code-review by paulrberg/agent-skills
npx skills add https://github.com/paulrberg/agent-skills --skill code-review通过证据找出变更代码中的高影响缺陷。优先关注安全性、正确性和回归问题,而非风格细节。
--fix: 报告发现后,按严重性顺序(CRITICAL -> HIGH -> MEDIUM -> LOW)自动应用所有建议的修复,然后重新运行针对性检查并准确报告更改内容。git rev-parse --git-dir。如果失败,停止并告知用户从 git 仓库中运行。git diff --name-only --diff-filter=ACMR
* 未跟踪:git ls-files --others --exclude-standard
* 合并两个列表并去重。广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
references/profiles/core.md 以及仅与当前差异匹配的领域配置文件。--fix 时:按严重性顺序应用所有建议的修复,然后运行针对性验证。references/output-schema.md 进行报告。references/profiles/security.md: 认证、外部输入、密钥、加密、公共网络接口、不安全解析。references/profiles/configuration.md: 环境/配置、超时、重试、连接池、限制、资源调优、发布控制。references/profiles/typescript-react.md: TypeScript/JavaScript/React/Node 文件。references/profiles/python.md: Python 服务、脚本、异步工作负载。references/profiles/shell.md: shell 脚本、CI 命令块、部署脚本。references/profiles/smart-contracts.md: Solidity/Solana/链上协议代码。references/profiles/data-formats.md: CSV/JSON/YAML/二进制数据导入/导出/解析。references/profiles/naming.md: 命名/意图清晰度(在正确性和安全性检查之后)。仅加载与触及文件相关的配置文件。除非用户请求深度审计,否则每次运行最好不超过三个领域配置文件。
运行最窄范围的检查以验证受影响的行为:
如果无法运行检查,请准确说明跳过了什么以及原因。
在以下情况时停止并请求指示:
每周安装次数
305
仓库
GitHub 星标数
41
首次出现
2026年2月5日
安全审计
安装于
codex256
opencode126
claude-code110
gemini-cli95
github-copilot95
amp95
Find high-impact defects in changed code with evidence. Prioritize security, correctness, and regressions over style nits.
--fix: After reporting findings, apply all suggested fixes automatically in severity order (CRITICAL -> HIGH -> MEDIUM -> LOW), then rerun targeted checks and report exactly what changed.git rev-parse --git-dir. If this fails, stop and tell the user to run from a git repository.git diff --name-only --diff-filter=ACMRgit ls-files --others --exclude-standardreferences/profiles/core.md plus only the domain profiles that match the current diff.--fix: apply all suggested fixes in severity order, then run targeted verification.references/output-schema.md.references/profiles/security.md: auth, external input, secrets, crypto, public network surfaces, unsafe parsing.references/profiles/configuration.md: env/config, timeouts, retries, pools, limits, resource tuning, rollout controls.references/profiles/typescript-react.md: TypeScript/JavaScript/React/Node files.references/profiles/python.md: Python services, scripts, async workloads.references/profiles/shell.md: shell scripts, CI command blocks, deployment scripts.references/profiles/smart-contracts.md: Solidity/Solana/on-chain protocol code.references/profiles/data-formats.md: CSV/JSON/YAML/binary ingestion/export/parsing.references/profiles/naming.md: naming/intent clarity (after correctness and security pass).Load only profiles relevant to touched files. Prefer no more than three domain profiles per pass unless the user requests a deep audit.
Run the narrowest checks that validate touched behavior:
If checks cannot run, state exactly what was skipped and why.
Stop and ask for direction when:
Weekly Installs
305
Repository
GitHub Stars
41
First Seen
Feb 5, 2026
Security Audits
Gen Agent Trust HubWarnSocketPassSnykFail
Installed on
codex256
opencode126
claude-code110
gemini-cli95
github-copilot95
amp95
agent-browser 浏览器自动化工具 - Vercel Labs 命令行网页操作与测试
138,300 周安装