Agent skill

Code Review

by yaklang in yaklang/yakit

对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

AGPL-3.0Auto-check: notesDevelopment

Install Code Review

skills CLI
$ npx skills add yaklang/yakit --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/yakit code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/yakit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
7.8k
Token cost
~1.4k tokens
SKILL.md length
417 words
Files
2 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
AGPL-3.0

At a glance

对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

  • Works in 6 steps: 确定审查对象 → 收集与分类 → 六维检查 → …
  • Tasks that involve Code review
  • SKILL.md covers 触发, 1. 确定审查对象, 2. 收集与分类 and 3. 六维检查, plus 4 more sections
  • Calls yarn, git and gh

What it does

Code Review is an agent skill from yaklang/yakit. 对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR 前先检查代码时触发。审查对象可以是 PR 编号、分支 diff(含当前分支相对基线的改动)或工作区未提交改动。

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/check-dimensions.md`).

It sits in Development, covering Code review, Pull requests and Unit testing. It works with Vitest, Burp Suite, Go and Git. The repository describes itself as: Cyber Security ALL-IN-ONE Platform. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Pull requests
  • Tasks that involve Unit testing

Example prompts

  • “/code-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 确定审查对象
  2. 收集与分类
  3. 六维检查
  4. 强制验证(每次必做)
  5. 测试用例缺失
  6. 输出三块报告

What it can do on your machine

Read from SKILL.md and the folder at commit 87904ea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn, git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 1.4k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 417 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:56
    、`.github/workflows/`、`scripts/`、`cli/`、`.env*`、`.husky/`、`.lintstagedrc` 等;package.json 的 `scripts` 段改动同时触发维度 5、6。

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/yakit at commit 87904ea, republished under its AGPL-3.0 licence (© yaklang). 417 words, ~1,363 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-review
description
对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR 前先检查代码时触发。审查对象可以是 PR 编号、分支 diff(含当前分支相对基线的改动)或工作区未提交改动。

code-review

产出规范化三块式 review 报告。只读:不改被审代码,不运行被审代码本体;对被审代码只允许执行 yarn type-check 与 yarn test:vitest ... --run,另允许在临时 worktree 内 yarn cli install 装依赖。tsc / vitest 未实际跑过,报告中不得标 ✅,不得编造结果。发现问题不瞒报、不把功能 bug 降成警告。

触发

  1. 语义:如「review」「审查这个 PR / 当前分支」「对比 master」「合并前检查」。
  2. /code-review,可带参数(如 /code-review review PR 4198)。
  3. 被其他 skill 调用(如 create-pr):已指定范围则直接执行,不弹框。三块报告全文返回调用方;落盘仍须用户同意。

1. 确定审查对象

能确定的直接用,不要多问:

优先级条件模式
1含 PR 编号(「review 4198」「审查 #4198」)PR
2含分支或基线(「review dev」「对比 feat-x」)分支
3外部 skill 已指定 diff 范围直接采用,不弹框
4以上都没有AskUserQuestion

弹框选项(question 注明「审查 PR 或其他基线请在 Other 中输入编号 / 分支名」):当前分支 vs master;工作区未提交改动。

模式获取改动报告文件名(仓库根)
PRgh pr view <编号> --repo yaklang/yakit --json title,headRefName,headRefOid,baseRefName,baseRefOid,files + gh pr diff <编号>。必须记录 baseRefOid / headRefOid 供步骤 4PR-<编号>-review.md
分支git diff <基线>...HEAD + git log --oneline <基线>..HEAD,基线默认 master<分支名>-review.md(/ → -)
工作区git diff HEAD + git status --short 未跟踪新文件(读内容纳入审查)working-tree-review.md

gh 未安装或未登录:PR 模式报错并停止;若本地分支恰好对应该 PR,经用户确认后降级为分支模式。

2. 收集与分类

git diff --stat(或 PR files 列表)列出全部改动。分类:源码(ts/tsx/js/jsx)、测试、样式(less/css/scss)、依赖(package.json / yarn.lock)、配置、文档。diff 为空 → 说明无改动并停止。 文件 > 50:优先审源码/依赖/配置,样式与文案抽检,报告开头说明覆盖度。

PR 模式只有 diff 没有本地上下文:结合文件清单审;本地有对应分支则读本地补充,否则注明「仅基于 diff 审查」。验证仍须在 OID worktree 双跑,不用当前目录结果。

