Agent skill

Feature-Level Code Review

by dataelement in dataelement/bisheng

Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files.

Apache-2.0Auto-check passedDevelopment

SKILL.md written in Chinese; this summary is our English description.

Install Feature-Level Code Review

skills CLI
$ npx skills add dataelement/bisheng --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dataelement/bisheng code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dataelement/bisheng.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
12k
Token cost
~1k tokens
SKILL.md length
324 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files.

  • Works in 5 steps: 执行 git diff 2.5.0-PM...HEAD --stat… → 执行 git diff 2.5.0-PM...HEAD 获取完整 diff → 对照 Feature 的 spec.md、design.md 和 tasks.md → …
  • Reviewing a finished feature branch before merging it
  • SKILL.md covers 描述, 触发, 审查流程 and 7 维度审查框架, plus 2 more sections
  • Calls git

What it does

This is a pre-merge review for a whole feature rather than a single commit, run with a `--base` branch option. The agent lists the changed files and the full diff between that branch and HEAD, reads the feature's `spec.md`, `design.md` and `tasks.md`, works through seven review dimensions in turn and writes up a review report.

The dimensions are boundary conditions, permissions and authentication, concurrency safety, information leakage, test coverage, code style and documentation sync. The checklists are tuned to the BISHENG codebase, with items such as a layered permission chain backed by OpenFGA, tenant isolation, idempotent Celery tasks, DDD layering and ruff formatting. The documentation check requires a `design.md` and treats a missing one as a blocking issue. The excerpt ends partway through that last dimension.

When your agent uses it

  • Reviewing a finished feature branch before merging it
  • Checking a diff against the feature's spec, design and task files
  • Auditing a change for permission, tenant isolation and data leakage problems

Example prompts

  • “Run a feature-level code review against the release branch before I merge.”
  • “Review this branch against spec.md and tasks.md and report anything blocking.”
  • “Check that the new endpoints enforce authentication and have tests.”

Requirements

  • A Git repository with the base branch available
  • Feature `spec.md`, `design.md` and `tasks.md` files

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 执行 git diff 2.5.0-PM...HEAD --stat 获取变更文件列表
  2. 执行 git diff 2.5.0-PM...HEAD 获取完整 diff
  3. 对照 Feature 的 spec.md、design.md 和 tasks.md
  4. 按 7 维度逐一审查
  5. 输出审查报告

What it can do on your machine

Read from SKILL.md and the folder at commit cb9b77a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Feature-Level Code Review loads about 1k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 324 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dataelement/bisheng at commit cb9b77a, republished under its Apache-2.0 licence (© dataelement). 324 words, ~1,046 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
L2 特性级多维度代码审查。Feature 全部任务完成后执行。 用法:/code-review --base <branch> TRIGGER when: 用户运行 /code-review,或在 merge 前要求特性级代码审查。

Skill: code-review

描述

L2 特性级多维度代码审查。Feature 全部任务完成后执行。

触发

/code-review --base 2.5.0-PM

审查流程

  1. 执行 git diff 2.5.0-PM...HEAD --stat 获取变更文件列表
  2. 执行 git diff 2.5.0-PM...HEAD 获取完整 diff
  3. 对照 Feature 的 spec.md、design.md 和 tasks.md
  4. 按 7 维度逐一审查
  5. 输出审查报告

7 维度审查框架

维度 1:边界条件
检查项说明
null/None 处理外部输入是否校验 None/空字符串
空集合列表/字典为空时是否正确处理(不抛异常)
数值边界分页 page/size 合法性、ID 为 0/-1
字符串长度数据库字段长度限制是否在 API 层校验
超时处理外部调用(LLM/MCP/HTTP)是否设置超时
分页溢出请求超出总页数时返回空列表而非错误
维度 2:权限与认证
检查项说明
认证注入需要认证的端点是否使用 UserPayload = Depends(UserPayload.get_login_user)
五级权限链路是否遵循:super_admin → tenant 归属 → tenant admin → ReBAC → RBAC 菜单
PermissionService权限检查是否走 PermissionService.check() 而非直接查旧表
资源授权创建资源时是否调用 PermissionService.authorize() 写入 owner 元组
tenant_id 隔离跨租户访问是否被阻止(SQLAlchemy event 自动注入)
WebSocket 认证WS 端点是否使用 UserPayload.get_login_user_from_ws
维度 3:并发安全
检查项说明
OpenFGA 双写MySQL + OpenFGA 写入是否有失败补偿(failed_tuples 表)
数据库事务多表写入是否在同一事务内
Celery 幂等异步任务是否支持重试不产生副作用
竞态条件并发创建同名资源是否有唯一约束或乐观锁
会话状态Redis 缓存读写是否考虑过期和并发更新
维度 4:信息泄漏
检查项说明
硬编码敏感信息代码中无明文密码/密钥/token
错误信息异常响应不暴露堆栈/SQL/内部路径
日志脱敏logger 输出中敏感字段已脱敏
前端暴露前端代码不包含后端 IP/密钥/内部 API 路径
tenant_id 泄漏API 响应不向前端返回其他租户的 tenant_id
维度 5:测试覆盖
检查项说明
Service 测试核心 Service 方法有单元测试(mock DAO)
API 测试新端点有集成测试(happy path + 主要 error path)
AC 覆盖spec 中每条 AC 都有对应测试或手动验证
错误路径权限拒绝、参数校验失败等错误路径有测试
测试质量mock 合理,不 mock 掉核心逻辑

