PR Finalize Review
microsoft/garnet
Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.
Gives Chinese-language templates and priority labels for code review feedback, plus guidance on bilingual comments, commit messages and common team anti-patterns.
SKILL.md written in Chinese; this summary is our English description.
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/chinese-code-review .claude/skills/chinese-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .claude/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/chinese-code-review .agents/skills/chinese-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .agents/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/chinese-code-review .cursor/skills/chinese-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .cursor/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jnMetaCode/superpowers-zh.git --path skills/chinese-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/chinese-code-review .gemini/skills/chinese-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .gemini/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/chinese-code-review .github/skills/chinese-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .github/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jnMetaCode/superpowers-zh chinese-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jnMetaCode/superpowers-zh.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/chinese-code-review .opencode/skills/chinese-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "chinese-code-review" agent skill from https://github.com/jnMetaCode/superpowers-zh/tree/main/skills/chinese-code-review into .opencode/skills/chinese-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chinese-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
chinese-code-reviewGives Chinese-language templates and priority labels for code review feedback, plus guidance on bilingual comments, commit messages and common team anti-patterns.
This is a communication guide for code review in Chinese-speaking teams, aimed at the balance between over-politeness that hides real bugs and blunt Western directness that embarrasses colleagues. Its principle is to phrase feedback as suggestions and questions rather than orders or rejections, without ever letting a bug through to save face. A table contrasts commanding phrases with suggestion-style ones.
Comments carry priority labels: must fix for security holes, data-loss risk and logic errors, suggested change for performance, maintainability and missing validation, for reference only for naming and style, and a question label for unclear intent. A comment template shows the format, and further sections cover when to write code comments in Chinese or English, spacing between Chinese and English text, bilingual commit messages in a Chinese Conventional Commits form, and anti-patterns such as excessive politeness and reluctance to review senior developers' code.
It is meant to run only when someone explicitly calls /chinese-code-review, and its instructions say it should not be triggered automatically from the surrounding conversation context.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2daf57c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
cheatsheetseries.owasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Chinese Code Review Etiquette loads about 1.2k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 235 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jnMetaCode/superpowers-zh at commit 2daf57c, republished under its MIT licence (© jnMetaCode). 235 words, ~1,185 tokens.
.claude/skills/chinese-code-review/SKILL.md (or your agent's skills folder).国内团队做 Code Review 常遇到两个极端:要么过度客气导致关键问题被放过,要么照搬西方直白风格让同事下不来台。本技能帮你找到平衡点——既不回避问题,又让人愿意接受反馈。
核心原则: 用"建议"代替"命令",用"提问"代替"否定",但绝不因为面子而放过 bug。
| 避免(命令式) | 推荐(建议式) |
|---|---|
| 你必须改成 X | 建议考虑用 X,因为 Y |
| 这里写错了 | 这里可能存在一个问题,是否考虑过 Z 的情况? |
| 不要用这个方法 | 这个方法在 A 场景下可能有性能问题,可以看看 B 方案 |
| 这段代码不行 | 这段逻辑我理解得对吗?如果输入为空的话会怎样? |
当你不确定对方意图时,先问再评:
# 好的方式
这里用 sync 方式读文件是出于什么考虑?如果并发量上来,可能会阻塞事件循环。
# 不好的方式
这里不应该用 sync 方式读文件。统一使用优先级标记,让作者快速判断轻重缓急:
[必须修复] SQL 注入风险
第 42 行:用户输入直接拼接到 SQL 语句中。
原因:攻击者可以通过 name 参数注入 `'; DROP TABLE users; --`。
建议:使用参数化查询:
db.query('SELECT * FROM users WHERE name = $1', [name])
参考:https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html/**
* 计算用户的会员等级折扣
*
* 业务规则:
* - 普通会员 9.5 折
* - 银卡会员 9 折
* - 金卡会员 8.5 折
* - 钻石会员 8 折
*
* @param level - 会员等级(MemberLevel enum)
* @param amount - 原始金额(单位:分)
* @returns 折后金额(单位:分)
*/
function calculateDiscount(level: MemberLevel, amount: number): number {
// ...
