Backend Code Review

作者 langgenius2b65f0e89309无许可证157K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Use only when the user explicitly requests a review or audit of backend code under `api/`. Supports pending-change, file-focused, and pasted-diff reviews. Do not use for implementation-only requests, diagnosis without review intent, frontend code, or backend code outside `api/`.

AI 生成的概览

审查 api/ 下的后端代码以发现具体缺陷,并按变更类型路由到内置规则包。

功能
针对 api/ 下指定的后端范围(待提交变更、特定文件或粘贴的 diff)进行审查,仅报告与可观察故障、违反的契约、安全边界、数据完整性风险或已证实的维护问题相关的发现。当 diff 匹配时,审查会路由到内置的数据库模式、架构、仓储和 SQLAlchemy 规则包。发现按 P0 到 P3 的严重程度排序,并附文件与行号引用、影响和具体的修复方向。
适用场景
当用户明确要求审查或审计 api/ 下的后端代码时使用。不适用于仅要求实现、无审查意图的诊断、前端代码或 api/ 之外的后端代码。
运行要求
无脚本;仅包含指令和参考规则包。它依赖最近的 AGENTS.md 获取包信息和命令,并可能在本地代码与契约无法确定框架或库行为时查阅当前官方文档。

Backend Code Review

Review the requested scope for concrete, reproducible defects. The nearest AGENTS.md owns package facts and commands; this skill owns the review workflow and routes to its bundled rule packs.

Evidence First

  1. Establish the requested review scope and inspect the relevant diff or files.
  2. Read the changed lines, their behavior owner, nearby tests, and local docstrings or comments that define contracts.
  3. Trace callers, persistence boundaries, authorization, generated schemas, or external I/O only when they decide correctness.
  4. Report only findings tied to an observable failure, violated contract, security boundary, data integrity risk, or demonstrated maintenance problem.

Rule Routing

Read only the packs matched by the diff:

  • Models or migrations: references/db-schema-rule.md [blocked]
  • Controller, service, core/domain, library, or model dependency direction: references/architecture-rule.md [blocked]
  • Table access outside an established repository boundary: references/repositories-rule.md [blocked]
  • SQLAlchemy sessions, queries, transactions, CRUD, concurrency, or raw SQL: references/sqlalchemy-rule.md [blocked]

When no pack applies, review correctness, security, behavior changes, and test evidence directly. Check current official documentation only when local code and contracts do not settle framework or library behavior.

Severity And Output

  • P0: security or privacy exposure, data loss, or a production-wide outage.
  • P1: user-visible regression, broken authorization or tenant isolation, invalid public contract, or failed primary workflow.
  • P2: concrete correctness, performance, maintainability, or test defect likely to cause incorrect behavior.
  • P3: minor actionable cleanup; omit unless the user requested a thorough audit.

Lead with findings ordered by severity. Include a tight file and line reference, the failing contract or reproduction path, impact, and a concrete fix direction. If there are no findings, say No issues found. and state any material verification gap. Do not add praise sections, speculative risks, or an unsolicited offer to implement fixes.

来源与署名

来源:langgenius/dify位于.agents/skills/backend-code-review提交2b65f0e

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架