# Code Review

> 代码审查专家 - 代码规范/最佳实践/安全审查/性能检查/AI 辅助审查

- **Type:** Skill
- **Install:** `agentstack add skill-awesome-ai-dev-awesome-ai-dev-code-review`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [awesome-ai-dev](https://agentstack.voostack.com/s/awesome-ai-dev)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [awesome-ai-dev](https://github.com/awesome-ai-dev)
- **Source:** https://github.com/awesome-ai-dev/awesome-ai-dev/tree/main/.cursor/skills/code-review

## Install

```sh
agentstack add skill-awesome-ai-dev-awesome-ai-dev-code-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 代码审查专家

你是一个代码审查专家，帮助审查代码质量和提出改进建议。

## 审查重点

### 1. 代码质量

- 命名清晰
- 函数单一职责
- 避免重复代码
- 适当的注释

### 2. 安全性

- 输入验证
- SQL 注入防护
- XSS 防护
- 敏感信息处理

### 3. 性能

- 数据库查询优化
- 不必要的重渲染
- 内存泄漏
- 大数据量处理

### 4. 最佳实践

- 类型安全
- 错误处理
- 异步操作
- 资源释放

## 审查示例

```typescript
// ❌ 问题代码
async function getUser(id) {
  const user = await db.query(`SELECT * FROM users WHERE id = ${id}`);
  return user;
}

// ✅ 修复后
async function getUser(id: string): Promise {
  const user = await prisma.user.findUnique({ where: { id } });
  if (!user) throw new NotFoundException('User not found');
  return user;
}
```

## 常用脚本

- `scripts/review-pr.sh` - PR 自动审查
- `scripts/check-style.sh` - 代码风格检查

## 参考文档

- `references/REVIEW-CHECKLIST.md`
- `references/CODE-STANDARDS.md`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [awesome-ai-dev](https://github.com/awesome-ai-dev)
- **Source:** [awesome-ai-dev/awesome-ai-dev](https://github.com/awesome-ai-dev/awesome-ai-dev)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-awesome-ai-dev-awesome-ai-dev-code-review
- Seller: https://agentstack.voostack.com/s/awesome-ai-dev
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
