Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Review

ASecurity

评审代码,不评审人:给可操作建议、提问而非命令、解释为什么、区分阻断与建议、肯定好的做法、知道何时收手。 Use when the user asks to review a PR, diff, or code change, or wants review feedback improved or responded to. 触发于「帮我评审这段代码/这个 PR」「回复 review 意见」。

17 stars
0 votes
0 copies
0 views
Added 10/5/2026
developmentcode-reviewgit

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 10/5/2026

$npx -y skills add AntheaLaffy/mvsep-rs --skill code-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/anthealaffy-code-review/badge)](https://www.skillsdirectory.com/skills/anthealaffy-code-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-review
description: >
  评审代码,不评审人:给可操作建议、提问而非命令、解释为什么、区分阻断与建议、肯定好的做法、知道何时收手。
  Use when the user asks to review a PR, diff, or code change, or wants review feedback
  improved or responded to. 触发于「帮我评审这段代码/这个 PR」「回复 review 意见」。
---

# 代码评审

主线:评审是异步地「谈论代码」——有人提出改动,其他人思考它、像头脑风暴一样讨论好在哪、坏在哪。它关乎**这段代码在此项目、此目的、此刻是否合理**,与写代码的人无关。评审不是官僚负担:它在代码入库前抓 bug、在团队内传播知识,也是最快的学习方式之一——既能看到要避免的错误,也能学到好模式。新鲜眼睛能抓到资深开发者忽视的东西。commit 拆分质量(`git add -p`)是评审的常规检查项,标准见 `writing-for-readers`。

## 给出评审

- **评审代码,不评审人**:「这个函数读起来费解」而非「你写的代码很难懂」。评审体验决定贡献者是否愿意回来——每次开口都是挑错,没人想再来第二次。
- **给可操作的建议**:「这里能否改用配置 dataclass,而不是全局变量?这样测试可以并行跑」而非「别用全局变量」。
- **提问而非命令**:「如果这里 X 为 null 会怎样?」而非「把 null 情况处理掉」——促进讨论,也让对方自己意识到问题。
- **解释为什么**:「这里用常量吧」不如「用常量,方便按环境调整超时时间」。
- **区分阻断性问题与建议**:说明哪些必须修改、哪些只是偏好;非阻断的按惯例标 `nit:`,让对方能按优先级分诊。
- **评论别泛滥**:一百条评论里,可能一半在头五十条改完后已经失效;对方也不知道哪条最重要。重复出现的模式只评第一处:「这是本仓库的变量命名规范,请在全代码库统一使用」,而不是逐行炮轰。
- **肯定做得好的地方**:指出巧妙的解法或干净的实现——结对编程时如果每次开口都是说对方做错了,那会是很糟的体验,评审同理。它让评审更平衡,也让对方更有动力改你要求的部分。
- **知道何时收手**:盯住大问题,小问题必要时自己事后顺手清理。
- **AI 只能做第一道筛查,不能替代人工评审**:LLM 做的是 zero-context review——只看 diff 和描述。而评审真正重要的部分(这个改动对整体代码库、产品方向、版本策略是否是好主意?是不是还没准备好发 breaking change?)恰恰需要它没有的上下文;给它塞上下文也常常只是复述模式而非真正理解。AI 说没问题 ≠ 维护者会同意。

## 收到评审

- **「代码不是你本人」**:审核者是在让代码更好,不是批评你。
- 不同意就提澄清问题——也许你能学到东西,或者他们能学到。

## 练习

学习材料在 `exercises.md`。

> 改编自 MIT The Missing Semester 课程 Lecture 8: Beyond the Code(讲义 + 口播稿,CC BY-NC-SA 4.0):https://creativecommons.org/licenses/by-nc-sa/4.0/ · 课程站点:https://missing.csail.mit.edu/ · 讲座视频:https://www.youtube.com/watch?v=2DOEATfXT8k

Attribution

AntheaLaffyAntheaLaffy
View sourceSee grades on GitHubMore from AntheaLaffy →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

286712 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

2927051 votes
View all in development →