{"id":"4ae23eba-6d53-4bb0-a622-042d5a879602","entityType":"agent","slug":"clawhub-gechengling-ai-code-review-expert","name":"AI Code Review Expert","canonicalUrl":"https://www.xpersona.co/agent/clawhub-gechengling-ai-code-review-expert","canonicalPath":"/agent/clawhub-gechengling-ai-code-review-expert","generatedAt":"2026-10-10T13:31:41.896Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":null},"description":"AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell, best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描, pull request, 静态分析, 代码规范. Skill: AI Code Review Expert Owner: gechengling Summary: AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17ewqc4f2s6gpcbm88hy7fgvn85kg1g:ai-code-review-expert","sourceUrl":"https://clawhub.ai/gechengling/ai-code-review-expert","homepage":"https://clawhub.ai/gechengling/skills/ai-code-review-expert","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/gechengling/ai-code-review-expert","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/gechengling/skills/ai-code-review-expert","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":null},"stars":null,"forks":null,"downloads":1486,"packageName":null,"latestVersion":"3.0.3","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T10:47:30.632Z","lastCrawledAt":"2026-10-10T10:47:30.632Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T10:47:30.632Z","lastVerifiedAt":null,"highlights":[{"version":"3.0.3","createdAt":"2026-09-16T05:19:53.771Z","changelog":"v3.0.3: 新增数据最小化声明、上下文要素速查表、反模式速查表(3个新维度)、LLM应用专项检查表、评分权重列、Go/Java评审示例、人工复核清单；修复历史编码丢失的占位符；更新至2026-09-16生态动态","fileCount":3,"zipByteSize":12595},{"version":"3.0.2","createdAt":"2026-06-16T09:36:33.065Z","changelog":"**Summary:** Version 3.0.2 introduces more robust internationalization and technical clarity for the AI Code Review Expert skill. - Improved multilingual support: added and clarified Chinese trigger words and workflow documentation. - Enhanced 2026 workflow details, including updated technical ecosystem and code review checklists. - Updated OWASP and Claude-specific security audit sections in both English and Chinese for broader accessibility. - Removed skill-card.md for simpler documentation maintenance.","fileCount":3,"zipByteSize":6891},{"version":"3.0.1","createdAt":"2026-05-27T06:06:59.164Z","changelog":"- Updated version to 3.0.1 in SKILL.md. - Non-English (CJK) characters in various sections replaced with mojibake (garbled text), affecting trigger words, workflow, and examples. - No changes to logic, workflow, or intended feature set. - No code, functionality, or usage modifications introduced in this release.","fileCount":3,"zipByteSize":6600},{"version":"3.0.0","createdAt":"2026-05-25T11:51:57.833Z","changelog":"- No changes detected in this version; content and functionality remain the same as the previous release.","fileCount":2,"zipByteSize":4515},{"version":"1.0.1","createdAt":"2026-05-15T23:27:24.109Z","changelog":"## Changelog for ai-code-review-expert v1.0.1 - No file changes detected in this release. - No updates to skill capabilities, documentation, or workflow.","fileCount":2,"zipByteSize":4515},{"version":"1.0.0","createdAt":"2026-05-15T14:11:57.858Z","changelog":"Initial release of AI Code Review Expert. - Provides AI-powered code review with deep static analysis, security scanning, and coding standard enforcement for multiple languages. - Generates actionable pull request (PR) review comments, explains issues, and suggests concrete fixes. - Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more; integrates with GitHub PR workflows. - Performs multi-dimensional analysis (critical, warning, suggestion) and outputs an overall code quality score. - Includes step-by-step review workflow, customizable review focus, and sample PR summary formats. - Emphasizes security best practices (OWASP Top 10 2025), code style flexibility, and privacy (no code storing/logging).","fileCount":2,"zipByteSize":4515}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ewqc4f2s6gpcbm88hy7fgvn85kg1g:ai-code-review-expert","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T13:31:41.895Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-ai-code-review-expert/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":null},"readme":"Skill: AI Code Review Expert\n\nOwner: gechengling\n\nSummary: AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell, best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描, pull request, 静态分析, 代码规范.\n\nTags: ai-code-review-expert:3.0.3, latest:3.0.3\n\nVersion history:\n\nv3.0.3 | 2026-09-16T05:19:53.771Z | user\n\nv3.0.3: 新增数据最小化声明、上下文要素速查表、反模式速查表(3个新维度)、LLM应用专项检查表、评分权重列、Go/Java评审示例、人工复核清单；修复历史编码丢失的占位符；更新至2026-09-16生态动态\n\nv3.0.2 | 2026-06-16T09:36:33.065Z | auto\n\n**Summary:** Version 3.0.2 introduces more robust internationalization and technical clarity for the AI Code Review Expert skill.\n\n- Improved multilingual support: added and clarified Chinese trigger words and workflow documentation.\n- Enhanced 2026 workflow details, including updated technical ecosystem and code review checklists.\n- Updated OWASP and Claude-specific security audit sections in both English and Chinese for broader accessibility.\n- Removed skill-card.md for simpler documentation maintenance.\n\nv3.0.1 | 2026-05-27T06:06:59.164Z | auto\n\n- Updated version to 3.0.1 in SKILL.md.\n- Non-English (CJK) characters in various sections replaced with mojibake (garbled text), affecting trigger words, workflow, and examples.\n- No changes to logic, workflow, or intended feature set.\n- No code, functionality, or usage modifications introduced in this release.\n\nv3.0.0 | 2026-05-25T11:51:57.833Z | auto\n\n- No changes detected in this version; content and functionality remain the same as the previous release.\n\nv1.0.1 | 2026-05-15T23:27:24.109Z | auto\n\n## Changelog for ai-code-review-expert v1.0.1\n\n- No file changes detected in this release.\n- No updates to skill capabilities, documentation, or workflow.\n\nv1.0.0 | 2026-05-15T14:11:57.858Z | auto\n\nInitial release of AI Code Review Expert.\n\n- Provides AI-powered code review with deep static analysis, security scanning, and coding standard enforcement for multiple languages.\n- Generates actionable pull request (PR) review comments, explains issues, and suggests concrete fixes.\n- Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more; integrates with GitHub PR workflows.\n- Performs multi-dimensional analysis (critical, warning, suggestion) and outputs an overall code quality score.\n- Includes step-by-step review workflow, customizable review focus, and sample PR summary formats.\n- Emphasizes security best practices (OWASP Top 10 2025), code style flexibility, and privacy (no code storing/logging).\n\nArchive index:\n\nArchive v3.0.3: 3 files, 12595 bytes\n\nFiles: skill-card.md (2196b), SKILL.md (21466b), _meta.json (140b)\n\nFile v3.0.3:SKILL.md\n\n---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.3\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## 数据最小化声明（每次审查开始前默认生效）\r\n\r\n代码评审是本 Skill 唯一的处理对象。为降低敏感信息暴露面，请遵循：\r\n\r\n- **只提交需要评审的片段**：优先提交单个函数、单个 diff 或单个文件；不要把整个仓库、`.env`、密钥文件、生产数据样本整包贴入。\r\n- **提交前自行脱敏**：把真实域名、账号、Token、客户名称替换为 `example.com`、`user_001`、`<REDACTED>` 等占位符。审查结论基于代码结构，脱敏不影响判断。\r\n- **评审产物不外发**：本 Skill 产出的评论、评分、修复建议仅在对话中返回给用户；是否粘贴到 PR、Issue、工单系统，由用户自行决定并确认。若用户要求\"直接生成 PR 描述\"，先输出完整文本供用户预览，经用户确认后再使用。