Backend Code Review

作者 langgenius2b65f0e89309無授權條款157K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Use only when the user explicitly requests a review or audit of backend code under `api/`. Supports pending-change, file-focused, and pasted-diff reviews. Do not use for implementation-only requests, diagnosis without review intent, frontend code, or backend code outside `api/`.

AI 產生的概覽

審查 api/ 下的後端程式碼以找出具體缺陷,並依變更類型導向內建規則包。

功能
針對 api/ 下指定的後端範圍(待提交變更、特定檔案或貼上的 diff)進行審查,僅回報與可觀察故障、違反的契約、安全邊界、資料完整性風險或已證實的維護問題相關的發現。當 diff 相符時,審查會導向內建的資料庫結構、架構、儲存庫與 SQLAlchemy 規則包。發現依 P0 到 P3 的嚴重程度排序,並附上檔案與行號參照、影響和具體的修正方向。
適用情境
當使用者明確要求審查或稽核 api/ 下的後端程式碼時使用。不適用於僅要求實作、無審查意圖的診斷、前端程式碼或 api/ 之外的後端程式碼。
執行需求
無指令碼;僅包含指示與參考規則包。它依賴最近的 AGENTS.md 取得套件資訊與命令,並可能在本地程式碼與契約無法確定框架或函式庫行為時查閱目前官方文件。

Backend Code Review

Review the requested scope for concrete, reproducible defects. The nearest AGENTS.md owns package facts and commands; this skill owns the review workflow and routes to its bundled rule packs.

Evidence First

  1. Establish the requested review scope and inspect the relevant diff or files.
  2. Read the changed lines, their behavior owner, nearby tests, and local docstrings or comments that define contracts.
  3. Trace callers, persistence boundaries, authorization, generated schemas, or external I/O only when they decide correctness.
  4. Report only findings tied to an observable failure, violated contract, security boundary, data integrity risk, or demonstrated maintenance problem.

Rule Routing

Read only the packs matched by the diff:

  • Models or migrations: references/db-schema-rule.md [blocked]
  • Controller, service, core/domain, library, or model dependency direction: references/architecture-rule.md [blocked]
  • Table access outside an established repository boundary: references/repositories-rule.md [blocked]
  • SQLAlchemy sessions, queries, transactions, CRUD, concurrency, or raw SQL: references/sqlalchemy-rule.md [blocked]

When no pack applies, review correctness, security, behavior changes, and test evidence directly. Check current official documentation only when local code and contracts do not settle framework or library behavior.

Severity And Output

  • P0: security or privacy exposure, data loss, or a production-wide outage.
  • P1: user-visible regression, broken authorization or tenant isolation, invalid public contract, or failed primary workflow.
  • P2: concrete correctness, performance, maintainability, or test defect likely to cause incorrect behavior.
  • P3: minor actionable cleanup; omit unless the user requested a thorough audit.

Lead with findings ordered by severity. Include a tight file and line reference, the failing contract or reproduction path, impact, and a concrete fix direction. If there are no findings, say No issues found. and state any material verification gap. Do not add praise sections, speculative risks, or an unsolicited offer to implement fixes.

來源與署名

來源:langgenius/dify位於.agents/skills/backend-code-review提交2b65f0e

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架