agentCLAWHUBUnverified

Code Reviewer

本技能从 6 个维度对代码进行全面审核:安全性、性能、代码质量、错误处理、测试和文档。适用于审核代码变更、Pull Request 或整个代码库(支持所有主流编程语言)。触发词包括:「帮我 review 这段代码」「检查安全问题」「审查这个 PR」「找出代码中的 Bug」,或用户请求代码质量分析时使用。技能内置自... Skill: Code Reviewer Owner: nameused Summary: 本技能从 6 个维度对代码进行全面审核:安全性、性能、代码质量、错误处理、测试和文档。适用于审核代码变更、Pull Request 或整个代码库(支持所有主流编程语言)。触发词包括:「帮我 review 这段代码」「检查安全问题」「审查这个 PR」「找出代码中的 Bug」,或用户请求代码质量分析时使用。技能内置自... Tags: latest:1.0.1 Version history: v1.0.1 | 2026-06-20T13:41:13.597Z | user - Refactored all documentation and instructions from English to Chinese for improved localization. - Updated descriptions, workflows, re

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 10, 2026

Version

1.0.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 10, 2026
Latest release
1.0.1release · observed Jun 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s174vwx6k6f5w6srbr5x7yc9x5890txq:code-reviewer
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-nameused-code-reviewer/snapshot"

Documentation

CLAWHUB

79,693 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: code-reviewer
description: "本技能从 6 个维度对代码进行全面审核:安全性、性能、代码质量、错误处理、测试和文档。适用于审核代码变更、Pull Request 或整个代码库(支持所有主流编程语言)。触发词包括:「帮我 review 这段代码」「检查安全问题」「审查这个 PR」「找出代码中的 Bug」,或用户请求代码质量分析时使用。技能内置自动化分析脚本、安全规则库、各语言最佳实践文档,并可生成可视化 HTML 审核报告。"
---

# 代码审核助手(Code Reviewer)

## 概述

通过自动化静态分析与 AI 上下文推理相结合的方式,对代码进行全面、多维度的审核。覆盖六大审核维度,支持所有主流编程语言,输出带严重性分级的可执行问题列表和可视化 HTML 报告。

## 适用场景

- 审核 Pull Request 或代码变更(diff)
- 对现有代码库进行安全或质量审计
- 合并前代码质量检查(Pre-merge gate)
- 对不熟悉的代码进行入门级审核
- 安全漏洞评估
- 性能瓶颈定位

## 审核工作流

每次代码审核均遵循以下 4 阶段工作流,各阶段依次递进。

### 第一阶段:确定范围与计划

确定审核对象和方式:

1. 确认审核范围:单文件、目录、git diff 还是 PR。若用户提供 git diff 或 PR,仅审核变更行及其上下文;若审核整个代码库,询问用户目标目录。
2. 根据文件扩展名检测编程语言,参考 `references/best-practices.md` 中各语言专属规则。
3. 确定审核深度:快速扫描(仅关注严重/高危)或全面审核(覆盖所有严重级别)。默认执行全面审核,除非用户明确要求快速扫描。
4. 检查自动化分析脚本是否可用。如果 Python 可用,优先使用脚本进行确定性分析。

### 第二阶段:自动化分析

在进行上下文推理之前,运行内置脚本获取确定性的基线问题。

**步骤 1:复杂度分析**

对目标代码运行复杂度分析器:

```bash
python scripts/analyze_complexity.py <目标路径> --format json
```

检测内容:过长函数(>50 行)、高圈复杂度(>10)、深层嵌套(>4 层)、参数过多(>5 个)。结果以 JSON 格式输出。

**步骤 2:模式扫描**

运行模式扫描器检测安全漏洞和代码质量问题:

```bash
python scripts/scan_patterns.py <目标路径> --format json
```

检测内容:SQL 注入、命令注入、硬编码密钥、eval 使用、弱哈希算法、XSS、空 catch 块、TODO/FIXME 标记,以及 20+ 其他反模式。结果以 JSON 格式输出。

**步骤 3:合并结果**

将两个脚本的 JSON 输出合并为一个问题列表,按(文件、行号、类型)去重。

若 Python 不可用,跳过本阶段直接进入第三阶段,对照 `references/security-rules.md` 和 `references/checklist.md` 手动检查代码中的等价问题。

