* feat(workflows): add 13 workflow templates across engineering, business, and productivity Engineering: - bug-triage: reproduce path → root cause → fix plan - api-design: resource model → endpoints → OpenAPI spec - incident-postmortem: timeline → RCA → full postmortem report - test-generation: code analysis → edge cases → full test suite - refactor-plan: smell analysis → prioritised opportunities → migration plan Business: - competitor-analysis: profiles → SWOT → strategy report - product-spec: problem definition → user stories → full PRD - market-research: landscape → segments → research report Productivity/Thinking: - meeting-summary: raw notes → structured summary → follow-up email - decision-matrix: criteria → weighted scoring → recommendation memo - learning-plan: gap analysis → roadmap → week-1 day-by-day plan - job-application: job analysis → tailored resume → cover letter → interview prep - blog-post: research → outline → draft → SEO optimisation Closes #1912 on librefang/librefang * fix(workflows): overhaul existing 9 templates - data-pipeline: redesigned — original 'extract from URL' step was broken (LLMs cannot fetch URLs); replaced with paste-data approach (profile → clean_transform → analyse) with analysis_goal parameter - translate-polish: added target_language and register parameters; added back-translation step for accuracy verification - weekly-report: added team/audience parameters, richer extraction step, added Metrics and Notes sections - content-pipeline: added audience/tone parameters, added outline step between research and writing - content-review: fix category 'content' → 'creation' - customer-support: fix category 'support' → 'business' * style(workflows): convert all prompt_template strings to TOML multiline syntax Replace \n escape sequences with real newlines using triple-quote multiline strings ("""...""") across all 22 workflow templates. No content changes — formatting only. * style(hands): replace \n escape in reddit writer format example with multiline code block
99 lines
2.6 KiB
TOML
99 lines
2.6 KiB
TOML
id = "code-review"
|
|
name = "Code Review"
|
|
description = "Parallel code analysis pipeline that evaluates correctness, security, and style independently, then synthesises findings into a unified review summary."
|
|
category = "engineering"
|
|
tags = ["code", "review", "security", "quality"]
|
|
|
|
[i18n.zh]
|
|
name = "代码审查"
|
|
description = "并行代码分析流水线,独立评估正确性、安全性和代码风格,然后将发现汇总为统一的审查报告。"
|
|
|
|
[[parameters]]
|
|
name = "code"
|
|
description = "The source code or diff to review"
|
|
param_type = "string"
|
|
required = true
|
|
|
|
[[parameters]]
|
|
name = "language"
|
|
description = "Programming language of the code"
|
|
param_type = "string"
|
|
required = false
|
|
default = "auto-detect"
|
|
|
|
[[parameters]]
|
|
name = "context"
|
|
description = "Additional context about the codebase or change purpose"
|
|
param_type = "string"
|
|
required = false
|
|
default = ""
|
|
|
|
[[steps]]
|
|
name = "review_correctness"
|
|
prompt_template = """
|
|
Review the following {{language}} code for correctness. Analyse:
|
|
- Logic errors and edge cases
|
|
- Error handling completeness
|
|
- Null/undefined safety
|
|
- Off-by-one errors and boundary conditions
|
|
- Resource leaks (memory, file handles, connections)
|
|
- Concurrency issues (race conditions, deadlocks)
|
|
|
|
Context: {{context}}
|
|
|
|
Code:
|
|
{{code}}
|
|
"""
|
|
|
|
[[steps]]
|
|
name = "review_security"
|
|
prompt_template = """
|
|
Perform a security review of the following {{language}} code. Check for:
|
|
- Injection vulnerabilities (SQL, command, XSS)
|
|
- Authentication and authorisation flaws
|
|
- Sensitive data exposure (logging secrets, hardcoded credentials)
|
|
- Input validation gaps
|
|
- Insecure cryptographic usage
|
|
- Path traversal and SSRF risks
|
|
- Dependency vulnerabilities
|
|
|
|
Context: {{context}}
|
|
|
|
Code:
|
|
{{code}}
|
|
"""
|
|
|
|
[[steps]]
|
|
name = "review_style"
|
|
prompt_template = """
|
|
Review the following {{language}} code for style and maintainability. Evaluate:
|
|
- Naming conventions and clarity
|
|
- Function/method length and complexity
|
|
- Code duplication
|
|
- Documentation and comments quality
|
|
- Consistent formatting
|
|
- Appropriate use of language idioms
|
|
- API design and public interface clarity
|
|
|
|
Context: {{context}}
|
|
|
|
Code:
|
|
{{code}}
|
|
"""
|
|
|
|
[[steps]]
|
|
name = "synthesise"
|
|
prompt_template = """
|
|
Synthesise the three independent code review analyses below into a unified review summary. Prioritise findings by severity (critical, high, medium, low). Remove duplicates across analyses. Produce a final verdict: approve, request-changes, or needs-discussion.
|
|
|
|
Correctness review:
|
|
{{review_correctness}}
|
|
|
|
Security review:
|
|
{{review_security}}
|
|
|
|
Style review:
|
|
{{review_style}}
|
|
"""
|
|
depends_on = ["review_correctness", "review_security", "review_style"]
|