Code Review — /code-review

Review code tự động với adversarial rigor. Mỗi review bao gồm 3 stages bắt buộc: spec compliance, code quality, và red-team analysis tìm security holes.
Cập nhật bộ claudekit mới: Thêm /review-pr <#> --fix --reply (tự động reply vào PR) và /design-review (visual QA + auto-fix). Xem cấu trúc skill mới để biết đầy đủ.

Cú pháp


Luồng hoạt động bên trong

Khi bạn gõ /code-review #123, đây là 3 stages xảy ra:
1

Stage 1: Spec Compliance Review

Kiểm tra code có khớp với requirements/plan không.
  • Code implement đúng những gì được yêu cầu?
  • Có thiếu requirement nào không?
  • Có code thừa không được yêu cầu?
PHẢI pass Stage 1 mới được chạy Stage 2. Nếu fail → fix → re-review Stage 1.
2

Stage 2: Code Quality Review

Spawn code-reviewer subagent kiểm tra:
  • Scout edge cases trước
  • Standards, security, performance
  • Naming, readability, maintainability
Chỉ chạy SAU khi Stage 1 pass.
3

Stage 3: Adversarial Review (Red Team)

Spawn adversarial reviewer CỐ TÌM CÁCH PHÁ code:
  • Security holes, false assumptions
  • Resource exhaustion, race conditions
  • Supply chain attacks, observability gaps
Mỗi finding được đánh giá: Accept (phải fix) / Reject (false positive) / Defer (tạo GitHub issue). Critical findings CHẶN merge.Skip nếu: <= 2 files, <= 30 lines, không có security files.

Input Modes

Auto-detect từ arguments. Nếu không rõ hoặc không có argument → hỏi user.

Ví dụ thực tế


So sánh với chat trực tiếp


Khi nào dùng / không dùng


Sub-commands


Review variants

/review-pr #123 --fix --reply — Auto-fix + reply PR

Review PR + auto-fix issues + post comments directly to PR:
Output:
  • PR comments with findings
  • Auto-fixed commit (if --fix enabled)
  • Inline reply to each comment (if --reply enabled)
Khi dùng: Reviewer wants to fix issues AND post feedback in one go.

/design-review — Visual QA + design system check

Review UI components, design system compliance, visual consistency:
Checks:
  • Design system tokens match (color, spacing, typography)
  • Component prop usage (Button, Card, Input variants)
  • Responsive design correctness
  • Accessibility (contrast, labels, ARIA)
  • Brand consistency
Output: Design findings + auto-fixes for style issues. Khi dùng: UI/frontend PRs, component library updates.

/review — GStack Pre-landing Review

Review diff trước khi merge, focus vào:
  • SQL safety (injection, raw queries)
  • LLM prompt changes (prompt injection risks)
  • Breaking API changes (endpoint, response shape)
  • Security vulnerabilities (OWASP Top 10)
  • Config safety (env vars, secrets)

Verification Gates — Iron Law

KHÔNG BAO GIỜ CLAIM “done” hay “fixed” MÀ KHÔNG CÓ FRESH EVIDENCE. Quy trình verify:
  1. IDENTIFY command cần chạy
  2. RUN full command
  3. READ output
  4. VERIFY output confirms claim
  5. THEN mới claim
Red flags (dấu hiệu CHƯA verify):
  • “should work”, “probably fine”, “seems to pass”
  • Hài lòng trước khi verify
  • Tin agent reports mà không double-check

Chi tiết lệnh Code Review (Accordion)

Prefix: /review-pr <#> --fix --replyReview GitHub PR + auto-fix issues + post comments to PR:
Flags:
  • --fix — Apply auto-fixes if possible
  • --reply — Post inline comments to PR
  • Both optional but recommended
Output:
  • PR comments with findings
  • Commit with auto-fixes (if --fix)
  • Reply to each review comment (if --reply)
Khi dùng: Full-service PR review + feedback in one command.
Prefix: /design-reviewReview UI/frontend code từ design system angle:
Checks:
  • Design tokens (color, spacing, typography match system)
  • Component usage (Button, Card variants correct?)
  • Responsive design correctness
  • Accessibility (contrast, ARIA labels)
  • Brand consistency
  • Visual hierarchy
Output: Design findings + auto-fixes for style issues.Khi dùng: UI/frontend PRs, component library updates, design system compliance.