ai-code-review
为 DSH 注册 ai_code_review 工具:复用 Node.js 引擎收集 diff、运行测试和覆盖率、分析影响并提供技能包。
tblong2105
@tblong2105
⬇ 1
★ 1
main
安装
dsh plugin --profile web add github:tblong2105/ai-code-review
需要可复现安装时,可在仓库后追加 #commit 固定提交。
为 DSH 注册 ai_code_review 工具:复用 Node.js 引擎收集 diff、运行测试和覆盖率、分析影响并提供技能包。
该插件未提供要点说明,请参考仓库 README。
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/tblong2105/ai-code-review |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 1 |
| 最近推送 | 2026-08-05 |
| 收录日期 | 2026-09-19 |
| 分类 | 开发与运行时 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# @tabilo/ai-code-review
[](LICENSE)
[](package.json)
Reusable, multi-language **AI code-review workflow** for VS Code Copilot, powered by
**Agent Skills**. Run `/ai-review` in Copilot Chat to get a structured, evidence-based
review of your branch/PR — with zero configuration beyond a one-time setup:
```
git diff context → pack routing → pack skills → impact analysis → tests → coverage gate → report
```
The whole workflow (rules, language packs, config, report template) is copied into
your repo as `.ai-code-review/`, so you can **tune it per project** without touching
the package.
---
## ✨ Features
- **6 Agent Skills** installed to `~/.copilot/skills/`:
`/ai-review`, `/ai-review-java`, `/ai-review-react`, `/ai-review-vue`,
`/ai-review-angular`, `/ai-review-help`
- **4 language packs**: `java` (JaCoCo coverage gate) and `react` / `vue` / `angular`
(Istanbul coverage gate)
- **Per-repo payload** `.ai-code-review/` — the workflow, packs, config and report
template live in the repo and can be customized freely
- **Cross-platform git context** — collects diffs with plain Node.js (no PowerShell
dependency), works on Windows, macOS and Linux
- **Mandatory impact analysis** — uses GitNexus MCP, CodeGraph, or falls back to
manual grep to answer *"what breaks if this merges?"*
- **Test + coverage gate** — runs your unit tests and enforces C0/C1 ≥ 80% on
changed code (JaCoCo / Istanbul)
- **Structured report** — severity-classified findings, verdict by exit gate,
Vietnamese or English output (`en` default, `vi` supported)
- **Context integrity** — a single `out/context.md` is the only diff source the
agent reviews; every finding must quote a real `file:line` from it
---
## 📋 Table of Contents
- [Requirements](#requirements)
- [How it works](#how-it-works)
- [Installation & Setup](#installation--setup)
- [Usage](#usage)
- [CLI Reference](#cli-reference)
- [Configuration](#configuration)
- [The Review Workflow](#the-review-workflow)
- [Report & Verdict](#report--verdict)
- [Extending](#extending)
- [Troubleshooting](#troubleshooting)
- [Docs](#docs)
- [License](#license)
---
## Requirements
| Dependency | Version / Notes |
| --- | --- |
| **Node.js** | ≥ 18 (≥ 16 for the package itself, 18+ recommended) |
| **VS Code** | latest, with the **GitHub Copilot Chat** extension (Agent Skills support) |
| **git** | on `PATH` (used for diff collection) |
| **Language toolchain** | `mvn` for Java, `npm`/`node` for frontend packs (needed for tests & coverage) |
---
## How it works
```
┌─ Agent Skills (installed once per machine) ────────────────┐
│ ~/.copilot/skills/ai-review/SKILL.md │ ← /ai-review slash command
│ ~/.copilot/skills/ai-review-java/SKILL.md │ ← force java pack
│ ~/.copilot/skills/ai-review-react|vue|angular/SKILL.md │ ← force frontend pack
│ ~/.copilot/skills/ai-review-help/SKILL.md │ ← cheat sheet
└───────────────────────────────────────────────────────────┘
│ reads / orchestrates
┌─ Repo payload (copied per repo by `setup`) ────────────────┐
│ .ai-code-review/ │
│ config/ai-review.yaml reportLanguage, defaultTarget, activePacks
│ core/workflow.md the mandatory 6-step workflow
│ core/synthesizer.md merging findings + exit gate
│ core/impact-analysis.md GitNexus / CodeGraph / grep strategy
│ core/report-template.md report structure
│ core/pr-comment.md PR comment structure
│ packs// pack.yaml + review skills
│ out/ generated context.md + review-report.md
└───────────────────────────────────────────────────────────┘
```
The **skills** are installed once per machine and describe *how* to review. The
**payload** is copied into every repo and describes *what* to review — routing
rules, priorities, test/coverage commands, thresholds and the report template.
