code-review
suxiao1824308603/Qoder-devtools-skills/skills/code-review/SKILL.md
Review code for correctness, security, performance, and maintainability. Use when reviewing pull requests, examining code changes, or when the user asks for a code review.
Skill3 starsChanged 7 months ago
--- name: code-review description: Review code for correctness, security, performance, and maintainability. Use when reviewing pull requests, examining code changes, or when the user asks for a code review. --- # Code Review Systematic code review following industry best practices. ## Review Checklist Copy and track progress: ``` Review Progress: - [ ] Step 1: Understand context - [ ] Step 2: Check correctness - [ ] Step 3: Security scan - [ ] Step 4: Performance check - [ ] Step 5: Maintainability review - [ ] Step 6: Summarize findings ``` ## Step 1: Understand Context - What problem does this code solve? - Read PR description or commit messages - Identify affected components ## Step 2: Check Correctness - Does logic handle all cases? - Are edge cases covered? - Does it match requirements? **Red flags:** - Off-by-one errors - Null/undefined access - Race conditions - Unclosed resources ## Step 3: Security Scan Check for OWASP Top 10: | Vulnerability | What to Look For | |---------------|------------------| | Injection | Unsanitized user input in queries | | Auth issues | Missing access checks, weak tokens | | XSS | Unescaped output in HTML | | IDOR | Direct object references without auth | | Secrets | Hardcoded credentials, API keys | ## Step 4: Performance Check - N+1 queries - Unnecessary loops - Missing indexes - Large memory allocations - Blocking operations in async code ## Step 5: Maintainability Review - Clear naming conventions - Appropriate function size - DRY principle followed - Adequate error handling - Test coverage ## Step 6: Summarize Findings Use this format: ```markdown ## Review Summary ### Critical (Must Fix) - Issue description and location - Suggested fix ### Suggestions (Should Consider) - Improvement opportunity ### Minor (Nice to Have) - Optional enhancement ``` ## Additional Resources For detailed coding standards, see [STANDARDS.md](STANDARDS.md)
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

