Code Review
AI 驱动的代码审查工具。对代码变更进行多维度审查,输出结构化的 Review 意见。 **当以下情况时使用此 Skill**: (1) 需要对代码进行 Code Review (2) 需要审查 PR/MR 的代码变更 (3) 用户提到"code review"、"代码审查"、"帮我看看代码"、"这段代码有问题吗... Skill: Code Review Owner: caingao Summary: AI 驱动的代码审查工具。对代码变更进行多维度审查,输出结构化的 Review 意见。 **当以下情况时使用此 Skill**: (1) 需要对代码进行 Code Review (2) 需要审查 PR/MR 的代码变更 (3) 用户提到"code review"、"代码审查"、"帮我看看代码"、"这段代码有问题吗... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-05-24T09:42:04.392Z | auto AI 驱动的智能代码审查工具 — 首个版本发布 - 支持五大审查维度:安全、性能、可维护性、逻辑、风格 - 提供四种审查模式:完整代码、PR 变更、安全专注、快速自查 - 风险分级:严重/警告/建议,并附带修复代码片段 - 自动根据语言切换审查规则,支持多语言 - 按模式生成结
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
1.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.0.0release · observed May 24, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bdzn7wt8m5gmr3egcws699n87ak7y:smart-code-review- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-caingao-smart-code-review/snapshot"
Documentation
CLAWHUB
18,045 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: code-review
description: |
AI 驱动的代码审查工具。对代码变更进行多维度审查,输出结构化的 Review 意见。
**当以下情况时使用此 Skill**:
(1) 需要对代码进行 Code Review
(2) 需要审查 PR/MR 的代码变更
(3) 用户提到"code review"、"代码审查"、"帮我看看代码"、"这段代码有问题吗"
(4) 需要检查代码安全性、性能、可维护性
(5) 提交代码前的自查
(6) 用户提到"PR review"、"代码质量"、"技术债务"
metadata:
openclaw:
emoji: "🔍"
version: "1.0.0"
author: "小摩事业部"
tags: ["code-review", "developer-tools", "security", "performance", "quality", "chinese"]
---
# 🔍 AI Code Review — 智能代码审查
> 不遗漏每一行有问题的代码。
## 🎯 核心功能
1. **多维度审查** — 从安全、性能、可维护性、逻辑、风格 5 个维度扫描代码
2. **风险评级** — 🔴严重 / 🟡警告 / 🔵建议,优先级清晰
3. **修复建议** — 每个问题附带具体的修复代码片段
4. **PR 审查模式** — 分析 diff 输出结构化的 PR Review 报告
5. **快速审查** — 只输出严重问题,适合紧急提交前自查
## 📋 使用模式
### 模式一:完整代码审查
用户提交代码片段或文件内容,进行全面的代码审查。
**输入格式**:
```
帮我 review 这段代码:[代码片段]
```
**输出格式**:
```markdown
## 🔍 Code Review 报告
**审查文件**: [文件名/代码片段]
**总体评级**: ⭐⭐⭐⭐ (4/5)
**发现**: 3 个问题(🔴 0 严重 / 🟡 1 警告 / 🔵 2 建议)
### 🔴 严重问题
(无)
### 🟡 警告
#### 1. [问题标题]
- **位置**: 第 42 行
- **维度**: 安全
- **问题**: SQL 拼接导致注入风险
- **修复**:
```语言
// 修复前
String query = "SELECT * FROM users WHERE id = " + userId;
// 修复后
String query = "SELECT * FROM users WHERE id = ?";
PreparedStatement stmt = conn.prepareStatement(query);
stmt.setString(1, userId);
```
### 🔵 建议
#### 2. [建议标题]
- **位置**: 第 15-20 行
- **维度**: 可维护性
- **建议**: 提取为独立方法
- **参考**:
```语言
// 建议重构为
private User findUserById(String userId) { ... }
```
### ✅ 做得好的地方
- 异常处理完整
- 日志记录规范
```
### 模式二:PR 审查
用户提交 diff 或 PR 内容,进行变更审查。
**输入格式**:
```
审查这个 PR:[diff 内容]
```
或
```
审查我最近的代码变更
```
**执行步骤**:
1. 如用户在工作目录中,主动用 `git diff` 获取变更
2. 分析变更文件列表和影响范围
3. 对每个文件的变更逐一审查
4. 汇总为 PR Review 报告
**输出格式**:
```markdown
## 🔍 PR Review 报告
**变更范围**: 5 个文件(+142/-38)
**风险等级**: 🟡 中
**审查结论**: ✅ 可以合并(修复 1 个警告后)
### 📊 变更概览
| 文件 | 变更行数 | 风险 | 评审结果 |
|------|---------|------|---------|
| auth/login.go | +45/-12 | 🟡 | 有 1 个警告 |
| utils/crypto.go | +23/-5 | 🟢 | 通过 |
| config.yaml | +8/-2 | 🟢 | 通过 |
| tests/auth_test.go | +58/-15 | 🟢 | 通过 |