This split lets you customize the review per repository while the package stays
up-to-date centrally.
---
## Installation & Setup
Run once per repository (a few seconds, no interactive prompts):
```bash
# at the repo root you want to review
npx @tabilo/ai-code-review setup
```
`setup` does the following:
1. **Copies the payload** → `/.ai-code-review/` (`core/`, `packs/`, `config/`,
`out/.gitkeep`). Skipped if it already exists (use `--force` to restore
template files — your `out/` reports are never deleted).
2. **Creates `.ai-code-review/out/`** — generated reports live here.
3. **Scans the repo** and auto-activates the matching packs (`java`, `react`,
`vue`, `angular`).
4. **Writes `.ai-code-review/config/ai-review.yaml`** if missing.
5. **Adds `.ai-code-review/` to the repo's `.gitignore`** (idempotent — never
duplicates the entry).
6. **Installs the 6 skills** into `~/.copilot/skills/` (idempotent: identical
files are skipped, changed files are updated).
Then:
1. **Reload the VS Code window** (so Copilot picks up the new skills).
2. Open **Copilot Chat** and type:
```text
/ai-review
```
> 💡 `.ai-code-review/` is often gitignored (added automatically by `setup`). The
> agent always reads it with `includeIgnoredFiles: true`, so this is fine — but
> don't be surprised if the folder doesn't show in your source control view.
### Verify the installation
```bash
npx @tabilo/ai-code-review doctor
```
`doctor` checks the payload, `config/ai-review.yaml`, `out/`, the 6 installed
skills and the activated packs, then prints a summary line telling you exactly
what to run if anything is missing. Exit code is `0` even when things are missing
— read the output.
```bash
npx @tabilo/ai-code-review list
```
`list` shows the shipped packs, packs present in the payload, **active** packs,
and the install state of every skill.
---
## Usage
### Quick start
```text
/ai-review # auto-detect pack, diff vs develop
```
That's it — the agent collects the diff, routes files to the right review area,
runs impact analysis + tests + coverage, and writes
`.ai-code-review/out/review-report.md`.
### Slash commands
| Command | Effect |
| --- | --- |
| `/ai-review` | Auto-detect the pack from changed files |
| `/ai-review-java` | Force the `java` pack |
| `/ai-review-react` | Force the `react` pack |
| `/ai-review-vue` | Force the `vue` pack |
| `/ai-review-angular` | Force the `angular` pack |
| `/ai-review-help` | Show the cheat sheet in chat |
### Options (tokens)
Append space-separated `key:value` tokens after the command (each token is split
on the **first** `:`):
| Token | Values | Default | Meaning |
| --- | --- | --- | --- |
| `target:` | any branch | config `defaultTarget` → `develop` | base branch to diff against (resolves `origin/` first, then local ``) |
| `source:` | any branch | current branch / HEAD | branch (or revision) to review |
| `scope:` | `branch` \| `staged` \| `working` \| `commit:..` | `branch` | what to review |
| `report-lang:` | `en` \| `vi` | config `reportLanguage` → `en` | report language |
| `severity:` | `critical` \| `high` \| `medium` | built-in gate | override the exit-gate severity levels |
| `pack:` | `java` \| `react` \| `vue` \| `angular` | auto-detect | force a specific pack |
**Precedence:** slash token > `.ai-code-review/config/ai-review.yaml` > built-in default.
### Examples
```text
# Basic — review current branch vs develop
/ai-review
# Review current branch vs main
/ai-review target:main
# Review only the staged changes
/ai-review scope:staged
# Review uncommitted working-tree changes
/ai-review scope:working
# Review a commit range
/ai-review scope:commit:abc123..def456
# Vietnamese report
/ai-review report-lang:vi
# Combine options
/ai-review target:main report-lang:vi
# Force the Java pack regardless of detected files
/ai-review-java target:develop
# Force a pack with a token (works from any skill)
/ai-review pack:react scope:staged
```
### Review scopes
| Scope | Reviews |
| --- | --- |
| `branch` | everything on the current branch since the merge-base with the target branch — the default for PR-style reviews |
| `staged` | only what is `git add`-ed in the index |
| `working` | only the uncommitted working-tree changes |
| `commit:..` | a specific commit range (both ends can be SHAs or branch names) |
---
## CLI Reference
All commands run through npx: `npx @tabilo/ai-code-review [options]`.
