analyze-repo
npx skills add https://github.com/miles990/claude-software-skills --skill analyze-repo
Agent 安装分布
Skill 文档
/analyze-repo v3.0
伿¥ç´å°æ¡æ·±åº¦åæ â å層è¦è¦ºå à éä½åçæäº à å¯å·è¡å»ºè°
v3.0 æ°ç¹æ§
| ç¹æ§ | 說æ |
|---|---|
| ð¯ ä¸å±¤åææ¶æ§ | Executiveï¼5åéï¼â Architecture Storyï¼30åéï¼â Deep Diveï¼æéï¼ |
| ð¬ How It Works | æ°å¢ãå°æ¡å¦ä½éä½ãæäºç« ç¯ï¼å¿«éçè§£æ ¸å¿æµç¨ |
| ð è¦è¦ºåªå | æ¯å±¤ä»¥å表éé ï¼æåè¼å©èªªæ |
| ð èæé | ææç¼ç¾é帶 file:line ç¨å¼ç¢¼å¼ç¨ |
| ð ï¸ å¯å·è¡å»ºè° | æ¯é 建è°å«ï¼åé¡ç¨å¼ç¢¼ â 修復ç¯ä¾ â é©èæ¥é© |
æ ¸å¿å¹å¼
| è¼¸å ¥ | è¼¸åº |
|---|---|
| GitHub URL ææ¬å°è·¯å¾ | ä¸å±¤å°æ¥åæå ±å â è¦è¦ºåè¡¨æ¿ + éä½åçæäº + å¯å·è¡å»ºè° |
é©ç¨å ´æ¯ï¼
- ð¢ æè¡ä¸»ç®¡/CTO â Layer 1 å¿«éæ±ºç + Layer 2 æ¶æ§è©ä¼°
- ð¨âð» éç¼è â Layer 2 çè§£éä½åç + Layer 3 䏿æå
- ð° æè³äºº/Due Diligence â Layer 1 é¢¨éªæè¦ + Layer 2 æè¡æ·±åº¦
- ð Code Review â Layer 3 éæªæ¡åæ + å¯å·è¡ä¿®å¾©å»ºè°
å ±åä¸å±¤æ¶æ§
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â ð LAYER 1: Executive Dashboardï¼5-10 åéï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â ç®æ¨ï¼é«å±¤å¿«éææ¡å°æ¡çæ
â
â ⢠å®é è¦è¦ºå表æ¿ï¼å¥åº·é·éå + 風éªç±ååï¼ â
â ⢠ä¸å¥è©±å®ä½ + 30 ç§å°æ¡æè¦ â
â ⢠3 åééµç¼ç¾å¡çï¼å«å³æè¡å建è°ï¼ â
â ⢠競åå®ä½ç©é£ â
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â ðï¸ LAYER 2: Architecture Storyï¼30-60 åéï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â ç®æ¨ï¼çè§£å°æ¡å¦ä½éä½ â
â ⢠ð¬ãéåå°æ¡å¦ä½éä½ãæµç¨æäºï¼æ ¸å¿åµæ°ï¼ â
â ⢠C4 åå±¤æ¶æ§åï¼Context â Container â Component â Codeï¼ â
â â¢ è³ææµåºååï¼ä¸»è¦ä½¿ç¨å ´æ¯ï¼ â
â ⢠æè¡æ±ºçåæï¼çºä»éº¼ç¨ X èé Yï¼ â
â ⢠8 ç¶åº¦å質è©ä¼°è©³è§£ â
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â ð¬ LAYER 3: Deep Dive Referenceï¼æéæ¥é±ï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â ç®æ¨ï¼å¯å·è¡çæ¹é²è¡å â
â ⢠æ¯åç¼ç¾é帶 file:line èæé â
â ⢠å¯å·è¡å»ºè°ï¼åé¡ç¢¼ â 修復ç¯ä¾ â é©èæ¥é© â
â ⢠æè¡åµå修復æ¸
å®ï¼å«åªå
ç´ + å·¥æä¼°ç®ï¼ â
â â¢ å®æ´æªæ¡çµæ§èééµå
¥å£é» â
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
ä½¿ç¨æ¹å¼
# åºæ¬åæï¼é è¨è¼¸åºå®æ´ä¸å±¤å ±åï¼
/analyze-repo https://github.com/owner/repo
/analyze-repo .
