Agent skill

Cloudbase Code Review

by TencentCloudBase in TencentCloudBase/CloudBase-AI-Toolkit

Code review and validation for CloudBase projects. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

MITAuto-check passedDevelopment

Install Cloudbase Code Review

skills CLI
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/config/source/skills/cloudbase-code-review .claude/skills/cloudbase-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudbase-code-review
GitHub stars
1.1k
Used in
2 other repos
Token cost
~1.1k tokens
SKILL.md length
311 words
Files
12 (incl. references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Code review and validation for CloudBase projects. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

  • Tasks that involve Code review
  • SKILL.md covers Sibling skills (local only), When to use, How it works and Rule index, plus 4 more sections
  • Calls node
  • Tasks that involve Serverless

What it does

Cloudbase Code Review is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `references/RULES_INDEX.md`, `references/lint-rules/README.md` and `references/rules/cross-cutting/AUTH001.md`).

It sits in Development, covering Code review, Serverless and Linting and formatting. It works with WeChat. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Serverless
  • Tasks that involve Linting and formatting

Example prompts

  • “/cloudbase-code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 21af91c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudbase Code Review loads about 1.1k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 311 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit 21af91c, republished under its MIT licence (© TencentCloudBase). 311 words, ~1,115 tokens.

Download SKILL.mdSave it as .claude/skills/cloudbase-code-review/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
cloudbase-code-review
description
Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review.
version
2.34.8
alwaysApply
false

Sibling skills (local only)

Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.

If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.

CloudBase Code Review

One-liner: After implementing CloudBase features, call this skill to catch common mistakes before users do.

When to use

Call this skill after completing a CloudBase implementation task, before declaring done:

  • You implemented auth (login / register / route guard)
  • You created database tables or wrote CRUD (NoSQL / PostgreSQL / MySQL)
  • You set up CloudBase Storage (file upload, hosting)
  • You configured security rules or RLS policies
  • You wrote MCP-dependent code
  • You wrote Cloud Function or CloudRun HTTP handlers (check for credential / header echo leaks)

How it works

The skill runs in two layers:

LayerMethodSpeedWhat it catches
Lint (optional)No executable script is shipped. If the user approves running lint, review the code block in references/lint-rules/README.md, copy it to a temporary local cloudbase-lint.mjs, then run node cloudbase-lint.mjs --project-dir <path>SecondsDeterministic regex checks — wrong API calls, missing configs, pattern mismatches
LLM reviewRead each rule's "LLM 检查" section, inspect code semanticallyVariableSemantic issues — route guard logic, RLS completeness, architecture-level problems

Rule index

See references/RULES_INDEX.md for the full matrix (module × frontend type → applicable rules).

Rule boundary

Do not promote a single failed run or case-specific workaround into a hard rule. A rule should be backed by stable SDK/API documentation, repeated failures, or deterministic runtime behavior. Case-specific observations belong in attribution reports; only broadly applicable constraints should enter RULES_INDEX.md or the optional lint checklist.

Quick start

bash
# Step 1: Read relevant rules for identified modules
#   references/rules/cross-cutting/AUTH001.md
#   references/rules/cross-cutting/SEC001.md
#   references/rules/postgresql/PG-CR001.md
#   ...

# Optional: if the user approves running lint, review the script code block in
# references/lint-rules/README.md, copy it to a temporary cloudbase-lint.mjs,
# then run: node cloudbase-lint.mjs --project-dir .

# Step 2: For each applicable rule, read the "LLM 检查" section
#         and manually inspect your code before claiming done.

Rule format

Each rule .md file follows this structure:

markdown
# RULE-ID Rule Name

- **Module**: which module (auth / postgresql / storage / ...)
- **Severity**: error | warning
- **Stage**: code-generation | deployment | config

## 正则检查 (Lint)

The condition checked by the optional script code block in `references/lint-rules/README.md`.

## LLM 检查

Semantic review prompt for human or LLM to evaluate.

## 修复指引

How to fix the issue.

Reference index

All packaged reference files (required for skill lint reachability):

© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references) in config/source/skills/cloudbase-code-review of TencentCloudBase/CloudBase-AI-Toolkit.