| README.md | +8/-4 | 🟢 | 通过 |
### 🟡 需要关注的问题
[详细问题列表和修复建议]
### 💡 改进建议
[非必须但能提升代码质量的建议]
### ✅ 值得肯定
[写得好的地方]
```
### 模式三:安全审查
专注于安全维度的深度审查。
**输入格式**:
```
安全审查这段代码:[代码]
```
**审查重点**:
- SQL 注入 / XSS / CSRF
- 硬编码密钥/密码
- 不安全的反序列化
- 权限/认证绕过
- 敏感数据泄露
- 依赖漏洞
### 模式四:快速自查
提交前快速扫描,只输出严重问题。
**输入格式**:
```
快速检查这段代码:[代码]
```
**输出格式**:
```
🔍 快速审查结果:✅ 可以提交 / ⚠️ 有 N 个问题
[如果有问题,列出简要说明和修复建议]
```
## 🧠 审查维度详解
加载 `review-rules.md` 获取完整的审查规则库。
### 五大审查维度
| 维度 | 关注点 | 严重级别 |
|------|--------|---------|
| 🔒 安全 | 注入、泄露、认证、加密 | 🔴 严重 |
| ⚡ 性能 | 算法复杂度、内存、缓存、N+1查询 | 🟡 警告 |
| 🔧 可维护性 | 代码复杂度、重复、命名、注释 | 🔵 建议 |
| 🧩 逻辑 | 边界条件、空值、并发、竞态 | 🔴 严重 |
| 📐 风格 | 编码规范、格式、最佳实践 | 🔵 建议 |
### 语言特定规则
根据代码语言自动切换审查规则:
| 语言 | 特定关注点 |
|------|-----------|
| Java | 资源泄漏、空指针、并发安全、Spring 最佳实践 |
| Python | 类型安全、GIL、装饰器滥用、异步陷阱 |
| Go | goroutine 泄漏、error 处理、channel 死锁 |
| JavaScript/TS | Promise 错误处理、原型污染、类型安全 |
| SQL | 注入、索引、N+1、事务隔离级别 |
| Rust | 生命周期、unsafe 使用、内存安全 |
## 🔄 工作流程
1. **读取审查规则** → 用 `read` 工具读取 `reREADME.md
# 🔍 Code Review — AI 智能代码审查 > 不遗漏每一行有问题的代码。 ## 它是什么? Code Review 是一个 [OpenClaw](https://openclaw.ai) Skill,为你的 AI Agent 添加专业的代码审查能力。 给它代码片段、diff 或 PR 内容,它就能输出: - 多维度代码审查报告(安全/性能/可维护性/逻辑/风格) - 风险评级和优先级标注 - 具体的修复代码建议 - PR 审查结论 ## ✨ 特性 - ✅ **5 大审查维度** — 安全、性能、可维护性、逻辑、风格,不遗漏 - ✅ **3 级风险标注** — 🔴 严重 / 🟡 警告 / 🔵 建议,优先级清晰 - ✅ **4 种使用模式** — 完整审查 / PR 审查 / 安全审查 / 快速自查 - ✅ **多语言支持** — Java / Python / Go / JavaScript / SQL / Rust - ✅ **修复建议** — 每个问题附带可直接使用的修复代码 - ✅ **中文优先** — 审查报告和说明使用中文 ## 📦 安装 ```bash # 复制到你的 OpenClaw Skills 目录 cp -r code-review/ ~/.openclaw/workspace/skills/ ``` ## 🎯 使用方式 ### 完整代码审查 ``` 帮我 review 这段代码:[代码片段] ``` ### PR 审查 ``` 审查这个 PR:[diff 内容] ``` ### 安全审查 ``` 安全审查这段代码:[代码] ``` ### 快速自查 ``` 快速检查这段代码:[代码] ``` ## 🧠 审查维度 | 维度 | 关注点 | 示例 | |------|--------|------| | 🔒 安全 | 注入、泄露、认证、加密 | SQL注入、硬编码密码、XSS | | ⚡ 性能 | 算法、内存、缓存、N+1 | 循环内查询、大列表无分页 | | 🔧 可维护性 | 复杂度、重复、命名 | 过长方法、嵌套过深、魔法数字 | | 🧩 逻辑 | 边界条件、空值、并发 | null 未处理、竞态条件 | | 📐 风格 | 规范、格式、最佳实践 | 未使用 import、行过长 | ## 📊 评级标准 | 评级 | 含义 | 标准 | |------|------|------| | ⭐ | 不可合并 | 严重安全漏洞或逻辑错误 | | ⭐⭐ | 需要大改 | 多个严重问题 | | ⭐⭐⭐ | 可以更好 | 有警告级问题 | | ⭐⭐⭐⭐ | 良好 | 只有建议级改进 | | ⭐⭐⭐⭐⭐ | 优秀 | 代码质量高 | ## 🏗️ 文件结构 ``` code-review/ ├── SKILL.md # 主入口,使用说明 ├── review-rules.md # 完整审查规则库(5大维度+多语言) ├── test-cases.md # 8个测试用例 └── README.md # 本文件 ``` ## 📝 版本 - **v1.0.0** (2026-05-23) — 初始版本,5 大审查维度,4 种使用模式,多语言支持 ## 📄 License MIT --- **作者**: 小摩事业部 | **Tags**: code-review, developer-tools, security, performance, quality
_meta.json
{
"ownerId": "kn7dfpp85z5fypb8h8x6f0awvd87bh9v",
"slug": "smart-code-review",
"version": "1.0.0",
"publishedAt": 1779615724392
}review-rules.md