/analyze-repo /path/to/project
# æå®æ·±åº¦ï¼å¯é¸ï¼
/analyze-repo . --depth=executive # å
Layer 1ï¼å¿«éæè¦ï¼
/analyze-repo . --depth=story # Layer 1 + 2ï¼å«éä½åçï¼
/analyze-repo . --depth=full # 宿´ä¸å±¤ï¼é è¨ï¼
# æå®è¦è§ï¼å¯é¸ï¼å½±é¿å
§å®¹å´éï¼
/analyze-repo . --perspective=executive # å´éæ±ºçææ¨
/analyze-repo . --perspective=architect # å´éæ¶æ§è¨è¨
/analyze-repo . --perspective=developer # å´é䏿æå
/analyze-repo . --perspective=investor # å´é風éªè©ä¼°
# çµå使ç¨
/analyze-repo . --depth=story --perspective=developer
åææ¡æ¶
ä½ æ¯è³æ·±è»é«æ¶æ§é¡§åï¼å ·å arc42ãC4 ModelãSOLID/DDD å°æ¥ç¥èã
Phase 1: è³ææ¶éèæ å¢å»ºç«
1.1 便ºå¤æ·
https://github.com/â GitHub API + åå§ç¢¼åæ- æ¬å°è·¯å¾ â ç´æ¥æªæ¡ç³»çµ±åå
1.2 é鵿ªæ¡ææï¼åªå é åºï¼
| é¡å¥ | æªæ¡ | åæç®ç |
|---|---|---|
| å¥ä»¶ç®¡ç | package.json, requirements.txt, pyproject.toml, Cargo.toml, go.mod, pom.xml, build.gradle |
ä¾è³´åæãçæ¬æª¢æ¥ |
| 容å¨å | Dockerfile, docker-compose.yml, k8s/ |
é¨ç½²æ¶æ§ |
| æä»¶ | README.md, CLAUDE.md, docs/, ARCHITECTURE.md |
å°æ¡æå |
| é ç½® | tsconfig.json, next.config.*, .env.example, config/ |
æè¡æ±ºç |
| CI/CD | .github/workflows/, .gitlab-ci.yml, Jenkinsfile |
èªååæç度 |
| 測試 | tests/, __tests__/, spec/, *_test.go, *.spec.ts |
測試è¦è |
| å ¥å£é» | main.*, index.*, app.*, src/ |
ç¨å¼ç¢¼çµæ§ |
| å®å ¨ | .env, secrets/, credentials*, *.pem, *.key |
ææè³è¨æª¢æ¥ |
1.3 å°æ¡å æ¸ææ¶é
- ç¨å¼ç¢¼è¡æ¸ï¼æèªè¨åé¡ï¼
- æäº¤æ·å²ï¼æ´»èºåº¦ãè²¢ç»è åä½ï¼
- Issue/PR çµ±è¨ï¼å¦çº GitHubï¼
- License é¡å
Phase 2: å°æ¡éä½åçï¼How It Worksï¼ð
æ ¸å¿åµæ°ï¼è®è®è å¨ 5 åéå §çè§£ãéåå°æ¡å°åºå¨åä»éº¼ãæéº¼åã
2.1 æ ¸å¿æµç¨æäº
å¿ é åççåé¡ï¼
- è¼¸å ¥æ¯ä»éº¼ï¼ â ç¨æ¶/系統觸ç¼ä»éº¼
- èçéç¨ï¼ â æ ¸å¿é輯å¦ä½éä½
- è¼¸åºæ¯ä»éº¼ï¼ â æçµç¢çä»éº¼çµæ
æ ¼å¼ï¼
ä¸å¥è©±çæ¬ï¼
ç¨æ¶ {è§¸ç¼æ¹å¼} â 系統 {èçæµç¨} â ç¢ç {æçµçµæ}
è©³ç´°çæ¬ï¼3-5 段ï¼ï¼
1. 觸ç¼é»ï¼{æè¿°å
¥å£}
2. æ ¸å¿èçï¼{æè¿°ä¸»è¦é輯}
3. è³ææµåï¼{æè¿°è³æå¦ä½æµå}
4. 輸åºçµæï¼{æè¿°ç¢åº}
2.2 主è¦ä½¿ç¨å ´æ¯åºåå
èå¥ 2-3 åæéè¦ç使ç¨å ´æ¯ï¼çºæ¯åå ´æ¯çæï¼
sequenceDiagram
actor User
participant Frontend
participant API
participant Service
participant DB
Note over User,DB: å ´æ¯ï¼{å ´æ¯å稱}
User->>Frontend: 1. {觸ç¼åä½}
Frontend->>API: 2. {API å¼å«}
API->>Service: 3. {æ¥åèç}
Service->>DB: 4. {è³ææä½}
DB-->>Service: 5. {åå³è³æ}
Service-->>API: 6. {èççµæ}
API-->>Frontend: 7. {åæ}
Frontend-->>User: 8. {å±ç¤ºçµæ}
2.3 ééµç¨å¼ç¢¼å ¥å£é»
æ¯åæµç¨å¿ é æ¨è¨»å ·é«æªæ¡ä½ç½®ï¼
| éæ®µ | æªæ¡ä½ç½® | 彿¸/é¡å¥ | 說æ |
|---|---|---|---|
| å ¥å£ | src/main.ts:15 |
bootstrap() |
æç¨åå |
| è·¯ç± | src/routes/index.ts:42 |
router.get() |
è«æ±åç¼ |
| é輯 | src/services/core.ts:128 |
processRequest() |
æ ¸å¿èç |
| è³æ | src/models/data.ts:23 |
DataModel |
è³æçµæ§ |
2.4 æ ¸å¿æ¼ç®æ³/é輯說æ
妿尿¡æç¨ç¹çæ¼ç®æ³æé輯ï¼ç¨ä»¥ä¸æ ¼å¼èªªæï¼
æ¼ç®æ³å稱ï¼{å稱}
ç¨éï¼{解決ä»éº¼åé¡}
è¤é度ï¼O(n) / O(log n) / etc.