务实适配:当前测试基础薄弱,降低阈值但要求核心 Service 方法必须有测试。 前端暂用手动验证替代(tasks.md 中有「手动验证」描述即可)。

维度 6:代码风格
检查项说明
DDD 分层新代码在正确的层级(domain/services vs api/endpoints)
命名一致DAO/Service/错误码命名遵循项目约定
代码重复无复制粘贴式重复逻辑(应提取到 Service 或工具函数)
未使用代码无 dead code、注释掉的代码块、空函数
格式化Python 代码通过 ruff check(hook 自动处理)
维度 7:文档同步(design.md 现状快照)

目的:确保 feature 合入后,新 agent 接手时读 design.md 能 5 分钟建立准确认知 —— 没有过期描述、没有缺失的反直觉坑、没有未声明的对外契约。

检查项说明严重度
design.md 存在feature 目录下有 design.md(按 features/_templates/design.md 起的稿)HIGH(缺失直接 NEEDS_FIX)
决策同步diff 中新增/替换的关键技术决策(数据格式、配对/匹配策略、同步 vs 异步、二进制依赖等)在 §3 方案对比有记录,且给出"何时该重新考虑"HIGH
数据流/契约同步diff 触及 API 路径 / 请求响应字段 / 内部 Service 入参出参 / 数据库新表新字段 / 关键文件职责变化 → §4.1 数据流、§4.2 字段约定、§4.3 模块职责对应章节已更新HIGH
已知坑同步修了一个"代码里看不出的"反直觉 bug(典型:上游字段格式不符合直觉、运行时值与文档不符、必须的兜底逻辑)→ §5 已知坑 表新增一行(带"如果不知道会怎样"+"在哪处理")HIGH
契约/依赖同步新增对外 endpoint / 新依赖 chat/knowledge/permission 等模块的隐式契约 / 新增系统二进制依赖 → §6 Outgoing / Incoming 已补HIGH
修订历史§修订历史 末尾追加了本次 feature 完成的条目(日期 + 改动 + 触发原因)MEDIUM
与 spec 不冲突design.md 对当前实现的描述未与 spec.md AC 矛盾(spec 是不变目标,design 是当前实现,二者口径必须对齐)HIGH

判定要点:

  • 若 design.md 与代码现状偏离 → 必须修复(视为 HIGH),不能合入
  • 仅本地小修小补(不改变对外行为、不引入新坑、不动决策)→ 本维度全 PASS 即可
  • design.md 不存在但已在 SDD 流程要求之内 → HIGH,要求按模板补全后再审

判定规则

结果条件动作
PASS无 HIGH 或 MEDIUM可合并
PASS_WITH_WARNINGS仅 MEDIUM 级可合并,记录待改进
NEEDS_FIX有 HIGH 级修复后重审(最多 2 轮)

输出格式

markdown
# Code Review Report

**Feature**: <feature_name>
**Review scope**: <描述>
**Base branch**: 2.5.0-PM
**Changed files**: <数量>

## Summary

| Dimension | High | Medium | Low | Status |
|-----------|------|--------|-----|--------|
| Boundary Conditions | 0 | 0 | 0 | PASS |
| Permission & Auth | 0 | 0 | 0 | PASS |
| Concurrency Safety | 0 | 0 | 0 | PASS |
| Information Leakage | 0 | 0 | 0 | PASS |
| Test Coverage | 0 | 0 | 0 | PASS |
| Code Style | 0 | 0 | 0 | PASS |
| Docs Sync (design.md) | 0 | 0 | 0 | PASS |

## Findings(如有)

### HIGH
- [Permission] `xxx_endpoint.py:42` — 缺少 PermissionService.check() 调用

### MEDIUM
- [Style] `xxx_service.py:18` — DAO 方法未使用 @classmethod

## Overall: PASS / PASS_WITH_WARNINGS / NEEDS_FIX

© dataelement, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/code-review of dataelement/bisheng.