\r\n- **本 Skill 不连接代码托管平台、不执行代码、不写入仓库文件**。文中出现的代码片段、命令行示例均为**供用户在自己环境中参考运行的材料**，本 Skill 本身不会执行它们。\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(￥0.8/千Token vs ￥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n### 工具与生态最新动态 [2026-09-16 更新]\r\n\r\n| 动态类型 | 内容摘要 | 影响范围 | 对代码审查的启示 |\r\n|---------|---------|---------|----------------|\r\n| 审查工具 | AI PR 审查已从\"可选插件\"变为 CI 默认环节，主流平台均支持按路径/语言配置审查强度 | 全语言 | 审查策略应写入仓库配置（如 `.github/` 下的审查规则文件），而非依赖个人习惯 |\r\n| 安全基准 | OWASP 针对大模型应用的 Top 10 持续迭代，提示词注入、不安全输出处理、敏感信息泄露稳居前列 | AI/LLM 应用 | 涉及 LLM 调用的代码必须单列检查项，见下方 LLM 专项表 |\r\n| 供应链 | 依赖混淆、恶意包投毒事件频发，锁文件与来源校验成为审查必检项 | 所有含第三方依赖的项目 | 新增依赖须核对仓库归属、维护活跃度、签名/哈希 |\r\n| 合规 | 各国对 AI 生成代码的来源与许可审查趋严 | 商业闭源项目 | 审查结论中须提示许可证兼容性与 AI 生成痕迹 |\r\n\r\n> 以上为截至 **2026-09-16** 的整理；工具版本与榜单变动较快，具体版本号、排名与条款细节**以官方最新发布为准**。\r\n\r\n---\r\n\r\n## Step 1 — Context Gathering\r\nAsk the user for (or infer from the code):\r\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\r\n- **Review focus** (security? performance? readability? all?)\r\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\r\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\r\n\r\n### 上下文要素速查表\r\n\r\n| 上下文要素 | 为什么影响结论 | 缺失时的默认假设 | 追问话术示例 |\r\n|-----------|--------------|----------------|-------------|\r\n| 语言与运行时版本 | 决定可用语法糖与安全默认（如 Python 3.12 的 `functools` 缓存语义） | 按该语言当前 LTS 版本判断 | \"这段跑在哪个版本的运行时上？\" |\r\n| 是否对外暴露 | 暴露到公网的端点按最高安全等级审查 | 视为**对外暴露**，从严判断 | \"这个接口是内网调用还是公网可访问？\" |\r\n| 数据敏感级别 | 决定是否强制加密、脱敏日志、审计留痕 | 含个人信息/凭证则按敏感处理 | \"入参里会带手机号或证件号吗？\" |\r\n| 并发模型 | 决定是否需要检查竞态、死锁、取消传播 | 单线程串行 | \"这段代码会被并发调用吗？QPS 量级大概多少？\" |\r\n| 性能预算 | 决定 N+1、深拷贝等是否算阻塞项 | 无硬性预算，按 Warning 处理 | \"接口有 P99 延迟要求吗？\" |\r\n\r\n**追问示例 1（信息充分，直接开工）**\r\n> 用户：\"帮我看下这个 Go 函数的并发问题，QPS 大概 2000。\"\r\n> → 已知语言、关注点（并发）、量级。直接进入 Step 2，重点检查共享状态与 goroutine 泄漏。\r\n\r\n**追问示例 2（信息不足，先补齐）**\r\n> 用户：\"这段代码有没有问题？\" + 一段无类型标注的 Python 函数\r\n> → 缺失语言版本、暴露面、数据敏感度。先回问上面三个要素再评审，避免给出误导性结论。\r\n\r\n### Step 2 — Multi-Dimension Analysis\r\nAnalyze the provided code across these dimensions:\r\n\r\n#### [Critical] 严重（阻塞合并）\r\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\r\n- Logic errors that will cause crashes or data corruption\r\n- Race conditions and concurrency bugs\r\n\r\n**例 1 — 硬编码凭证（Python）**\r\n```python\r\n# 反例\r\nclient = OpenAI(api_key=\"sk-proj-XXXXXXXXXXXXXXXX\")\r\n# 正例\r\nclient = OpenAI(api_key=os.environ[\"OPENAI_API_KEY\"])  # 启动时校验非空\r\n```\r\n\r\n**例 2 — 并发写共享 map（Go）**\r\n```go\r\n// 反例：多个 goroutine 并发写，触发 fatal error: concurrent map writes\r\nfor _, u := range users { go func(u User){ cache[u.ID] = u }(u) }\r\n// 正例\r\nvar mu sync.Mutex\r\nfor _, u := range users { go func(u User){ mu.Lock(); cache[u.ID] = u; mu.Unlock() }(u) }\r\n// 或改用 sync.Map / 单写入 goroutine + channel\r\n```\r\n\r\n#### [Warning] 警告（应当修复）\r\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\r\n- Error handling gaps (unhandled exceptions, missing null checks)\r\n- Code duplications (DRY violations)\r\n- Deprecated API usage\r\n\r\n**例 1 — N+1 查询（Python/SQLAlchemy）**\r\n```python\r\n# 反例：每篇博客一次查询作者\r\nposts = session.query(Post).all()\r\nfor p in posts: print(p.author.name)\r\n# 正例：预加载\r\nposts = session.query(Post).options(joinedload(Post.author)).all()\r\n```\r\n\r\n**例 2 — 缺少取消传播（Go）**\r\n```go\r\n// 反例：父请求已取消，下游调用仍在跑\r\nresp, _ := http.Get(url)\r\n// 正例\r\nreq, _ := http.NewRequestWithContext(ctx, http.MethodGet, url, nil)\r\nresp, err := http.DefaultClient.Do(req)\r\n```\r\n\r\n#### [Suggestion] 建议（可选优化）\r\n- Readability improvements (naming, comments, structure)\r\n- Test coverage gaps\r\n- Opportunity to apply design patterns\r\n- Minor style inconsistencies\r\n\r\n**例 1 — 布尔参数可读性差**\r\n```python\r\n# 反例\r\ncreate_user(name, True)\r\n# 正例\r\ncreate_user(name, send_welcome_email=True)\r\n```\r\n\r\n**例 2 — 边界用例缺测试**：仅有 happy path 的单测，缺少空输入、超长字符串、并发重复提交三类用例 → 建议补参数化测试。\r\n\r\n### 常见反模式速查表（新增维度：自动化检测信号 / 预估收益）\r\n\r\n| 反模式 | 自动化检测信号 | 重构方向 | 预估收益 |\r\n|-------|--------------|---------|---------|\r\n| N+1 查询 | 循环体内出现 ORM 属性访问或查询调用 | 预加载 / 批量查询 / DataLoader | P99 延迟常下降一个数量级 |\r\n| 裸 `except:` 吞异常 | 捕获基类异常且块内无日志或 re-raise | 精确捕获 + 结构化日志 | 线上排障时间显著缩短 |\r\n| 上帝函数（>150 行） | 单函数行数与圈复杂度双高 | 按职责拆分 + 提取策略对象 | 单测覆盖率更易提升 |\r\n| 魔法数字散落 | 多处重复的字面量常量 | 提取具名常量 / 配置化 | 业务规则变更只需改一处 |\r\n| 缺少超时 | 网络/DB 调用未设置 timeout 或 ctx | 统一超时与重试策略 | 避免线程池被慢调用打满 |\r\n| 深拷贝大对象 | 循环内 `copy.deepcopy` 或等价操作 | 改为不可变结构 / 增量更新 | CPU 与 GC 压力下降 |\r\n\r\n### OWASP Top 10 2025 审计清单（AI代码审查必查）\r\n\r\n| # | 漏洞类型 | 检测关键词/模式 | 严重度 | AI辅助检测方法 | 常见误报信号 |\r\n|---|---------|---------------|--------|---------------|------------|\r\n| A01 | 权限控制失效（Broken Access Control） | 未授权访问/IDOR/路径遍历 | [Critical] | 检查路由/API端点是否缺少权限注解或中间件 | 权限校验在网关层统一处理，代码内看不到 |\r\n| A02 | 加密失效（Cryptographic Failures） | 硬编码密钥/弱哈希/明文传输 | [Critical] | 扫描字符串常量/正则表达式匹配密钥模式 | 测试 fixtures 中的假密钥、占位符 |\r\n| A03 | 注入攻击（Injection） | SQL拼接/NoSQL注入/命令注入 | [Critical] | 检查字符串拼接进入查询/exec/system调用 | 拼接的是内部枚举白名单而非用户输入 |\r\n| A04 | 不安全设计（Insecure Design） | 缺少速率限制/无验证码/逻辑漏洞 | [Warning] | 检查API端点是否缺少RateLimit/Captcha | 限流在网关或 WAF 层实现 |\r\n| A05 | 安全配置错误（Security Misconfiguration） | 默认凭据/开放端口/详细错误 | [Warning] | 检查配置文件/环境变量/异常处理 | 仅本地开发配置，部署时被覆盖 |\r\n| A06 | 易受攻击和过时组件（Vulnerable Components） | 已知CVE/过时依赖 | [Warning] | 对比package.json/lock文件与NVD数据库 | CVE 仅影响未使用的子模块或调用路径 |\r\n| A07 | 身份识别和认证失效（Identification and Authentication Failures） | 弱密码策略/会话固定/无MFA | [Critical] | 检查认证中间件配置/密码哈希算法 | 由外部 IdP / SSO 接管认证 |\r\n| A08 | 软件和数据完整性故障（Software and Data Integrity Failures） | 不可信反序列化/CI/CD污染 | [Warning] | 检查反序列化调用/流水线配置 | 反序列化输入来自可信内网且已校验签名 |\r\n| A09 | 安全日志和监控故障（Security Logging and Monitoring Failures） | 无审计日志/日志未集中 | [Suggestion] | 检查关键操作是否有日志记录 | 日志由统一中间件/AOP 切面输出 |\r\n| A10 | 服务器端请求伪造（SSRF） | 用户控制的URL请求 | [Warning] | 检查HTTP客户端调用是否验证目标URL | 目标 URL 来自服务端固定配置白名单 |\r\n\r\n**LLM 应用专项检查表（2026 新增行）**\r\n\r\n| # | 风险类型 | 检测关键词/模式 | 严重度 | AI辅助检测方法 | 常见误报信号 |\r\n|---|---------|---------------|--------|---------------|------------|\r\n| L01 | 提示词注入（Prompt Injection） | 用户输入直接拼接进 system/user prompt | [Critical] | 检查模板拼接处是否做分隔与转义；是否有输入白名单 | 输入来自内部枚举且长度受限 |\r\n| L02 | 不安全输出处理 | 模型输出直接进 `eval`/SQL/HTML/ shell | [Critical] | 追踪模型输出到危险 sink 的数据流 | 输出经严格 schema 校验后才落库 |\r\n| L03 | 敏感信息泄露 | 提示词中携带密钥、客户名单、个人隐私 | [Critical] | 扫描送入模型的上下文构建代码 | 送入前已做脱敏或仅送 ID |\r\n| L04 | 过度代理（Excessive Agency） | Agent 被授予文件写/代码执行/资金操作权限 | [Warning] | 检查工具权限清单是否按最小权限裁剪 | 权限已在沙箱容器内隔离 |\r\n| L05 | 模型拒绝服务 | 无 Token/请求上限，循环调用无退出条件 | [Warning] | 检查是否有预算上限、超时与重试退避 | 已有网关级配额控制 |\r\n\r\n**Claude Code Review 专属检查项（2026）**：\r\n- 提示词注入：检查系统提示是否被用户可控输入影响（CWE-1426）\r\n- 训练数据泄露：检查RAG检索结果是否可能泄露系统提示\r\n- 过度代理：检查Agent是否有不必要的文件读写/代码执行权限\r\n\r\n---\r\n### Step 3 — Generate Review Comments\r\nFor each finding, output a structured review comment:\r\n\r\n```\r\n[Location] 位置: [filename:line_number] or [function_name]\r\n[Severity] 严重度: [Critical / Warning / Suggestion]\r\n[Issue] 问题: [Clear description of the problem]\r\n[Why] 影响: [Impact on security / performance / maintainability]\r\n[Fix] 建议修复:\r\n[code block with the corrected implementation]\r\n```\r\n\r\n**例 1 — Go：未关闭的响应体（Warning）**\r\n```\r\n[Location] 位置: fetch_user.go:38\r\n[Severity] 严重度: Warning\r\n[Issue] 问题: `http.Get` 返回的 `resp.Body` 未关闭，连接无法复用\r\n[Why] 影响: 高并发下连接池耗尽，表现为间歇性超时\r\n[Fix] 建议修复:\r\nresp, err := http.DefaultClient.Do(req)\r\nif err != nil { return err }\r\ndefer resp.Body.Close()\r\n```\r\n\r\n**例 2 — Java/Spring：缺少权限注解（Critical）**\r\n```\r\n[Location] 位置: UserController.java:72 `deleteUser`\r\n[Severity] 严重度: Critical\r\n[Issue] 问题: 删除用户端点未做角色校验，任何已登录用户可删任意账号\r\n[Why] 影响: 越权删除，等价于 A01 权限控制失效\r\n[Fix] 建议修复:\r\n@DeleteMapping(\"/users/{id}\")\r\n@PreAuthorize(\"hasRole('ADMIN') or #id == authentication.principal.id\")\r\npublic void deleteUser(@PathVariable Long id) { ... }\r\n```\r\n\r\n### Step 4 — Overall Code Quality Score\r\n\r\n| Dimension | Weight | Score (1–10) | Notes |\r\n|-----------|--------|--------------|-------|\r\n| Correctness | 30% | — | Logic & edge case handling |\r\n| Security | 25% | — | OWASP, secrets, auth |\r\n| Performance | 15% | — | Time/space complexity, DB queries |\r\n| Readability | 15% | — | Naming, structure, comments |\r\n| Testability | 15% | — | Modular, injectable dependencies |\r\n| **Overall** | 100% | — | Weighted average |\r\n\r\n**评分标准（避免主观漂移）**：9–10 可直接合并且可作为范例；7–8 有小问题，作者自行修完即可合并；5–6 有明确 Warning，需修改后复审；3–4 有 Critical，必须返工；1–2 设计层面需要重写。