AI Agent Hub
Back to skills
Code Review Assistant icon

Code Review Assistant

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please install @user_8513044c/codereview2skill following https://skillhub.cn/install/skillhub.md.

About this skill

Risk-First Review Instead of a Change Summary

Many pull-request reviews drift into restating the diff, naming style preferences, or saying that the code looks generally fine. cr skill narrows the goal to a practical engineering question: will this change cause problems? It is aimed at pre-merge review, focusing on logic errors, missing edge cases, security and data risks, performance hazards, maintainability issues, and whether tests cover the main path, error paths, and regressions.

Evidence-Driven Review Flow

The skill first clarifies scope: whether the target is a PR, git diff, a single file, or a code fragment; whether the change affects backend, frontend, scripts, configuration, or tests; and whether the priority is correctness, security, performance, or maintainability. It then builds a minimal context: what problem the change is trying to solve, the implementation path, inputs and outputs, side effects, key dependencies, and callers.

The main output is structured:
- Findings: explain location, issue, impact, and why the evidence makes it a real problem rather than a preference.
- Open Questions / Assumptions: list insufficient evidence, unverified paths, and runtime dependencies.
- Brief Summary: add context and remaining risk without replacing the findings.

It scans across dimensions such as correctness, regression, data safety, concurrency and timing, performance, maintainability, and test coverage. Issues are classified as severe, moderate, or minor. When no clear defect is found, it states that directly and notes boundaries that still need verification.

Fit and Limits

This skill fits engineering review where the goal is risk judgment before merging. It is not ideal for diff-only summaries, pure translation, style-only refactoring, or tasks without code context. Because the guidance emphasizes evidence-based conclusions, missing call chains, configuration, permission models, or test coverage should be treated as follow-up validation items.

Use Cases

  • Before merging a backend PR, review permission checks, tenant filtering, and rollback behavior to decide readiness.
  • Audit frontend changes for empty states, failure states, duplicate submissions, and effect dependencies that may regress.
  • Scan a git diff for concurrency, idempotency, and performance issues such as races, repeated queries, and blocking paths.
  • Check whether tests cover main flows, error paths, and edge values, then list regression risks not yet locked down.

Best For

  • Backend engineers responsible for merge gates need to judge PR risks in permissions, data, and rollback.
  • Frontend maintainers of components or pages need to surface stale state, missing dependencies, and duplicate submissions.
  • Engineers taking over legacy modules need to locate logic errors, missed edge cases, and test gaps quickly.
  • Engineers reviewing release scripts and configs need to confirm environment failure, idempotency, and accidental production impact.