  • SKILL.md
  • references/RULES_INDEX.md
  • references/lint-rules/README.md
  • references/rules/cross-cutting/AUTH001.md
  • references/rules/cross-cutting/SEC001.md
  • references/rules/cross-cutting/SKILL001.md
  • references/rules/postgresql/PG-CR001.md
  • references/rules/postgresql/PG-CR002.md
  • references/rules/postgresql/PG-CR003.md
  • references/rules/postgresql/PG-CR004.md
  • references/rules/postgresql/PG-CR005.md
  • references/rules/storage/STORAGE001.md

Open the folder on GitHubat commit 21af91c

Used in 2 other repositories

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in TencentCloudBase/CloudBase-AI-Toolkit, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudbase Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudbase Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudbase Code Review this skillTencentCloudBase/CloudBase-AI-Toolkit1.1k2 repos~1.1kAutomated safety check: PassMIT
Qt Cpp ReviewSerial-Studio/Serial-Studio7.2k—~4.3kAutomated safety check: PassCustom licence
Qt Qml ReviewSerial-Studio/Serial-Studio7.2k—~3.7kAutomated safety check: PassCustom licence
Qt6 QML Code Reviewerx-tools-author/x-tools1.1k1 repos~3.6kAutomated safety check: PassBSD-3-Clause
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0
Review Loopdidi/mpx3.9k—~828Automated safety check: PassApache-2.0

Similar skills

  • Qt Cpp Review

    Serial-Studio/Serial-Studio

    Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.

    7.2k GitHub stars~4.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Qt Qml Review

    Serial-Studio/Serial-Studio

    Qt6/QML deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.

    7.2k GitHub stars~3.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Qt6 QML Code Reviewer

    x-tools-author/x-tools

    Runs a 47-rule deterministic QML linter, then six parallel deep-analysis passes over bindings, layout, loaders, delegates, states, and performance.

    1.1k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Review Loop

    didi/mpx

    当用户要求评审循环、自评审工作流、planner/reviewer/coder/code-reviewer 协作、先方案后编码、多轮 Agent 评审,或要求稳定的子 Agent 工作流依次产出方案、等待用户确认、实现代码、评审差异并保留修订记录时,使用此 Skill。此 Skill 必须使用真实子 Agent,不得退化为单 Agent 角色扮演。

    3.9k GitHub stars~828 tokensUpdated today
    DevelopmentAuto-check passed
  • Openqodex

    openqodex/openqodex

    Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

    303 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from TencentCloudBase/CloudBase-AI-Toolkit

All 49 skills in this repo
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • HTTP API Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 3 repos~2.1k tokens
    Auto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Manage Local Skills

    TencentCloudBase/CloudBase-AI-Toolkit

    Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Cloudbase Agent Python

    TencentCloudBase/CloudBase-AI-Toolkit

    Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…

    1.1k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check: notes
  • Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…

    1.1k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

Works with

Categories

Questions about Cloudbase Code Review

What does Cloudbase Code Review do?

Code review and validation for CloudBase projects. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Cloudbase Code Review is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Code review and validation for CloudBase projects.

When should I use Cloudbase Code Review?

Cloudbase Code Review fits situations like: tasks that involve Code review; tasks that involve Serverless; tasks that involve Linting and formatting.

How do I install Cloudbase Code Review in Claude Code?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-review -a claude-code`. Or copy the skill folder (config/source/skills/cloudbase-code-review in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/cloudbase-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Cloudbase Code Review in Codex?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-review -a codex`. Or copy the skill folder (config/source/skills/cloudbase-code-review in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/cloudbase-code-review in your project. Codex loads it when a task matches its description.

Can I use Cloudbase Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudbase-code-review, .gemini/skills/cloudbase-code-review, .github/skills/cloudbase-code-review and .opencode/skills/cloudbase-code-review in your project.

What does Cloudbase Code Review need to run?

Going by SKILL.md and its folder, Cloudbase Code Review needs the command-line tools its instructions call (node).

Does Cloudbase Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloudbase Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudbase Code Review use?

Cloudbase Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudbase Code Review use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Cloudbase Code Review?

Skills that share tags, products or a category with Cloudbase Code Review: Qt Cpp Review (Serial-Studio/Serial-Studio, 7.2k stars), Qt Qml Review (Serial-Studio/Serial-Studio, 7.2k stars), Qt6 QML Code Reviewer (x-tools-author/x-tools, 1.1k stars) and Code Review (nteract/semiotic, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudbase Code Review?

TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,133 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 7, 2026.

Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.