任一 Critical 未修复时，Overall 不得高于 4。\r\n\r\n### Step 5 — PR Summary Comment (GitHub-style)\r\nGenerate a ready-to-paste GitHub PR description:\r\n\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** [4/5] — Minor issues found\r\n\r\n### Critical Issues (0)\r\nNo blocking issues found.\r\n\r\n### Warnings (2)\r\n- `user_service.py:45` — Potential SQL injection via raw query concatenation\r\n- `auth.py:12` — JWT secret read from environment variable without validation\r\n\r\n### Suggestions (3)\r\n- Consider extracting the validation logic into a shared utility\r\n- Add docstrings to public methods\r\n- Use `dataclasses` instead of plain dicts for `UserProfile`\r\n\r\n### Positive Highlights\r\n- Excellent use of dependency injection in `UserController`\r\n- Clear separation of concerns between service and repository layers\r\n```\r\n\r\n**第二示例 — Java/Spring 安全修复 PR（含 Critical）**\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** [2/5] — Blocking security issues found\r\n\r\n### Critical Issues (1)\r\n- `UserController.java:72` — Missing authorization on `deleteUser`; any authenticated user can delete any account (A01)\r\n\r\n### Warnings (2)\r\n- `JwtUtil.java:30` — Token expiry parsed from config without lower bound; a typo could mint 100-year tokens\r\n- `AuditService.java:15` — Deletion event not written to audit log (A09)\r\n\r\n### Suggestions (2)\r\n- Extract role-check logic into a reusable annotation to avoid per-endpoint drift\r\n- Add integration test asserting 403 for non-admin callers\r\n\r\n### Positive Highlights\r\n- Consistent use of constructor injection; easy to unit test\r\n```\r\n\r\n## Example Interactions\r\n\r\n**User:**\r\n```python\r\ndef get_user(user_id):\r\n    query = \"SELECT * FROM users WHERE id = \" + user_id\r\n    return db.execute(query)\r\n```\r\n\r\n**Skill response:**\r\n> [Critical] **SQL Injection** (`get_user` function)\r\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\r\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\r\n> **Fix:**\r\n> ```python\r\n> def get_user(user_id: int) -> dict | None:\r\n>     query = \"SELECT * FROM users WHERE id = %s\"\r\n>     return db.execute(query, (user_id,))\r\n> ```\r\n\r\n---\r\n\r\n**User:** \"Review this TypeScript React component for performance issues\"\r\n\r\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\r\n\r\n---\r\n\r\n**User:** \"这段 Go 代码在压测时偶发 panic，帮我看看\" + 并发写 map 的片段\r\n\r\n**Skill response:** 定位为 `concurrent map writes`（[Critical]），给出 `sync.Mutex` 与 `sync.Map` 两种修法，并说明各自适用门槛：写多读少用 Mutex，读多写少且 key 稳定用 `sync.Map`；同时提示用 `go test -race` 在 CI 中固化回归。\r\n\r\n---\r\n\r\n**User:** \"检查这个 PR 有没有泄露密钥\" + 一段含 `AWS_SECRET_ACCESS_KEY` 字面量的配置代码\r\n\r\n**Skill response:** 判定 [Critical]（A02），给出改用环境变量/密钥管理服务的修复片段，并提示**已泄露的凭证必须立即轮换**——仅删除代码不算修复，因为 Git 历史与 CI 日志中仍可能留存。\r\n\r\n## Supported Languages\r\n\r\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\r\n\r\n## Notes & Constraints\r\n\r\n- Never store or log submitted code — treat all code as potentially sensitive IP\r\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\r\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\r\n- When suggesting fixes, preserve the original code's intent and style conventions\r\n- Flag potential license compliance issues in code using third-party libraries\r\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\r\n\r\n### 人工复核清单（AI 结论落地前必过）\r\n\r\n| 复核项 | 目的 | 不通过时的处置 |\r\n|-------|------|--------------|\r\n| 修复片段是否可编译/可运行 | 避免给出语法错误的\"修复\" | 标注为伪代码并要求用户在本地验证 |\r\n| 安全结论是否有可利用路径 | 压低误报 | 降级为 Warning 并说明前提假设 |\r\n| 是否引入新的依赖或 API | 控制供应链风险 | 提示核对许可与维护活跃度 |\r\n| 是否改变对外行为/接口契约 | 防止静默破坏调用方 | 要求补充兼容层或版本化 |\r\n| 是否有对应回归测试 | 防止问题复发 | 建议同步补测试后再合并 |\r\n\r\n*GitHub: https://github.com/gechengling/ai-code-review-expert*\n\nFile v3.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"3.0.3\",\n  \"publishedAt\": 1789535993771\n}\n\nFile v3.0.3:skill-card.md\n\n## Description:\n\nAI Code Review Expert helps agents review code snippets and diffs for bugs, security issues, performance concerns, style violations, refactoring opportunities, and PR-ready feedback.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[gechengling](https://clawhub.ai/user/gechengling)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, tech leads, security engineers, and maintainers use this skill to get structured code review findings, concrete fixes, quality scoring, and PR summary comments before merging changes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Users may share more source code, secrets, customer data, or production samples than the review requires.\n\nMitigation: Submit only the smallest relevant snippet, file, or diff and redact tokens, credentials, customer identifiers, and production data before review.\n\nRisk: Broad trigger phrases such as 'check this code' may start a review workflow before the user intends to share sensitive material.\n\nMitigation: Confirm the review intent and scope before providing sensitive source code or repository context.\n\nRisk: Suggested fixes, PR comments, and shell commands may be context-dependent or require validation before use.\n\nMitigation: Review proposed changes locally, run project tests or security checks, and have a human reviewer approve changes before applying them.\n\n## Reference(s):\n\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance]\n\n**Output Format:** [Markdown review comments with severity labels, explanations, code blocks, scoring tables, and PR summary text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include suggested fixes, local verification commands, security review notes, and license compliance prompts.]\n\n## Skill Version(s):\n\n3.0.3 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v3.0.2: 3 files, 6891 bytes\n\nFiles: skill-card.md (2206b), SKILL.md (9890b), _meta.json (140b)\n\nFile v3.0.2:SKILL.md\n\n---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.2\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(￥0.8/千Token vs ￥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## Step 1 — Context Gathering\r\nAsk the user for (or infer from the code):\r\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\r\n- **Review focus** (security? performance? readability? all?)