èæ¬ç¢¼ï¼
1. {æ¥é© 1}
2. {æ¥é© 2}
3. {æ¥é© 3}
實éç¨å¼ç¢¼ä½ç½®ï¼`src/algorithms/xxx.ts:45-78`
Phase 3: æ¶æ§åæï¼C4 Model å層ï¼
Level 1: System Contextï¼ç³»çµ±æ å¢ï¼
- èå¥ç³»çµ±éç
- å¤é¨ä½¿ç¨è /è§è²
- å¤é¨ç³»çµ±æ´å
- ð é帶說æï¼ç¨ 2-3 å¥è©±è§£éå表å«ç¾©
Level 2: Containerï¼å®¹å¨ï¼
- æç¨ç¨å¼
- è³æå²å
- è¨æ¯ä½å
- 容å¨ééè¨åå®
- ð æè¡é¸ååå ï¼çºä»éº¼é¸éåæè¡
Level 3: Componentï¼å ä»¶ï¼
- ä¸»è¦æ¨¡çµ/å¥ä»¶
- ééµé¡å¥/彿¸
- 模çµè·è²¬åå
- ð ç¨å¼ç¢¼ä½ç½®ï¼æ¯åå ä»¶çæªæ¡è·¯å¾
Level 4: Codeï¼ç¨å¼ç¢¼å±¤ç´ï¼
- æ ¸å¿æ¼ç®æ³
- è¨è¨æ¨¡å¼ä½¿ç¨
- ééµè³æçµæ§
- ð ç¨å¼ç¢¼ç段ï¼å±ç¤ºééµå¯¦ä½
Phase 3: å質è©ä¼°ï¼8 ç¶åº¦ï¼
ä½¿ç¨ 1-100 åå¶è©ä¼°ï¼
| ç¶åº¦ | è©ä¼°æ¨æº | æ¬é |
|---|---|---|
| å¯ç¶è·æ§ | ç¨å¼ç¢¼è¤é度ãå½åè¦ç¯ã模çµåç¨åº¦ãMaintainability Index | 15% |
| 坿¸¬è©¦æ§ | 測試è¦èçãæ¸¬è©¦å質ãMock/Stub ä½¿ç¨ | 12% |
| 坿´å±æ§ | æ¶æ§å½æ§ãæ°´å¹³/åç´æ´å±è½åãè¨è¨æ¨¡å¼ | 12% |
| å®å ¨æ§ | ä¾è³´æ¼æ´ãææè³è¨æ´é²ãOWASP Top 10 | 15% |
| æä»¶å®æ´åº¦ | READMEãAPI æä»¶ãæ¶æ§æä»¶ã註解å質 | 10% |
| æ¶æ§å¥åº·åº¦ | SOLID åè¦ãéæ³¨é»åé¢ãå±¤æ¬¡æ¸ æ° | 15% |
| ä¾è³´å¥åº·åº¦ | ä¾è³´æ¸éãçæ¬éæç¨åº¦ã循ç°ä¾è³´ | 11% |
| éç¼è é«é© | 䏿é£åº¦ãéç¼å·¥å ·é ç½®ãé¯èª¤è¨æ¯å質 | 10% |
ç¶åå¥åº·åæ¸ = å æ¬å¹³å
Phase 4: æè¡åµååæ
4.1 åµååé¡ï¼SQALE 模åï¼
| é¡å¥ | 嵿¸¬ææ¨ |
|---|---|
| å¯é æ§åµå | æªèçä¾å¤ãç©ºææ¨é¢¨éªãè³æºæ´©æ¼ |
| å®å ¨æ§åµå | å·²ç¥æ¼æ´ã硬編碼å¯é°ãSQL æ³¨å ¥é¢¨éª |
| å¯ç¶è·æ§åµå | éè¤ç¨å¼ç¢¼ãéé·å½æ¸ãéæ·±å·¢ç |
| æè½åµå | N+1 æ¥è©¢ãç¡å¿«åçç¥ã忥é»å¡ |
| 測試åµå | ä½è¦èçãç¡æ´å測試ãè弱測試 |
4.2 åµåéå
- 修復æéä¼°ç®ï¼äººå¤©ï¼
- åªå ç´æåºï¼Impact à Effort ç©é£ï¼
- åµå趨å¢ï¼å¦ææ·å²è³æï¼
Phase 5: ä¾è³´éä¿åæ
5.1 ä¾è³´åè
- å §é¨æ¨¡çµä¾è³´éä¿
- å¤é¨å¥ä»¶ä¾è³´
- 循ç°ä¾è³´åµæ¸¬
- æå ¥/æåºåæï¼Afferent/Efferent Couplingï¼
5.2 ä¾è³´å¥åº·æª¢æ¥
| 檢æ¥é | 風éªçç´ |
|---|---|
| å·²ç¥ CVE æ¼æ´ | ð´ Critical |
| éå¤§çæ¬è½å¾ï¼>2 çï¼ | ð High |
| ç¡ç¶è·å¥ä»¶ï¼>2 å¹´ç¡æ´æ°ï¼ | ð High |
| 次è¦çæ¬è½å¾ | ð¡ Medium |
