Code Review Assistant
Paste the following prompt into your AI chat to install this skill:
Please install @user_8513044c/codereview2skill following https://skillhub.cn/install/skillhub.md.
About this skill
Risk-First Review Instead of a Change Summary
Many pull-request reviews drift into restating the diff, naming style preferences, or saying that the code looks generally fine. cr skill narrows the goal to a practical engineering question: will this change cause problems? It is aimed at pre-merge review, focusing on logic errors, missing edge cases, security and data risks, performance hazards, maintainability issues, and whether tests cover the main path, error paths, and regressions.
Evidence-Driven Review Flow
The skill first clarifies scope: whether the target is a PR, git diff, a single file, or a code fragment; whether the change affects backend, frontend, scripts, configuration, or tests; and whether the priority is correctness, security, performance, or maintainability. It then builds a minimal context: what problem the change is trying to solve, the implementation path, inputs and outputs, side effects, key dependencies, and callers.
The main output is structured:
- Findings: explain location, issue, impact, and why the evidence makes it a real problem rather than a preference.
- Open Questions / Assumptions: list insufficient evidence, unverified paths, and runtime dependencies.
- Brief Summary: add context and remaining risk without replacing the findings.
It scans across dimensions such as correctness, regression, data safety, concurrency and timing, performance, maintainability, and test coverage. Issues are classified as severe, moderate, or minor. When no clear defect is found, it states that directly and notes boundaries that still need verification.
Fit and Limits
This skill fits engineering review where the goal is risk judgment before merging. It is not ideal for diff-only summaries, pure translation, style-only refactoring, or tasks without code context. Because the guidance emphasizes evidence-based conclusions, missing call chains, configuration, permission models, or test coverage should be treated as follow-up validation items.
Use Cases
- Before merging a backend PR, review permission checks, tenant filtering, and rollback behavior to decide readiness.
- Audit frontend changes for empty states, failure states, duplicate submissions, and effect dependencies that may regress.
- Scan a git diff for concurrency, idempotency, and performance issues such as races, repeated queries, and blocking paths.
- Check whether tests cover main flows, error paths, and edge values, then list regression risks not yet locked down.
Best For
- Backend engineers responsible for merge gates need to judge PR risks in permissions, data, and rollback.
- Frontend maintainers of components or pages need to surface stale state, missing dependencies, and duplicate submissions.
- Engineers taking over legacy modules need to locate logic errors, missed edge cases, and test gaps quickly.
- Engineers reviewing release scripts and configs need to confirm environment failure, idempotency, and accidental production impact.
Related Skills
Automatically indexes Gradle-cached AAR/JAR dependency classes and returns library coordinates, versions, and public APIs by fully qualified name, using only the Python standard library.
Codifies AMT and YourMT3 training conventions, script patterns, hyperparameters, precision, checkpoints, and NaN safeguards.
Retrieve relevant chunks from a customer-managed PKM dataset by dataset_id and return concise, source-annotated answers.
Convert PRDs, user stories, or functional specs into prioritized test-point checklists covering functional, business-rule, boundary, exception, and non-functional dimensions.