Agent skill

Backend Code Review

by ProgrammerAnthony in ProgrammerAnthony/Anything-Extract

指导在项目(python项目)中队后端代码进行质量、安全、可维护性与最佳实践审查,基于既定规则清单。适用于用户请求对 backend/ 下后端文件(如 .py)进行审查、分析或改进。不用于前端文件(如 .tsx、.ts、.js)。支持待提交变更审查、代码片段审查、按文件审查。

MITAuto-check passedDevelopment

Install Backend Code Review

skills CLI
$ npx skills add ProgrammerAnthony/Anything-Extract --skill backend-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ProgrammerAnthony/Anything-Extract backend-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Anything-Extract.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/backend-code-review .claude/skills/backend-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backend-code-review
GitHub stars
139
Token cost
~791 tokens
SKILL.md length
165 words
Files
5 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

指导在项目(python项目)中队后端代码进行质量、安全、可维护性与最佳实践审查,基于既定规则清单。适用于用户请求对 backend/ 下后端文件(如 .py)进行审查、分析或改进。不用于前端文件(如 .tsx、.ts、.js)。支持待提交变更审查、代码片段审查、按文件审查。

  • Works in 4 steps: Security → Performance → Code Quality → …
  • Tasks that involve React components
  • SKILL.md covers 何时使用本 Skill, 如何使用本 Skill, 项目后端结构(审查范围参考) and Checklist, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Backend Code Review is an agent skill from ProgrammerAnthony/Anything-Extract. 指导在项目(python项目)中队后端代码进行质量、安全、可维护性与最佳实践审查,基于既定规则清单。适用于用户请求对 backend/ 下后端文件(如 .py)进行审查、分析或改进。不用于前端文件(如 .tsx、.ts、.js)。支持待提交变更审查、代码片段审查、按文件审查。

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/architecture-rule.md`, `references/data-access-rule.md` and `references/db-schema-rule.md`).

It sits in Development, covering React components and Code review. It works with Python and SQLAlchemy. The repository describes itself as: 高效文档识别&知识库&本地启动,前后端;整合QAnything、dify等思想和源码,快速批量可靠提取文档关键信息并导出. The licence is MIT.

When your agent uses it

  • Tasks that involve React components
  • Tasks that involve Code review

Example prompts

  • “/backend-code-review”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Security
  2. Performance
  3. Code Quality
  4. Testing

What it can do on your machine

Read from SKILL.md and the folder at commit f1ed557. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backend Code Review loads about 791 tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 40 tokens; SKILL.md has 165 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~791
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ProgrammerAnthony/Anything-Extract at commit f1ed557, republished under its MIT licence (© ProgrammerAnthony). 165 words, ~791 tokens.

Download SKILL.mdSave it as .claude/skills/backend-code-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
backend-code-review
description
指导在项目(python项目)中队后端代码进行质量、安全、可维护性与最佳实践审查,基于既定规则清单。适用于用户请求对 backend/ 下后端文件(如 .py)进行审查、分析或改进。不用于前端文件(如 .tsx、.ts、.js)。支持待提交变更审查、代码片段审查、按文件审查。

Backend Code Review(后端代码审查)

何时使用本 Skill

当用户要求审查、分析或改进当前项目的后端代码(如 .py 文件)时使用本 skill。审查范围以用户指定或项目约定为准,常见为项目中的后端根目录(如 backend/、api/ 等)。支持以下审查模式:

  • 待提交变更审查:用户要求审查当前变更(查看已暂存/工作区中拟提交的变更)。
  • 代码片段审查:用户粘贴代码片段(如函数/类/模块摘录)并请求审查。
  • 按文件审查:用户指定一个或少量文件(如后端下的 app/api/...、services/... 等)请求审查。

以下情况不要使用本 skill:

  • 请求涉及前端代码或 UI(如 .tsx、.ts、.js、web/、前端 app/ 等)。
  • 用户并非要求对后端代码进行审查/分析/改进。
  • 审查范围不在项目约定的后端目录下(除非用户明确要求审查后端相关但位于别处的改动)。

如何使用本 Skill

  1. 确定审查模式(待提交变更 / 片段 / 按文件),并根据用户输入限定范围:只审查用户提供或明确引用的内容。
  2. 按 Checklist 中的规则执行审查。若没有匹配的 Checklist 规则,则使用 General Review Rules 做尽力审查。
  3. 最终输出必须严格遵循 Required Output Format。

注意:

