code-quality

GitHub

提供跨语言代码质量检查技能,涵盖静态分析、Lint配置及审查清单,用于确保Rust、TS、Python等代码的规范性与可维护性。

skills/code-quality/SKILL.md waybarrios/opencode-power-pack

Trigger Scenarios

代码审查请求 静态分析工具配置 代码规范检查

Install

npx skills add waybarrios/opencode-power-pack --skill code-quality -g -y
More Options

Use without installing

npx skills use waybarrios/opencode-power-pack@code-quality

指定 Agent (Claude Code)

npx skills add waybarrios/opencode-power-pack --skill code-quality -a claude-code -g -y

安装 repo 全部 skill

npx skills add waybarrios/opencode-power-pack --all -g -y

预览 repo 内 skill

npx skills add waybarrios/opencode-power-pack --list

SKILL.md

Frontmatter
{
    "name": "code-quality",
    "license": "MIT (modified; see UPSTREAMS.json)",
    "description": "Agents should invoke this skill for code reviews, linting\/formatting setup, maintainability checks, complexity concerns, warning cleanup, coding standards, or quality gates in Rust, TypeScript, Python, shell, and mixed repos."
}

Code Quality

Structured code review and quality enforcement across common tech stacks. Checklists, linting strategies, and metrics to keep codebases healthy.

Quick Start

Run a Code Quality Check

  1. Run static analysis: Linters, type checkers, formatters
  2. Review against checklist: Language-specific items below
  3. Check complexity metrics: Cyclomatic < 25, data flow < 25
  4. Report findings: Structured output with severity and recommendations

Linting Configurations

Rust — Clippy Config

Standard clippy configuration (in Cargo.toml or .clippy.toml):

[lints.clippy]
cognitive_complexity = "warn"
pedantic = { level = "deny", priority = -1 }
nursery = { level = "deny", priority = -1 }
unwrap_used = "deny"

Standard commands:

cargo fmt
cargo clippy --all-targets --all-features -- -D warnings
cargo check
cargo test -- --test-threads=1

Key rules to enforce:

  • No .unwrap() in non-test code (use ? or .expect("reason"))
  • All public items have rustdoc (#[warn(missing_docs)])
  • #[must_use] on functions that return values that should be checked
  • When using #[allow(...)], always add a comment explaining why
  • If no good explanation exists for #[allow(...)], fix the issue instead

TypeScript — ESLint + Strict Mode

Recommended tsconfig.json strictness:

{
  "compilerOptions": {
    "strict": true,
    "noUncheckedIndexedAccess": true,
    "noImplicitReturns": true,
    "noFallthroughCasesInSwitch": true,
    "exactOptionalPropertyTypes": true
  }
}

Key rules to enforce:

  • No any — use unknown and type guards instead
  • No // @ts-ignore — fix the type issue or use // @ts-expect-error with explanation
  • Prefer const over let, never use var
  • Use discriminated unions for state modeling
  • Explicit return types on exported functions

Python — Ruff + Mypy

Recommended pyproject.toml:

[tool.ruff]
target-version = "py312"
line-length = 88

[tool.ruff.lint]
select = ["E", "F", "W", "I", "N", "UP", "ANN", "B", "A", "C4", "DTZ", "ISC", "PIE", "PT", "RET", "SIM", "TCH", "ARG", "PTH", "ERA"]

[tool.mypy]
strict = true
warn_return_any = true
warn_unreachable = true

Key rules to enforce:

  • Type hints on all public functions and methods
  • Docstrings on all public classes, functions, and methods
  • Use pathlib.Path over os.path
  • Use uv as package manager
  • No bare except: — always catch specific exceptions

Code Review Checklists

Universal Checklist (All Languages)

Correctness:

  • Does the code do what it claims to do?
  • Are edge cases handled (empty collections, null/None, zero, negative)?
  • Are error paths handled gracefully?
  • Are there any off-by-one errors?

Clarity:

  • Can you understand the code without the PR description?
  • Are variable/function names descriptive and consistent?
  • Are complex sections commented with "why" (not "what")?
  • Is the code self-documenting where possible?

Architecture:

  • Does this change respect existing module boundaries?
  • Is the change at the right abstraction level?
  • Are dependencies reasonable (not pulling in a huge lib for one function)?

Testing:

  • Are new functions/methods covered by tests?
  • Do tests cover edge cases and error paths?
  • Are tests readable and maintainable?

Security (flag for a security follow-up if concerns found):

  • No hardcoded secrets or credentials
  • User input is validated before use
  • No SQL injection, XSS, or path traversal vectors

Rust-Specific Checklist

  • cargo fmt applied
  • cargo clippy clean (pedantic + nursery)
  • No .unwrap() outside tests
  • Error handling uses ? with proper error types
  • Public items have rustdoc comments
  • #[allow(...)] includes explanatory comment
  • New functions have unit tests
  • Cyclomatic complexity < 25 per function
  • Data flow complexity < 25 per function

TypeScript/React-Specific Checklist

  • No any types
  • Strict mode compliance
  • Components have clear prop types
  • Hooks follow rules of hooks
  • No unnecessary re-renders (check memo/callback usage)
  • Bundle impact considered for new dependencies

Django/Python-Specific Checklist

  • Type hints present on public interfaces
  • Ruff + mypy clean
  • No N+1 queries (use select_related/prefetch_related)
  • Migrations are reviewed and reversible
  • No business logic in views (use service layer)

Complexity Metrics

Cyclomatic Complexity

Measures the number of independent paths through code. Recommended threshold: < 25.

