autorenew

SKILL DETAIL

Code Review

Use this skill when you need a risk-driven code review of a PR/diff with severity-ranked findings and actionable fixes; triggers include code review, PR review,.

StatusStable
TypeAtomic Skill
DomainSoftware testing
SDLCTest design
Good forQA / DEV
LanguageChinese / English
EvalsEvals ✓
Synced2026-09-15

Why this Skill

It turns this Skill's method into a quality input that can be executed, reviewed, and reused.

  • Need to review a PR / diff / commit and catch logic, security, financial-loss, or maintainability risks before merge.
  • Risk-driven: prioritize production failures, financial loss, security, and core maintainability — not naming/indent noise.
  • Evidence-based: prefer file path, line, or snippet plus trigger path and impact for each finding.
  • Two gates: require both identifiable code version (for example repository + PR / commit / branch / tag / revision) and reviewable change (for example diff/patch, changed-file contents, or an accessible base-to-head range). Code identity, change content, and role reports cannot substitute for one another.
  • Do not treat a code snippet or role report as code identity, or a PR / commit identifier as the diff; block when either gate is missing.

When to use

Use this Skill
  • Need to review a PR / diff / commit and catch logic, security, financial-loss, or maintainability risks before merge.
  • Need a P0/P1/P2-ranked report with locations and actionable fix guidance.
  • Need a QA / engineering-quality lens beyond author self-review.
Common pitfalls
  • Do not treat a code snippet or role report as code identity, or a PR / commit identifier as the diff; block when either gate is missing.
  • Do not activate Product or UI/UX concerns merely because a report exists; first establish relevance and retain its source.
  • Do not treat every item as equally important, or dump low-value style nits.
  • Do not skip assumptions and information gaps.
  • Do not force refactors outside the change under review.

Input

Minimum Input
  • The current task scope, objective, and subject under review.
Recommended Input
  • Before producing output, read and follow prompts/code-review.md (minimum coverage, output structure, quality bar).
  • When Excel/CSV/JSON/Word is requested: read output-formats.md and honor the format.
  • When a ready-made template fits: use matching files under output-templates/.
  • For deeper review dimensions or severity rubrics: read references/review-dimensions.md.
Optional Context
  • For examples or calibration: read matching files under examples/.
  • For format conversion or helper checks: prefer existing scripts/ over reinventing.
  • For the shortest path: read quick-start.md.
  • For evaluating/regressing this skill: use evals/ with skill-up.

Output

The output follows this Skill's method and makes facts, assumptions, risks, and next steps explicit.

Judge the output value before installing

  1. 01Followed the main prompt's output structure
  2. 02Confirmed both code-identity and reviewable-change gates; if blocked, did not issue a completed review or merge recommendation
  3. 03Minimum coverage focus: change summary, overall risk rating, P0/P1/P2 list, testability/observability, API/contract compatibility, fix order, residual risks and assumptions… (details in main prompt)
  4. 04Covered the minimum checklist, or explained omissions
View full output structure
  1. 05High-risk items have explicit P0/P1 severity with rationale
  2. 06Did not invent details the user did not provide
  3. 07Assumptions and gaps are marked

How It Works

  1. 01Read and follow the main prompt listed under Progressive disclosure (coverage, structure, quality bar).
  2. 02Before reviewing, confirm both an identifiable code version and its reviewable changes; if either is missing, return a blocked result and request the exact material.
  3. 03Add only project context that changes the result: change scope, business goal, stack, upstream/downstream deps, known risks, team norms.
  4. 04Treat role reports as optional, source-identified context; use Product and UI/UX reports only when this change touches their concerns.
  5. 05Default to Markdown; switch formats only when the user asks.

Install & Quick Start

Install command / SHELL
npx skills add \
  https://github.com/naodeng/awesome-qa-skills/tree/main/skills/en/testing-types/code-review
  -g
code-review.prompt
@skill code-review

Using the current project context, produce an actionable result following this Skill.

Additional context:
[Paste project context or requirement]