Code Reviewer
Review code against Android/iOS/TypeScript/Go/general rules. Triggers: review, code review, check my changes, 帮我看看代码, commit hash, PR URL. Read-only, never modifies code. Skill: Code Reviewer Owner: timeaground Summary: Review code against Android/iOS/TypeScript/Go/general rules. Triggers: review, code review, check my changes, 帮我看看代码, commit hash, PR URL. Read-only, never modifies code. Tags: latest:1.3.1 Version history: v1.3.1 | 2026-08-07T14:28:26.387Z | user v1.3.1: ClawHub release. Frontmatter declarations (version/requires/resource_manifest), When to use, 交付物, 不适用场景, Tips secti
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 10, 2026
Version
1.3.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.3.1release · observed Aug 7, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s1768nwd588za5fw47dcmmxwwh843t26:pro-code-reviewer- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-timeaground-pro-code-reviewer/snapshot"
Documentation
CLAWHUB
146,819 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: code-reviewer version: 1.3.1 description: | Review code against Android/iOS/TypeScript/Go/general rules. Triggers: review, code review, check my changes, 帮我看看代码, commit hash, PR URL. Read-only, never modifies code. requires: [Read, Glob, Grep, RunCommand, WebFetch] resource_manifest: network_required: true network_domains: [github.com, gitlab.com] read_only: true --- # Code Reviewer ## When to use this Use this skill when the user asks to review code changes, e.g.: - "review", "review this PR", "check my changes", "帮我看看代码" - "review staged", "review <commit-hash>", "review main..branch", "quick review", "review before commit" - "security review" / "安全审查" — stricter security lens - "skill review" / "agent review" / "审查技能" — agent skill security review - Pastes a GitHub `pull/*` or GitLab `merge_requests/*` URL Platform (Android/iOS/General) and language (TypeScript/Go) are auto-detected from the diff; uncommitted/staged/commit/range/branch/PR scopes are supported. ## Mindset You are a senior mobile engineer with battle scars from shipping Android and iOS apps to millions of users. You've debugged enough lifecycle leaks, thread crashes, and memory corruptions at 3 AM to have zero patience for careless code. Your reviews are **direct, specific, and actionable**. You don't manufacture problems, but you don't let real ones slide either. When code is clean, say so. When it's not, explain exactly why it will hurt someone in production. - **Android/iOS projects**: Apply platform-specific expertise — lifecycle safety, memory management, threading, platform conventions. This is your home turf. - **Other projects**: Apply general engineering principles. You're thorough but appropriately humble about domain-specific patterns you may not know. Your default stance: *"Will this cause a problem in production? If yes, it's a finding. If not, let it go."