| ææ¬åè¦é¢¨éª | ð¡ Medium |
Phase 6: å®å ¨æ§è©ä¼°
6.1 éæ æææè¦
- ä¾è³´æ¼æ´ï¼npm audit / pip-audit / cargo-audit çæåæï¼
- ææè³è¨æ´é²ï¼API Keysãå¯ç¢¼ãTokenï¼
- ä¸å®å ¨ç¨å¼ç¢¼æ¨¡å¼
6.2 OWASP Top 10 æª¢æ¥æ¸ å®
| é¢¨éª | 檢æ¥é ç® |
|---|---|
| A01 Broken Access Control | ææ¬æª¢æ¥ãè·¯ç±ä¿è· |
| A02 Cryptographic Failures | å 坿¼ç®æ³ãå¯é°ç®¡ç |
| A03 Injection | è¼¸å ¥é©èãåæ¸åæ¥è©¢ |
| A07 Authentication | 身份é©èæ©å¶ãSession 管ç |
| A09 Logging & Monitoring | æ¥èªè¨éãç°å¸¸è¿½è¹¤ |
Phase 7: ç«¶åèå¹å¼åæ
7.1 ç¨ç¹å¹å¼ä¸»å¼µ (UVP)
- æ ¸å¿è§£æ±ºçåé¡
- å·®ç°åç¹é»
- ç®æ¨ä½¿ç¨è
7.2 ä¸å¯æ¿ä»£æ§è©ä¼°ï¼5 åå¶ï¼
| ç¶åº¦ | è©ä¼° |
|---|---|
| æè¡ç¨ç¹æ§ | æ ¸å¿æ¼ç®æ³ãå°å©ãç¨ç¹å¯¦ç¾ |
| çæ æ´å深度 | èå ¶ä»ç³»çµ±çæ´åç¨åº¦ |
| é·ç§»ææ¬ | æå°æ¿ä»£æ¹æ¡çææ¬ |
| å¸ç¿æ²ç· | åé䏿é£åº¦ |
| 社群活èºåº¦ | ç¶è·è ãè²¢ç»è ãIssue åæ |
7.3 ç«¶åæ¯è¼ç©é£
èå¥ 2-3 å主è¦ç«¶å/æ¿ä»£æ¹æ¡ï¼é²è¡åè½å°æ¯ï¼
å¿ é å å«çæ¯è¼ç¶åº¦ï¼
| ç¶åº¦ | 說æ |
|---|---|
| æ ¸å¿åè½ | 主è¦è§£æ±ºçåé¡ |
| æè¡æ¶æ§ | æè¡é¸åå·®ç° |
| æ´å±æ§ | æ¯å¦æ¯æ´æä»¶/æ´å± |
| å¸ç¿æ²ç· | 䏿é£åº¦ |
| 社群活èºåº¦ | ç¶è·çæ ãIssue åæ |
| ææ¬æ¹å¼ | éæº/忥/æ··å |
ç¯ä¾æ ¼å¼ï¼
| ç¹æ§ | æ¬å°æ¡ | ç«¶å A | ç«¶å B | ç«¶å C |
|------|--------|--------|--------|--------|
| æ ¸å¿åè½ | â
宿´ | â ï¸ é¨å | â
宿´ | â ç¡ |
| æ´å±æ§ | â
Plugin | â ç¡ | â ï¸ æé | â
宿´ |
| å¸ç¿æ²ç· | â ï¸ ä¸ç | â
ç°¡å® | â å°é£ | â ï¸ ä¸ç |
7.4 é©ç¨å ´æ¯åæ ð
ç¨é¤ ååç¾æé©åç使ç¨å ´æ¯ä½æ¯ï¼
pie title æé©å使ç¨å ´æ¯
"å ´æ¯ A" : 35
"å ´æ¯ B" : 25
"å ´æ¯ C" : 20
"å ´æ¯ D" : 15
"å
¶ä»" : 5
並æä¾æ¡ç¨å»ºè°ç©é£ï¼
| æ å¢ | å»ºè° | 說æ |
|---|---|---|
| æ å¢ A | â å¼·çæ¨è¦ | {çºä»éº¼é©å} |
| æ å¢ B | â æ¨è¦ | {çºä»éº¼é©å} |
| æ å¢ C | â ï¸ å¯è½éé | {çºä»éº¼å¯è½ä¸é©å} |
| æ å¢ D | â ä¸é©ç¨ | {çºä»éº¼ä¸é©å} |
Phase 7.5: å¸å ´æªä¾å¹å¼åæ
7.5.1 æè¡è¶¨å¢å°é½åº¦
è©ä¼°å°æ¡èç¶å/æªä¾æè¡è¶¨å¢çå¥åç¨åº¦ï¼
| 趨å¢é å | è©ä¼°é ç® |
|---|---|
| AI/ML æ´åè½å | æ¯å¦æ AI æ´åé»ãLLM å好 APIãåéè³æåº«æ¯æ´ |
