Conduct context-driven code reviews focusing on quality, testability, and maintainability. Use when reviewing code, providing feedback, or establishing review practices.
Conduct context-driven code reviews focusing on quality, testability, and maintainability. Use when reviewing code, providing feedback, or establishing review practices.
Fast feedback (< 24h) > thorough feedback
</default_to_action>
Quick Reference Card
When to Use
PR code reviews
Pair programming feedback
Establishing team review standards
Mentoring developers
Feedback Priority Levels
Level
Icon
Meaning
Action
Blocker
🔴
Bug/security/crash
Must fix before merge
Major
🟡
Logic issue/test gap
Should fix before merge
Minor
🟢
Style/naming
Nice to fix
Suggestion
💡
Alternative approach
Consider for future
Review Scope Limits
Lines Changed
Recommendation
< 200
Single review session
200-400
Review in chunks
> 400
Request PR split
What to Focus On
✅ Review
❌ Skip
Logic correctness
Formatting (use linter)
Security risks
Naming preferences
Test coverage
Architecture debates
Performance issues
Style opinions
Error handling
Trivial changes
Feedback Templates
Blocker (Must Fix)
🔴 **BLOCKER: SQL Injection Risk**
This query is vulnerable to SQL injection:
```javascript
db.query(`SELECT * FROM users WHERE id = ${userId}`)
Fix: Use parameterized queries:
db.query('SELECT * FROM users WHERE id = ?', [userId])
Why: User input directly in SQL allows attackers to execute arbitrary queries.
### Major (Should Fix)
```markdown
🟡 **MAJOR: Missing Error Handling**
What happens if `fetchUser()` throws? The error bubbles up unhandled.
**Suggestion:** Add try/catch with appropriate error response:
```javascript
try {
const user = await fetchUser(id);
return user;
} catch (error) {
logger.error('Failed to fetch user', { id, error });
throw new NotFoundError('User not found');
}
### Minor (Nice to Fix)
```markdown
🟢 **minor:** Variable name could be clearer
`d` doesn't convey meaning. Consider `daysSinceLastLogin`.
Suggestion (Consider)
💡 **suggestion:** Consider extracting this to a helper
This validation logic appears in 3 places. A `validateEmail()` helper would reduce duplication. Not blocking, but might be worth a follow-up PR.
Prioritize feedback: 🔴 Blocker → 🟡 Major → 🟢 Minor → 💡 Suggestion. Focus on bugs and security, not style. Ask questions, don't command. Review < 400 lines at a time. Fast feedback (< 24h) beats thorough feedback.
With Agents: Agents automate security, performance, and coverage checks, freeing human reviewers to focus on logic and design. Use agents for consistent, fast initial review.