### 第三阶段:上下文审核

阅读代码并进行自动化工具无法完成的上下文推理,这是审核的核心价值所在。

按需加载以下参考文档:
- `references/checklist.md` — 6 维度全面检查清单
- `references/security-rules.md` — OWASP Top 10、各语言安全模式、密钥检测正则
- `references/best-practices.md` — 各语言惯用写法与反模式
- `references/severity-guide.md` — 严重性分级标准与示例

对第二阶段的每个问题进行确认或排除误报,然后检查模式匹配无法发现的问题:

**安全性(参考 `references/security-rules.md`):**
- 业务逻辑漏洞(如订单中的负数数量、转账中的竞态条件)
- 特定业务操作缺少授权检查
- 不安全的数据流(source → sink 分析)
- 信任边界违规

**性能(参考 `references/checklist.md` 第 2 节):**
- 算法效率问题(错误的数据结构、不必要的计算)
- 资源泄漏(未关闭的连接、孤立的事件监听器)
- 可扩展性隐患(无限增长、锁竞争)

**代码质量(参考 `references/best-practices.md`):**
- SOLID 原则违反
- 设计模式误用或缺失
- 命名清晰度与一致性
- 抽象层级是否适当

**错误处理(参考 `references/checklist.md` 第 4 节):**
- 关键业务流程中未处理的错误路径
- 泄露内部状态的错误消息
- 瞬态错误缺少重试/降级机制
- 错误传播不当(被吞噬、重新包装或丢失上下文)

**测试(参考 `references/checklist.md` 第 5 节):**
- 核心业务逻辑缺少测试
- 边界情况和错误路径未被测试覆盖
- 测试隔离问题(共享状态、顺序依赖)
- Mock 质量(过度 Mock 或 Mock 不足)

**文档(参考 `references/checklist.md` 第 6 节):**
- 公共接口缺少 API 文档
- 注释与代码不符(过时注释)
- 非显而易见的设计决策缺少架构决策记录

### 第四阶段:报告与建议

生成最终审核输出。

**步骤 1:对所有问题进行分级**(参考 `references/severity-guide.md`):
- 严重(Critical):远程代码执行、SQL 注入、绕过认证、硬编码生产环境密钥
- 高危(High):数据泄露、XSS、缺少鉴权、反序列化漏洞
- 中危(Medium):弱加密、N+1 查询、高复杂度、空 catch 块
- 低危(Low):死代码、命名问题、魔法数字、调试打印语句
- 提示(Info):建议、替代方案、正向反馈

