代码审查

安全 社区
解读按原文结构重写,命令、链接、术语均保留;右侧可核对作者原始 SKILL.md

方法与流程

  • Workflow:Identify the review target, user constraints, and whether fixes are requested. Inspect the diff first, then inspect surrounding code needed to understand each changed path. Map changed behavior to callers, state, errors, permissions, data flow, and tests.

适用与边界

  • 当前原文没有单列适用场景。
  • Validation:Run the narrowest useful checks for the reviewed area. Prefer existing project commands from package.json, Makefile, CI config, README, or AGENTS.md. Common examples: If validation is expensive, unavailable, or unrelated to the change, state what was skipped…

原文中的明确线索

  • 要点:「This skill is for reviewing code.」、「- Treat review findings as hypotheses until verified against the real code path.」、「Choose the smallest target that matches the user's request.」、「Fetch remote refs only when needed for an accurate branch/PR review.」、「1. Identify the review target, user constraints, and whether fixes are requested.」、「- Correctness: logic errors, broken invariants, off-by-one issues, bad assumptions, incomplete state updates.」、「Run the narrowest useful checks for the reviewed area.」、「If validation is expensive, unavailable, or unrelated to the change, state what was skipped and why.」
  • 文件与命令package.jsonMakefileAGENTS.mdpath:line

流狐整理:以上内容来自当前 SKILL.md 的章节与原词;未补写作者没有声明的工具、兼容性或能力。

流狐档案 作者与许可取自来源;运行、权限和网络为流狐检测或估算
流狐分类
安全
作者声明 Agent
未找到明确声明;不据此推断已兼容或已测试
静态检查
88 / 100 · 启发式扫描,不代表运行安全
作者 / 版本 / 许可
@tomevault-io · 未声明 license
流狐 Token 估算
低消耗
流狐接入估算
即装即用
是否需要外部 API Key
未发现要求
检测到的系统要求
macOS · Linux · Windows
底层运行要求
未声明
检测到的文件与系统行为
  • 只读
检测到的网络行为
允许外网请求
安装命令数
无(仅作为资料)

档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。

需要注意: 未限定 allowed-tools,默认拥有全部工具权限。

输出预览 code-review-3ea9c5bbca.preview
作者没有在当前 SKILL.md 中定义固定输出样例。

讨论

基于 GitHub Discussions。登录 GitHub 即可参与讨论、点赞、订阅更新。