3. 六维检查

逐维度先读 references/check-dimensions.md 对应节。

#维度触发无涉及时
1代码逻辑有源码改动汇总表标 ⏭️ N/A
2TS 定义有 ts/tsx 改动同上
3UI 引用与 Props有组件 / props 改动同上
4CSS 样式有样式文件或 tsx 内样式改动同上
5依赖版本影响仅当改动含 package.json⏭️ N/A(无依赖改动)
6配置项影响仅当改动含配置文件⏭️ N/A(无配置改动)

维度 5、6 不可放宽:无 package.json 不审依赖,无配置文件不审配置。N/A 行必须出现在汇总表,不许整行消失。配置文件:tsconfig*.json、vite/vitest、electron-builder、.github/workflows/、scripts/、cli/、.env*、.husky/、.lintstagedrc 等;package.json 的 scripts 段改动同时触发维度 5、6。

4. 强制验证(每次必做)

工作区 / 分支:在当前工作目录跑。

PR 模式禁止在当前工作目录跑(本地可能不是该 PR head)。必须 base / head 双快照:

  1. 用步骤 1 的 baseRefOid / headRefOid,git fetch origin <OID>(用 OID,不用分支名)。
  2. git worktree add --detach <临时目录> <OID> 建 head、base 两个隔离 worktree,不动用户当前状态。
  3. 两处跑完全相同的 tsc / vitest;依赖未就绪则在对应子项目 yarn cli install,仍无法运行 →「环境异常降级」。
  4. 结束后 git worktree remove <临时目录>。

归因:head 失败且 base 同项失败 → 基线遗留,不记本 PR 的 P0(注明「base 同样失败,非本 PR 引入」,可作警告);head 失败且 base 通过 → ❌ P0;head 通过 → ✅。fetch / worktree 失败等无法构造快照 → 环境异常降级,不得标 ✅,也不得用当前目录结果代替。

Show full SKILL.md (154 more words)Show less
TS

对改动所在子项目跑整个子项目 type-check(不是单文件):

改动位置命令
app/renderer/src/main/cd app/renderer/src/main && yarn type-check
app/renderer/engine-link-startup/cd app/renderer/engine-link-startup && yarn type-check
仅 app/main/ 或不含 TS 子项目跳过,注明原因(主进程纯 JS 无 tsconfig / 本次无 TS)

通过 → 1 条 ✅;失败 → 1 条 ❌ P0(附 文件:行号 摘要);PR 模式 head 失败但 base 同样失败不记 P0。

测试

与 CI(scripts/ci-select-vitest-tests.js)相同的三条规则选相关测试:

  1. 变更文件本身是 __test__/ 下 *.test.* / *.spec.* → 纳入;
  2. 业务文件同目录 __test__/<stem>.(test|spec).* 存在 → 纳入;
  3. __test__/ 用例 import 了某个变更模块(grep 路径 / @renderer / @engine 等)→ 纳入。

仓库根执行(PR 模式在 base / head worktree 各跑相同命令):

bash
yarn test:vitest <测试文件...> --run

全通过 → 1 条 ✅(注明文件数与用例数);有失败 → 每个失败用例 ❌ P0(用例名 + 断言摘要);PR 模式 base 同样失败的不记 P0。找不到相关测试 → 汇总表「⏭️ 无相关测试」。

环境异常降级

tsc / vitest 因环境无法运行(依赖未装、node 版本等),而非代码报错:汇总表标 ⚠️「验证环境异常」,提示 yarn cli install。既不得标 ✅,也不得算代码问题。 PR 模式无法构造快照时同样降级。

5. 测试用例缺失

需要用例:新增/修改逻辑分支、纯工具函数、状态转换、复杂组件交互、bug 修复(防回归)。不需要:纯样式、纯文案/i18n、类型声明、构建/CI 配置本身。

需要但同目录无 __test__/<stem>.test.* → ❌ P1「缺失测试用例」,建议路径 <业务目录>/__test__/<stem>.test.ts。

严重程度

级别含义典型对结论
❌ P0必须修复安全漏洞、明确功能 bug、TS/测试验证失败存在即不通过
❌ P1需要修复边界缺陷、props 与定义不符、缺失测试存在即需要修复
⚠️ 警告不阻塞风格偏离、冗余、命名、依赖升级缺动机不影响结论

