원클릭으로
code-review
Perform thorough code review with security, quality, and test coverage analysis
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Perform thorough code review with security, quality, and test coverage analysis
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
Build and publish Docker services to container registry (GHCR)
Run scientific and engineering computations using containerized services
Build and publish a new scientific computing service to GHCR. Use when the user wants to add a new package/service like ngspice, fenics, etc.
SOC 직업 분류 기준
| name | code-review |
| description | Perform thorough code review with security, quality, and test coverage analysis |
| triggers | ["review.*(code|pr|pull)","check.*(code|quality)","audit","security.*review","code.*analysis"] |
Perform a comprehensive code review covering security, quality, and test coverage.
If reviewing a PR/diff: Focus on changed files
# Get list of changed files
search(command="glob", pattern="**/*.py") # or relevant extensions
If reviewing a directory: Identify key files
Create a review todo list:
{"todos": [
{"id": "scope", "content": "Define review scope", "status": "in_progress"},
{"id": "security", "content": "Security review", "task_type": "review", "depends_on": ["scope"]},
{"id": "quality", "content": "Code quality review", "depends_on": ["security"]},
{"id": "tests", "content": "Test coverage review", "depends_on": ["quality"]},
{"id": "report", "content": "Write review report", "depends_on": ["tests"], "produces": "file:_outputs/code_review.md"}
]}
Injection Vulnerabilities:
Authentication & Authorization:
Data Exposure:
Search patterns:
# Find potential SQL injection
search(command="grep", pattern="execute.*\\+|format.*SELECT|f\"SELECT")
# Find potential command injection
search(command="grep", pattern="subprocess|os.system|shell=True")
# Find hardcoded secrets
search(command="grep", pattern="password.*=.*[\"']|api_key.*=.*[\"']|secret.*=.*[\"']")
For thorough security review, use a sub-agent:
task(agent_name="reviewer", task="Security review of <files>. Check for: injection vulnerabilities, auth issues, data exposure, insecure dependencies. Report findings with file:line references.")
Code Clarity:
DRY Violations:
Error Handling:
Edge Cases:
Performance:
Check test existence:
search(command="glob", pattern="**/test_*.py|**/*_test.py|**/tests/*.py")
Assess coverage:
Test quality indicators:
assertTrue)Create _outputs/code_review.md with this structure:
# Code Review: [Scope]
**Reviewed:** [date]
**Files:** [count]
## Critical Issues
These MUST be fixed before merge:
- [ ] **[CRITICAL]** [file:line] - [Issue description]
- Impact: [What could go wrong]
- Fix: [Suggested fix]
## Warnings
Should be addressed:
- [ ] **[WARNING]** [file:line] - [Issue description]
- Why: [Reason this matters]
## Suggestions
Nice to have improvements:
- **[SUGGESTION]** [file:line] - [Improvement idea]
## Test Coverage
- [ ] Critical paths covered: [Yes/No]
- [ ] Edge cases tested: [Yes/No]
- [ ] Missing tests: [List]
## Positive Notes
What's done well:
- [Good practice 1]
- [Good practice 2]
## Summary
[Overall assessment and recommendation: Approve / Request Changes / Needs Discussion]