**步骤 2:生成 HTML 报告**(可选,当用户需要可视化报告时):

```bash
# 双语报告,带切换按钮(默认)
python scripts/generate_report.py <findings.json> --project "<项目名称>" --output review-report.html

# 仅中文
python scripts/generate_report.py <findings.json> --lang zh --output review-report.html

# 

_meta.json

{
  "ownerId": "kn77qvnxzvd6mty516h2m09kan891gd9",
  "slug": "code-reviewer",
  "version": "1.0.1",
  "publishedAt": 1781962873597
}

references/best-practices.md

# Language-Specific Best Practices

## JavaScript / TypeScript

### Modern Syntax
- Use `const` by default, `let` when reassignment needed, never `var`
- Use arrow functions for callbacks and short functions; use `function` for methods and constructors
- Use template literals over string concatenation
- Use destructuring for object/array extraction
- Use spread operator instead of `Object.assign` for immutability
- Use optional chaining (`?.`) and nullish coalescing (`??`) instead of manual checks

### TypeScript Specific
- Enable `strict: true` in tsconfig.json
- Avoid `any` type - use `unknown` when type is truly unknown, then narrow
- Use `interface` for object shapes, `type` for unions and intersections
- Use `enum` or union types for fixed value sets
- Prefer `readonly` for immutable properties
- Use generics for reusable components/functions
- Enable `noUncheckedIndexedAccess` for safer array/object access

### Async Patterns
- Use `async/await` over `.then()` chains for readability
- Always handle promise rejections (try/catch or .catch())
- Use `Promise.all()` for parallel operations, not sequential awaits
- Avoid fire-and-forget async calls (always await or handle)
- Use `AbortController` for cancellable fetch requests

### Node.js
- Use `path.join()` / `path.resolve()` instead of string concatenation for paths
- Use `fs.promises` (async) over `fs` (sync) in server code
- Validate input with Zod / Joi / express-validator at API boundaries
- Use `crypto.randomUUID()` for ID generation, not `Math.random()`
- Set `helmet()` middleware for security headers
- Use `express-rate-limit` for API rate limiting

### Common Anti-Patterns
- Mutating function arguments
- Comparing with `==` instead of `===`
- Using `forEach` when `map`/`filter`/`reduce` is intended
- Async function without await inside (missing `await` keyword)
- `any` type in TypeScript (loss of type safety)
- Empty catch blocks (`catch (e) {}`)

---

## Python

### Modern Syntax (3.9+)
- Use type hints on all function signatures (`def foo(x: int) -> str:`)
- Use `from __future__ import annotations` for forward references
- Use f-strings for string formatting (not `%` or `.format()`)
- Use `pathlib.Path` instead of `os.path` for path manipulation
- Use dataclasses or Pydantic for data containers
- Use `match` statement for complex pattern matching (3.10+)
- Use `walrus operator` (`:=`) for assignment expressions where it improves readability

### Error Handling
- Catch specific exceptions, not bare `except:` or `except Exception:`
- Use context managers (`with` statements) for resource management
- Raise exceptions with meaningful messages and proper exception types
- Use custom exception hierarchies for application-specific errors
- Never use `except: pass` - at minimum log the error

### Security
- Use `secrets` module for tokens/passwords, not `random`
- Use `bcrypt` or `argon2-cffi` for password hashing
- Use parameterized queries with `psycopg2` / `SQLAlchemy` (never string conc

references/checklist.md

# Code Review Checklist

## 1. Security

### Injection Attacks
- [ ] SQL queries use parameterized statements / prepared statements (no string concatenation)
- [ ] No OS command execution with user input (`os.system`, `exec`, `Runtime.exec`, `child_process.exec`)
- [ ] Template engines use auto-escaping (no `dangerouslySetInnerHTML`, `{!! !!}`, `innerHTML` with user data)
- [ ] No eval on user input (`eval()`, `Function()`, `new Function()`)

### Authentication & Authorization
- [ ] Passwords hashed with bcrypt/scrypt/argon2 (not MD5/SHA1/plaintext)
- [ ] JWT tokens validated for signature, expiry, and issuer
- [ ] Authorization checks present on every protected route/endpoint
- [ ] No hardcoded credentials, API keys, or tokens in source code
- [ ] Secrets loaded from environment variables or secret managers

### Data Exposure
- [ ] Sensitive data not logged (passwords, tokens, PII, credit card numbers)
- [ ] API responses do not leak internal field names or stack traces
- [ ] HTTPS enforced; no mixed content
- [ ] CORS configured restrictively (no `Access-Control-Allow-Origin: *` on sensitive endpoints)

### File Operations
- [ ] File paths validated against traversal attacks (no `../` in user-controlled paths)
- [ ] Upload restrictions: file type, size, and content validation
- [ ] Download paths restricted to allowed directories

### Dependencies
- [ ] No known vulnerable dependencies (checked via `npm audit` / `pip audit` / `snyk`)
- [ ] Dependency versions pinned (no floating `*` or `latest`)

---

## 2. Performance

### Database
- [ ] No N+1 query patterns (queries inside loops)
- [ ] Database indexes exist for frequently queried columns
- [ ] Pagination applied to list endpoints (no unbounded `SELECT *`)
- [ ] ORM queries select only needed columns (no `SELECT *` when only 2 fields used)

### Algorithms & Data Structures
- [ ] No O(n^2) or worse inside hot paths / loops
- [ ] Appropriate data structures used (Set for lookups instead of Array.includes)
- [ ] No unnecessary re-computation of the same value inside loops

### Memory
- [ ] No memory leaks (event listeners removed, intervals cleared, connections closed)
- [ ] Large collections streamed rather than loaded entirely into memory
- [ ] No unnecessary object retention in long-lived scopes (closures, globals, singletons)

### Concurrency
- [ ] Async operations not blocking the event loop (no sync I/O in async contexts)
- [ ] Database connections released properly (try/finally or using context managers)
- [ ] Race conditions addressed (proper locking / atomic operations)

---

## 3. Code Quality

### Readability
- [ ] Variable/function names are descriptive and self-documenting
- [ ] Functions do one thing (Single Responsibility)
- [ ] No dead code (unused variables, functions, imports, unreachable code)
- [ ] No magic numbers / strings (use named constants)
- [ ] Consistent naming convention (camelCase / snake_case per language convention)

### Complexity
- [ ] Functions under 50 lines

references/security-rules.md

# Security Vulnerability Detection Rules

## OWASP Top 10 Quick Reference

### A01 - Broken Access Control
| Pattern | Indicators | Languages |
|---------|-----------|-----------|
| Missing auth check | Route handler without auth middleware | All |
| IDOR | Direct object reference from user input without ownership check | All |
| Privilege escalation | Role check missing before sensitive operation | All |
| Force browsing | No authorization on API endpoints | All |

**Detection patterns:**
- Route definitions without `auth` / `requireAuth` / `@login_required` / `@Authorized`
- `req.params.id` / `request.getParameter("id")` used directly in DB query without ownership validation
- `isAdmin` check only on frontend, not backend

### A02 - Cryptographic Failures
| Pattern | Indicators | Languages |
|---------|-----------|-----------|
| Weak hashing | MD5, SHA1 used for passwords | All |
| Hardcoded secrets | API keys in source code | All |
| No encryption | Sensitive data stored/transmitted in plaintext | All |
| Weak randomness | `Math.random()` / `random.random()` for security tokens | All |

**Detection patterns (regex):**
```
# Hardcoded API keys
(api[_-]?key|secret|token|password)\s*[:=]\s*['"][A-Za-z0-9]{16,}['"]