| Command | Description | Options |
| --- | --- | --- |
| `setup` | Copy the `.ai-code-review/` payload into the repo, gitignore it, and install the Agent Skills | `--dir `, `--force` / `-f` |
| `doctor` | Verify payload, config, packs and skills are in place | `--dir ` |
| `list` | Show shipped/installed/active packs and skill install state | `--dir ` |
| `add ` | Activate a pack (`java` \| `react` \| `vue` \| `angular`) | `--dir `, `--force` / `-f` |
| `context` | Regenerate `.ai-code-review/out/context.md` (the diff source) | `--dir `, `--target `, `--source `, `--scope ` |
| `open-report` | Open the latest report in the default browser | `--dir `, `--file ` |
| `help` | Print the command summary + slash-command tokens | — |
### Command details
**`context`** — the cross-platform diff collector (pure Node.js, no PowerShell).
```bash
npx @tabilo/ai-code-review context
npx @tabilo/ai-code-review context --target main --source my-feature
npx @tabilo/ai-code-review context --scope staged
```
Output sections written to `.ai-code-review/out/context.md`:
- **Git Information** — branch, base, merge-base, changed files, added/removed
lines, CodeGraph/GitNexus index presence
- **Changed Files** — list with per-file stats
- **Diff Stat** — numeric summary
- **Full Diff** — truncated at 4000 lines with a clear marker
You normally don't need to run this yourself — the agent regenerates it
automatically at review time when missing or stale.
**`open-report`** — opens `.ai-code-review/out/review-report.md` (or `--file`) in
the browser, using `start` (Windows), `open` (macOS) or `xdg-open` (Linux).
**`add`** — activate another pack later without re-running full setup:
```bash
npx @tabilo/ai-code-review add react
```
Copies the pack template if not already present, then appends it to `activePacks`
in `.ai-code-review/config/ai-review.yaml`.
---
## Configuration
There are three configuration layers, applied in this order:
```
slash-command tokens > .ai-code-review/config/ai-review.yaml > built-in defaults
```
### 1. Repo config — `.ai-code-review/config/ai-review.yaml`
```yaml
reportLanguage: en # en | vi — report output language
defaultTarget: develop # base branch used when no target: token is given
activePacks: # packs enabled for this repo (auto-detected at setup)
- java
```
The file also embeds (read by the agent, not the CLI) the **severity definitions**
(critical/high/medium/low), the **exit gate** and the **large-diff threshold** —
all editable.
### 2. Pack config — `.ai-code-review/packs//pack.yaml`
```yaml
name: java # pack id
language: java # primary language
routing: # glob → review area
java: ["**/*.java", "**/src/main/java/**"]
logic: ["**/*Service*.java", "**/service/**"]
business: ["**/domain/**", "**/policy/**"]
config: ["**/application*.yml", "**/pom.xml"]
security: ["**/*Security*.java", "**/filter/**"]
priority: [business, security, logic, java, config] # review order
test:
command: "mvn -q test" # run to verify tests
framework: junit5
coverage:
tool: jacoco # jacoco (java) | istanbul (frontend)
command: "mvn test jacoco:report"
reportPath: target/site/jacoco/index.html
c0: 80 # line/statement threshold %
c1: 80 # branch threshold %
scope: changedClasses # what the gate applies to
skills: # skill files under packs//skills/
- java-review
- logic-review
- business-review
- config-review
- security-review
- unit-test-generation
```
Globs are matched against the **repo-relative** path with forward slashes.
### 3. Built-in defaults
| Setting | Default |
| --- | --- |
| Base branch | `develop` |
| Report language | `en` |
| Exit gate | `>=1 critical` **OR** `>=2 high` → *Request changes* |
| Coverage thresholds | C0/C1 ≥ 80% on changed code |
| Large-diff threshold | 30 files / 1500 LOC |
---
## The Review Workflow
When you run `/ai-review`, the agent follows this exact 6-step workflow
(defined in `.ai-code-review/core/workflow.md`, which you can edit):
1. **Collect context** — regenerates `out/context.md` (the single diff source) and
cross-checks it against the GitKraken MCP diff when available.
2. **Route changed files** — each changed file is matched against the active
pack's routing globs; a file matching several areas (e.g. a payment service)
is reviewed for **all** of them, in the pack's declared priority order.