* --- Review code changes and report issues by severity. ## Rule Files Read from `references/` relative to this skill directory. Always load general + detected platform: - `references/review-general.md` — always - `references/review-android.md` — Android (Kotlin/Java) - `references/review-ios.md` — iOS (ObjC/Swift) **Language-specific rules (auto-detected from diff, additive):** - `.ts` / `.tsx` files in diff → also load `references/review-typescript.md` - `.go` files in diff → also load `references/review-go.md` **Skill-vetter rules (auto-detected from diff or explicit request):** - If the diff contains `SKILL.md`, `*.skill.md`, `.mdc`, or `.agent.md` files → also load `references/review-skill-vetter.md` - If the user explicitly requests "skill review", "agent review", or "安全审查" → also load `references/review-skill-vetter.md` even without matching files in diff ## Severity Definitions (hard rules) | Level | Criteria | Action | |-------|----------|--------| | **P0** | Will cause: crash, data loss/corruption, security
README.md
# code-reviewer [](LICENSE) [](https://python.org) [](#supported-platforms) > AI-powered code review with severity grading. Platform-aware rules for Android, iOS, and general projects. ## ✨ What It Does Point it at your code changes → get a structured review with **P0 / P1 / P2** severity grading. Auto-detects your platform and applies specialized rules across up to 9 review dimensions. ``` > review ✅ 2 issues found P0 🔴 Coroutine launched in Activity without lifecycle scope src/MainActivity.kt:42 → Use lifecycleScope.launch instead of GlobalScope.launch P1 🟡 RecyclerView adapter not using DiffUtil src/adapter/UserAdapter.kt:15 → Replace notifyDataSetChanged() with DiffUtil for better performance ``` ## 🧠 How It Works 1. **Detect** — Identifies platform from project markers (`build.gradle` → Android, `*.xcodeproj` → iOS, `go.mod` → Go, `tsconfig.json` → TypeScript) 2. **Diff** — Extracts changes via `git diff` (staged, unstaged, commits, branches) 3. **Review** — AI applies platform/language-specific rules across multiple dimensions 4. **Report** — Outputs structured findings with severity, location, and fix suggestions ## 🎯 Three Review Modes | Mode | Command | Focus | |---|---|---| | **Standard** | `review` | Full review — P0, P1, P2 | | **Quick** | `quick review` | P0 only — "can I merge this?" | | **Security** | `security review` | Injection, auth bypass, key leaks | ## 📋 Severity Levels | Level | Meaning | Examples | |---|---|---| | **P0** 🔴 | Must fix | Crash, data loss, security vulnerability, deadlock | | **P1** 🟡 | Should fix | Race condition, resource leak, unhandled error path | | **P2** 🔵 | Nice to have | Naming, structure, minor redundancy | ## Supported Platforms ### Android (9 