code-review-expert
npx skills add https://github.com/wei-shaw/sub2api --skill code-review-expert
Agent 安装分布
Skill 文档
Universal Code Review Expert
åºäº git worktree é离 + 5 å Agent å¹¶è¡ + Context7 åå¹»è§éªè¯çéç¨ä»£ç å®¡æ ¸ç³»ç»ã
Guardrails
- åªè¯»å®¡æ ¸ï¼ç»ä¸ä¿®æ¹æºä»£ç ï¼åå ¥ä» éæ¥åæä»¶
- è¯è¨æ å ³ï¼éè¿ä»£ç 模å¼è¯å«èéç¼è¯åç°é®é¢
- æ¯ä¸ªå Agent å¨ç¬ç« git worktree ä¸å·¥ä½
- å®¡æ ¸ç»æåæ æ¡ä»¶æ¸ çææ worktreeï¼å³ä½¿ä¸éåºéï¼
- é®é¢å¿
é¡»ç»åºå
·ä½
file:lineï¼ä¸æ¥åæ³æ³èè° - æ¶åç¬¬ä¸æ¹åº API çåç°å¿ é¡»éè¿ Context7 MCP éªè¯ï¼ä¸¥ç¦åè®°å¿æè¨ API ç¶æ
- æä»¶ > 500 个æ¶èªå¨å¯ç¨éæ ·çç¥
- ä¸ä¸æä¿æ¤ï¼ä¸¥æ ¼éµå¾ªä¸æ¹ Context Budget Control è§åï¼é²æ¢ 200K ä¸ä¸æèå°½
Context Budget Control (ä¸ä¸æé¢ç®ç®¡ç)
æ ¸å¿é®é¢ï¼5 个å Agent å¹¶è¡å®¡æ ¸æ¶ï¼æ¯ä¸ª Agent 读å大éæä»¶ä¼å¿«éèå°½ 200K ä¸ä¸æï¼å¯¼è´å®¡æ ¸å¡ä½æå¤±è´¥ã
é¢ç®åé çç¥
主 Agent å¨ Phase 0 å¿ é¡»è®¡ç®ä¸ä¸æé¢ç®ï¼å¹¶åé ç»å Agentï¼
æ»å¯ç¨ä¸ä¸æ â 180K tokensï¼é¢ç 20K ç»ä¸» Agent æ±æ»ï¼
æ¯ä¸ªå Agent é¢ç® = 180K / 5 = 36K tokens
æ¯ä¸ªå Agent å¯è¯»åçæä»¶æ° â 36K / å¹³åæä»¶å¤§å°
ä¸é¡¹å¼ºå¶è§å
-
æä»¶åçä¸éå ï¼æ¯ä¸ªæä»¶åªåé ç»ä¸ä¸ªä¸»è¦ç»´åº¦ï¼ææä»¶ç±»å/è·¯å¾èªå¨å¤æï¼ï¼ä¸è¦å¤ç»´åº¦éå¤å®¡æ ¸å䏿件ãé«é£é©æä»¶ï¼authãcryptoãpaymentï¼ä¾å¤ï¼å¯åé ç»æå¤ 2 个维度ã
-
åæä»¶è¯»åä¸éï¼å Agent 读åå个æä»¶æ¶ï¼ä½¿ç¨
Readå·¥å ·çlimitåæ°ï¼æ¯æ¬¡æå¤è¯»å 300 è¡ãè¶ è¿ 300 è¡çæä»¶å段读åï¼ä» å®¡æ ¸å ³é®æ®µè½ã -
å Agent prompt ç²¾ç®ï¼ä¼ éç»å Agent ç prompt åªå å«ï¼
- 该维度çç²¾ç®æ£æ¥æ¸ åï¼ä¸è¦ä¼ å ¨é¨ 170 项ï¼åªä¼ 该维度ç ~30 项ï¼
- æä»¶å表ï¼è·¯å¾å³å¯ï¼ä¸å å«å 容ï¼
- C7 ç¼åä¸è¯¥ç»´åº¦ç¸å ³çé¨åï¼ä¸ä¼ å ¨éç¼åï¼
- è¾åºæ ¼å¼æ¨¡æ¿ï¼ä¸æ¬¡ï¼ä¸éå¤ï¼
-
ç»æè¾åºç²¾ç®ï¼å Agent æ¾å°é®é¢ååªè¾åº JSON Linesï¼ä¸è¦è¾åºè§£éæ§æåãæèè¿ç¨ææ»ç»ã宿ååªè¾åº status è¡ã
-
å Agent max_turns éå¶ï¼æ¯ä¸ªå Agent 使ç¨
max_turnsåæ°éå¶æå¤§è½®æ¬¡ï¼- æä»¶æ° ⤠10:
max_turns=15 - æä»¶æ° 11-30:
max_turns=25 - æä»¶æ° 31-60:
max_turns=40 - æä»¶æ° > 60:
max_turns=50
- æä»¶æ° ⤠10:
-
大ä»åºèªå¨é级ï¼
- æä»¶æ° > 200ï¼å为 3 个å Agentï¼å®å ¨+å¯é æ§ãæ¶æ+æ§è½ãè´¨é+å¯è§æµæ§ï¼
- æä»¶æ° > 500ï¼å为 2 个å Agentï¼å®å ¨éç¹ãè´¨ééç¹ï¼+ éæ · 30%
