Agent Skills
› langfuse/langfuse
› code-review
code-review
GitHub用于代码审查,聚焦正确性、回归、安全及性能问题。强调测试验证需与风险成比例,避免无效断言,依据严重程度输出发现。
Trigger Scenarios
需要审查代码变更而非实现功能时
检查代码正确性、回归或最佳实践时
Install
npx skills add langfuse/langfuse --skill code-review -g -y
SKILL.md
Frontmatter
{
"name": "code-review",
"description": "Review Langfuse code changes for correctness, regressions, and best practices."
}
Code Review
Use this skill when the task is to review code changes rather than implement a feature.
Start Here
- Read
references/review-checklist.mdfor the repo's canonical review rules. - Read root
AGENTS.mdand the nearest packageAGENTS.mdfor the files under review. - If the review touches ClickHouse, also use the shared
clickhouse-best-practicesskill. - If the review touches backend code, also use the shared
backend-dev-guidelinesskill where relevant. - If the change accepts a user-supplied URL, adds outbound HTTP, introduces a
new integration, touches secrets, RBAC, redirect handling, product
analytics, browser monitoring, or session replay, also use the shared
security-reviewskill. Run itsreferences/checklist.mdbefore signoff.
Review Priorities
Focus on:
- correctness bugs
- behavioral regressions
- security and tenant-isolation risks
- performance issues with real impact
- missing or weak tests for risky changes
- Before calling coverage missing, identify the unique regression each proposed test catches. Do not ask for one whose only assertion would restate the diff — a spacing value, a label — because it costs a file and proves nothing. Prefer merging into the closest existing suite. Flag repeated tests of the same predicate across layers unless each proves a distinct transport, projection, or execution boundary.
Output Expectations
- Findings first, ordered by severity
- File and line references for each finding
- Short summary only after findings
- If no findings, say so explicitly and mention any residual risk or coverage gaps
Scope Guidance
Use references/review-checklist.md for Langfuse-specific checks such as:
- ClickHouse and Postgres migration expectations
- project-scoped tenant isolation checks
- API/Fern consistency
- banner-offset UI positioning
- environment variable access patterns
Do not duplicate those rules in ad hoc prompts or tool-specific command files.
Version History
-
5b59af4
Current 2026-09-23 09:06
调整验证规则以匹配风险程度,明确测试应针对可能退行的行为,区分不确定结果与微小视觉变化,避免生成无意义的冗余测试。
-
f6e56cb
2026-08-29 05:19
在安全审查触发条件中新增了产品分析、浏览器监控和会话回放相关的检查项。
- f7e3c26 2026-08-20 17:47