Complexity Risk Level Action
1-10 Low Simple, well-structured code
11-20 Moderate Consider simplification if growing
21-24 High Refactoring recommended
25+ Violation Must refactor before merge

How to reduce:

  • Extract helper functions for each branch
  • Use early returns / guard clauses
  • Replace complex conditionals with lookup tables or pattern matching
  • Use strategy pattern for variant-dependent behavior

Data Flow Complexity

Measures how many variables interact within a function. Recommended threshold: < 25.

How to reduce:

  • Extract pure functions that take fewer parameters
  • Group related parameters into structs/objects
  • Split functions that transform data in multiple stages

Measurement Tools

Language Tool Command
Rust cargo clippy (cognitive_complexity) Built into clippy config
TypeScript eslint-plugin-sonarjs Configure complexity rule
Python radon radon cc <file> -s -a
Python ruff Rule C901 (mccabe complexity)

Review Output Format

When delivering a code review:

## Code Review: [PR/File/Module]

**Date:** YYYY-MM-DD

### Summary
[1-2 sentences: overall quality assessment]

### Findings

| # | Severity | File | Line(s) | Finding | Suggestion |
|---|---|---|---|---|---|
| 1 | High | src/app.rs | 45-67 | Cyclomatic complexity 28 (limit: 25) | Extract match arms into helper functions |
| 2 | Medium | src/ui.rs | 120 | Unwrap without context | Use `.expect("reason")` or `?` |

### Positive Observations
[What's well-written — acknowledge good code]

### Metrics
- Linter: [clean / N warnings]
- Tests: [pass / fail]
- Complexity: [within limits / violations noted above]

### Security Notes
[Items to flag for follow-up, if any]

Integration

  • Can run linters, formatters, and type checkers without asking, per the project's AGENTS.md/CLAUDE.md execution policies.
  • Cross-reference: this pack's code-reviewer skill for adversarial review of a focused change set, and design-patterns for fixing complexity violations through better structure.

Version History

  • f198a18 Current 2026-08-16 09:11

Same Skill Collection

skills/agentic-actions-auditor/SKILL.md
skills/agents-md-revise/SKILL.md
skills/ai-slop/SKILL.md
skills/code-architect/SKILL.md
skills/code-explorer/SKILL.md
skills/code-review/SKILL.md
skills/code-reviewer/SKILL.md
skills/codeql/SKILL.md
skills/design-patterns/SKILL.md
skills/differential-review/SKILL.md
skills/feature-dev/SKILL.md
skills/fp-check/SKILL.md
skills/frontend-design/SKILL.md
skills/hf-cli/SKILL.md
skills/hf-cloud-aws-context-discovery/SKILL.md
skills/hf-cloud-python-env-setup/SKILL.md
skills/hf-cloud-sagemaker-deployment-planner/SKILL.md
skills/hf-cloud-sagemaker-iam-preflight/SKILL.md
skills/hf-cloud-sagemaker-production-defaults/SKILL.md
skills/hf-cloud-serving-image-selection/SKILL.md
skills/hf-mem/SKILL.md
skills/huggingface-best/SKILL.md
skills/huggingface-community-evals/SKILL.md
skills/huggingface-datasets/SKILL.md
skills/huggingface-gradio/SKILL.md
skills/huggingface-llm-trainer/SKILL.md
skills/huggingface-local-models/SKILL.md
skills/huggingface-lora-space-builder/SKILL.md
skills/huggingface-paper-publisher/SKILL.md
skills/huggingface-papers/SKILL.md
skills/huggingface-spaces/SKILL.md
skills/huggingface-tool-builder/SKILL.md
skills/huggingface-trackio/SKILL.md
skills/huggingface-vision-trainer/SKILL.md
skills/huggingface-zerogpu/SKILL.md
skills/insecure-defaults/SKILL.md
skills/mcp-builder/SKILL.md
skills/paper-summarizer/SKILL.md
skills/sarif-parsing/SKILL.md
skills/security-review/SKILL.md
skills/security-threat-model/SKILL.md
skills/semgrep-rule-creator/SKILL.md
skills/semgrep-rule-variant-creator/SKILL.md
skills/semgrep/SKILL.md
skills/sharp-edges/SKILL.md
skills/skill-creator/SKILL.md
skills/supply-chain-risk-auditor/SKILL.md
skills/train-sentence-transformers/SKILL.md
skills/transformers-js/SKILL.md

Metadata

Files
0
Version
f198a18
Hash
9751bcf7
Indexed
2026-08-16 09:11

inicio - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-16 18:43
浙ICP备14020137号-1 $mapa de visitantes$