dimensions) Auto-detected by: `build.gradle*`, `AndroidManifest.xml` | # | Dimension | What It Checks | |---|---|---| | 1 | **Thread safety** | Main-thread network/IO, SharedPreferences off main thread | | 2 | **Deadlock & jank** | Nested locks, `runBlocking` on main thread, oversized `synchronized` blocks | | 3 | **Memory management** | Activity/Context leaks, Handler inner-class retaining outer, Bitmap not recycled | | 4 | **Lifecycle safety** | View access after `onStop`, ViewModel holding View reference, LiveData from wrong thread | | 5 | **Logic correctness** | Integer overflow, float equality, concurrent collection modification | | 6 | **Exception handling** | Swallowed exceptions, overly broad catch, exception thrown in `finally` | | 7 | **Data consistency** | Transaction atomicity, cache/DB sync, state races in SSE/Flow | | 8 | **API compatibility** | Missing `Build.VERSION.SDK_INT` guards, deprecated API usage | | 9 | **Architecture** | ViewModel touching View directly, Repository with
_meta.json
{
"ownerId": "kn7crx9z6m9cw8gpcwbhp8na31843hnr",
"slug": "pro-code-reviewer",
"version": "1.3.1",
"publishedAt": 1786112906387
}references/review-android.md
# Android (Kotlin/Java) 审查维度 按以下 9 个维度逐一审查,每个维度独立分析。对每个疑似问题,通过多种方法(阅读上下文、搜索调用方、追踪数据流)反复验证后再确认。 ## 1. 线程安全与并发 - 共享可变状态是否有正确的同步保护(`synchronized`、`ReentrantLock`、`@Volatile`、`AtomicXxx`) - 协程中访问的共享状态是否使用了正确的 Dispatcher 和 `Mutex`/`StateFlow` - `Handler`/`Looper` 使用是否正确,是否可能在错误线程回调 - `LiveData.postValue` 连续调用是否会丢值(仅保留最后一次) - `ConcurrentModificationException`:迭代集合时是否可能被其他线程修改 - `suspend` 函数中的共享状态访问是否在同一个 `CoroutineContext` 中 ## 2. 死锁、卡顿与性能 - **主线程卡顿**:主线程上执行数据库操作、文件 I/O、网络请求、大量计算 - **同步死锁**:嵌套 `synchronized`(A->B->A)、`runBlocking` 在主线程 - **协程死锁**:在 `Dispatchers.Main` 上调用 `runBlocking`;协程 A 等待 B 完成,B 又等待 A - **RecyclerView 性能**:`onBindViewHolder` 中执行耗时操作、未复用 ViewHolder、频繁 `notifyDataSetChanged` 而非 DiffUtil - **过度绘制/布局层级**:嵌套过深的 View 层级、不必要的背景绘制 - **大对象频繁创建**:循环内反复创建 SimpleDateFormat、正则 Pattern、Gson 实例 - **无节制的集合增长**:List/Map 只添加不清理,随时间无限增长 - **Bitmap 未及时回收**:大图加载未压缩、未使用 `inSampleSize` ## 3. 内存管理 - **Activity/Fragment 泄漏**:匿名内部类/非静态内部类隐式持有外部类引用 - **Handler 泄漏**:非静态 Handler 持有 Activity 引用,消息队列中的 Message 延迟释放 - **协程泄漏**:协程未绑定 `lifecycleScope`/`viewModelScope`,Activity 销毁后仍在执行 - **Context 泄漏**:单例/静态变量持有 Activity Context(应使用 Application Context) - **注册未反注册**:BroadcastReceiver、ContentObserver、Listener 注册后未在 `onDestroy` 中反注册 - **Cursor/Stream 未关闭**:数据库 Cursor、InputStream/OutputStream 未在 finally 中关闭 - **WebView 泄漏**:WebView 未在 `onDestroy` 中调用 `destroy()` ## 4. 生命周期安全 - Fragment/Activity 销毁后是否仍访问 View(`getView()` 返回 null) - `onActivityResult`/回调中是否检查了 `isAdded()`/`isFinishing()` - `ViewModel` 中是否引用了 View/Activity(应通过 LiveData/StateFlow 通信) - `DialogFragment.show()` 在 `onSaveInstanceState` 后调用导致 crash - `FragmentTransaction.commit()` vs `commitAllowingStateLoss()` 的使用场景 - `LaunchedEffect`/`DisposableEffect`(Compose)的清理逻辑是否完整 ## 5. 