# Weak hash algorithms
\b(MD5|SHA1|md5|sha1)\b.*password

# Insecure random
\b(Math\.random|random\.random)\(\).*token|session|password|key
```

### A03 - Injection
| Pattern | Indicators | Languages |
|---------|-----------|-----------|
| SQL Injection | String concatenation in SQL queries | All |
| Command Injection | User input in shell commands | All |
| LDAP Injection | String concat in LDAP queries | All |
| Template Injection | User input in template engine | All |

**Detection patterns:**
```
# SQL injection
(SELECT|INSERT|UPDATE|DELETE|DROP).*\+.*\$_(GET|POST|REQUEST)
query\s*\+\s*['"].*['"]\s*\+
execute\s*\(\s*['"].*\{.*\}.*['"]\s*\)

# Command injection
(os\.system|subprocess\.call|exec|child_process\.exec)\s*\(.*\+.*(input|req|param)
```

### A04 - Insecure Design
- Missing rate limiting on authentication endpoints
- No account lockout after failed login attempts
- Predictable URL patterns for sensitive resources
- Missing input validation (length, type, format, range)

### A05 - Security Misconfiguration
- Debug mode enabled in production (`DEBUG=True`)
- Detailed error pages in production (stack traces exposed)
- Default credentials not changed
- Unnecessary features enabled (directory listing, HTTP methods)

### A07 - Identification & Authentication Failures
- Weak password policy (no minimum length, complexity)
- Session ID in URL parameters
- Session fixation (session not regenerated after login)
- No session timeout

### A08 - Software & Data Integrity Failures
- Unsigned software updates
- Deserialization of untrusted data (`pickle.loads`, `yaml.load` without SafeLoader)
- Dependencies from untrusted sources

### A09 - Logging & Monitoring Failures
- Security events not logged (login, logout, password change, privile
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/nameused/skills/code-reviewer",
      "sourceUrl": "https://clawhub.ai/nameused/skills/code-reviewer",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T21:52:39.587Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-nameused-code-reviewer/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nameused-code-reviewer/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T21:52:39.587Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/nameused/code-reviewer",
      "sourceUrl": "https://clawhub.ai/nameused/code-reviewer",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T21:52:39.587Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.1",
      "href": "https://clawhub.ai/nameused/code-reviewer",
      "sourceUrl": "https://clawhub.ai/nameused/code-reviewer",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-20T13:41:13.597Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-nameused-code-reviewer/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nameused-code-reviewer/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.1",
      "description": "- Refactored all documentation and instructions from English to Chinese for improved localization. - Updated descriptions, workflows, report generation steps, and best practice guidelines with Chinese text and terminology. - No changes to scripts or core review workflow logic; functionality and structure remain the same. - Maintains full feature parity, including automated/deterministic analysis, report generation, and cross-platform support.",
      "href": "https://clawhub.ai/nameused/code-reviewer",
      "sourceUrl": "https://clawhub.ai/nameused/code-reviewer",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-20T13:41:13.597Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Code Reviewer and adjacent AI workflows.