  • 始终给出可执行的修复或建议(可含代码示例)。
  • 若有文件路径与行号,尽量使用 File:Line 引用;否则使用最具体的标识。

项目后端结构(审查范围参考)

以下为常见 Python 后端分层示例,实际路径以当前项目为准(后端根目录可能是 backend/、api/ 等):

  • API 层:路由/控制器(如 app/api/、api/)
  • 服务层:业务逻辑与编排(如 services/)
  • 核心/领域:数据库、配置、领域核心(如 core/)
  • 数据模型:ORM 模型与 Session(如 core/database.py、models/)
  • 领域模型:DTO/实体(如 app/models/,无 DB)
  • 提供方:外部能力封装(如 providers/)
  • 工具:通用工具(如 utils/)
  • Worker:异步/队列消费(如 workers/)
  • 若项目无独立 repository 层,数据访问多在 API 或 service 中通过 db.query(Model) 完成;复杂或重复查询建议收敛到 service 或后续引入 repository。

Checklist

  • db schema 设计:若审查范围包含模型定义或迁移/init 逻辑(如 core/database.py、init_db),按 references/db-schema-rule.md 审查。
  • architecture:若涉及 router/service/core/provider 分层、依赖方向、职责归属,按 references/architecture-rule.md 审查。
  • data access:若审查范围包含对表/模型的查询与写入(如 db.query(...)、session.execute(...)、CRUD),且逻辑分散在 router 或重复出现,按 references/data-access-rule.md 审查。
  • sqlalchemy 使用:若涉及 Session/事务、查询构造、knowledge_base_id 作用域、原始 SQL,按 references/sqlalchemy-rule.md 审查。

General Review Rules

1. Security
  • SQL 注入、SSRF、命令注入、不安全反序列化
  • 硬编码密钥或凭证
  • 不当的鉴权/授权
  • 不安全的直接对象引用(如未校验 knowledge_base_id 即访问文档/分段)
2. Performance
  • N+1 查询
  • 缺失的数据库索引
  • 在异步路径中的阻塞操作
  • 可缓存而未缓存
3. Code Quality
  • 向前兼容性、重复代码(DRY)、单职责违反
  • 过深嵌套与复杂条件
  • 魔法数字/字符串、命名不清
  • 缺失错误处理、类型标注不完整
4. Testing
  • 新代码缺少测试、测试未覆盖行为、不稳定测试模式、缺少边界情况

Required Output Format

审查结果必须严格采用以下两种模板之一。

Template A(存在问题时)
markdown
# Code Review Summary

Found <X> critical issues need to be fixed:

## 🔴 Critical (Must Fix)

### 1. <简要描述>

FilePath: <path> line <line>
<相关代码片段或引用>

#### Explanation

<详细说明与依据>

#### Suggested Fix

1. <修复建议>
2. <代码示例>(可选,不适用可省略)

---
(每个 critical 重复上述结构)

Found <Y> suggestions for improvement:

## 🟡 Suggestions (Should Consider)

### 1. <简要描述>
...
(结构同上)

Found <Z> optional nits:

## 🟢 Nits (Optional)
...
(结构同上)

## ✅ What's Good

- <对良好模式的正面反馈>
  • 若没有 critical/suggestions/nits/good,则省略对应区块。
  • 若某项数量超过 10,可汇总为 "Found 10+ critical issues/..." 且只列出前 10 条。
  • 若存在需要改代码的问题,可在结构化输出后附一句简短追问,例如:"需要我按上述建议直接改代码吗?"
Template B(无问题时)
markdown
## Code Review Summary
✅ No issues found.

© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .agents/skills/backend-code-review of ProgrammerAnthony/Anything-Extract.

  • SKILL.md
  • references/architecture-rule.md
  • references/data-access-rule.md
  • references/db-schema-rule.md
  • references/sqlalchemy-rule.md

Open the folder on GitHubat commit f1ed557

Compare with similar skills

Backend Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backend Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backend Code Review this skillProgrammerAnthony/Anything-Extract139—~791Automated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence
@pierre/diffs Code Renderingpierrecomputer/pierre6.2k2 repos~803Automated safety check: PassApache-2.0
Dignified Python Standardsdocling-project/docling68k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • @pierre/diffs Code Rendering

    pierrecomputer/pierre

    Guides an agent through using @pierre/diffs to render syntax-highlighted files and diffs, and to build editing and review surfaces in React or plain JavaScript.