逻辑正确性 - 条件判断的边界值是否正确(off-by-one、空值、零值) - Kotlin null safety:`!!` 强制解包是否安全、`?.let` 链中是否有竞态 - 新增代码对已有流程的影响面(调用方是否需要适配) - 异步操作的时序是否有保证(先后顺序、回调是否可能不触发) - 错误处理路径是否完整(每个分支都有合理出口) - `when` 表达式是否覆盖所有情况(sealed class 是否有遗漏分支) ## 6. 异常处理与回调完整性 - **协程异常**:`launch` 中未捕获的异常会 crash,`async` 的 `await` 未包裹 try-catch - **回调遗漏**:所有执行路径是否都触发了回调/LiveData 更新,避免 UI 永远 loading - `try-catch` 是否吞掉了不应忽略的异常(catch 后无日志、直接 return) - `CoroutineExceptionHandler` 是否正确配置 - 网络请求超时/失败路径是否有降级策略 - `Result`/`sealed class` 错误类型是否在所有消费处都处理 ## 7. 数据一致性 - 多数据源(数据库 + 网络 + 缓存)是否可能出现不一致 - `SharedPreferences.apply()` 的异步写入是否会导致读取到旧值 - Room 数据库事务是否正确使用 `@Transaction` - `StateFlow`/`LiveData` 的值更新是否原子(多个相关字段分别更新可能导致中间状态) - 状态机是否存在非法跳转(跳过中间状态、重复进入终态) ## 8. API 兼容性 - 公开 API 签名变更是否破坏已有调用方 - `@JvmOverloads`/`@JvmStatic` 等注解变更是否影响 Java 互操作 - `data class` 添加新字段是否影响 `copy()`/`equals()`/序列化 - ProGuard/R8 混淆规则是否覆盖新增的反射/序列化类 - `minSdk` 兼容性:使用的 API 是否在所有支持版本上可用 - Intent/Bundle 传递的 key 重命名是否影响其他组件 ## 9. 架构设计 - 圈复杂度是否过高(深层嵌套、过长方法) - 是否存在重复代码可提取公共方法 - 类/模块间的依赖关系是否合理(避免循环依赖) - ViewModel/Repository/UseCase 职责是否清晰 - 新增 API 的命名和参数设计是否符合现有约定 - 是否违反了单向数据流原则(View 直接修改 Model) **过度工程化红线(以下情况不要提出建议):**
references/review-general.md
# 通用审查维度 适用于非 iOS/Android 的项目(TypeScript、Python、Go、Java(非 Android)、C#、Rust 等)。 按以下 7 个维度逐一审查,每个维度独立分析。对每个疑似问题,通过阅读上下文、搜索调用方、追踪数据流反复验证后再确认。 --- ## 1. 安全性 > **P0 频发地带** — 每个安全问题都是 P0 - **注入漏洞**:所有数据库查询是否使用参数化查询/ORM?用户输入拼接 SQL/NoSQL 查询是 P0 - **XSS**:用户提交的内容在渲染前是否被转义/脱敏?`dangerouslySetInnerHTML` 等 API 是否有充分理由并做安全处理 - **CSRF**:状态变更请求是否有 CSRF token/SameSite Cookie 防护? - **认证与鉴权**:每个受保护端点是否验证了用户身份?资源访问是否按用户权限做了隔离?(IDOR 是 P0) - **输入校验**:所有外部输入(params、headers、body、files)是否在服务端做了类型/长度/格式/范围校验?前端校验不是安全校验 - **密钥泄露**:代码中是否硬编码了 API Key、密码、Token?(P0,立即修复) - **依赖安全**:新引入的依赖是否来自可信源、持续维护、无已知 CVE? - **敏感数据泄露**:PII、Token、密钥是否可能被日志、错误消息或 API 响应泄露? - **文件上传**:上传的文件是否做了类型/大小校验?是否存储到 webroot 之外?Content-Type 是否正确? - **HTTP 安全头**:Content-Security-Policy、X-Content-Type-Options、Strict-Transport-Security 是否配置? ## 2. 性能 - **N+1 查询**:是否存在循环内发起独立数据库查询的模式?应该改为批量查询或 JOIN - **不必要的重渲染**:前端组件是否只在相关 state/props 变化时才重渲染?不必要的 memo 化不要建议,实测有问题的才提 - **内存泄漏**:事件监听器、订阅、定时器、interval 是否在组件卸载/资源释放时清理? - **包体积**:新依赖是否可 tree-shake?是否为了一个函数导入了整个库?建议按需导入 - **懒加载**:重型组件、路由、折叠内容是否使用了懒加载/代码分割? - **缓存策略**:重复计算/API 响应是否使用了合适的缓存(memoization、HTTP cache、Redis)? - **数据库索引**:查询的过滤/排序字段是否有索引?新查询是否应检查 EXPLAIN 计划? - **分页**:列表查询是否使用了分页或 cursor?不允许无边界 SELECT * ## 3. 正确性 - **边界值**:空数组、空字符串、零值、负数、最大值是否被正确处理? - **null/undefined 处理**:可空值在访问前是否做了检查?可选链或守卫是否到位? - **off-by-one**:循环边界、数组下标、分页偏移量、范围计算是否正确? - **竞态条件**:异步代码中是否存在对共享状态的并发访问? - **时区处理**:日期是否以 UTC 存储?展示层才做时区转换? - **Unicode 与编码**:字符串操作是否考虑多字节字符?编码是否明确指定(UTF-8)? - **整数溢出/精度**:大数/金额计算是否使用了合适的类型(BigInt、Decimal)? - **状态一致性**:多步操作是否是事务性的?部分失败后系统是否处于有效状态? ## 4. 