- æä»¶æ° > 1000ï¼å Agent ä¸²è¡ + éæ · 15% + ä» å®¡æ ¸åæ´æä»¶
-
å Agent 使ç¨
run_in_backgroundï¼ææå Agent Task è°ç¨è®¾ç½®run_in_background=trueï¼ä¸» Agent éè¿ Read å·¥å ·è½®è¯¢ output_file è·åç»æï¼é¿å å Agent ç宿´è¾åºåå¡«å°ä¸» Agent ä¸ä¸æã
æä»¶åé ç®æ³
ææä»¶è·¯å¾/åç¼èªå¨åé å°ä¸»è¦ç»´åº¦ï¼
| æ¨¡å¼ | 主维度 | è¾ å©ç»´åº¦ï¼ä» é«é£é©æä»¶ï¼ |
|---|---|---|
*auth*, *login*, *jwt*, *oauth*, *crypto*, *secret* |
Security | Reliability |
*route*, *controller*, *handler*, *middleware*, *service* |
Architecture | – |
*cache*, *pool*, *buffer*, *queue*, *worker* |
Performance | – |
*db*, *model*, *migration*, *transaction* |
Reliability | Performance |
*test*, *spec*, *log*, *metric*, *config*, *deploy* |
Quality | – |
| å ¶ä½æä»¶ | æç®å½è½®è¯¢åé å° 5 个维度 | – |
主 Agent æ±æ»æ¶çä¸ä¸ææ§å¶
Phase 3 æ±æ»æ¶ï¼ä¸» Agent ä¸è¦éæ°è¯»åå Agent å®¡æ ¸è¿çæä»¶ãä» åºäºå Agent è¾åºç JSON Lines è¿è¡ï¼
- å»éåå¹¶
- 严éç级æåº
- Context7 交åéªè¯ï¼ä» 对 critical/high 䏿ªéªè¯çå°æ°åç°ï¼
- å¡«å æ¥å模æ¿
Workflow
Phase 0 â Scope Determination
-
ç¡®å®å®¡æ ¸èå´ï¼æä¼å 级ï¼ï¼
- ç¨æ·æå®çæä»¶/ç®å½
- æªæäº¤åæ´ï¼
git diff --name-only+git diff --cached --name-only - æªæ¨éæäº¤ï¼
git log origin/{main}..HEAD --name-only --pretty=format:"" - å ¨ä»åºï¼å¯ç¨éæ ·ï¼åæ´æä»¶ â é«é£é©ç®å½ â å ¥å£æä»¶ â å ¶ä½ 30% éæ ·ï¼
-
æ¶é项ç®å ä¿¡æ¯ï¼è¯è¨ææãç®å½ç»æãæä»¶æ°é
-
çæä¼è¯ IDï¼
SESSION_ID="cr-$(date +%Y%m%d-%H%M%S)-$(openssl rand -hex 4)" WORKTREE_BASE="/tmp/${SESSION_ID}" -
å°æä»¶åé ç» 5 ä¸ªå®¡æ ¸ç»´åº¦ï¼æ¯ä¸ªæä»¶å¯è¢«å¤ç»´åº¦å®¡æ ¸ï¼
Phase 0.5 â Context7 Documentation Warm-up (åå¹»è§ç¬¬ä¸é)
è¯¦ç»æµç¨è§ references/context7-integration.md
- æ«æä¾èµæ¸ åï¼go.mod, package.json, requirements.txt, Cargo.toml, pom.xml çï¼
- æåæ ¸å¿ç´æ¥ä¾èµï¼æä¼å
级çéæå¤ 10 个å
³é®åºï¼
- P0 æ¡æ¶æ ¸å¿ï¼web æ¡æ¶ãORMï¼â P1 å®å ¨ç¸å ³ â P2 é«é¢ import â P3 å ¶ä½
- 对æ¯ä¸ªåºè°ç¨
resolve-library-idâget-library-docsï¼æ¯åº ⤠5000 tokensï¼ - æå»º C7 ç¥è¯ç¼å JSONï¼ä¼ éç»ææå Agent
- é级ï¼Context7 ä¸å¯ç¨æ¶è·³è¿ï¼æ¥åæ æ³¨ “æªç»å®æ¹ææ¡£éªè¯”
Phase 1 â Worktree Creation
CURRENT_COMMIT=$(git rev-parse HEAD)