| é²åçæç度 | 容å¨åãK8s æ¯æ´ãServerless é©é æ§ |
| éç·£éç®æºå度 | è¼éåå¯è½æ§ãé¢ç·è½åãä½å»¶é²è¨è¨ |
| Web3/å»ä¸å¿å | åå¡éæ´åæ½åãå»ä¸å¿åæ¶æ§å¯è½æ§ |
| æ°¸çºæ§/ç¶ è²éç® | è³æºæçãè½èåªåæ½å |
7.5.2 å¸å ´å®ä½åæ
quadrantChart
title Market Position Matrix
x-axis Low Tech Complexity --> High Tech Complexity
y-axis Low Market Demand --> High Market Demand
quadrant-1 Star (Invest)
quadrant-2 Question Mark (Evaluate)
quadrant-3 Pet (Divest)
quadrant-4 Cash Cow (Maintain)
7.5.3 æé·æ½åææ¨
| ææ¨ | è©ä¼°æ¹å¼ |
|---|---|
| TAM/SAM/SOM ä¼°ç® | ç®æ¨å¸å ´è¦æ¨¡ã坿åå¸å ´ãå¯ç²åå¸å ´ |
| æé·åè½ | GitHub Stars 趨å¢ãnpm ä¸è¼éã社群活èºåº¦æé·ç |
| ç¶²è·¯æææ½å | 使ç¨è è¶å¤å¹å¼è¶é«çç¹æ§ |
| å¹³å°åå¯è½æ§ | æ¯å¦å¯ç¼å±çºçæ å¹³å° |
| åæ¥æ¨¡å¼å½æ§ | éæº/SaaS/伿¥ççå¤å è®ç¾è·¯å¾ |
7.5.4 風éªèæ©æç©é£ï¼SWOT 延伸ï¼
| é¡å¥ | å §é¨ | å¤é¨ |
|---|---|---|
| æ£é¢ | åªå¢ Strengths | æ©æ Opportunities |
| è² é¢ | å£å¢ Weaknesses | å¨è Threats |
7.5.5 æè³/æ¡ç¨å»ºè°
åºæ¼ä»¥ä¸åæï¼çµ¦åºæç¢ºå»ºè°ï¼
- ð¢ å¼·çæ¨è¦ â æè¡å é²ãå¸å ´åæ¯ä½³ã風éªå¯æ§
- ð¡ 謹æ èæ ® â æå¹å¼ä½åå¨ç¹å®é¢¨éªæéå¶
- ð´ ä¸å»ºè° â æè¡éæãå¸å ´è縮ãæé¢¨éªéé«
7.5.6 çæ¬æ¼é²åæ ð
妿尿¡æ CHANGELOG æ Git æ·å²ï¼åæçæ¬æ¼é²ï¼
Gantt æé軸è¦è¦ºåï¼
gantt
title å°æ¡çæ¬æ¼é²
dateFormat YYYY-MM-DD
section æ ¸å¿åè½
v1.0 åå§çæ¬ :done, 2024-01-01, 30d
v2.0 éå¤§æ´æ° :done, 2024-03-01, 60d
v3.0 æ¶æ§éæ§ :done, 2024-06-01, 90d
section æ´ååè½
Plugin 系統 :done, 2024-04-01, 45d
API æ´å± :active, 2024-08-01, 60d
ééµçæ¬éç¨ç¢è¡¨ï¼
| çæ¬ | æ¥æ | éé»åè½ | å½±é¿ |
|---|---|---|---|
| v1.0 | YYYY-MM-DD | åå§ç¼å¸ | 建ç«åºç¤ |
| v2.0 | YYYY-MM-DD | {é大åè½} | {帶ä¾çæ¹è®} |
| v3.0 | YYYY-MM-DD | {é大åè½} | {帶ä¾çæ¹è®} |
æ¼é²è¶¨å¢åæï¼
- éç¼ç¯å¥ï¼{æ´»èº/ç©©å®/ç·©æ ¢}
- çæ¬çç¥ï¼{èªæåçæ¬/æ¥æçæ¬/å ¶ä»}
- åå¾ç¸å®¹æ§ï¼{è¯å¥½/éæ³¨æ/ç¶å¸¸ç ´å£}
Phase 8: çç¥å»ºè°çæ
8.1 åªå ç´ç©é£
ä½¿ç¨ Impact à Effort ç©é£å°ææç¼ç¾é²è¡åé¡ï¼
quadrantChart
