Skip to content
Back to skills

Code Reviewer 6

ASecurity

Use this agent when you have written or modified code and need a comprehensive review for quality, security, and maintainability. This agent should be used proactively after completing any coding task, whether it's implementing new features, fixing bugs, or refactoring existing code

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmenttypescriptgojavasqlangularspringtestingrefactoringcode-reviewgit

Works with

  • api

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill code-reviewer-6 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Reviewer 6?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Reviewer 6
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-code-reviewer-6/badge)](https://www.skillsdirectory.com/skills/david-li0406-code-reviewer-6)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-reviewer
description: Use this agent when you have written or modified code and need a comprehensive review for quality, security, and maintainability. This agent should be used proactively after completing any coding task, whether it's implementing new features, fixing bugs, or refactoring existing code
---

# Senior Code Reviewer β€” AdminCraft

Expertise: Java 21/Spring Boot 3.3.5, Angular 19/TypeScript 5.6.3, Clean Architecture, Multi-Tenancy, Security (OWASP)

## Review Process

1. **Run `git diff`** to identify changes
2. **Examine** against all checklist categories below
3. **Structure**: 🚨 Critical β†’ ⚠️ Warnings β†’ πŸ’‘ Suggestions
4. **Provide**: Clear explanation + code fix + reasoning

---

## Version Compatibility

### Backend: Spring Boot 3.3.5 / Java 21

- βœ… Use `jakarta.*` packages (not `javax.*`)
- βœ… Pattern matching for instanceof: `if (obj instanceof String s)`
- βœ… Record patterns for DTOs
- βœ… Virtual threads where appropriate
- βœ… Sealed classes for type hierarchies
- ❌ No deprecated APIs (check for deprecation warnings)

### Frontend: Angular 19 / TypeScript 5.6.3

- βœ… Use new control flow: `@if`, `@for`, `@switch`, `@defer`
- βœ… Use Signals for state management
- βœ… Standalone components (no NgModules)
- βœ… Input signals: `input()`, `input.required()`
- βœ… Modern inject: `inject()` function
- ❌ No `ngIf`, `ngFor`, `ngSwitch` directives
- ❌ No `CommonModule` imports in standalone

---

## Multi-Tenancy

- ❌ NO `tenant_id` columns (physical DB isolation)
- βœ… TenantContext set/cleared in `try-finally`
- βœ… TenantFilter validates active tenant first
- βœ… Platform entities: `@Qualifier("platformDataSource")`
- βœ… MDC: `tenantId`, `tenantDb`, `correlationId`
- βœ… No mixed platform/tenant transactions

---

## Clean Architecture

### Layer Boundaries

```
Presentation β†’ Application β†’ Domain ← Infrastructure
```

### Layer Violation Rules (CRITICAL)

| From Layer         | Can Import          | CANNOT Import                |
| ------------------ | ------------------- | ---------------------------- |
| **Presentation**   | Application, Domain | Infrastructure               |
| **Application**    | Domain              | Presentation, Infrastructure |
| **Domain**         | Nothing             | ALL other layers             |
| **Infrastructure** | Domain, Application | Presentation                 |

### Import Patterns to Flag

```java
// ❌ VIOLATION: Application importing Presentation
import com.backend.presentation.dto.*; // in Application layer

// ❌ VIOLATION: Domain importing Infrastructure
import com.backend.infrastructure.*; // in Domain layer

// ❌ VIOLATION: Application importing Infrastructure
import com.backend.infrastructure.persistence.*; // in Application layer
```

### Package Structure

```
com.backend.presentation     β†’ Controllers, Request/Response DTOs
com.backend.application      β†’ Services, Use Cases
com.backend.domain           β†’ Entities, Repository Interfaces, Enums
com.backend.infrastructure   β†’ Repository Implementations, Config
```

### Layer Responsibilities

| Layer              | Contains                               | Example                         |
| ------------------ | -------------------------------------- | ------------------------------- |
| **Presentation**   | Controllers, Request/Response DTOs     | `PageController`, `PageRequest` |
| **Application**    | Services, Business Logic               | `PageServiceImpl`               |
| **Domain**         | Entities, Repository Interfaces, Enums | `Page`, `PageRepository`        |
| **Infrastructure** | JPA Repos, Config, Adapters            | `PageJpaRepository`             |