# 代码审查规则库 > Code Review Rules — 按维度和语言分类的审查规则 --- ## 一、安全维度 🔒 ### 通用安全规则 | # | 规则 | 严重级别 | 检测模式 | |---|------|---------|---------| | S-01 | SQL 拼接而非参数化查询 | 🔴 | `SELECT.*\+.*\|".*".*\+` | | S-02 | 硬编码密钥/密码/Token | 🔴 | `password\s*=\s*["']\|api_key\s*=\s*["']\|secret\s*=\s*["']` | | S-03 | 不安全的反序列化 | 🔴 | `pickle\.load\|unserialize\|ObjectInputStream` | | S-04 | 命令注入 | 🔴 | `exec\(|Runtime\.getRuntime\(\)\.exec\|os\.system\(` | | S-05 | XSS 风险 — 未转义的用户输入直接输出到 HTML | 🔴 | `innerHTML\s*=.*\$\|document\.write` | | S-06 | 不安全的随机数生成 | 🟡 | `Math\.random()\|random\.random()` (用于安全场景时) | | S-07 | 过于宽松的 CORS 配置 | 🟡 | `Access-Control-Allow-Origin.*\*` | | S-08 | 未验证的 URL 重定向 | 🟡 | `redirect.*request\.\|header.*Location.*\+` | | S-09 | 敏感信息写入日志 | 🟡 | `log\.\(.*password\|print\(.*token\|console\.log\(.*secret` | | S-10 | 缺少认证/授权检查 | 🟡 | 公开 API 端点没有 auth middleware | ### Java 安全规则 | # | 规则 | 严重级别 | |---|------|---------| | S-J01 | 使用 `java.security.MessageDigest` 但未指定安全算法 | 🔴 | | S-J02 | Spring Security 配置中 `permitAll()` 使用不当 | 🔴 | | S-J03 | 未关闭的数据库连接/文件流(缺少 try-with-resources) | 🟡 | | S-J04 | 在日志中打印完整的 HttpServletRequest body | 🟡 | ### Python 安全规则 | # | 规则 | 严重级别 | |---|------|---------| | S-P01 | `eval()` 或 `exec()` 处理用户输入 | 🔴 | | S-P02 | Django `DEBUG = True` 在生产环境 | 🔴 | | S-P03 | Flask `secret_key` 硬编码或过弱 | 🔴 | | S-P04 | `subprocess` 使用 `shell=True` | 🟡 | ### Go 安全规则 | # | 规则 | 严重级别 | |---|------|---------| | S-G01 | `crypto/md5` 或 `crypto/sha1` 用于安全场景 | 🔴 | | S-G02 | `math/rand` 用于生成安全随机数 | 🔴 | | S-G03 | HTTP 服务未设置超时 | 🟡 | --- ## 二、性能维度 ⚡ ### 通用性能规则 | # | 规则 | 严重级别 | 检测说明 | |---|------|---------|---------| | P-01 | 循环内执行数据库查询(N+1 问题) | 🔴 | for/while 循环体内有 SQL 查询或 ORM 查询 | | P-02 | O(n²) 或更高复杂度算法处理大数据集 | 🟡 | 嵌套循环且内层循环与外层循环使用相同数据 | | P-03 | 在循环内创建不可变对象(如 Java String 拼接) | 🟡 | `String += ` 在循环内 | | P-04 | 未使用分页的大数据量查询 | 🟡 | `SELECT *` 无 LIMIT 且无分页 | | P-05 | 频繁的小文件 I/O 替代批量操作 | 🔵 | 循环内 open/write/close | | P-06 | 可以并行但串行执行的独立任务 | 🔵 | 顺序 await 多个无依赖的异步操作 | | P-07 | 缓存可复用的计算结果 | 🔵 | 重复计算相同值 | | P-08 | 未关闭的资源(连接/流/文件) | 🟡 | 缺少 finally/close 保障 | ### Java 性能规则 | # | 规则 | 严重级别 | |---|------|---------| | P-J01 | HashMap 初始容量过小导致频繁扩容 | 🔵 | | P-J02 | 使用 `LinkedList` 而非 `ArrayList`(随机访问场景) | 🔵 | | P-J03 | BigDecimal 构造使用 double 而非 String | 🟡 | | P-J04 | 未使用连接池 | 🔴 | ### Python 性能规则 | # | 规则 | 严重级别 | |---|------|---------| | P-P01 | 列表推导替代 map/filter 的简单场景(可读性换性能) | 🔵 | | P-P02 | 使用 Python 循环替代 numpy 向量化操作(数值计算) | 🟡 | | P-P03 | 未使用 `__slots__` 的大量实例化类 | 🔵 | --- ## 三、可维护性维度 🔧 ### 通用可维护性规则 | # | 规则 | 严重级别 | 说明 | |---|------|---------|------| | M-01 | 方法/函数超过 50 行 | 🟡 | 拆分为更小的函数 | | M-02 | 嵌套超过 3 层的 if/for | 🟡 | 提取方法或使用卫语句 | | M-03 | 重复代码块(>5 行相似) | 🟡 | 提取公共方法 | | M-04 | 魔法数字/字符串未提取为常量 | 🔵 | 定义命名常量 | | M-05 | 函数参数超过 4 个 | 🔵 | 使用对象/结构体封装 | | M-06 | 过于通用的命名(data/info/result/temp) | 🔵 | 使用具体描述性命名 | | M-07 | 缺少必要的注释(复杂逻辑/业务规则) | 🔵 | 添加为什么(why)的注释 | | M-08 | 过多的注释(注释掉的代码) | 🔵 | 删除无用代码,版本控制负责历史 | | M-09 | 上帝类/上帝函
skill-card.md