for dim in security architecture performance reliability quality; do
git worktree add "${WORKTREE_BASE}/${dim}" "${CURRENT_COMMIT}" --detach
done
Phase 2 â Parallel Sub-Agent Dispatch (åå¹»è§ç¬¬äºé)
å¨ä¸æ¡æ¶æ¯ä¸ååºææ Task è°ç¨ï¼subagent_type: general-purposeï¼ï¼å¿
须设置ï¼
run_in_background: trueâ å Agent åå°è¿è¡ï¼ç»æåå ¥ output_fileï¼é¿å å填主 Agent ä¸ä¸æmax_turnsâ ææä»¶æ°é设置ï¼è§ Context Budget Controlï¼model: "sonnet"â å Agent ä½¿ç¨ sonnet 模åéä½å»¶è¿å token æ¶è
Agent æ°éæ ¹æ®æä»¶è§æ¨¡èªå¨è°æ´ï¼è§ Context Budget Control 大ä»åºé级è§åï¼ã
æ¯ä¸ª Agent æ¶å°ï¼
| åæ° | å 容 |
|---|---|
| worktree è·¯å¾ | ${WORKTREE_BASE}/{dimension} |
| æä»¶å表 | 该维度ç¬å åé çæä»¶ï¼ä¸éå ï¼ |
| æ£æ¥æ¸ å | 该维度对åºçç²¾ç®æ¸ åï¼~30 项ï¼éå ¨é 170 é¡¹ï¼ |
| C7 ç¼å | ä» è¯¥ç»´åº¦ç¸å ³çåºææ¡£æè¦ |
| è¾åºæ ¼å¼ | JSON Linesï¼è§ä¸æ¹ï¼ |
| æä»¶è¯»åéå¶ | åæä»¶æå¤ 300 è¡ï¼ä½¿ç¨ Read ç limit åæ° |
æ¯ä¸ªåç°è¾åºä¸è¡ JSONï¼
{
"dimension": "security",
"severity": "critical|high|medium|low|info",
"file": "path/to/file.go",
"line": 42,
"rule": "SEC-001",
"title": "SQL Injection",
"description": "è¯¦ç»æè¿°",
"suggestion": "ä¿®å¤å»ºè®®ï¼å«ä»£ç çæ®µï¼",
"confidence": "high|medium|low",
"c7_verified": true,
"verification_method": "c7_cache|c7_realtime|model_knowledge",
"references": ["CWE-89"]
}
å ³é®è§åï¼
- æ¶åç¬¬ä¸æ¹åº API çåç°ï¼æªç» Context7 éªè¯æ¶
confidenceä¸å¾ä¸ºhigh verification_method == "model_knowledge"çåç°èªå¨éä¸çº§ç½®ä¿¡åº¦- æ¯ä¸ªå Agent æå¤æ¶èåé ç Context7 æ¥è¯¢é¢ç®
- 宿åè¾åºï¼
{"status":"complete","dimension":"...","files_reviewed":N,"issues_found":N,"c7_queries_used":N}
Phase 3 â Aggregation + Cross-Validation (åå¹»è§ç¬¬ä¸é)
- çå¾ ææå Agent 宿
- åå¹¶ findingsï¼æ severity æåº
- Context7 交åéªè¯ï¼
- çé
c7_verified==falseä¸ severity 为 critical/high ç API ç¸å ³åç° - 主 Agent ç¬ç«è°ç¨ Context7 éªè¯
- éªè¯éè¿ â ä¿ç | éªè¯å¤±è´¥ â é级æå é¤ï¼æ è®°
c7_invalidatedï¼
- çé
- å»éï¼åä¸ file:line åå¹¶ï¼
- çææ¥åå°
code-review-report.mdï¼æ¨¡æ¿è§ references/report-template.mdï¼
Phase 4 â Cleanup (å¿ é¡»æ§è¡)