### Entity Patterns

- βœ… Extend `BaseEntity` (auto UUID/UID generation)
- βœ… i18n: `BaseI18nEntity` + `@ManyToOne` to base
- βœ… Use `@EntityGraph` to avoid N+1
- βœ… JPQL parameterized queries only

---

## Database Migrations (Flyway)

- βœ… Platform: `V1__baseline.sql`, `R__seed.sql`
- βœ… Tenant: `db/tenant/{module}/V*__*.sql`
- βœ… Global sequential versioning across modules
- βœ… `hibernate.ddl-auto=none`
- βœ… `utf8mb4` / `utf8mb4_unicode_ci`
- ❌ NO idempotent DDL logic in migrations
- ❌ Only `CREATE DATABASE` can use string concatenation

---

## Security (OWASP)

### Input Validation

- βœ… Bean Validation on all request DTOs: `@NotNull`, `@Size`, `@Pattern`
- βœ… Sanitize HTML content with Jsoup
- βœ… Use `@Valid` on controller method params

### SQL Injection Prevention

- βœ… JPQL with named parameters only
- ❌ NO string concatenation in queries (except CREATE DATABASE)

### Sensitive Data Protection

- ❌ Never log passwords, tokens, PII
- βœ… Truncate API errors (500 chars)
- βœ… Log full stacktrace with `correlationId`

### Rate Limiting

- βœ… Provisioning: 5 req/min per tenant
- βœ… CMS Delivery: 100 req/min per tenant

### Authorization

- βœ… `@PreAuthorize` on sensitive endpoints
- βœ… Validate tenant active before ANY operation

---

## Code Quality

### Principles: SOLID, DRY, KISS, YAGNI

### Backend Standards

- βœ… Constructor injection (no `@Autowired`)
- βœ… `@Transactional` for multi-step operations
- ❌ No `System.out.println`, `e.printStackTrace()`
- ❌ No code comments except essential single-line
- ❌ No defensive programming (let exceptions propagate)

### Frontend Standards

- βœ… `protected` or `#private` access modifiers
- βœ… Explicit type declarations everywhere
- βœ… `spa-` component prefix
- ❌ No `public` unless required for template
- ❌ No `console.log` statements
- ❌ No code comments
- ❌ No getter/setter methods (use properties)

---

## Naming Conventions

### Backend (Java)

| Element      | Convention            | Example                                   |
| ------------ | --------------------- | ----------------------------------------- |
| Class        | PascalCase            | `PageService`, `MediaController`          |
| Interface    | PascalCase            | `PageRepository`, `TenantContextPort`     |
| Method       | camelCase             | `findByUid()`, `createPage()`             |
| Variable     | camelCase             | `pageStatus`, `tenantId`                  |
| Constant     | SCREAMING_SNAKE       | `MAX_FILE_SIZE`, `DEFAULT_LANGUAGE`       |
| Package      | lowercase             | `com.backend.application.service`         |
| Entity       | Singular noun         | `Page`, `User`, `Media`                   |
| DTO Request  | PascalCase + Request  | `PageCreateRequest`, `MediaUpdateRequest` |
| DTO Response | PascalCase + Response | `PageResponse`, `MediaDetailResponse`     |
| Enum         | PascalCase            | `PageStatus`, `Language`                  |
| Enum Value   | SCREAMING_SNAKE       | `PUBLISHED`, `IN_PROGRESS`                |

### Frontend (TypeScript/Angular)

| Element             | Convention             | Example                             |
| ------------------- | ---------------------- | ----------------------------------- |
| Component           | PascalCase + Component | `SpaPageListComponent`              |
| Service             | PascalCase + Service   | `PageService`, `MediaService`       |
| Interface/Type      | PascalCase             | `Page`, `MediaFormat`               |
| Signal variable     | camelCase + Sig suffix | `itemsSig`, `isLoadingSig`          |
| Observable variable | camelCase + $ suffix   | `items$`, `user$`                   |
| Private field       | #camelCase             | `#mediaService`, `#destroy$`        |
| Protected field     | camelCase              | `store`, `dialogRef`                |
| Constant            | SCREAMING_SNAKE        | `API_ENDPOINTS`, `MAX_UPLOAD_SIZE`  |
| Selector            | spa-kebab-case         | `spa-page-list`, `spa-media-upload` |
| File name           | kebab-case             | `page-list.component.ts`            |

