id = "code-review" name = "Code Review" description = "Parallel code analysis pipeline that evaluates correctness, security, and style independently, then synthesises findings into a unified review summary." category = "engineering" tags = ["code", "review", "security", "quality"] [i18n.zh] name = "代码审查" description = "并行代码分析流水线,独立评估正确性、安全性和代码风格,然后将发现汇总为统一的审查报告。" [[parameters]] name = "code" description = "The source code or diff to review" param_type = "string" required = true [[parameters]] name = "language" description = "Programming language of the code" param_type = "string" required = false default = "auto-detect" [[parameters]] name = "context" description = "Additional context about the codebase or change purpose" param_type = "string" required = false default = "" [[steps]] name = "review_correctness" prompt_template = """ Review the following {{language}} code for correctness. Analyse: - Logic errors and edge cases - Error handling completeness - Null/undefined safety - Off-by-one errors and boundary conditions - Resource leaks (memory, file handles, connections) - Concurrency issues (race conditions, deadlocks) Context: {{context}} Code: {{code}} """ [[steps]] name = "review_security" prompt_template = """ Perform a security review of the following {{language}} code. Check for: - Injection vulnerabilities (SQL, command, XSS) - Authentication and authorisation flaws - Sensitive data exposure (logging secrets, hardcoded credentials) - Input validation gaps - Insecure cryptographic usage - Path traversal and SSRF risks - Dependency vulnerabilities Context: {{context}} Code: {{code}} """ [[steps]] name = "review_style" prompt_template = """ Review the following {{language}} code for style and maintainability. Evaluate: - Naming conventions and clarity - Function/method length and complexity - Code duplication - Documentation and comments quality - Consistent formatting - Appropriate use of language idioms - API design and public interface clarity Context: {{context}} Code: {{code}} """ [[steps]] name = "synthesise" prompt_template = """ Synthesise the three independent code review analyses below into a unified review summary. Prioritise findings by severity (critical, high, medium, low). Remove duplicates across analyses. Produce a final verdict: approve, request-changes, or needs-discussion. Correctness review: {{review_correctness}} Security review: {{review_security}} Style review: {{review_style}} """ depends_on = ["review_correctness", "review_security", "review_style"]