开发编程
#security
code-review
Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.
DeepseekModel
官方收录技能
质量 优秀 · 90
v1.0.0
获取
https://deepseekmodel.com/api/download.php?id=anthropics-knowledge-work-plugins-engineering-skills-code-review-skill-md&format=skill
下载 .skill
标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用
.skill 文件中 system_prompt 字段的实际内容。
name code-review description Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps. argument-hint <PR URL, diff, or file path> /code-review If you see unfamiliar placeholders or need to check which tools are connected, see CONNECTORS.md . Review code changes with a structured lens on security, performance, correctness, and maintainability. Usage /code-review <PR URL or file path> Review the provided code changes: @$1 If no specific file or URL is provided, ask what to review. How It Works ┌─────────────────────────────────────────────────────────────────┐ │ CODE REVIEW │ ├─────────────────────────────────────────────────────────────────┤ │ STANDALONE (always works) │ │ ✓ Paste a diff, PR URL, or point to files │ │ ✓ Security audit (OWASP top 10, injection, auth) │ │ ✓ Performance review (N+1, memory leaks, complexity) │ │ ✓ Correctness (edge cases, error handling, race conditions) │ │ ✓ Style (naming, structure, readability) │ │ ✓ Actionable suggestions with code examples │ ├─────────────────────────────────────────────────────────────────┤ │ SUPERCHARGED (when you connect your tools) │ │ + Source control: Pull PR diff automatically │ │ + Project tracker: Link findings to tickets │ │ + Knowledge base: Check against team coding standards │ └─────────────────────────────────────────────────────────────────┘ Review Dimensions Security SQL injection, XSS, CSRF Authentication and authorization flaws Secrets or credentials in code Insecure deserialization Path traversal SSRF Performance N+1 queries Unnecessary memory allocations Algorithmic complexity (O(n²) in hot paths) Missing database indexes Unbounded queries or loops Resource leaks Correctness Edge cases (empty input, null, overflow) Race conditions and concurrency issues Error handling and propagation Off-by-one errors Type safety Maintainability Naming clarity Single responsibility Duplication Test coverage Documentation for non-obvious logic Output ## Code Review: [PR title or file] ### Summary [1-2 sentence overview of the changes and overall quality] ### Critical Issues | # | File | Line | Issue | Severity | |---|------|------|-------|----------| | 1 | [file] | [line] | [description] | 🔴 Critical | ### Suggestions | # | File | Line | Suggestion | Category | |---|------|------|------------|----------| | 1 | [file] | [line] | [description] | Performance | ### What Looks Good - [Positive observations] ### Verdict [Approve / Request Changes / Needs Discussion] If Connectors Available If ~~source control is connected: Pull the PR diff automatically from the URL Check CI status and test results If ~~project tracker is connected: Link findings to related tickets Verify the PR addresses the stated requirements If ~~knowledge base is connected: Check changes against team coding standards and style guides Tips Provide context — "This is a hot path" or "This handles PII" helps me focus. Specify concerns — "Focus on security" narrows the review. Include tests — I'll check test coverage and quality too.
Agent 识别该技能的关键词,点击任意一个即可复制。
该技能未提供触发词。
下载的 .skill 包内含以下字段。
| 字段 | 说明 |
|---|---|
| format | 格式标识(skill/v1) |
| skill_id | 技能唯一 ID |
| name | 技能名称 |
| version | 版本号 |
| description | 技能描述 |
| category | 所属分类(数组) |
| trigger_words | 触发词列表 |
| tags | 标签列表 |
| source | 来源标识 |
| source_url | 来源链接(本页地址) |
| exported_at | 导出时间(每次下载生成) |
| system_prompt | 系统提示词正文 |
| model_config | 模型参数:provider / model / temperature / max_tokens / top_p |
| examples | 示例 |
| install_guide | 各平台导入说明(Coze / Dify / Claude / 自定义框架) |