}// 好:中英文之间加空格
// 使用 Redis 缓存来减少 MySQL 的查询压力
// 坏:中英文之间没有空格
// 使用Redis缓存来减少MySQL的查询压力
// 好:技术术语保留英文
// 这里用 debounce 防抖处理,避免频繁触发 API 请求
// 坏:强行翻译技术术语
// 这里用防抖动处理,避免频繁触发应用程序接口请求团队内部项目使用中文 commit message,采用约定式提交(Conventional Commits)的中文版:
<类型>(<范围>): <简要描述>
<详细说明(可选)>
<关联信息(可选)>| 类型 | 含义 | 示例 |
|---|---|---|
| feat | 新功能 | feat(用户): 新增手机号登录功能 |
| fix | 修复 Bug | fix(支付): 修复微信支付回调重复处理的问题 |
| docs | 文档变更 | docs: 更新 API 接口文档 |
| style | 代码格式 | style: 统一缩进为 2 个空格 |
| refactor | 重构 | refactor(订单): 拆分订单服务,提取公共逻辑 |
| perf | 性能优化 | perf(列表): 虚拟滚动优化长列表渲染性能 |
| test | 测试 | test(auth): 补充登录模块单元测试 |
| chore | 构建/工具 | chore: 升级 Node.js 至 v20 |
fix(支付): 修复支付宝异步回调签名校验失败的问题
原因:升级 SDK 后签名算法从 RSA 变为 RSA2,但回调校验仍使用旧算法。
方案:回调处理中同时兼容 RSA 和 RSA2 签名校验。
Closes #1234如果项目面向国际社区或有外籍成员,commit message 用英文,PR 描述中可附加中文说明:
fix(payment): fix Alipay async callback signature verification failure
The SDK upgrade changed the signature algorithm from RSA to RSA2,
but the callback handler still used the old algorithm.
Closes #1234表现: 所有评论都是"我觉得可能也许大概好像这里有个小问题"。
后果: 关键 bug 被隐藏在一堆委婉语里,作者根本不知道哪些必须改。
对策: 使用分级标注。[必须修复] 就是必须修复,语气可以温和,但级别必须准确。
# 坏:过度客气
不知道我理解得对不对,这里好像可能有一点点并发问题,不过也许我看错了...
# 好:温和但清晰
[必须修复] 并发安全问题
这里的 map 在多个 goroutine 中同时读写,会触发 panic。
建议加 sync.RWMutex,或者换成 sync.Map。
复现方式:加 -race flag 跑测试就能看到。表现: 高级开发者或 Leader 的代码直接 Approve,不仔细看。
后果: 代码质量双标,团队对 Code Review 失去信任。
对策: Code Review 对事不对人。可以换个表达方式:
# 提问式(适合给资深同事的反馈)
想请教一下,这里选择用递归而不是迭代,是出于什么考虑?
我在想如果递归深度超过 1000 层会不会有栈溢出的风险?
# 学习式
学到了一个新写法!不过有个小疑问——这里的类型断言在运行时不会做检查,
如果上游数据结构变了,这里会静默通过。是否考虑加个 runtime validation?表现: 大量评论纠结于缩进、空格、花括号位置。
后果: 浪费时间,忽略真正的问题。
对策: 风格问题交给 ESLint / Prettier / gofmt 等工具自动处理。Code Review 聚焦逻辑、安全、性能。
表现: 随手一个 LGTM 就 Approve,没有实质性审查。
后果: Code Review 形同虚设,出了问题没人兜底。
对策: 即使代码质量很好,也要写出你关注了哪些方面:
LGTM
审查了以下方面:
- 并发安全:锁的粒度合理
- 错误处理:所有外部调用都有 error handling
- 向下兼容:新增字段都有默认值,不影响老版本
一个小建议 [仅供参考]:第 78 行的变量名 `d` 可以改成 `duration`,更易读。审查结束后,给一段总结,包括:
总结:整体实现思路清晰,支付回调的幂等处理很到位。
主要问题:
1. [必须修复] 并发写 map 的问题(2 处)
2. [建议修改] 缺少对空值的校验(3 处)
3. [仅供参考] 几个变量命名可以更语义化
建议先修复并发问题,校验的部分可以本次一起改或者拆到下个迭代。在提交审查意见前,确认:
© jnMetaCode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/chinese-code-review of jnMetaCode/superpowers-zh.
