review-code

GitHub

针对OpenAEV项目的PR代码审查流程,涵盖范围评估、元数据检查、构建验证、架构对齐、代码质量、测试覆盖及专家代理委派。

.github/skills/review-code/SKILL.md OpenAEV-Platform/openaev

Trigger Scenarios

收到Pull Request需要审查 执行代码合并前检查

Install

npx skills add OpenAEV-Platform/openaev --skill review-code -g -y
More Options

Non-standard path

npx skills add https://github.com/OpenAEV-Platform/openaev/tree/main/.github/skills/review-code -g -y

Use without installing

npx skills use OpenAEV-Platform/openaev@review-code

指定 Agent (Claude Code)

npx skills add OpenAEV-Platform/openaev --skill review-code -a claude-code -g -y

安装 repo 全部 skill

npx skills add OpenAEV-Platform/openaev --all -g -y

预览 repo 内 skill

npx skills add OpenAEV-Platform/openaev --list

SKILL.md

Frontmatter
{
    "name": "review-code",
    "description": "Step-by-step general code review procedure for OpenAEV pull requests. Covers architecture, conventions, code quality, and delegation to specialized agents."
}

Review Code

Step 1 — Assess PR scope

# Count changed files and lines
git diff --stat HEAD~1
  • If >500 lines changed: flag for splitting before detailed review
  • If >20 files changed: flag for splitting before detailed review

Step 2 — Check PR metadata

Verify:

  • ☐ PR title follows conventional commits (type(scope?): description (#issue) — NO [context] prefix; [context] is for commit messages only)
  • ☐ PR description explains WHAT and WHY
  • ☐ Linked issue/ticket exists

Step 3 — Check build

mvn spotless:check -pl openaev-api
mvn compile -pl openaev-api -q

If build fails: stop review, report build failure.

For frontend changes:

cd openaev-front && yarn check-ts && yarn lint

Step 4 — Review architecture alignment

# Check for entity exposure in API layer (should use DTOs)
grep -rn "import io.openaev.database.model" openaev-api/src/main/java/io/openaev/api/ openaev-api/src/main/java/io/openaev/rest/ --include="*.java" | grep -v "Action\|ResourceType\|Capability\|Filters\|Grant"

Flag any direct entity usage in controllers or API responses (should use Output records + Mapper).

# Check for repository injection in controllers (should go through service)
grep -rn "Repository" openaev-api/src/main/java/io/openaev/api/ openaev-api/src/main/java/io/openaev/rest/ --include="*.java" | grep -v "test\|Test"

Step 5 — Review code quality

# System.out.println (should use @Slf4j)
grep -rn "System.out\|System.err\|printStackTrace" --include="*.java" openaev-api/src/main/java/

# jakarta.transaction.Transactional (should use Spring's)
grep -rn "jakarta.transaction.Transactional" --include="*.java" openaev-api/src/main/java/

# New code in deprecated module
git diff --name-only HEAD~1 | grep "openaev-framework"

# New code in legacy rest/ package (should be in api/)
git diff --name-only HEAD~1 | grep "io/openaev/rest/" | grep -v "test"

Step 6 — Check test coverage

# Are there test files for the changed production files?
for f in $(git diff --name-only HEAD~1 | grep "src/main/java" | grep -v "migration"); do
  testfile=$(echo "$f" | sed 's|src/main/java|src/test/java|' | sed 's|\.java$|Test.java|')
  if [ ! -f "$testfile" ]; then
    echo "⚠️ Missing test: $testfile"
  fi
done

Step 7 — Determine delegation

Based on changed files, determine if specialized agents should run:

# Security signals
grep -rn "AccessControl\|@Filter\|Capability\|Permission\|nativeQuery" --include="*.java" $(git diff --name-only HEAD~1) 2>/dev/null | head -10

# Performance signals
grep -rn "OneToMany\|ManyToMany\|FetchType\|findAll\|Pageable" --include="*.java" $(git diff --name-only HEAD~1) 2>/dev/null | head -10

# Tenancy signals (v1 @Filter + v2 TxCtx/active-tables)
grep -rn "TenantBase\|tenant_id\|TenantContext\|TxCtx\|active-tables\|TenantScopedTransaction\|RequireTenantSelector\|can_access_tenant" --include="*.java" $(git diff --name-only HEAD~1) 2>/dev/null | head -10

# Frontend signals
git diff --name-only HEAD~1 | grep -E "\.tsx$|\.ts$" | head -10

Step 8 — Check common anti-patterns (learned from reviews)

Apply these checks based on past review feedback:

  • Root cause vs workaround: If a bug is backend-originated, don't add frontend workarounds (onError handlers, fallback states). Fix the root cause in the correct layer.
  • String/value duplication: When introducing new methods that share data with existing methods (e.g., logo filenames, config keys), extract the shared value to a private method or constant — never compute the same formatted string in multiple places.
  • Non-critical operations: Startup operations that interact with external services (MinIO, S3, etc.) for non-critical assets (logos, thumbnails) should be best-effort: wrap in try-catch with log.warn so failures don't block application startup.
  • Test proportionality: Don't require tests for small mechanical changes (1-line additions, parameter threading). Tests should be proportionate to the risk and complexity of the change.
  • Pre-existing issues: Don't fix unrelated pre-existing issues (e.g., alt text, parameter naming) in a bug fix PR. Track them as follow-up.

Step 9 — Compile review

Generate the Code Review Summary following the output format defined in code-reviewer.agent.md.

Version History

  • 3.260818.1 Current 2026-08-20 12:00

Same Skill Collection

.github/skills/add-contract-output-type/SKILL.md
.github/skills/add-migration/SKILL.md
.github/skills/add-test/SKILL.md
.github/skills/create-feature-module/SKILL.md
.github/skills/reduce-tx-baseline/SKILL.md
.github/skills/review-docs/SKILL.md
.github/skills/review-frontend/SKILL.md
.github/skills/review-migration/SKILL.md
.github/skills/review-multi-tenancy/SKILL.md
.github/skills/review-performance/SKILL.md
.github/skills/review-security/SKILL.md
.github/skills/activate-tenant-table/SKILL.md

Metadata

Files
0
Version
3.260818.1
Hash
48af1e36
Indexed
2026-08-20 12:00

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-25 00:34
浙ICP备14020137号-1 $방문자$