\r\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\r\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\r\n\r\n### Step 2 — Multi-Dimension Analysis\r\nAnalyze the provided code across these dimensions:\r\n\r\n#### ?? Critical (Blocking)\r\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\r\n- Logic errors that will cause crashes or data corruption\r\n- Race conditions and concurrency bugs\r\n\r\n#### ?? Warning (Should Fix)\r\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\r\n- Error handling gaps (unhandled exceptions, missing null checks)\r\n- Code duplications (DRY violations)\r\n- Deprecated API usage\r\n\r\n#### ?? Suggestion (Nice to Have)\r\n- Readability improvements (naming, comments, structure)\r\n- Test coverage gaps\r\n- Opportunity to apply design patterns\r\n- Minor style inconsistencies\r\n\r\n### OWASP Top 10 2025 审计清单（AI代码审查必查）\r\n\r\n| # | 漏洞类型 | 检测关键词/模式 | 严重度 | AI辅助检测方法 |\r\n|---|---------|---------------|--------|---------------|\r\n| A01 | 权限控制失效（Broken Access Control） | 未授权访问/IDOR/路径遍历 | ?? Critical | 检查路由/API端点是否缺少权限注解或中间件 |\r\n| A02 | 加密失败（Cryptographic Failure） | 硬编码密钥/弱哈希/明文传输 | ?? Critical | 扫描字符串常量/正则表达式匹配密钥模式 |\r\n| A03 | 注入攻击（Injection） | SQL拼接/NoSQL注入/命令注入 | ?? Critical | 检查字符串拼接进入查询/exec/system调用 |\r\n| A04 | 不安全设计（Insecure Design） | 缺少速率限制/无验证码/逻辑漏洞 | ?? Warning | 检查API端点是否缺少RateLimit/ Captcha |\r\n| A05 | 安全配置错误（Security Misconfiguration） | 默认凭据/开放端口/详细错误 | ?? Warning | 检查配置文件/环境变量/异常处理 |\r\n| A06 | 易受攻击和过时组件（Vulnerable Components） | 已知CVE/过时依赖 | ?? Warning | 对比package.json/lock文件与NVD数据库 |\r\n| A07 | 身份识别和认证失效（Identification and Authentication Failures） | 弱密码策略/会话固定/无MFA | ?? Critical | 检查认证中间件配置/密码哈希算法 |\r\n| A08 | 软件和数据完整性故障（Software and Data Integrity Failures） | 不可信反序列化/CI/CD污染 | ?? Warning | 检查反序列化调用/流水线配置 |\r\n| A09 | 安全日志和监控故障（Security Logging and Monitoring Failures） | 无审计日志/日志未集中 | ?? Suggestion | 检查关键操作是否有日志记录 |\r\n| A10 | 服务器端请求伪造（Server-Side Request Forgery） | 用户控制的URL请求 | ?? Warning | 检查HTTP客户端调用是否验证目标URL |\r\n\r\n**Claude Code Review 专属检查项（2026）**：\r\n- 提示词注入：检查系统提示是否被用户可控输入影响（CWE-1426）\r\n- 训练数据泄露：检查RAG检索结果是否可能泄露系统提示\r\n- 过度代理：检查Agent是否有不必要的文件读写/代码执行权限\r\n\r\n---\r\n### Step 3 — Generate Review Comments\r\nFor each finding, output a structured review comment:\r\n\r\n```\r\n?? Location: [filename:line_number] or [function_name]\r\n??/??/?? Severity: [Critical / Warning / Suggestion]\r\n?? Issue: [Clear description of the problem]\r\n?? Why it matters: [Impact on security / performance / maintainability]\r\n? Recommended fix:\r\n[code block with the corrected implementation]\r\n```\r\n\r\n### Step 4 — Overall Code Quality Score\r\n\r\n| Dimension | Score (1–10) | Notes |\r\n|-----------|--------------|-------|\r\n| Correctness | — | Logic & edge case handling |\r\n| Security | — | OWASP, secrets, auth |\r\n| Performance | — | Time/space complexity, DB queries |\r\n| Readability | — | Naming, structure, comments |\r\n| Testability | — | Modular, injectable dependencies |\r\n| **Overall** | — | Weighted average |\r\n\r\n### Step 5 — PR Summary Comment (GitHub-style)\r\nGenerate a ready-to-paste GitHub PR description:\r\n\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** ???? (4/5 — Minor issues found)\r\n\r\n### Critical Issues (0)\r\nNo blocking issues found. ?\r\n\r\n### Warnings (2)\r\n- `user_service.py:45` — Potential SQL injection via raw query concatenation\r\n- `auth.py:12` — JWT secret read from environment variable without validation\r\n\r\n### Suggestions (3)\r\n- Consider extracting the validation logic into a shared utility\r\n- Add docstrings to public methods\r\n- Use `dataclasses` instead of plain dicts for `UserProfile`\r\n\r\n### Positive Highlights ??\r\n- Excellent use of dependency injection in `UserController`\r\n- Clear separation of concerns between service and repository layers\r\n```\r\n\r\n## Example Interactions\r\n\r\n**User:**\r\n```python\r\ndef get_user(user_id):\r\n    query = \"SELECT * FROM users WHERE id = \" + user_id\r\n    return db.execute(query)\r\n```\r\n\r\n**Skill response:**\r\n> ?? **Critical — SQL Injection** (`get_user` function)\r\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\r\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\r\n> **Fix:**\r\n> ```python\r\n> def get_user(user_id: int) -> dict | None:\r\n>     query = \"SELECT * FROM users WHERE id = %s\"\r\n>     return db.execute(query, (user_id,))\r\n> ```\r\n\r\n---\r\n\r\n**User:** \"Review this TypeScript React component for performance issues\"\r\n\r\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\r\n\r\n## Supported Languages\r\n\r\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\r\n\r\n## Notes & Constraints\r\n\r\n- Never store or log submitted code — treat all code as potentially sensitive IP\r\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\r\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\r\n- When suggesting fixes, preserve the original code's intent and style conventions\r\n- Flag potential license compliance issues in code using third-party libraries\r\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\r\n\r\n*GitHub: https://github.com/gechengling/ai-code-review-expert*\n\nFile v3.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"3.0.2\",\n  \"publishedAt\": 1781602593065\n}\n\nFile v3.0.2:skill-card.md\n\n## Description: <br>\nAI-powered code review assistant that performs static analysis, identifies security vulnerabilities, enforces coding standards, suggests refactoring patterns, and generates PR review comments. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[gechengling](https://clawhub.ai/user/gechengling) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, tech leads, security engineers, and open source maintainers use this skill to review code snippets, files, diffs, and pull requests for bugs, security issues, performance problems, style violations, and concrete remediation guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may activate on broad code-review phrases and receive sensitive or proprietary code in the agent context. <br>\nMitigation: Use clear prompts for intended reviews and avoid sharing proprietary code, secrets, or sensitive data unless that exposure is acceptable. <br>\nRisk: Generated review findings and suggested fixes may be incomplete or incorrect. <br>\nMitigation: Treat the output as review assistance; require human review, tests, and security validation before applying changes. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/gechengling/ai-code-review-expert) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, configuration, guidance] <br>\n**Output Format:** [Markdown review findings with severity labels, code blocks, quality scoring tables, PR summary text, and optional CI/CD guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include proposed fixes, review comments, checklists, and implementation notes; submitted code should be treated as sensitive.] <br>\n\n## Skill Version(s): <br>\n3.0.2 (source: SKILL.md frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.1: 3 files, 6600 bytes\n\nFiles: skill-card.md (2245b), SKILL.md (8998b), _meta.json (140b)\n\nFile v3.0.1:SKILL.md\n\n---\nname: AI Code Review Expert\ndescription: >\n  AI-powered code review assistant �� perform deep static analysis, identify security\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\n  best practices, AI code reviewer, CI/CD, �������, ��������, �����ع�, ��ȫɨ��,\n  pull request, ��̬����, ����淶.\nversion: \"3.0.1\"\n---\n\n# AI Code Review Expert\n\n> Automated, opinionated, actionable �� code reviews that actually ship better software.