Code Review — /code-review
Review code tự động với adversarial rigor. Mỗi review bao gồm 3 stages bắt buộc: spec compliance, code quality, và red-team analysis tìm security holes.
Cập nhật bộ claudekit mới: Thêm
/review-pr <#> --fix --reply (tự động reply vào PR) và /design-review (visual QA + auto-fix). Xem cấu trúc skill mới để biết đầy đủ.Cú pháp
Luồng hoạt động bên trong
Khi bạn gõ/code-review #123, đây là 3 stages xảy ra:
1
Stage 1: Spec Compliance Review
Kiểm tra code có khớp với requirements/plan không.
- Code implement đúng những gì được yêu cầu?
- Có thiếu requirement nào không?
- Có code thừa không được yêu cầu?
2
Stage 2: Code Quality Review
Spawn
code-reviewer subagent kiểm tra:- Scout edge cases trước
- Standards, security, performance
- Naming, readability, maintainability
3
Stage 3: Adversarial Review (Red Team)
Spawn adversarial reviewer CỐ TÌM CÁCH PHÁ code:
- Security holes, false assumptions
- Resource exhaustion, race conditions
- Supply chain attacks, observability gaps
Input Modes
Auto-detect từ arguments. Nếu không rõ hoặc không có argument → hỏi user.Ví dụ thực tế
- Input
- Output
So sánh với chat trực tiếp
Khi nào dùng / không dùng
Sub-commands
Review variants
/review-pr #123 --fix --reply — Auto-fix + reply PR
Review PR + auto-fix issues + post comments directly to PR:
- PR comments with findings
- Auto-fixed commit (if
--fixenabled) - Inline reply to each comment (if
--replyenabled)
/design-review — Visual QA + design system check
Review UI components, design system compliance, visual consistency:
- Design system tokens match (color, spacing, typography)
- Component prop usage (Button, Card, Input variants)
- Responsive design correctness
- Accessibility (contrast, labels, ARIA)
- Brand consistency
/review — GStack Pre-landing Review
Review diff trước khi merge, focus vào:
- SQL safety (injection, raw queries)
- LLM prompt changes (prompt injection risks)
- Breaking API changes (endpoint, response shape)
- Security vulnerabilities (OWASP Top 10)
- Config safety (env vars, secrets)
Verification Gates — Iron Law
KHÔNG BAO GIỜ CLAIM “done” hay “fixed” MÀ KHÔNG CÓ FRESH EVIDENCE. Quy trình verify:- IDENTIFY command cần chạy
- RUN full command
- READ output
- VERIFY output confirms claim
- THEN mới claim
- “should work”, “probably fine”, “seems to pass”
- Hài lòng trước khi verify
- Tin agent reports mà không double-check
Chi tiết lệnh Code Review (Accordion)
/review-pr #123 --fix --reply — Auto-fix + reply
/review-pr #123 --fix --reply — Auto-fix + reply
Prefix: Flags:
/review-pr <#> --fix --replyReview GitHub PR + auto-fix issues + post comments to PR:--fix— Apply auto-fixes if possible--reply— Post inline comments to PR- Both optional but recommended
- PR comments with findings
- Commit with auto-fixes (if
--fix) - Reply to each review comment (if
--reply)
/design-review — Visual QA + design system
/design-review — Visual QA + design system
Prefix: Checks:
/design-reviewReview UI/frontend code từ design system angle:- Design tokens (color, spacing, typography match system)
- Component usage (Button, Card variants correct?)
- Responsive design correctness
- Accessibility (contrast, ARIA labels)
- Brand consistency
- Visual hierarchy