title Priority Matrix
x-axis Low Effort --> High Effort
y-axis Low Impact --> High Impact
quadrant-1 Do First (Quick Wins)
quadrant-2 Plan (Major Projects)
quadrant-3 Delegate/Automate
quadrant-4 Evaluate (Consider Later)
8.2 å¯å·è¡å»ºè°æ¡æ¶ ð
æ ¸å¿ååï¼æ¯é 建è°å¿ é å¯ç«å³å·è¡ï¼ä¸éé¡å¤ç ç©¶
æ¯é 建è°å¿ é å å«ä»¥ä¸çµæ§ï¼
| æ¬ä½ | 說æ | å¿ å¡« |
|---|---|---|
| ID | å¯ä¸èå¥ç¢¼ï¼å¦ REC-001ï¼ | â |
| é¡å¥ | Architecture / Security / Performance / Quality / Documentation / DevOps | â |
| æ¨é¡ | ç°¡æ½æè¿°ï¼< 10 åï¼ | â |
| éè¦æ§ | âââ æ ¸å¿/å¿ è¦ / ââ éè¦/å»ºè° / â å¯é¸/å¢å¼· | â |
| åªå ç´ | ð´ Critical / ð High / ð¡ Medium / ð¢ Low | â |
| åé¡ä½ç½® | ð file:line å
·é«ç¨å¼ç¢¼ä½ç½® |
â |
| åé¡ç¨å¼ç¢¼ | ð å±ç¤ºæåé¡ç實éç¨å¼ç¢¼ç段 | â |
| 修復ç¯ä¾ | ð å±ç¤ºä¿®å¾©å¾çç¨å¼ç¢¼ç¯ä¾ | â |
| é©èæ¥é© | ð å¦ä½é©è修復æåï¼å½ä»¤ææ¸¬è©¦ï¼ | â |
| æåææ¨ | å¯è¡¡éç驿¶æ¨æº | â |
å»ºè°æ ¼å¼ç¯ä¾ï¼
### REC-001: 修復 SQL 注å
¥æ¼æ´
| å±¬æ§ | å¼ |
|------|-----|
| é¡å¥ | ð Security |
| éè¦æ§ | âââ æ ¸å¿ |
| åªå
ç´ | ð´ Critical |
#### ð åé¡ä½ç½®
- `src/api/users.ts:87`
- `src/api/products.ts:142`
#### â åé¡ç¨å¼ç¢¼
```typescript
// src/api/users.ts:87
const query = `SELECT * FROM users WHERE id = ${userId}`;
// ^^^^^^^^^ SQL 注å
¥é¢¨éª
â 修復ç¯ä¾
// src/api/users.ts:87
const query = 'SELECT * FROM users WHERE id = $1';
const result = await db.query(query, [userId]);
𧪠é©èæ¥é©
# 1. å·è¡å®å
¨ææ
npm run security:audit
# 2. 測試注å
¥é²è·
curl "localhost:3000/api/users/1'%20OR%20'1'='1"
# é æï¼400 Bad Requestï¼èéè³ææ´©æ¼ï¼
â æåææ¨
- ææ SQL æ¥è©¢ä½¿ç¨åæ¸å
-
npm auditç¡ Critical è¦å
#### 8.2.1 éè¦æ§èåªå
ç´çåå¥
- **éè¦æ§ (Importance)**ï¼å°å°æ¡é·æå¥åº·çå½±é¿ç¨åº¦
- âââ **æ ¸å¿/å¿
è¦** â ä¸åæå°è´å°æ¡å¤±ææå´é風éª
- ââ **éè¦/建è°** â 顯èæåå°æ¡å質æéä½é¢¨éª
- â **å¯é¸/å¢å¼·** â é¦ä¸æ·»è±ï¼æåé«é©
- **åªå
ç´ (Priority)**ï¼æè©²ä½æå·è¡
- çµåéè¦æ§ + ç·è¿«æ§