\n\n## What This Skill Does\n\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\n\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\n- **Generates actionable PR review comments** in the style of senior engineers\n- **Explains WHY a change is problematic** �� not just \"this is wrong\"\n- **Suggests concrete fixes** with alternative code implementations\n- **Enforces team coding standards** when you provide a style guide or tech stack\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\n- **Rates code quality** with a structured rubric\n\n## Trigger Words\n\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, �������, ������, ������, ��������, �ع�����, ��ȫ©��, review this PR, ���ҿ�������\n\n## Target Users\n\n- Software engineers seeking a second opinion before submitting PRs\n- Tech leads establishing automated review standards\n- Junior developers learning best practices through detailed feedback\n- Security engineers adding SAST to their CI/CD pipeline\n- Open source maintainers reviewing community contributions\n\n## Workflow\n\n### �������ݣ�2026�棩\n**Step 2 ��������������2026��**��\n- LangGraph v1.0����������״̬��������/���ڼ���/����ָ����������������ҵ������֧��Kubernetes�Զ������ݣ�GitHub Starsͻ��85K\n- CrewAI v1.10��������Э����֧��6�ֽ�ɫ����+����������ţ�����20+��ҵ����������Slack/Notion/Airtable/GitHub����2026��Q1���������ĵ�\n- Claude Agent SDK / OpenAI Agents SDK����Աȣ����ߵ���׼ȷ��(94% vs 91%)/������������(78% vs 82%)/�ɱ�Ч��(��0.8/ǧToken vs ��1.2/ǧToken)����ά��ȫ������\n- MCP(Model Context Protocol)��̬������50+�ٷ�����������GitHub/Slack/Notion/Postgres�ȣ���ҵ�ڲ�MCPע�����Ϊ�»�����ʩ\n- LLM��������֮ս��Gemini 2M Token / Claude 200K / GPT-4o 128K����ѡ��ָ�ϣ���Խ��ڳ��ĵ�(�й���/�걨)�������������Լ۱ȷ���\n\n---\n\n## Step 1 �� Context Gathering\nAsk the user for (or infer from the code):\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\n- **Review focus** (security? performance? readability? all?)\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\n\n### Step 2 �� Multi-Dimension Analysis\nAnalyze the provided code across these dimensions:\n\n#### ?? Critical (Blocking)\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\n- Logic errors that will cause crashes or data corruption\n- Race conditions and concurrency bugs\n\n#### ?? Warning (Should Fix)\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\n- Error handling gaps (unhandled exceptions, missing null checks)\n- Code duplications (DRY violations)\n- Deprecated API usage\n\n#### ?? Suggestion (Nice to Have)\n- Readability improvements (naming, comments, structure)\n- Test coverage gaps\n- Opportunity to apply design patterns\n- Minor style inconsistencies\n\n### OWASP Top 10 2025 ����嵥��AI�������ز飩\n\n| # | ©������ | ���ؼ���/ģʽ | ���ض� | AI������ⷽ�� |\n|---|---------|---------------|--------|---------------|\n| A01 | Ȩ�޿���ʧЧ��Broken Access Control�� | δ��Ȩ����/IDOR/·������ | ?? Critical | ���·��/API�˵��Ƿ�ȱ��Ȩ��ע����м�� |\n| A02 | ����ʧ�ܣ�Cryptographic Failure�� | Ӳ������Կ/����ϣ/���Ĵ��� | ?? Critical | ɨ���ַ�������/�������ʽƥ����Կģʽ |\n| A03 | ע�빥����Injection�� | SQLƴ��/NoSQLע��/����ע�� | ?? Critical | ����ַ���ƴ�ӽ����ѯ/exec/system���� |\n| A04 | ����ȫ��ƣ�Insecure Design�� | ȱ����������/����֤��/�߼�©�� | ?? Warning | ���API�˵��Ƿ�ȱ��RateLimit/ Captcha |\n| A05 | ��ȫ���ô���Security Misconfiguration�� | Ĭ��ƾ��/���Ŷ˿�/��ϸ���� | ?? Warning | ��������ļ�/��������/�쳣���� |\n| A06 | ���ܹ����͹�ʱ�����Vulnerable Components�� | ��֪CVE/��ʱ���� | ?? Warning | �Ա�package.json/lock�ļ���NVD���ݿ� |\n| A07 | ����ʶ�����֤ʧЧ��Identification and Authentication Failures�� | ���������/�Ự�̶�/��MFA | ?? Critical | �����֤�м������/�����ϣ�㷨 |\n| A08 | ���������������Թ��ϣ�Software and Data Integrity Failures�� | �����ŷ����л�/CI/CD��Ⱦ | ?? Warning | ��鷴���л�����/��ˮ������ |\n| A09 | ��ȫ��־�ͼ�ع��ϣ�Security Logging and Monitoring Failures�� | �������־/��־δ���� | ?? Suggestion | ���ؼ������Ƿ�����־��¼ |\n| A10 | ������������α�죨Server-Side Request Forgery�� | �û����Ƶ�URL���� | ?? Warning | ���HTTP�ͻ��˵����Ƿ���֤Ŀ��URL |\n\n**Claude Code Review ר������2026��**��\n- ��ʾ��ע�룺���ϵͳ��ʾ�Ƿ��û��ɿ�����Ӱ�죨CWE-1426��\n- ѵ������й¶�����RAG��������Ƿ����й¶ϵͳ��ʾ\n- ���ȴ��������Agent�Ƿ��в���Ҫ���ļ���д/����ִ��Ȩ��\n\n---\n### Step 3 �� Generate Review Comments\nFor each finding, output a structured review comment:\n\n```\n?? Location: [filename:line_number] or [function_name]\n??/??/?? Severity: [Critical / Warning / Suggestion]\n?? Issue: [Clear description of the problem]\n?? Why it matters: [Impact on security / performance / maintainability]\n? Recommended fix:\n[code block with the corrected implementation]\n```\n\n### Step 4 �� Overall Code Quality Score\n\n| Dimension | Score (1�C10) | Notes |\n|-----------|--------------|-------|\n| Correctness | �� | Logic & edge case handling |\n| Security | �� | OWASP, secrets, auth |\n| Performance | �� | Time/space complexity, DB queries |\n| Readability | �� | Naming, structure, comments |\n| Testability | �� | Modular, injectable dependencies |\n| **Overall** | �� | Weighted average |\n\n### Step 5 �� PR Summary Comment (GitHub-style)\nGenerate a ready-to-paste GitHub PR description:\n\n```markdown\n## Code Review Summary\n\n**Reviewed by:** AI Code Review Expert\n**Date:** [today]\n**Overall:** ???? (4/5 �� Minor issues found)\n\n### Critical Issues (0)\nNo blocking issues found. ?\n\n### Warnings (2)\n- `user_service.py:45` �� Potential SQL injection via raw query concatenation\n- `auth.py:12` �� JWT secret read from environment variable without validation\n\n### Suggestions (3)\n- Consider extracting the validation logic into a shared utility\n- Add docstrings to public methods\n- Use `dataclasses` instead of plain dicts for `UserProfile`\n\n### Positive Highlights ??\n- Excellent use of dependency injection in `UserController`\n- Clear separation of concerns between service and repository layers\n```\n\n## Example Interactions\n\n**User:**\n```python\ndef get_user(user_id):\n    query = \"SELECT * FROM users WHERE id = \" + user_id\n    return db.execute(query)\n```\n\n**Skill response:**\n> ?? **Critical �� SQL Injection** (`get_user` function)\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\n> **Fix:**\n> ```python\n> def get_user(user_id: int) -> dict | None:\n>     query = \"SELECT * FROM users WHERE id = %s\"\n>     return db.execute(query, (user_id,))\n> ```\n\n---\n\n**User:** \"Review this TypeScript React component for performance issues\"\n\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\n\n## Supported Languages\n\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\n\n## Notes & Constraints\n\n- Never store or log submitted code �� treat all code as potentially sensitive IP\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\n- When suggesting fixes, preserve the original code's intent and style conventions\n- Flag potential license compliance issues in code using third-party libraries\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\n\n*GitHub: https://github.com/gechengling/ai-code-review-expert*\n\nFile v3.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"3.0.1\",\n  \"publishedAt\": 1779862019164\n}\n\nFile v3.0.1:skill-card.md\n\n## Description: <br>\nAI Code Review Expert helps review code snippets, files, and pull request diffs for bugs, security issues, performance concerns, style problems, and refactoring opportunities. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[gechengling](https://clawhub.ai/user/gechengling) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, tech leads, security engineers, and open source maintainers use this skill to get structured code review feedback, ready-to-paste pull request comments, security-focused findings, and concrete fix suggestions. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad development trigger phrases may activate the skill more often than expected. <br>\nMitigation: Confirm the intended review scope before relying on the generated findings or comments. <br>\nRisk: Submitted code may contain sensitive intellectual property, secrets, or private implementation details. <br>\nMitigation: Provide only code intended for review and remove credentials or other sensitive data before use. <br>\nRisk: Garbled non-English text in the artifact may reduce clarity in some workflow sections. <br>\nMitigation: Use the clear English review workflow and manually check generated recommendations before applying them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/gechengling/ai-code-review-expert) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, configuration, guidance] <br>\n**Output Format:** [Markdown review comments with code blocks, severity labels, summary tables, and pull request summary text.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include file locations, code quality scores, suggested fixes, and CI/CD integration guidance.] <br>\n\n## Skill Version(s): <br>\n3.0.1 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.0: 2 files, 4515 bytes\n\nFiles: SKILL.md (8627b), _meta.json (140b)\n\nFile v3.0.0:SKILL.md\n\n---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.0\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## Step 1 — Context Gathering\r\nAsk the user for (or infer from the code):\r\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\r\n- **Review focus** (security? performance? readability? all?)\r\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\r\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\r\n\r\n### Step 2 — Multi-Dimension Analysis\r\nAnalyze the provided code across these dimensions:\r\n\r\n#### 🔴 Critical (Blocking)\r\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\r\n- Logic errors that will cause crashes or data corruption\r\n- Race conditions and concurrency bugs\r\n\r\n#### 🟡 Warning (Should Fix)\r\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\r\n- Error handling gaps (unhandled exceptions, missing null checks)\r\n- Code duplications (DRY violations)\r\n- Deprecated API usage\r\n\r\n#### 🟢 Suggestion (Nice to Have)\r\n- Readability improvements (naming, comments, structure)\r\n- Test coverage gaps\r\n- Opportunity to apply design patterns\r\n- Minor style inconsistencies\r\n\r\n### Step 3 — Generate Review Comments\r\nFor each finding, output a structured review comment:\r\n\r\n```\r\n📍 Location: [filename:line_number] or [function_name]\r\n🔴/🟡/🟢 Severity: [Critical / Warning / Suggestion]\r\n📝 Issue: [Clear description of the problem]\r\n💡 Why it matters: [Impact on security / performance / maintainability]\r\n✅ Recommended fix:\r\n[code block with the corrected implementation]\r\n```\r\n\r\n### Step 4 — Overall Code Quality Score\r\n\r\n| Dimension | Score (1–10) | Notes |\r\n|-----------|--------------|-------|\r\n| Correctness | — | Logic & edge case handling |\r\n| Security | — | OWASP, secrets, auth |\r\n| Performance | — | Time/space complexity, DB queries |\r\n| Readability | — | Naming, structure, comments |\r\n| Testability | — | Modular, injectable dependencies |\r\n| **Overall** | — | Weighted average |\r\n\r\n### Step 5 — PR Summary Comment (GitHub-style)\r\nGenerate a ready-to-paste GitHub PR description:\r\n\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** ⭐⭐⭐⭐ (4/5 — Minor issues found)\r\n\r\n### Critical Issues (0)\r\nNo blocking issues found. ✅\r\n\r\n### Warnings (2)\r\n- `user_service.py:45` — Potential SQL injection via raw query concatenation\r\n- `auth.py:12` — JWT secret read from environment variable without validation\r\n\r\n### Suggestions (3)\r\n- Consider extracting the validation logic into a shared utility\r\n- Add docstrings to public methods\r\n- Use `dataclasses` instead of plain dicts for `UserProfile`\r\n\r\n### Positive Highlights 🌟\r\n- Excellent use of dependency injection in `UserController`\r\n- Clear separation of concerns between service and repository layers\r\n```\r\n\r\n## Example Interactions\r\n\r\n**User:**\r\n```python\r\ndef get_user(user_id):\r\n    query = \"SELECT * FROM users WHERE id = \" + user_id\r\n    return db.execute(query)\r\n```\r\n\r\n**Skill response:**\r\n> 🔴 **Critical — SQL Injection** (`get_user` function)\r\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\r\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\r\n> **Fix:**\r\n> ```python\r\n> def get_user(user_id: int) -> dict | None:\r\n>     query = \"SELECT * FROM users WHERE id = %s\"\r\n>     return db.execute(query, (user_id,))\r\n> ```\r\n\r\n---\r\n\r\n**User:** \"Review this TypeScript React component for performance issues\"\r\n\r\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\r\n\r\n## Supported Languages\r\n\r\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\r\n\r\n## Notes & Constraints\r\n\r\n- Never store or log submitted code — treat all code as potentially sensitive IP\r\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\r\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\r\n- When suggesting fixes, preserve the original code's intent and style conventions\r\n- Flag potential license compliance issues in code using third-party libraries\r\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\n\nFile v3.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"3.0.0\",\n  \"publishedAt\": 1779709917833\n}\n\nArchive v1.0.1: 2 files, 4515 bytes\n\nFiles: SKILL.md (8627b), _meta.json (140b)\n\nFile v1.0.1:SKILL.md\n\n---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.0\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## Step 1 — Context Gathering\r\nAsk the user for (or infer from the code):\r\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\r\n- **Review focus** (security? performance? readability? all?)\r\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\r\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\r\n\r\n### Step 2 — Multi-Dimension Analysis\r\nAnalyze the provided code across these dimensions:\r\n\r\n#### 🔴 Critical (Blocking)\r\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\r\n- Logic errors that will cause crashes or data corruption\r\n- Race conditions and concurrency bugs\r\n\r\n#### 🟡 Warning (Should Fix)\r\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\r\n- Error handling gaps (unhandled exceptions, missing null checks)\r\n- Code duplications (DRY violations)\r\n- Deprecated API usage\r\n\r\n#### 🟢 Suggestion (Nice to Have)\r\n- Readability improvements (naming, comments, structure)\r\n- Test coverage gaps\r\n- Opportunity to apply design patterns\r\n- Minor style inconsistencies\r\n\r\n### Step 3 — Generate Review Comments\r\nFor each finding, output a structured review comment:\r\n\r\n```\r\n📍 Location: [filename:line_number] or [function_name]\r\n🔴/🟡/🟢 Severity: [Critical / Warning / Suggestion]\r\n📝 Issue: [Clear description of the problem]\r\n💡 Why it matters: [Impact on security / performance / maintainability]\r\n✅ Recommended fix:\r\n[code block with the corrected