention before merge.
### Critical (must fix before merge)- **Missing CancellationToken propagation** — CreateOrder.cs:38  SaveChangesAsync() called without the token. Client disconnects keep  burning server resources. Pass `ct` from the handler parameter.
### Warnings (should fix, creates tech debt)- **N+1 query in GetOrder** — GetOrder.cs:25  Order loaded without `.Include(o => o.Items)`; one lazy load per item  during serialization. Eager-load or use a projection.
### Suggestions (nice to have)- **Seal the handler** — CreateOrderHandler.cs:10  Not designed for inheritance; `sealed` enables devirtualization.
### Architecture CompliancePASS — all changes within Features/Orders/, no layer violations.
### Test CoverageHappy path covered. Add tests for validation failure and not-found.
### What's Good- Clean command/query separation; FluentValidation covers edge cases- Response DTOs are records, no entity leaks

Related

  • /de-sloppify — Cleanup pass for the style/formatting issues review skips
  • /verify — Automated verification pipeline (complements manual review)
  • /health-check — Broader project health assessment beyond a single PR

来源与署名

来源:codewithmukesh/dotnet-claude-kit位于skills/code-review提交2330089

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 codewithmukesh/dotnet-claude-kit 的技能

Wrap Up

codewithmukesh

在会话结束时把已完成工作、待办任务与经验写入交接文件,并在会话开始时重新载入。

Productivity & Workflow7542个月前更新

Workflow Mastery

codewithmukesh

Claude Code workflow mastery for .NET developers. Covers parallel execution with git worktrees, plan mode strategy, verification loops, auto-formatting hooks, permission setup for dotnet CLI, prompting techniques, subagent patterns, and context discipline — token budget management, MCP-first navigation, lazy loading, and subagent isolation — all adapted for the .NET ecosystem. Load this skill when setting up Claude Code for a .NET project, optimizing workflows, running parallel sessions, when context is running low or sessions feel sluggish, when exploring a large codebase efficiently, or when the user mentions "productivity", "workflow", "parallel", "worktree", "plan mode", "permissions", "hooks", "10x", "setup Claude Code", "speed up development", "context", "tokens", "budget", "running out of context", "too many files", or "large codebase". Inspired by tips from Boris Cherny (creator of Claude Code) and the Anthropic team.

待分类7542个月前更新

Vertical Slice

codewithmukesh

指导 .NET 开发者采用垂直切片架构组织应用,涵盖功能文件夹、端点分组与处理程序模式。

Software Development7542个月前更新

Testing

codewithmukesh

Testing strategy for .NET 10 applications. Covers xUnit v3, WebApplicationFactory for integration tests, Testcontainers for real database testing, Verify for snapshot testing, and the AAA pattern. Load this skill when writing tests, setting up test infrastructure, reviewing test coverage, or when the user mentions "test", "xUnit", "WebApplicationFactory", "Testcontainers", "integration test", "unit test", "bUnit", "snapshot test", "Verify", "test coverage", "AAA pattern", "WireMock", or "FakeTimeProvider".

待分类7542个月前更新

Tdd

codewithmukesh

Guided test-driven development workflow for .NET 10 using xUnit v3, WebApplicationFactory, Testcontainers, and Verify snapshots. Follows the strict red-green-refactor cycle. Use when: "TDD", "test-driven", "let's TDD this", "red green refactor", "write the test first", or when building a feature with clear acceptance criteria.

待分类7542个月前更新

Spec

codewithmukesh

通过结构化提问,把模糊的功能想法转化为双方确认并持久化的规格说明文件。

Productivity & Workflow7542个月前更新