    6.2k GitHub starsUsed in 2 repos~803 tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes

More from ProgrammerAnthony/Anything-Extract

All 13 skills in this repo
  • Frontend Code Review

    ProgrammerAnthony/Anything-Extract

    指导在项目中对前端代码(Next.js/React/TypeScript/Tailwind 等)进行结构、可维护性、性能与一致性审查,基于既定规则清单。适用于用户请求审查 .tsx/.ts/.js/.jsx 等前端文件或前端目录下的页面与组件。不用于后端代码(如 .py)。

    139 GitHub stars~957 tokensUpdated 4 mo ago
    Auto-check passed
  • Design An Interface

    ProgrammerAnthony/Anything-Extract

    使用并行子 agent 为某个模块生成多个根本不同的接口设计。适用于用户希望设计某个 API、探索接口选项、对比模块形状(module shapes),或提到“design it twice(把它设计两遍)”。

    139 GitHub stars~448 tokensUpdated 4 mo ago
    Auto-check passed
  • TDD

    ProgrammerAnthony/Anything-Extract

    使用 RED-GREEN-重构(red-green-refactor)循环进行测试驱动开发。适用于用户希望用 TDD 构建新功能或修复 bug,提到 “red-green-refactor”,希望使用集成测试,或询问“test-first development(先写测试)”。

    139 GitHub stars~572 tokensUpdated 4 mo ago
    Auto-check passed
  • Ubiquitous Language

    ProgrammerAnthony/Anything-Extract

    从当前对话中抽取 DDD 风格的“统一语言”术语表(ubiquitous language glossary),标记歧义,并提出规范的术语选择。保存为 UBIQUITOUSLANGUAGE.md。适用于用户希望定义领域术语、构建术语表、固化用词并强化术语一致性,或提到 “domain model” / “DDD”(领域模型与 DDD)。

    139 GitHub stars~647 tokensUpdated 4 mo ago
    Auto-check passed
  • Write A Skill

    ProgrammerAnthony/Anything-Extract

    以正确的技能结构、渐进式披露与打包资源来创建新的 agent 技能。适用于用户希望创建、编写或构建新的技能. An agent skill from ProgrammerAnthony/Anything-Extract.

    139 GitHub stars~407 tokensUpdated 4 mo ago
    Auto-check passed
  • Architecture Doc

    ProgrammerAnthony/Anything-Extract

    指导在项目中编写、更新与使用架构文档(ARCHITECTURE.md)。在根目录维护架构文档,修改前后需阅读文档;文档关注最终结果与流程串联,不陷入实现细节。适用于新增/变更功能、重构、或需要理解系统整体时。

    139 GitHub stars~606 tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Backend Code Review

What does Backend Code Review do?

指导在项目(python项目)中队后端代码进行质量、安全、可维护性与最佳实践审查,基于既定规则清单。适用于用户请求对 backend/ 下后端文件(如 .py)进行审查、分析或改进。不用于前端文件(如 .tsx、.ts、.js)。支持待提交变更审查、代码片段审查、按文件审查。. Backend Code Review is an agent skill from ProgrammerAnthony/Anything-Extract.

When should I use Backend Code Review?

Backend Code Review fits situations like: tasks that involve React components; tasks that involve Code review.

How do I install Backend Code Review in Claude Code?

Run `npx skills add ProgrammerAnthony/Anything-Extract --skill backend-code-review -a claude-code`. Or copy the skill folder (.agents/skills/backend-code-review in ProgrammerAnthony/Anything-Extract) into .claude/skills/backend-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Backend Code Review in Codex?

Run `npx skills add ProgrammerAnthony/Anything-Extract --skill backend-code-review -a codex`. Or copy the skill folder (.agents/skills/backend-code-review in ProgrammerAnthony/Anything-Extract) into .agents/skills/backend-code-review in your project. Codex loads it when a task matches its description.

Can I use Backend Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Anything-Extract --skill backend-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backend-code-review, .gemini/skills/backend-code-review, .github/skills/backend-code-review and .opencode/skills/backend-code-review in your project.

What does Backend Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Backend Code Review is instructions for the agent only. Our summary lists: Python 3.

Does Backend Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Backend Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Backend Code Review use?

Backend Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Backend Code Review use?

About 791 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Backend Code Review?

Skills that share tags, products or a category with Backend Code Review: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars), Backend Code Review (langgenius/dify, 158k stars) and @pierre/diffs Code Rendering (pierrecomputer/pierre, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backend Code Review?

ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Anything-Extract, which has 139 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on May 13, 2026.

Source: ProgrammerAnthony/Anything-Extract on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.