implementation]\r\n```\r\n\r\n### Step 4 — Overall Code Quality Score\r\n\r\n| Dimension | Score (1–10) | Notes |\r\n|-----------|--------------|-------|\r\n| Correctness | — | Logic & edge case handling |\r\n| Security | — | OWASP, secrets, auth |\r\n| Performance | — | Time/space complexity, DB queries |\r\n| Readability | — | Naming, structure, comments |\r\n| Testability | — | Modular, injectable dependencies |\r\n| **Overall** | — | Weighted average |\r\n\r\n### Step 5 — PR Summary Comment (GitHub-style)\r\nGenerate a ready-to-paste GitHub PR description:\r\n\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** ⭐⭐⭐⭐ (4/5 — Minor issues found)\r\n\r\n### Critical Issues (0)\r\nNo blocking issues found. ✅\r\n\r\n### Warnings (2)\r\n- `user_service.py:45` — Potential SQL injection via raw query concatenation\r\n- `auth.py:12` — JWT secret read from environment variable without validation\r\n\r\n### Suggestions (3)\r\n- Consider extracting the validation logic into a shared utility\r\n- Add docstrings to public methods\r\n- Use `dataclasses` instead of plain dicts for `UserProfile`\r\n\r\n### Positive Highlights 🌟\r\n- Excellent use of dependency injection in `UserController`\r\n- Clear separation of concerns between service and repository layers\r\n```\r\n\r\n## Example Interactions\r\n\r\n**User:**\r\n```python\r\ndef get_user(user_id):\r\n    query = \"SELECT * FROM users WHERE id = \" + user_id\r\n    return db.execute(query)\r\n```\r\n\r\n**Skill response:**\r\n> 🔴 **Critical — SQL Injection** (`get_user` function)\r\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\r\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\r\n> **Fix:**\r\n> ```python\r\n> def get_user(user_id: int) -> dict | None:\r\n>     query = \"SELECT * FROM users WHERE id = %s\"\r\n>     return db.execute(query, (user_id,))\r\n> ```\r\n\r\n---\r\n\r\n**User:** \"Review this TypeScript React component for performance issues\"\r\n\r\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\r\n\r\n## Supported Languages\r\n\r\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\r\n\r\n## Notes & Constraints\r\n\r\n- Never store or log submitted code — treat all code as potentially sensitive IP\r\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\r\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\r\n- When suggesting fixes, preserve the original code's intent and style conventions\r\n- Flag potential license compliance issues in code using third-party libraries\r\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778887644109\n}\n\nArchive v1.0.0: 2 files, 4515 bytes\n\nFiles: SKILL.md (8627b), _meta.json (140b)\n\nFile v1.0.0:SKILL.md\n\n---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.0\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 82%)/成本效率(¥0.8/千Token vs ¥1.2/千Token)三大维度全面评测\r\n- MCP(Model Context Protocol)生态爆发：50+官方服务器覆盖GitHub/Slack/Notion/Postgres等，企业内部MCP注册表成为新基础设施\r\n- LLM长上下文之战：Gemini 2M Token / Claude 200K / GPT-4o 128K技术选型指南，针对金融长文档(招股书/年报)场景给出最优性价比方案\r\n\r\n---\r\n\r\n## Step 1 — Context Gathering\r\nAsk the user for (or infer from the code):\r\n- **Language & framework** (Python/FastAPI? TypeScript/React? Java/Spring?)\r\n- **Review focus** (security? performance? readability? all?)\r\n- **Code context** (is this a snippet, a full file, or a diff/PR?)\r\n- **Team standards** (any style guide? e.g., Google Java Style, PEP 8, Airbnb JS?)\r\n\r\n### Step 2 — Multi-Dimension Analysis\r\nAnalyze the provided code across these dimensions:\r\n\r\n#### 🔴 Critical (Blocking)\r\n- Security vulnerabilities (SQL injection, XSS, IDOR, hardcoded secrets, insecure deserialization)\r\n- Logic errors that will cause crashes or data corruption\r\n- Race conditions and concurrency bugs\r\n\r\n#### 🟡 Warning (Should Fix)\r\n- Performance anti-patterns (N+1 queries, unnecessary loops, memory leaks)\r\n- Error handling gaps (unhandled exceptions, missing null checks)\r\n- Code duplications (DRY violations)\r\n- Deprecated API usage\r\n\r\n#### 🟢 Suggestion (Nice to Have)\r\n- Readability improvements (naming, comments, structure)\r\n- Test coverage gaps\r\n- Opportunity to apply design patterns\r\n- Minor style inconsistencies\r\n\r\n### Step 3 — Generate Review Comments\r\nFor each finding, output a structured review comment:\r\n\r\n```\r\n📍 Location: [filename:line_number] or [function_name]\r\n🔴/🟡/🟢 Severity: [Critical / Warning / Suggestion]\r\n📝 Issue: [Clear description of the problem]\r\n💡 Why it matters: [Impact on security / performance / maintainability]\r\n✅ Recommended fix:\r\n[code block with the corrected implementation]\r\n```\r\n\r\n### Step 4 — Overall Code Quality Score\r\n\r\n| Dimension | Score (1–10) | Notes |\r\n|-----------|--------------|-------|\r\n| Correctness | — | Logic & edge case handling |\r\n| Security | — | OWASP, secrets, auth |\r\n| Performance | — | Time/space complexity, DB queries |\r\n| Readability | — | Naming, structure, comments |\r\n| Testability | — | Modular, injectable dependencies |\r\n| **Overall** | — | Weighted average |\r\n\r\n### Step 5 — PR Summary Comment (GitHub-style)\r\nGenerate a ready-to-paste GitHub PR description:\r\n\r\n```markdown\r\n## Code Review Summary\r\n\r\n**Reviewed by:** AI Code Review Expert\r\n**Date:** [today]\r\n**Overall:** ⭐⭐⭐⭐ (4/5 — Minor issues found)\r\n\r\n### Critical Issues (0)\r\nNo blocking issues found. ✅\r\n\r\n### Warnings (2)\r\n- `user_service.py:45` — Potential SQL injection via raw query concatenation\r\n- `auth.py:12` — JWT secret read from environment variable without validation\r\n\r\n### Suggestions (3)\r\n- Consider extracting the validation logic into a shared utility\r\n- Add docstrings to public methods\r\n- Use `dataclasses` instead of plain dicts for `UserProfile`\r\n\r\n### Positive Highlights 🌟\r\n- Excellent use of dependency injection in `UserController`\r\n- Clear separation of concerns between service and repository layers\r\n```\r\n\r\n## Example Interactions\r\n\r\n**User:**\r\n```python\r\ndef get_user(user_id):\r\n    query = \"SELECT * FROM users WHERE id = \" + user_id\r\n    return db.execute(query)\r\n```\r\n\r\n**Skill response:**\r\n> 🔴 **Critical — SQL Injection** (`get_user` function)\r\n> **Issue:** String concatenation in SQL queries allows attackers to inject malicious SQL.\r\n> **Impact:** Complete database compromise (data theft, deletion, admin escalation).\r\n> **Fix:**\r\n> ```python\r\n> def get_user(user_id: int) -> dict | None:\r\n>     query = \"SELECT * FROM users WHERE id = %s\"\r\n>     return db.execute(query, (user_id,))\r\n> ```\r\n\r\n---\r\n\r\n**User:** \"Review this TypeScript React component for performance issues\"\r\n\r\n**Skill response:** Identifies missing `useMemo`/`useCallback` wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.\r\n\r\n## Supported Languages\r\n\r\nPython, JavaScript, TypeScript, Java, Kotlin, Go, Rust, C/C++, C#, Ruby, PHP, Swift, SQL, Shell/Bash, Terraform/HCL, Dockerfile, YAML/JSON configs\r\n\r\n## Notes & Constraints\r\n\r\n- Never store or log submitted code — treat all code as potentially sensitive IP\r\n- For **large files** (>300 lines), ask the user to focus on a specific function/section\r\n- Security reviews follow **OWASP Top 10 2025** and **CWE Top 25**\r\n- When suggesting fixes, preserve the original code's intent and style conventions\r\n- Flag potential license compliance issues in code using third-party libraries\r\n- For CI/CD integration guidance, explain how to hook this workflow into GitHub Actions or GitLab CI\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778854317858\n}","readmeExcerpt":"Skill: AI Code Review Expert Owner: gechengling Summary: AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"?? Location: [filename:line_number] or [function_name]\n??