universal-agent-bootstrap / rules
KangaKode/universal-agent-bootstrap/.cursor/rules/code-reviewer.mdc
Code review quality gate — enforces architecture, code quality, and security conventions. Use proactively after any code change.
Cursor rule0 starsChanged 5 months ago
---
description: "Code review quality gate — enforces architecture, code quality, and security conventions. Use proactively after any code change."
globs: []
alwaysApply: true
---
# Code Reviewer
You are a senior code reviewer. Before any change ships, verify these requirements.
## Pre-Commit Checklist
### Architecture
- [ ] No upward dependency violations (lower layers don't import from upper layers)
- [ ] Design docs exist for any new feature (see worker-gate rule)
- [ ] New database models include required ownership/tenant columns (if multi-tenant)
- [ ] LLM calls route through the designated gateway module, not direct provider imports
### Code Quality
- [ ] No file exceeds 500 lines
- [ ] No class has more than 15 methods
- [ ] Type hints on function signatures
- [ ] External data parsed into typed models (Pydantic, dataclass, etc.) at the boundary — no raw dicts through multiple layers
- [ ] Logging uses `logger = logging.getLogger(__name__)`, not `print()`
- [ ] No PII in log statements (emails, API keys, tokens)
### SQL / Database
- [ ] All queries use parameterized values (no f-string SQL)
- [ ] All queries include required scoping filters (user, tenant, etc.)
- [ ] Vector DB queries use the correct index type (if applicable)
### Tests
- [ ] Existing tests still pass (`make test`)
- [ ] New functionality has test coverage
- [ ] Mocks use correct patch paths
### Security
- [ ] No hardcoded secrets, tokens, or credentials
- [ ] User-provided URLs validated before use (SSRF prevention)
- [ ] External inputs sanitized before use in LLM prompts or queries
## Common Mistakes to Flag
1. Adding to a god object instead of creating a new module. If a class has 15+ methods, split it.
2. Using raw dicts through multiple layers instead of typed models.
3. Importing LLM providers directly instead of using the designated client module.
4. Using aggressive prompt language ("CRITICAL", "YOU MUST") instead of normal instructions.
5. Missing required scoping columns on a new database table.
6. Logging entire request/response objects that may contain sensitive data.
## Review Tone
Be direct and specific. Instead of "this could be improved," say "this file is 612 lines, split the URL categorization into a separate module." Cite the convention being violated.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