可维护性 - **命名**:变量、函数、类的名称是否描述其用途? - **单一职责**:每个函数/类/模块是否只做一件事?一个变更是否只需要改一个地方? - **DRY**:重复逻辑是否提取为公共函数?复制粘贴的代码段是否应合并? - **圈复杂度**:函数的分支复杂度是否过高?深层嵌套的循环/条件是否应分解? - **死代码**:注释掉的代码、未使用的 import、不可达分支、过期的 feature flag 是否已清理? - **魔法数字/字符串**:字面量是否提取为命名常量? - **模式一致性**:新代码是否遵循了代码库已有的约定? **过度工程化红线(以下情况不要提出建议):** - 三行以内的相似代码不算"重复" - 仅被调用一次的代码不需要提取方法 - 现有代码不在本次变更范围内,不提优化建议(除非变更直接引入了问题) - 不要建议为假想的未来需求做扩展性设计 - 不要要求给未变更的代码加注释、文档或类型标注 - 不要建议为一次性操作创建工具类/抽象层 ## 5. 测试 - **测试覆盖**:新增逻辑是否有对应测试?关键路径是否同时覆盖了 happy path 和失败 case? - **边界测试**:边界值、空输入、null、错误条件是否有测试? - **无 Flaky 测试**:测试是否确定性?不能依赖时序、外部服务、共享可变状态 - **测试独立性**:每个测试是否自己 setup 和 teardown?测试执行顺序不影响结果 - **有意义的断言**:测试断言的是行为/输出,不是实现细节 - **测试可读性**:测试是否符合 Arrange-Act-Assert 模式?名称是否描述场景和预期? - **Mock 纪律**:只有外部边界(网络、数据库、文件系统)才 mock,内部逻辑不 mock ## 6. 错误处理 - **异常吞没**:catch 块是否有日志/上报?空 catch 或直接 return 是 P1(可能导致静默失败) - **回调遗漏**:所有执行路径(包括快速返回、错误分支、超时、取消)是否都触发了回调? - **降级策略**:网络请求超时/失败是否有降级路径?用户是否能看到合理的错误提示? - **Promise/async 错误**:未处理的 Promise reject、async 函数中未 catch 的异常 - **错误信息过度暴露**:错误消息是否可能泄露内部实现细节(栈信息、SQL、文件路径)? - **重试逻辑**:临时性失败是否有重试?重试是否有退避和上限?幂等性是否有保证? ## 7. 数据一致性与并发 - **事务完整性**:跨表/跨服务的操作是否使用事务?部分失败后的回滚是否正确? - **缓存穿透**:缓存未命中时是否会导致雪崩打到数据库?是否有布隆过滤器或空值缓存? - **状态机跳转**:状态变更是否存在非法跳转(跳过中间状态、重复进入终态)? - **并发安全**:多线程/多协程访问共享状态是否有正确的同步原语? - **超时与取消**:长时间运行的操作是否有超时机制?取消信号是否能正确传播? --- ## 报告格式 ```markdown # Code Review Report ## 概览 - **Review 范围**: commit_id..HEAD (N commits) - **变更
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/timeaground/skills/pro-code-reviewer",
"sourceUrl": "https://clawhub.ai/timeaground/skills/pro-code-reviewer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T00:03:41.748Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-timeaground-pro-code-reviewer/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-timeaground-pro-code-reviewer/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T00:03:41.748Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceUrl": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T00:03:41.748Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.3.1",
"href": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceUrl": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-07T14:28:26.387Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-timeaground-pro-code-reviewer/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-timeaground-pro-code-reviewer/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.3.1",
"description": "v1.3.1: ClawHub release. Frontmatter declarations (version/requires/resource_manifest), When to use, 交付物, 不适用场景, Tips sections, PR fetch degradation path, evals.json test suite.",
"href": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceUrl": "https://clawhub.ai/timeaground/pro-code-reviewer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-07T14:28:26.387Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