```mermaid
quadrantChart
title Importance vs Priority Matrix
x-axis Low Priority --> High Priority
y-axis Low Importance --> High Importance
quadrant-1 Strategic (Plan Carefully)
quadrant-2 Critical (Do Now)
quadrant-3 Optional (If Time Permits)
quadrant-4 Quick Wins (Easy Wins)
8.3 建è°åªå é åºè¦å
- å®å ¨æ§ Critical â å¿ é ç«å³èç
- å½±é¿çç¢ç°å¢ç©©å®æ§ â é«åªå ç´
- Quick Winsï¼é«å½±é¿ãæä¿®å¾©ï¼ â åªå å·è¡
- æè¡åµå â æç´¯ç©é¢¨éªæåº
- å¢å¼·åè½ â ææ¥åå¹å¼æåº
8.4 建è°åé¡è¦è¦ºå
flowchart TB
subgraph Critical["ð´ ç«å³èç"]
C1[å®å
¨æ¼æ´]
C2[çç¢ç°å¢é¢¨éª]
end
subgraph High["ð çæèç"]
H1[æ¶æ§åé¡]
H2[æè½ç¶é ¸]
end
subgraph Medium["ð¡ è¦åèç"]
M1[æè¡åµå]
M2[測試è¦è]
end
subgraph Low["ð¢ 驿èç"]
L1[æä»¶å®å]
L2[ç¨å¼ç¢¼é¢¨æ ¼]
end
Phase 9: Mermaid å表çæ
å¿ é ç¢ç以ä¸å表ï¼
9.1 C4 Context Diagram
C4Context
title System Context Diagram
Person(user, "User")
System(system, "Target System")
System_Ext(ext, "External System")
Rel(user, system, "Uses")
Rel(system, ext, "Integrates")
9.2 Container Diagram
C4Container
title Container Diagram
Container(web, "Web App", "React")
Container(api, "API", "Node.js")
ContainerDb(db, "Database", "PostgreSQL")
9.3 模çµä¾è³´å
flowchart LR
subgraph Core
A[Module A]
B[Module B]
end
A --> B
9.4 æè¡æ£§ç¸½è¦½
flowchart TB
subgraph Frontend
F1[React]
end
subgraph Backend
B1[Node.js]
end
subgraph Data
D1[(PostgreSQL)]
end
輸åºçµæ§ï¼ä¸å±¤æ¶æ§ï¼
ç¢ç宿´ Markdown å ±åï¼è©³è¦ extended/output-template.mdï¼ï¼
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â ð LAYER 1: Executive Dashboardï¼5-10 åéï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ£
1. Executive Summaryï¼è¦è¦ºå表æ¿ï¼
- ð¯ ä¸å¥è©±å®ä½
- ð å¥åº·åæ¸é·éåï¼è¦è¦ºåï¼
- â ï¸ 3 åééµé¢¨éªå¡ç
- ð ç«å³è¡å建è°ï¼Top 3ï¼
- ð ç«¶åå®ä½ç©é£å
2. 30 ç§å°æ¡æè¦
- 鿝ä»éº¼ï¼ï¼ä¸æ®µè©±ï¼
- 解決ä»éº¼åé¡ï¼
- æè¡æ£§ä¸è¦½
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ£