6. 输出三块报告

先在对话完整输出,再 AskUserQuestion 是否写入本地文件(文件名见步骤 1);同意才写,不同意仅留在对话。布局:

markdown
# Code Review 报告:<PR 标题 / 分支名 / 工作区改动>

## 一、Review 结果汇总

| 检查项 | 结果 |
| --- | --- |
| 代码逻辑检查 | ✅ / ❌ / ⏭️ N/A |
| TS 定义检查 | ✅ / ❌ / ⏭️ N/A |
| UI 引用与 Props 检查 | ✅ / ❌ / ⏭️ N/A |
| CSS 样式检查 | ✅ / ❌ / ⏭️ N/A |
| 依赖版本影响检查 | ✅ / ❌ / ⏭️ N/A(无 package.json 改动) |
| 配置项影响检查 | ✅ / ❌ / ⏭️ N/A(无配置文件改动) |
| TS 验证(tsc) | ✅ 通过 / ❌ 失败 / ⚠️ 环境异常 / ⏭️ 跳过(原因) |
| 测试验证(vitest) | ✅ N 个文件全通过 / ❌ 失败 / ⏭️ 无相关测试 |
| 测试用例缺失检查 | ✅ 齐全 / ❌ 缺失 N 处 |

**统计:正确 X 项 / 问题 Y 项(P0 a 项 / P1 b 项)/ 警告 Z 项**

## 二、明细解释

> 每项固定两行:第一行定位,第二行缩进两格写原因。第一行末尾两个空格(markdown hard break;下方 `··` 表示这两个空格,不要真写点号)。不得并成一行,也不得超过两行;细节压缩进第二行。

### ✅ 正确项

- 内容描述(确认了什么)··
  原因结果(为什么正确 / 验证依据)

### ❌ 问题项

行号必须写(函数定义行等);缺测试用关键函数行号。不允许只写路径。

- [P0] `文件:行号`··
  原因结果:<问题是什么> → <修复建议>
- [P1] `文件:行号`··
  原因结果:<问题是什么> → <修复建议>

### ⚠️ 警告项

- `文件:行号` 或 <一句话标题>··
  原因结果:<说明与建议>

## 三、合并结论

**结论:不通过 / 需要修复 / 可以合并**

<只允许这三种,不得出现「修复后可合并」等中间态>

统计:维度整体通过计 1 条正确项;每个问题/警告各 1 条;tsc / vitest 通过各 1 条正确项。⏭️ N/A 与 ⚠️ 环境异常不计入三项统计。

情况结论
任一 P0不通过
无 P0,有 P1需要修复
仅警告或全部正确可以合并

© yaklang, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/code-review of yaklang/yakit.

  • SKILL.md
  • references/check-dimensions.md

Open the folder on GitHubat commit 87904ea

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillyaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.0
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0
Code Reviewflutter/flutter179k—~1.4kAutomated safety check: PassBSD-3-Clause
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0

Similar skills

  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from yaklang/yakit

  • Create PR

    yaklang/yakit

    为 Yakit 仓库一站式完成提 PR 流程:提交工作区改动、调用 code-review skill 评审、推送远端后在 yaklang/yakit 创建或更新 PR。当用户要求提 PR、提交 PR、创建 PR、发 PR、raise/submit/open PR、"create PR"、更新已有 PR,或使用 /create-pr 时触发。

    7.8k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Commit Msg

    yaklang/yakit

    为 Yakit 仓库完成一次本地提交:确定提交范围(暂存区优先,空则弹框确认)、基于 diff 归纳一行符合仓库风格的 message、commit 前弹窗确认、执行 git commit(不推送)。只要 message 时仅输出文本。用户说「提交」「commit 代码」或输入 /commit-msg,或被 create-pr 等 skill 调用时使用。

    7.8k GitHub stars~559 tokensUpdated today
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…. Code Review is an agent skill from yaklang/yakit.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review; tasks that involve Pull requests; tasks that involve Unit testing.

How do I install Code Review in Claude Code?

Run `npx skills add yaklang/yakit --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in yaklang/yakit) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add yaklang/yakit --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in yaklang/yakit) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/yakit --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (yarn, git and gh).

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Open Code Review CLI (alibaba/open-code-review, 44k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars), Open Code Review Delegate (alibaba/open-code-review, 44k stars) and Code Review (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

yaklang (a GitHub organization) maintains it in yaklang/yakit, which has 7,792 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: yaklang/yakit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.