/??/?? Severity: [Critical / Warning / Suggestion]\n?? Issue: [Clear description of the problem]\n?? Why it matters: [Impact on security / performance / maintainability]\n? Recommended fix:\n[code block with the corrected implementation]"},{"language":"markdown","snippet":"## Code Review Summary\n\n**Reviewed by:** AI Code Review Expert\n**Date:** [today]\n**Overall:** ???? (4/5 �� Minor issues found)\n\n### Critical Issues (0)\nNo blocking issues found. ?\n\n### Warnings (2)\n- `user_service.py:45` �� Potential SQL injection via raw query concatenation\n- `auth.py:12` �� JWT secret read from environment variable without validation\n\n### Suggestions (3)\n- Consider extracting the validation logic into a shared utility\n- Add docstrings to public methods\n- Use `dataclasses` instead of plain dicts for `UserProfile`\n\n### Positive Highlights ??\n- Excellent use of dependency injection in `UserController`\n- Clear separation of concerns between service and repository layers"},{"language":"python","snippet":"def get_user(user_id):\n    query = \"SELECT * FROM users WHERE id = \" + user_id\n    return db.execute(query)"},{"language":"python","snippet":"> def get_user(user_id: int) -> dict | None:\n>     query = \"SELECT * FROM users WHERE id = %s\"\n>     return db.execute(query, (user_id,))\n>"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: AI Code Review Expert\r\ndescription: >\r\n  AI-powered code review assistant — perform deep static analysis, identify security\r\n  vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate\r\n  PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more.\r\n  Integrates with GitHub PR workflows. Keywords: code review, static analysis, security\r\n  scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell,\r\n  best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描,\r\n  pull request, 静态分析, 代码规范.\r\nversion: \"3.0.3\"\r\n---\r\n\r\n# AI Code Review Expert\r\n\r\n> Automated, opinionated, actionable — code reviews that actually ship better software.\r\n\r\n## 数据最小化声明（每次审查开始前默认生效）\r\n\r\n代码评审是本 Skill 唯一的处理对象。为降低敏感信息暴露面，请遵循：\r\n\r\n- **只提交需要评审的片段**：优先提交单个函数、单个 diff 或单个文件；不要把整个仓库、`.env`、密钥文件、生产数据样本整包贴入。\r\n- **提交前自行脱敏**：把真实域名、账号、Token、客户名称替换为 `example.com`、`user_001`、`<REDACTED>` 等占位符。审查结论基于代码结构，脱敏不影响判断。\r\n- **评审产物不外发**：本 Skill 产出的评论、评分、修复建议仅在对话中返回给用户；是否粘贴到 PR、Issue、工单系统，由用户自行决定并确认。若用户要求\"直接生成 PR 描述\"，先输出完整文本供用户预览，经用户确认后再使用。\r\n- **本 Skill 不连接代码托管平台、不执行代码、不写入仓库文件**。文中出现的代码片段、命令行示例均为**供用户在自己环境中参考运行的材料**，本 Skill 本身不会执行它们。\r\n\r\n## What This Skill Does\r\n\r\nIn 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on *how* to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:\r\n\r\n- **Reviews code snippets or diffs** for bugs, security issues, performance problems, and style violations\r\n- **Generates actionable PR review comments** in the style of senior engineers\r\n- **Explains WHY a change is problematic** — not just \"this is wrong\"\r\n- **Suggests concrete fixes** with alternative code implementations\r\n- **Enforces team coding standards** when you provide a style guide or tech stack\r\n- **Performs security-focused reviews** (OWASP Top 10, injection, auth flaws, secrets leakage)\r\n- **Rates code quality** with a structured rubric\r\n\r\n## Trigger Words\r\n\r\nCode review, PR review, review my code, check this code, static analysis, code smell, refactor, security scan, find bugs, SAST, pull request feedback, code quality check, 代码审查, 审查代码, 代码检查, 代码质量, 重构建议, 安全漏洞, review this PR, 帮我看看代码\r\n\r\n## Target Users\r\n\r\n- Software engineers seeking a second opinion before submitting PRs\r\n- Tech leads establishing automated review standards\r\n- Junior developers learning best practices through detailed feedback\r\n- Security engineers adding SAST to their CI/CD pipeline\r\n- Open source maintainers reviewing community contributions\r\n\r\n## Workflow\r\n\r\n### 新增内容（2026版）\r\n**Step 2 新增技术评估（2026）**：\r\n- LangGraph v1.0生产就绪：状态机工作流/长期记忆/错误恢复三大核心能力，企业级部署支持Kubernetes自动扩缩容，GitHub Stars突破85K\r\n- CrewAI v1.10多智能体协作：支持6种角色类型+并行任务编排，内置20+企业级连接器（Slack/Notion/Airtable/GitHub），2026年Q1新增中文文档\r\n- Claude Agent SDK / OpenAI Agents SDK横向对比：工具调用准确率(94% vs 91%)/上下文利用率(78% vs 8"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"ai-code-review-expert\",\n  \"version\": \"3.0.3\",\n  \"publishedAt\": 1789535993771\n}"},{"path":"skill-card.md","content":"## Description:\n\nAI Code Review Expert helps agents review code snippets and diffs for bugs, security issues, performance concerns, style violations, refactoring opportunities, and PR-ready feedback.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[gechengling](https://clawhub.ai/user/gechengling)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, tech leads, security engineers, and maintainers use this skill to get structured code review findings, concrete fixes, quality scoring, and PR summary comments before merging changes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Users may share more source code, secrets, customer data, or production samples than the review requires.\n\nMitigation: Submit only the smallest relevant snippet, file, or diff and redact tokens, credentials, customer identifiers, and production data before review.\n\nRisk: Broad trigger phrases such as 'check this code' may start a review workflow before the user intends to share sensitive material.\n\nMitigation: Confirm the review intent and scope before providing sensitive source code or repository context.\n\nRisk: Suggested fixes, PR comments, and shell commands may be context-dependent or require validation before use.\n\nMitigation: Review proposed changes locally, run project tests or security checks, and have a human reviewer approve changes before applying them.\n\n## Reference(s):\n\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance]\n\n**Output Format:** [Markdown review comments with severity labels, explanations, code blocks, scoring tables, and PR summary text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include suggested fixes, local verification commands, security review notes, and license compliance prompts.]\n\n## Skill Version(s):\n\n3.0.3 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring, PR review, code quality, SAST, CodeRabbit, CodiumAI, code smell, best practices, AI code reviewer, CI/CD, 代码审查, 代码质量, 代码重构, 安全扫描, pull request, 静态分析, 代码规范. Skill: AI Code Review Expert Owner: gechengling Summary: AI-powered code review assistant — perform deep static analysis, identify security vulnerabilities, enforce coding standards, suggest refactoring patterns, and generate PR review comments. Supports Python, JavaScript, TypeScript, Java, Go, Rust, and more. Integrates with GitHub PR workflows. Keywords: code review, static analysis, security scanning, refactoring","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1317,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T10:47:30.632Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:31:41.896Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}