## Description: Code Review helps agents review code snippets, diffs, and PR changes across security, performance, maintainability, logic, and style, then produce structured findings with risk ratings and fix suggestions. This skill is ready for commercial/non-commercial use. ## Publisher: [caingao](https://clawhub.ai/user/caingao) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill to ask an agent for full, PR, security-focused, or quick code reviews before merge or release. It is designed to surface prioritized issues and practical remediation guidance. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill may ask the agent to inspect proprietary or sensitive source code and diffs. Mitigation: Use it only with code the user is authorized to share, and keep review input within the intended agent or workspace boundary. Risk: Generated findings and fix snippets may be incomplete or wrong even when the security scan verdict is clean. Mitigation: Treat results as review assistance and have a developer validate security, logic, and generated fixes before merging. Risk: The artifact is Chinese-first, which may be unsuitable for teams expecting English review output. Mitigation: Request English output explicitly when needed. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/caingao/skills/smart-code-review) - [OpenClaw](https://openclaw.ai) ## Skill Output: **Output Type(s):** [text, markdown, code, guidance] **Output Format:** [Markdown review reports with prioritized findings, summaries, and code snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [Chinese-first output by default; users can request English output explicitly.] ## Skill Version(s): 1.0.0 (source: server release metadata, OpenClaw metadata, README) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/caingao/skills/smart-code-review",
"sourceUrl": "https://clawhub.ai/caingao/skills/smart-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T13:55:35.754Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-caingao-smart-code-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-caingao-smart-code-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T13:55:35.754Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/caingao/smart-code-review",
"sourceUrl": "https://clawhub.ai/caingao/smart-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T13:55:35.754Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.0",
"href": "https://clawhub.ai/caingao/smart-code-review",
"sourceUrl": "https://clawhub.ai/caingao/smart-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-24T09:42:04.392Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-caingao-smart-code-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-caingao-smart-code-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.0",
"description": "AI 驱动的智能代码审查工具 — 首个版本发布 - 支持五大审查维度:安全、性能、可维护性、逻辑、风格 - 提供四种审查模式:完整代码、PR 变更、安全专注、快速自查 - 风险分级:严重/警告/建议,并附带修复代码片段 - 自动根据语言切换审查规则,支持多语言 - 按模式生成结构化审查/Review 报告,突出问题与优点 - 可自定义模式、严格度、关注维度和输出语言",
"href": "https://clawhub.ai/caingao/smart-code-review",
"sourceUrl": "https://clawhub.ai/caingao/smart-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-24T09:42:04.392Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
