Agent skill

Backend Code Review

by langgenius in langgenius/dify

Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

Custom licenceAuto-check passedDevelopment

Install Backend Code Review

skills CLI
$ npx skills add langgenius/dify --skill backend-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langgenius/dify backend-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langgenius/dify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/backend-code-review .claude/skills/backend-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backend-code-review
GitHub stars
158k
Token cost
~676 tokens
SKILL.md length
288 words
Files
5 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
Custom licence

At a glance

Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

  • Works in 4 steps: Establish the requested review scope and… → Read the changed lines, their behavior… → Trace callers, persistence boundaries,… → …
  • Reviewing pending backend changes under api/ before merge
  • SKILL.md covers Evidence First, Rule Routing and Severity And Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill applies only when you explicitly ask for a review or audit of backend code under api/, whether as pending changes, specific files or a pasted diff. The agent works evidence-first. It fixes the scope, reads the changed lines with their behavior owner, nearby tests and local docstrings, and traces callers, persistence boundaries, authorization, generated schemas or external I/O only when they decide correctness. It reports only findings tied to an observable failure, a violated contract, a security boundary, a data-integrity risk or a demonstrated maintenance problem.

Rule routing loads only the packs the diff matches: schema rules for models and migrations, architecture rules for dependency direction between controllers, services, core and libraries, repository rules for table access outside an established repository boundary, and SQLAlchemy rules for sessions, queries, transactions, CRUD, concurrency and raw SQL. Findings come first, ordered by severity from P0 for security exposure, data loss or a production-wide outage down to P3 for minor cleanup, and each carries a file and line reference, the broken contract, its impact and a fix direction. With nothing to report, the agent says so, without praise sections or speculative risks.

When your agent uses it

  • Reviewing pending backend changes under api/ before merge
  • Auditing specific backend files for defects
  • Reviewing a pasted diff of backend code
  • Checking that a change respects layering and repository boundaries

Example prompts

  • “Review my pending changes under api/ and rank the findings by severity.”
  • “Audit api/services/workspace_service.py for SQLAlchemy session and transaction problems.”
  • “Review this diff of the new migration for schema and data-integrity issues.”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Establish the requested review scope and inspect the relevant diff or files.
  2. Read the changed lines, their behavior owner, nearby tests, and local docstrings or comments that define contracts.
  3. Trace callers, persistence boundaries, authorization, generated schemas, or external I/O only when they decide correctness.
  4. Report only findings tied to an observable failure, violated contract, security boundary, data integrity risk, or demonstrated maintenance…

What it can do on your machine

Read from SKILL.md and the folder at commit cecdb28. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backend Code Review loads about 676 tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 288 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~676
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 288 words (~676 tokens).

“Review the requested scope for concrete, reproducible defects. The nearest AGENTS.md owns package facts and commands; this skill owns the review workflow and routes to its bundled rule packs.”

— opening of SKILL.md by langgenius, Custom licence
name
backend-code-review

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in .agents/skills/backend-code-review of langgenius/dify.

  • SKILL.md
  • references/architecture-rule.md
  • references/db-schema-rule.md
  • references/repositories-rule.md
  • references/sqlalchemy-rule.md

Open the folder on GitHubat commit cecdb28

Compare with similar skills

Backend Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backend Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backend Code Review this skilllanggenius/dify158k—~676Automated safety check: PassCustom licence
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Pascal Architecture PR Reviewpascalorg/editor25k—~7.5kAutomated safety check: PassMIT
Brooks Audithyhmrright/brooks-lint1.5k1 repos~537Automated safety check: PassMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Pattern Conformance AuditTotoro-jam/battle-tested-patterns344—~1.6kAutomated safety check: PassMIT

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Reviews a pull request against the Pascal editor's architectural rules: package boundaries, registry-driven node composition, hook hygiene and selector performance.

    25k GitHub stars~7.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Brooks Audit

    hyhmrright/brooks-lint

    Architecture audit that maps module dependencies, checks layering integrity, and flags structural decay across a codebase, drawing on twelve classic engineering books.

    1.5k GitHub starsUsed in 1 repo~537 tokens
    DevelopmentAuto-check passed
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Pattern Conformance Audit

    Totoro-jam/battle-tested-patterns

    Audits a codebase's existing patterns, such as rate limiters, circuit breakers and caches, against canonical invariants and flags mislabeled or divergent ones.

    344 GitHub stars~1.6k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Adversarial Spec Review

    JuliusBrussee/cavekit

    Builds a skeptical reviewer grounded in the codebase and research notes to try to refute a spec before any code is written, citing file:line evidence and ending in a go or no-go gate.

    1.1k GitHub stars~959 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from langgenius/dify

  • Guides changes and reviews of the Cucumber and Playwright end-to-end suite under `e2e/`: feature files, step definitions, support code, tags, locators and assertions.

    158k GitHub stars~682 tokensUpdated today
    Auto-check passed
  • Frontend Code Review

    langgenius/dify

    Reviews frontend changes under `web/` or `packages/dify-ui/` for concrete defects and broken project contracts, using routed rule packs and a severity scale for findings.

    158k GitHub stars~938 tokensUpdated today
    Auto-check passed
  • Use when implementing or refactoring React/TypeScript components and the task requires decisions about component ownership, feature boundaries, state, data…

    158k GitHub stars~626 tokensUpdated today
    Auto-check passed
  • Base skill for the difyctl CLI: discover a Dify server's operations through help output and run them as commands, always with JSON output.

    158k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Dify Frontend Testing

    langgenius/dify

    Use when writing or changing Vitest or React Testing Library tests under `web/` or `packages/dify-ui/`, or when the user explicitly requests frontend test…

    158k GitHub stars~242 tokensUpdated today
    Auto-check passed

Works with

Questions about Backend Code Review

What does Backend Code Review do?

Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3. The skill applies only when you explicitly ask for a review or audit of backend code under api/, whether as pending changes, specific files or a pasted diff. The agent works evidence-first.

When should I use Backend Code Review?

Backend Code Review fits situations like: reviewing pending backend changes under api/ before merge; auditing specific backend files for defects; reviewing a pasted diff of backend code; checking that a change respects layering and repository boundaries.

How do I install Backend Code Review in Claude Code?

Run `npx skills add langgenius/dify --skill backend-code-review -a claude-code`. Or copy the skill folder (.agents/skills/backend-code-review in langgenius/dify) into .claude/skills/backend-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Backend Code Review in Codex?

Run `npx skills add langgenius/dify --skill backend-code-review -a codex`. Or copy the skill folder (.agents/skills/backend-code-review in langgenius/dify) into .agents/skills/backend-code-review in your project. Codex loads it when a task matches its description.

Can I use Backend Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langgenius/dify --skill backend-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backend-code-review, .gemini/skills/backend-code-review, .github/skills/backend-code-review and .opencode/skills/backend-code-review in your project.

What does Backend Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Backend Code Review is instructions for the agent only.

Does Backend Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Backend Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Backend Code Review use?

Backend Code Review has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Backend Code Review use?

About 676 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Backend Code Review?

Skills that share tags, products or a category with Backend Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Pascal Architecture PR Review (pascalorg/editor, 25k stars), Brooks Audit (hyhmrright/brooks-lint, 1.5k stars) and Code Review Skill (Rain-kl/OpenFlare, 288 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backend Code Review?

langgenius (a GitHub organization) maintains it in langgenius/dify, which has 158,055 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: langgenius/dify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.