Open the folder on GitHubat commit 2daf57c
Chinese Code Review Etiquette next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Chinese Code Review Etiquette this skilljnMetaCode/superpowers-zh | 8.3k | — | ~1.2k | Automated safety check: Pass | MIT | |
| PR Finalize Reviewmicrosoft/garnet | 12k | — | ~3.1k | Automated safety check: Pass | MIT | |
| PR Finalizedotnet/maui | 23k | — | ~3.1k | Automated safety check: Pass | MIT | |
| GitHub Workflowtransilienceai/communitytools | 562 | — | ~812 | Automated safety check: Notes | MIT | |
| CommitZhangShenao/harness9 | 141 | — | ~327 | Automated safety check: Notes | MIT | |
| Review Before Commithoneybadger-io/honeybadger-js | 116 | — | ~195 | Automated safety check: Pass | MIT |
microsoft/garnet
Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.
dotnet/maui
Checks that a pull request's title and description match its implementation and reviews the code for best practices before merge, without posting anything.
transilienceai/communitytools
GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.
ZhangShenao/harness9
A skill your agent uses when the user invokes /commit or asks to commit changes, after a code review has been completed and the changes are confirmed ready to stage and commit to git.
honeybadger-io/honeybadger-js
Mandatory AI code review before committing in honeybadger-js.
planetabhi/riseofmachine
Load this skill before shipping a UI change, to statically review the diff for design-craft regressions (accessibility, motion, responsive, and visual or UX drift), correctness and security issues…
jnMetaCode/superpowers-zh
Turns a rough idea into an approved design before any code is written, sorting the request into spike, bounded or architectural and enforcing an approval gate.
jnMetaCode/superpowers-zh
Sets up an isolated workspace before feature work or plan execution, preferring native worktree tools and falling back to git worktree, with instructions in Chinese.
jnMetaCode/superpowers-zh
Executes a written implementation plan task by task in the current session, with a progress ledger, test-first gates and one fresh-context review at the end.
jnMetaCode/superpowers-zh
Reference for Chinese-language git commits and changelogs: Conventional Commits adapted for Chinese teams, with templates, breaking-change notes and issue links for several platforms.
jnMetaCode/superpowers-zh
Reference rules for typesetting Chinese technical documents: spacing around English and digits, punctuation, term handling, bilingual API docs and README layout.
jnMetaCode/superpowers-zh
Methodology for designing, implementing and testing Model Context Protocol servers in TypeScript or Python, covering tool design, error handling and security, in Chinese.
Categories
Gives Chinese-language templates and priority labels for code review feedback, plus guidance on bilingual comments, commit messages and common team anti-patterns. This is a communication guide for code review in Chinese-speaking teams, aimed at the balance between over-politeness that hides real bugs and blunt Western directness that embarrasses colleagues. Its principle is to phrase feedback as suggestions and questions rather than orders or rejections, without ever letting a bug through to save face.
Chinese Code Review Etiquette fits situations like: writing review comments for a Chinese-speaking team; deciding how to label review feedback by severity; choosing between Chinese and English for comments and commit messages.
Run `npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a claude-code`. Or copy the skill folder (skills/chinese-code-review in jnMetaCode/superpowers-zh) into .claude/skills/chinese-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a codex`. Or copy the skill folder (skills/chinese-code-review in jnMetaCode/superpowers-zh) into .agents/skills/chinese-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jnMetaCode/superpowers-zh --skill chinese-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chinese-code-review, .gemini/skills/chinese-code-review, .github/skills/chinese-code-review and .opencode/skills/chinese-code-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Chinese Code Review Etiquette is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: cheatsheetseries.owasp.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Chinese Code Review Etiquette is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Chinese Code Review Etiquette: PR Finalize Review (microsoft/garnet, 12k stars), PR Finalize (dotnet/maui, 23k stars), GitHub Workflow (transilienceai/communitytools, 562 stars) and Commit (ZhangShenao/harness9, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jnMetaCode (a GitHub user) maintains it in jnMetaCode/superpowers-zh, which has 8,280 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.
Source: jnMetaCode/superpowers-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.