Code Review Pro
多视角代码审�?- 安全(OWASP)/性能/正确�?风格,每视角输出严重级别+修复建议,支持PASS/BLOCK裁定 Skill: Code Review Pro Owner: 534422530 Summary: 多视角代码审�?- 安全(OWASP)/性能/正确�?风格,每视角输出严重级别+修复建议,支持PASS/BLOCK裁定 Tags: code-review:2.0.0, latest:2.0.0, performance:2.0.0, pro:2.0.0, quality:1.1.0, security:2.0.0 Version history: v2.0.0 | 2026-05-29T23:31:26.365Z | auto - Added hub.json to support hub integration. - Updated SKILL.md for version and metadata changes (now v1.1.0, added premium badge). - Expanded and updated
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
2.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 2.0.0release · observed May 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s170k9770tgh0506hw0dwtb6pd83kwyq:laosi-code-review- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-code-review/snapshot"
Documentation
CLAWHUB
20,540 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
badge: premium
name: code-review
version: 1.1.0
description: 多视角代码审�?- 安全(OWASP)/性能/正确�?风格,每视角输出严重级别+修复建议,支持PASS/BLOCK裁定
tags: [code-review, security, performance, quality, development]
author: laosi
source: original
---
# Code Review - 多视角代码审�?
> 激活词: 审查 / code review / CR
## 4视角框架
```
┌────────────────────────────────────────�?�? 代码审查 整体裁定 �?├──────────┬──────────┬─────────┬─────────�?�?SECURITY │PERFORM- │CORRECT- �? STYLE �?�? 安全 �?ANCE 性能 �?NESS正确�? 风格 �?├──────────┼──────────┼─────────┼─────────�?�?CRITICAL �? MAJOR �? MINOR �? INFO �?└──────────┴──────────┴─────────┴─────────�?```
## Python 实现
```python
from dataclasses import dataclass, field
from typing import List, Optional
from enum import Enum
class Severity(Enum):
CRITICAL = "CRITICAL" # 必须修复
MAJOR = "MAJOR" # 强烈建议
MINOR = "MINOR" # 建议改进
INFO = "INFO" # 仅供参�?
class Verdict(Enum):
PASS = "PASS"
PASS_WITH_COMMENTS = "PASS_WITH_COMMENTS"
BLOCK = "BLOCK"
@dataclass
class Finding:
perspective: str
severity: Severity
file: str
line: int
title: str
detail: str
suggestion: str
@dataclass
class ReviewResult:
findings: List[Finding] = field(default_factory=list)
def add(self, perspective: str, severity: Severity, file: str,
line: int, title: str, detail: str, suggestion: str = ""):
self.findings.append(Finding(
perspective, severity, file, line, title, detail, suggestion
))
def security_check(self, code: str, file: str = "unknown"):
"""安全视角检�?""
checks = [
("SQL注入风险", "execute(", "使用参数化查询代替字符串拼接"),
("XSS风险", "innerHTML", "使用textContent或安全转�?),
("硬编码密�?, "api_key", "移动到环境变量或密钥管理服务"),
("路径遍历", "../", "验证用户输入路径,使用basename"),
("命令注入", "os.system(", "使用subprocess.run传参数组"),
("eval执行", "eval(", "避免使用eval,改用安全替代方�?),
]
for title, pattern, suggestion in checks:
for i, line_text in enumerate(code.split('\n'), 1):
if pattern in line_text:
self.add("SECURITY", Severity.CRITICAL, file, i,
f"发现{title}: `{line_text.strip()}`",
f"第{i}�? `{line_text.strip()}`",
suggestion)
def performance_check(self, code: str, file: str = "unknown"):
perform_checks = [
("N+1查询", "for.*in.*query"),
("大循�?, "for.*in range"),
("重复计算", ".count("),
]
# 简化示�? for title, _, _ in perform_checks:
pass # 实际检查会解析AST
def correctness_check(self, code: str, file: str = "unknown"):
correct_checks = [
("除以0", "/ (", "除法前检查分母是否为0"),
("空指�?, "None."),
("索引越界", "[len("),
]
def style_check(self, code: str, file: str = "unknown"):
style_checks = [
_meta.json
{
"ownerId": "kn71pk44ca87scz3pstt90r66n80xhaa",
"slug": "laosi-code-review",
"version": "2.0.0",
"publishedAt": 1780097486365
}skill-card.md
## Description: A code review helper that evaluates code across security, performance, correctness, and style perspectives, assigns severity levels, suggests fixes, and returns PASS/BLOCK-style decisions. This skill is ready for commercial/non-commercial use. ## Publisher: [534422530](https://clawhub.ai/user/534422530) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineering teams use this skill to structure pull request review, security audit, performance review, and code-quality findings before merge or release decisions. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The artifact is incomplete or malformed, and the paid full-implementation claims are not supported by the uploaded files. Mitigation: Review the artifact manually and validate behavior on representative code before relying on it for PR gates, CI blocking, paid security review, or audit decisions. Risk: The advertised code review coverage may be narrower than readers expect from the release claims. Mitigation: Treat findings as advisory and pair the skill with human review and established security, performance, and correctness checks for high-impact decisions. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/534422530/skills/laosi-code-review) ## Skill Output: **Output Type(s):** [text, markdown, code, guidance] **Output Format:** [Markdown code review report with severity-labeled findings and PASS, PASS_WITH_COMMENTS, or BLOCK verdicts.] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include file and line references, remediation suggestions, and severity labels.] ## Skill Version(s): 2.0.0 (source: server release metadata and hub.json) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
hub.json
{
"description": "Premium version with full implementation, examples, and enterprise support",
"minOpenClawVersion": "1.2.0",
"version": "2.0.0",
"tags": [
"code-review",
"security",
"performance",
"pro"
],
"author": "laosi",
"name": "code-review",
"pricing": {
"price": 3900,
"model": "one-time"
},
"license": "MIT",
"displayName": "Code Review Pro"
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/534422530/skills/laosi-code-review",
"sourceUrl": "https://clawhub.ai/534422530/skills/laosi-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:01:45.795Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-code-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-code-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T00:01:45.795Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/534422530/laosi-code-review",
"sourceUrl": "https://clawhub.ai/534422530/laosi-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:01:45.795Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.0",
"href": "https://clawhub.ai/534422530/laosi-code-review",
"sourceUrl": "https://clawhub.ai/534422530/laosi-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T23:31:26.365Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-code-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-code-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.0",
"description": "- Added hub.json to support hub integration. - Updated SKILL.md for version and metadata changes (now v1.1.0, added premium badge). - Expanded and updated content in SKILL.md; some text corruption/encoding issues present in the update. - The core logic and usage examples remain consistent.",
"href": "https://clawhub.ai/534422530/laosi-code-review",
"sourceUrl": "https://clawhub.ai/534422530/laosi-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T23:31:26.365Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