3. **Review with pack skills** — applies the pack's area skills (correctness,
logic, business, config, security). Every finding carries a severity, an exact
`file:line`, a suggestion, a solution and required tests.
4. **Impact analysis (mandatory)** — checks what else breaks: GitNexus MCP
(`mcp_gitnexus_impact`, depth 1→3 on hot paths), CodeGraph
(`codegraph explore ""`), or manual grep as fallback.
5. **Tests & coverage gate** — generates missing unit tests per the pack's skill
(JUnit 5 + Mockito / Vitest / Jest), runs the pack's `test.command`, then runs
the coverage command and checks the changed classes against `c0`/`c1`.
6. **Synthesize** — merges findings (same root cause = one finding), applies the
exit gate, and writes `.ai-code-review/out/review-report.md` (plus fills the
PR-comment template).
### Guardrails (always enforced)
- **No hallucination** — every finding must be traceable to a concrete line in
`context.md`; the agent must say "not sure" instead of inventing.
- **Report honestly** — broken builds, missing dependencies and skipped coverage
are reported in Limitations with real command output.
- **`.ai-code-review/` is read-only** for the agent — reports go **only** in
`.ai-code-review/out/`.
---
## Report & Verdict
The report (`.ai-code-review/out/review-report.md`) follows the template in
`.ai-code-review/core/report-template.md` and ends with a verdict computed by the
**exit gate**:
| Findings | Verdict |
| --- | --- |
| ≥ 1 **critical** OR ≥ 2 **high** | 🔴 **Request changes** |
| Only **medium** / **low** | 🟡 **Approve with comments** |
| None | 🟢 **Approve** |
Severity definitions (editable in `ai-review.yaml`):
- **critical** — data loss, wrong money, security breach (SQLi, auth bypass,
secret leak), or a bug that breaks the main feature. Must be fixed before merge.
- **high** — bug affecting the main flow or many users, clear regression, or an
exploitable security risk.
- **medium** — edge-case bug, missing validation, code smell, or an interaction
issue between two modules.
- **low** — style, naming, docs, missing tests, best practice not applied.
### Report language
Set `reportLanguage: vi` in `ai-review.yaml`, or pass `report-lang:vi` per review,
to get the report (and PR comment) in Vietnamese. Technical terms stay in English:
file/class/method names, paths, CLI commands, severity labels, C0/C1, JaCoCo,
GitNexus, CodeGraph.
---
## Extending
The whole workflow lives in the repo payload, so it's customizable per repo:
- **Add a new language pack** — create `.ai-code-review/packs//pack.yaml`
plus skills under `packs//skills/*.md`; optionally add a forcing slash
command. See [Extending](docs/extending.md).
- **Tune the workflow** — edit `.ai-code-review/core/workflow.md`,
`synthesizer.md`, `impact-analysis.md`, `report-template.md` or
`config/ai-review.yaml`. `setup --force` restores template files (never your
`out/` reports), so keep customizations in the payload after setup.
- **Customize the skills** — the installed `~/.copilot/skills/*/SKILL.md` files are
updated by `setup` only when the content differs from the package template;
edit them directly for manual control.
---
## Troubleshooting
| Symptom | Fix |
| --- | --- |
| `/ai-review` says the payload is missing | Run `npx @tabilo/ai-code-review setup` at the repo root, **reload VS Code**, try again |
| Slash command not recognized | Confirm the skills exist: `npx @tabilo/ai-code-review doctor`, then reload VS Code |
| Wrong base branch used | Pass `target:` or change `defaultTarget` in `.ai-code-review/config/ai-review.yaml` |
| Report in the wrong language | Pass `report-lang:vi` (or `en`) or set `reportLanguage` in the config |
| Pack not reviewing my files | Run `npx @tabilo/ai-code-review list` to see active packs; `add` the missing one |
| `.ai-code-review/` not visible in the editor | It's gitignored (added by `setup`) — that's expected; the agent reads it with `includeIgnoredFiles: true` |
| Coverage not running | Check `pack.yaml` → `coverage.command` matches your toolchain (`mvn`/`npm` on PATH) |
| Agent reports "file not found" inside `.ai-code-review/` | Ask it to re-read with `includeIgnoredFiles: true` (or report the issue) |
---
## Docs
- [Package docs](docs/README.md)
- [Commands](docs/commands.md)
- [Configuration](docs/configuration.md)
- [Extending](docs/extending.md)
## License
MIT
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。