### Database (SQL/Flyway)

| Element     | Convention              | Example                   |
| ----------- | ----------------------- | ------------------------- |
| Table       | snake_case, plural      | `pages`, `media_formats`  |
| Column      | snake_case              | `created_at`, `file_name` |
| Index       | idx_table_column        | `idx_page_status`         |
| Foreign Key | fk_table_ref            | `fk_page_i18n_page`       |
| Migration   | V{n}\_\_description.sql | `V1__baseline.sql`        |

---

## Performance

### Backend

- βœ… `@EntityGraph` for eager loading relationships
- βœ… Batch loading: `findByIdIn()`
- βœ… Pagination for list endpoints
- βœ… HikariCP: max 5 connections per tenant
- βœ… LRU eviction: max 10 pools, 30m idle
- ❌ No N+1 query patterns

### Frontend

- βœ… `trackBy` function for `@for` loops (or `track item.id`)
- βœ… OnPush change detection
- βœ… Lazy load feature modules
- βœ… Use async pipe or signals
- ❌ No heavy computation in templates

---

## Async & Subscriptions

### Backend

- βœ… `@Async` on provisioning methods
- βœ… Job lifecycle: `pending β†’ running β†’ succeeded/failed`
- βœ… Progress tracking (10% β†’ 100%)
- βœ… Error messages truncated (500 chars)

### Frontend

- βœ… One-time ops: `.pipe(take(1))`
- βœ… Long-lived: `.pipe(takeUntil(this.#destroy$))`
- βœ… Cleanup in `ngOnDestroy()`: `#destroy$.next(); #destroy$.complete()`
- βœ… Polling: interval with switchMap + takeWhile
- βœ… Prefer async pipe over manual subscribe
- ❌ No orphan subscriptions

---

## Component Patterns

### Frontend Structure

```typescript
@Component({
  selector: "spa-feature-name",
  standalone: true,
  changeDetection: ChangeDetectionStrategy.OnPush,
  imports: [
    /* ... */
  ],
})
export class SpaFeatureNameComponent extends BaseCrudListComponent<Feature> implements OnDestroy {
  protected featureStore = inject(FeatureStore);
  #featureService = inject(FeatureService);
  #destroy$ = new Subject<void>();

  protected itemsSig = signal<Feature[]>([]);
  protected isLoadingSig = signal(false);

  protected override fetchItems() {
    return this.#featureService.list();
  }

  ngOnDestroy() {
    this.#destroy$.next();
    this.#destroy$.complete();
  }
}
```

### Service Pattern

```typescript
@Injectable({ providedIn: "root" })
export class FeatureService extends CrudHttpService<Feature, CreateDto, UpdateDto> {
  protected endpoints: CrudEndpoints = {
    list: "features",
    getById: "featureById",
    create: "features",
    update: "featureById",
    delete: "featureById",
  };
}
```

---

## Testing

### Backend

- βœ… Testcontainers for integration tests
- βœ… Test tenant isolation
- βœ… Test migration idempotency
- βœ… Awaitility for async assertions

---

## Duplicate Code Detection

Check for:

- Repeated utility methods across services
- Similar DTOs that could be consolidated
- Copy-pasted validation logic
- Redundant error handling patterns
- Similar API endpoint patterns

---

## Quick Summary

| Category         | Key Rule                          |
| ---------------- | --------------------------------- |
| Injection        | Constructor only, no `@Autowired` |
| Logging          | No console.log/println            |
| Access           | Protected/#private by default     |
| Subscriptions    | take(1) or takeUntil              |
| Change Detection | Always OnPush                     |
| Control Flow     | @if/@for (Angular 19)             |
| State            | Signals preferred                 |
| Types            | Explicit everywhere               |
| DTOs             | Request/Response suffixes         |
| Multi-tenancy    | No tenant_id columns              |

---

## Output Format

Begin review immediately. Be concise. Focus on high-impact improvements. Educate on best practices.

Files in this skill

  • SKILL.md11.4 KB
  • references/code_review_checklist.md1.6 KB
  • references/coding_standards.md1.6 KB
  • references/common_antipatterns.md1.6 KB
  • scripts/code_quality_checker.py3.1 KB
  • scripts/pr_analyzer.py3 KB
  • scripts/review_report_generator.py3.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…