for dim in security architecture performance reliability quality; do
git worktree remove "${WORKTREE_BASE}/${dim}" --force 2>/dev/null
done
git worktree prune
rm -rf "${WORKTREE_BASE}"
å³ä½¿å颿¥éª¤å¤±è´¥ä¹å¿ é¡»æ§è¡æ¤æ¸ çã
Severity Classification
| ç级 | æ ç¾ | å®ä¹ |
|---|---|---|
| P0 | critical |
å·²åå¨çå®å ¨æ¼æ´æå¿ ç¶å¯¼è´æ°æ®ä¸¢å¤±/å´©æº |
| P1 | high |
髿¦ç触åç严éé®é¢æé大æ§è½ç¼ºé· |
| P2 | medium |
å¯è½è§¦åçé®é¢æææ¾è®¾è®¡ç¼ºé· |
| P3 | low |
代ç è´¨éé®é¢ï¼ä¸ç´æ¥å½±åè¿è¡ |
| P4 | info |
ä¼å建议ææä½³å®è·µæé |
置信度ï¼high / medium / lowï¼ä½ç½®ä¿¡åº¦é¡»è¯´æåå ã
Five Review Dimensions
æ¯ä¸ªç»´åº¦å¯¹åºä¸ä¸ªå Agentï¼è¯¦ç»æ£æ¥æ¸ åè§ references/checklists.mdï¼
- Security & Compliance â æ³¨å ¥æ¼æ´(10 ç±»)ãè®¤è¯ææãå¯é¥æ³é²ãå¯ç å¦ãä¾èµå®å ¨ãéç§ä¿æ¤
- Architecture & Design â SOLID ååãæ¶ææ¨¡å¼ãAPI 设计ãé误çç¥ã模åè¾¹ç
- Performance & Resource â ç®æ³å¤æåº¦ãæ°æ®åºæ§è½ãå å管çãå¹¶åæ§è½ãI/Oãç¼åãèµæºæ³æ¼
- Reliability & Data Integrity â é误å¤çã空å¼å®å ¨ãå¹¶åå®å ¨ãäºå¡ä¸è´æ§ãè¶ æ¶éè¯ãè¾¹çæ¡ä»¶ãä¼é å ³é
- Code Quality & Observability â å¤æåº¦ãéå¤ãå½åãæ»ä»£ç ãæµè¯è´¨éãæ¥å¿ãå¯è§æµæ§ãæå»ºé¨ç½²
Context7 Anti-Hallucination Overview
详ç»éæææ¡£è§ references/context7-integration.md
ä¸ééªè¯é²å¾¡ 5 ç±» LLM å¹»è§ï¼
| å¹»è§ç±»å | 说æ | é²å¾¡å± |
|---|---|---|
| API å¹»è§ | é误æè¨å½æ°ç¾å | 第ä¸é + 第äºé |
| åºå¼å¹»è§ | é误æ è®°ä»å¨ç¨ç API 为 deprecated | 第äºé + 第ä¸é |
| ä¸åå¨å¹»è§ | 声称æ°å¢ API ä¸åå¨ | 第ä¸é + 第äºé |
| åæ°å¹»è§ | é误æè¿°åæ°ç±»å/é»è®¤å¼ | 第äºé宿¶æ¥ |
| çæ¬æ··æ· | æ··æ·ä¸åçæ¬ API è¡ä¸º | 第ä¸éçæ¬éå® |
éªè¯è¦ç度è¯çº§ï¼FULL (100% API åç°å·²éªè¯) > PARTIAL (50%+) > LIMITED (<50%) > NONE
Error Handling
- æä¸ªå Agent 失败ï¼ç»§ç»æ±æ»å ¶ä»ç»æï¼æ¥åæ æ³¨ä¸å®æ´ç»´åº¦
- git worktree å建失败ï¼
git worktree pruneéè¯ â ä»å¤±è´¥ååéä¸²è¡æ¨¡å¼ - Context7 ä¸å¯ç¨ï¼è·³è¿éªè¯é¶æ®µï¼æ¥åæ æ³¨ “æªç»å®æ¹ææ¡£éªè¯”
- æææ åµä¸ Phase 4 æ¸ çå¿ é¡»æ§è¡
Resources
- references/checklists.md â 5 个å Agent ç宿´æ£æ¥æ¸ å (~170 项)
- references/context7-integration.md â Context7 MCP éæè¯¦ç»æµç¨ãç¼åæ ¼å¼ãæ¥è¯¢è§è
- references/report-template.md â å®¡æ ¸æ¥å Markdown 模æ¿