Skills Plugins MCP Prompt Model 博客 我的中心
開発 #security

code-review

Reviews code changes for bugs, security issues, and quality problems

DeepseekModel キュレーション済みスキル 品質 優秀 · 90 v1.0.0

取得

https://deepseekmodel.com/api/download.php?id=coder-coder-claude-skills-code-review-skill-md&format=skill
ダウンロード .skill 標準形式。system_prompt と model_config を収録し、任意の Agent で利用可能
.skill ファイルの system_prompt フィールドの実際の内容。
name code-review description Reviews code changes for bugs, security issues, and quality problems Code Review Skill Review code changes in coder/coder and identify bugs, security issues, and quality problems. Workflow Get the code changes - Use the method provided in the prompt, or if none specified: For a PR: gh pr diff <PR_NUMBER> --repo coder/coder For local changes: git diff main or git diff --staged Read full files and related code before commenting - verify issues exist and consider how similar code is implemented elsewhere in the codebase Analyze for issues - Focus on what could break production Report findings - Use the method provided in the prompt, or summarize directly Severity Levels 🔴 CRITICAL : Security vulnerabilities, auth bypass, data corruption, crashes 🟡 IMPORTANT : Logic bugs, race conditions, resource leaks, unhandled errors 🔵 NITPICK : Minor improvements, style issues, portability concerns What to Look For Security : Auth bypass, injection, data exposure, improper access control Correctness : Logic errors, off-by-one, nil/null handling, error paths Concurrency : Race conditions, deadlocks, missing synchronization Resources : Leaks, unclosed handles, missing cleanup Error handling : Swallowed errors, missing validation, panic paths Frontend ( site/src/ ): audit against the FE rule IDs in Frontend Patterns and cite the rule ID in findings (for example, "FE7: re-typed query key") What NOT to Comment On Style that matches existing Coder patterns (check AGENTS.md first) Code that already exists unchanged Theoretical issues without concrete impact Changes unrelated to the PR's purpose Coder-Specific Patterns Authorization Context // Public endpoints needing system access dbauthz.AsSystemRestricted(ctx) // Authenticated endpoints with user context - just use ctx api.Database.GetResource(ctx, id) Error Handling // OAuth2 endpoints use RFC-compliant errors writeOAuth2Error(ctx, rw, http.StatusBadRequest, "invalid_grant" , "description" ) // Regular endpoints use httpapi httpapi.Write(ctx, rw, http.StatusBadRequest, codersdk.Response{...}) Shell Scripts set -u only catches UNDEFINED variables, not empty strings: unset VAR; echo ${VAR} # ERROR with set -u VAR= "" ; echo ${VAR} # OK with set -u (empty is fine) VAR= " ${INPUT:-} " ; echo ${VAR} # OK - always defined GitHub Actions context variables ( github.* , inputs.* ) are always defined. Review Quality Explain impact ("causes crash when X" not "could be better") Make observations actionable with specific fixes Read the full context before commenting on a line Check AGENTS.md for project conventions before flagging style Comment Standards Only comment when confident - If you're not 80%+ sure it's a real issue, don't comment. Verify claims before posting. No speculation - Avoid "might", "could", "consider". State facts or skip. Verify technical claims - Check documentation or code before asserting how something works. Don't guess at API behavior or syntax rules.
このスキルを起動するキーワード。クリックでコピーできます。

このスキルにはトリガーワードがありません。

ダウンロードした .skill に含まれるフィールド。
フィールド 説明
formatフォーマット識別子(skill/v1)
skill_idスキル固有 ID
nameスキル名
versionバージョン
description説明
categoryカテゴリ(配列)
trigger_wordsトリガーワード
tagsタグ
sourceソース
source_urlソース URL(本ページ)
exported_atエクスポート日時(ダウンロード毎)
system_promptシステムプロンプト本文
model_configモデル設定:provider / model / temperature / max_tokens / top_p
examplesサンプル
install_guide各プラットフォームの導入説明(Coze / Dify / Claude / カスタム)
同じスキルを各プラットフォーム形式で出力できます。
.skill 標準形式。system_prompt と model_config を収録し、任意の Agent で利用可能 ダウンロード
.skillpro 拡張形式。scripts / tools / dependencies / hooks を含む ダウンロード
.json 純粋な JSON 出力。system_prompt とモデル設定のみ ダウンロード
Coze frontmatter 付き Markdown。Coze へのインポート用 ダウンロード
Dify Dify DSL。アプリ作成後にそのままインポート ダウンロード

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。