Open the folder on GitHubat commit cb9b77a

Compare with similar skills

Feature-Level Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Feature-Level Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Feature-Level Code Review this skilldataelement/bisheng12k—~1kAutomated safety check: PassApache-2.0
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
Adversarial Reviewer302ai/302-AI-Studio1321 repos~3kAutomated safety check: PassMIT
Two-Axis Code Reviewrengwu/wayfinder-maps134—~1.8kAutomated safety check: PassMIT
Code Revieweralirezarezvani/claude-code-tresor777—~1.8kAutomated safety check: PassMIT
Code ReviewerMageByte-Zero/spec-superflow8391 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Adversarial Reviewer

    302ai/302-AI-Studio

    Adversarial code review that breaks the self-review monoculture.

    132 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Two-Axis Code Review

    rengwu/wayfinder-maps

    Reviews the changes since a commit, branch or tag along two separate axes: the repo's documented coding standards and fidelity to the originating spec or PRD.

    134 GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Reviewer

    MageByte-Zero/spec-superflow

    Review completed implementation batches for spec compliance and code quality.

    839 GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    259 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed

More from dataelement/bisheng

All 10 skills in this repo
  • BiSheng DOCX Builder

    dataelement/bisheng

    Builds or edits Word .docx documents inside BiSheng's code executor with python-docx, handling Chinese fonts, tables of contents, page numbers and official-document layout.

    12k GitHub stars~2.6k tokensUpdated 7 days ago
    Auto-check passed
  • BiSheng PPTX Builder

    dataelement/bisheng

    Builds PowerPoint decks in BiSheng's code executor with python-pptx, from scratch, from a supplied template or by rewriting an existing file, with Chinese layout rules.

    12k GitHub stars~1.8k tokensUpdated 7 days ago
    Auto-check passed
  • Builds, edits and cleans Excel workbooks inside BiSheng's code executor using openpyxl, with LibreOffice recalculation and a pre-delivery check.

    12k GitHub stars~1.7k tokensUpdated 7 days ago
    Auto-check passed
  • BiSheng SDD Document Review

    dataelement/bisheng

    Reviews BiSheng spec, design and tasks documents with checklists for PRD gaps, handover readiness and acceptance traceability, producing a report or an LGTM.

    12k GitHub stars~717 tokensUpdated 7 days ago
    Auto-check passed
  • Task-Level Code Review

    dataelement/bisheng

    Runs a light convention check on one finished spec-driven task, choosing checks by task type and ending in pass, pass-with-notes or needs-fix.

    12k GitHub stars~652 tokensUpdated 7 days ago
    Auto-check passed
  • Maps BiSheng's approval-center architecture to exact service files and methods, so a change to approval logic can be located without searching the whole repo.

    12k GitHub stars~4k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Feature-Level Code Review

What does Feature-Level Code Review do?

Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files. This is a pre-merge review for a whole feature rather than a single commit, run with a `--base` branch option.md`, works through seven review dimensions in turn and writes up a review report.

When should I use Feature-Level Code Review?

Feature-Level Code Review fits situations like: reviewing a finished feature branch before merging it; checking a diff against the feature's spec, design and task files; auditing a change for permission, tenant isolation and data leakage problems.

How do I install Feature-Level Code Review in Claude Code?

Run `npx skills add dataelement/bisheng --skill code-review -a claude-code`. Or copy the skill folder (.cursor/skills/code-review in dataelement/bisheng) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Feature-Level Code Review in Codex?

Run `npx skills add dataelement/bisheng --skill code-review -a codex`. Or copy the skill folder (.cursor/skills/code-review in dataelement/bisheng) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Feature-Level Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dataelement/bisheng --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Feature-Level Code Review need to run?

Going by SKILL.md and its folder, Feature-Level Code Review needs the command-line tools its instructions call (git). Our summary lists: A Git repository with the base branch available; Feature `spec.md`, `design.md` and `tasks.md` files.

Does Feature-Level Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Feature-Level Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Feature-Level Code Review use?

Feature-Level Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Feature-Level Code Review use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Feature-Level Code Review?

Skills that share tags, products or a category with Feature-Level Code Review: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Adversarial Reviewer (302ai/302-AI-Studio, 132 stars), Two-Axis Code Review (rengwu/wayfinder-maps, 134 stars) and Code Reviewer (alirezarezvani/claude-code-tresor, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Feature-Level Code Review?

dataelement (a GitHub organization) maintains it in dataelement/bisheng, which has 12,027 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 30, 2026.

Source: dataelement/bisheng on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.