code-review
Conducts and responds to code review — reviewing a change for correctness, design, and risk, and evaluating review feedback received on your own wor…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Code review
Two directions, one skill: reviewing, and being reviewed.
Reviewing
Read the diff against what the change is for, not against your preferences. Order matters — spend
attention where damage is expensive:
- Correctness — does it do what it claims, including at the boundaries and on the error path?
- Blast radius — what else consumes this? Signature and schema changes are the ones that break
things far away.
- Security and data — untrusted input, authorization, anything logged or persisted.
- Tests — do they pin the new behavior, or do they pass regardless?
- Design — will this shape hold under the next change?
- Style — last, and only where a linter cannot.
Say which category each comment is, and whether it blocks. A review that mixes a data-loss bug with
a naming preference in one undifferentiated list wastes the author's judgment.
Receiving
Feedback is a report of a reader's experience, and that part is always valid — if the reviewer
misread it, the code is misleading. The proposed remedy is a separate thing and may be wrong.
- Verify before implementing. A suggestion that would break behavior gets a reply, not a commit.
- Disagreeing is fine; ignoring is not. Answer every comment: changed, or why not.
- Do not batch-accept. Applying every suggestion without judgment is how good code becomes
incoherent.
- Where a reviewer is factually wrong, show the evidence — the test, the spec, the failing case —
rather than asserting.
Never
- Approve your own work, or a change you authored under another name.
- Leave a blocking comment without saying what would unblock it.
- Rewrite the author's approach in a review comment. Propose it, and let them decide.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。