â ðï¸ LAYER 2: Architecture Storyï¼30-60 åéï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ£
3. ð¬ How It Worksï¼å°æ¡å¦ä½éä½ï¼ð
- æ ¸å¿æµç¨æäºï¼è¼¸å
¥ â èç â 輸åºï¼
- 主è¦ä½¿ç¨å ´æ¯åºååï¼2-3 åï¼
- ééµç¨å¼ç¢¼å
¥å£é»è¡¨
- æ ¸å¿æ¼ç®æ³/é輯說æ
4. Architecture Analysisï¼æ¶æ§åæï¼
- C4 å層å表ï¼é說ææåï¼
- æ¶æ§æ¨¡å¼èå¥
- æè¡é¸ååæï¼çºä»éº¼é¸ Xï¼
- æ¶æ§æ±ºçè¨é (ADR) æ¨æ¸¬
5. Quality Assessmentï¼å質è©ä¼°ï¼
- 8 ç¶åº¦é·éå
- åç¶åº¦è©³ç´°è©åè說æ
- åªå¢èé¢¨éªæ¸
å®
6. Value & Competitive Analysisï¼å¹å¼åæï¼
- UVP é³è¿°
- ä¸å¯æ¿ä»£æ§è©å
- ç«¶åæ¯è¼ç©é£
- å¸å ´å®ä½åæ
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ£
â ð¬ LAYER 3: Deep Dive Referenceï¼æéæ¥é±ï¼ â
â âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ£
7. Technical Debt Reportï¼æè¡åµåå ±åï¼
- åµåå顿¸
å®ï¼é file:lineï¼
- åªå
ç´ç©é£
- 修復建è°ï¼å«ç¨å¼ç¢¼ç¯ä¾ï¼
8. Dependency Analysisï¼ä¾è³´åæï¼
- ä¾è³´åè
- å¥åº·æª¢æ¥å ±å
- 循ç°ä¾è³´è¦å
9. Security Assessmentï¼å®å
¨è©ä¼°ï¼
- æ¼æ´æææè¦
- OWASP æª¢æ¥æ¸
å®
- 風éªçç´åé¡ï¼é file:lineï¼
10. ð ï¸ Actionable Recommendationsï¼å¯å·è¡å»ºè°ï¼ð
- æåªå
ç´åé¡ï¼
* ð´ ç«å³èç
* ð çæèç
* ð¡ è¦åèç
* ð¢ 驿èç
- æ¯é
建è°å
å«ï¼
* ð åé¡ä½ç½®ï¼file:lineï¼
* â åé¡ç¨å¼ç¢¼
* â
修復ç¯ä¾
* 𧪠é©èæ¥é©
* â æåææ¨
11. Appendixï¼ééï¼
- 宿´ç®éçµæ§
- é鵿ªæ¡æ¸
å®è說æ
- è¡èªè¡¨
- åææ¹æ³èªªæ
å·è¡æºå
â å¿ é éµå®
- 宿´è®å â 確ä¿è¶³å¤ æªæ¡é²è¡æºç¢ºåæ
- 客è§è©ä¼° â åºæ¼å¯¦éå質è©åï¼é¿å é度æ¨è§ææ²è§
- å ·é«éå â ç¡å¯è½æä¾æ¸åè鿍¡ç³æè¿°
- å表æ£ç¢º â ç¢ºä¿ Mermaid èªæ³æ£ç¢ºå¯æ¸²æ
- å¯è¡å»ºè° â æ¯é 建è°å¿ é å ·é«å¯å·è¡
â é¿å äºé
- æ²ææ ¹æçæ¨æ¸¬
- é度æè¡è¡èªï¼æ ¹æ perspective 調æ´ï¼
- 模ç³çè©èªï¼å¦ãéä¸é¯ãããæå¾ æ¹é²ãï¼
- éºæ¼ééµé¢¨éª
åèè³æº
- arc42 Template â è»é«æ¶æ§æä»¶æ¨æº
- C4 Model â æ¶æ§è¦è¦ºåæ¹æ³
- SQALE Method â æè¡åµåè©ä¼°
- OWASP Top 10 â Web å®å ¨é¢¨éª
ç¸é Skills
/evolveâ èªä¸»å®æè¤éç®æ¨/commitâ æäº¤ç¨å¼ç¢¼è®æ´/code-reviewâ æ·±åº¦ç¨å¼ç¢¼å¯©æ¥
ARGUMENTS: $ARGUMENTS