本文へ移動
cccskills
無料GitHub で公開

add-code-review

Code review: IoC, RESTful, Contracts, Security (OWASP), Clean Architecture, SOLID.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md8.9 KB
  • source.json602 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Code Review

Skill for validating implemented code against project standards.

Use for: Validate code, identify violations, auto-fix (autopilot) Do not use for:

  • Implementing new features (use add-backend-development / add-frontend-development)
  • Planning or specifying work (use add-planning / add-feature-specification)
  • Codebase discovery or architecture analysis (use add-feature-discovery / add-architecture-discovery)

Reference: Always consult CLAUDE.md for general project standards.


MANDATORY RULE: TodoWrite

BEFORE starting any review, you MUST create a todo list using TodoWrite.

The code-review agent MUST create todos for each validation category and for each changed file. This ensures:

  1. Progress visibility for the user
  2. No validation is forgotten
  3. Traceability of fixes

Reference Skills

Load BEFORE reviewing:

  • Backend: {{skill:add-backend-development/SKILL.md}}
  • Database: {{skill:add-database-development/SKILL.md}}
  • Frontend (Code): {{skill:add-frontend-development/SKILL.md}}
  • Frontend (UI): {{skill:add-ux-design/SKILL.md}}
  • Security: {{skill:add-security-audit/SKILL.md}}

Validation Categories

1. Spec Compliance (CRITICAL)

Spec vs implementation gap = the root cause of features that "pass review" but diverge from what was planned.

Sources (lookup):

{"sources":{"contracts":"docs/features/${FEATURE_ID}/plan.md (prose: routes, services, DTOs, queues)","tick_state":"docs/features/${FEATURE_ID}/tasks.md → ## Acceptance Checklist"}}

Validation procedure:

  1. READ contracts from plan.md prose (routes, services, DTOs, queues)
  2. READ tick state from tasks.md → ## Acceptance Checklist (each item ends with (RFNN/RNNN) reference)
  3. For EACH contract item:
    1. Locate implementation with file:line
    2. Validate EXISTENCE and BEHAVIOR:
      • Route exists AND accepts correct params?
      • Service is generic as spec OR hardcoded?
      • DTO has all specified fields?
    3. Cross-reference: do items cover ALL RF/RN from about.md?
    4. Status: COMPLIANT | DIVERGENT (exists but differs) | MISSING

Examples:

TypeSpecCodeFix
DIVERGENTPOST /billing/webhook/:providerPOST /webhook (fixed route)Refactor route to accept :provider param
DIVERGENTWebhookNormalizerService (generic)StripeWebhookService (hardcoded)Extract generic interface, rename service
MISSINGWebhookSignatureGuardNo guard foundImplement guard or document explicit scope exclusion

Spec Compliance scoring:

  • COMPLIANT (all items match): full points
  • DIVERGENT (functional but differs): -1 per item
  • MISSING (not implemented): -2 per item, blocks merge if RF-linked

2. Architecture Contract (MOST CRITICAL)

Architecture violation = CRITICAL BLOCKER. Fix BEFORE any other validation.

Source: CLAUDE.md → ## Architecture Contract.

Validation steps:

For EACH new/modified file:

  1. Identify the file's layer/package
  2. Grep imports of @org/* (or project alias)
  3. Verify against Import rules from the contract
  4. Verify the artefact is in the correct package (Placement)

Examples:

ViolationFix
interfaces imports databaseMove artefact or adjust import
Service-contract DTO in databaseMove DTO to interfaces
domain imports anythingRemove import — domain has zero deps

3. IoC Configuration (CRITICAL)

Code without correct IoC does NOT work at runtime.

Checklist by component type (lookup)

{"iocChecklist":{"Service":{"decorator":"@Injectable()","providers":"feature module","exports":false,"controllers":false,"indexTs":false},"Repository":{"decorator":"@Injectable()","providers":"db module","exports":"db module","controllers":false,"indexTs":"libs/"},"Handler":{"decorator":"@Injectable()","providers":"feature module","exports":false,"controllers":false,"indexTs":"NEVER"},"Guard":{"decorator":"@Injectable()","providers":"feature/global","exports":false,"controllers":false,"indexTs":false},"Controller":{"decorator":"@Controller()","providers":false,"exports":false,"controllers":"feature module","indexTs":false}}}

Files to verify for IoC

FileCheck
apps/backend/src/app.module.tsimports[] contains module
[feature].module.tsproviders[], controllers[], imports[]
libs/app-database/src/app-database.module.tsproviders[], exports[] for repos
libs/app-database/src/index.tspublic repo exports
libs/app-database/src/types/Database.tsnew table types
libs/domain/src/index.tsnew entity/enum exports

Common IoC Errors

ErrorCauseFix
Nest can't resolve dependencies of XX not in providers[] or X's dependency not registeredAdd X and its dependencies to providers[]
X is not a providerMissing @Injectable() or not registeredAdd decorator and register in providers[]
Module X not foundModule not imported in AppModuleAdd to AppModule.imports[]
Repository not foundRepo not exported in db module exports[]Add to AppDatabaseModule exports[]
404 on endpointController not registered or module not importedCheck controllers[] and AppModule.imports[]

4. RESTful Compliance (CRITICAL)

RuleCorrectWrong
HTTP methodGET read, POST create, DELETE removePOST for read
URL/users (noun)/getUsers (verb)
Status201 POST, 204 DELETE200 for all

5. Contract Validation (CRITICAL)

Frontend ↔ Backend:

BackendFrontend
Datestring
Enumunion type

Sync required / optional fields between backend and frontend.

JSONB rules:

  • NO double parse
  • NO double stringify
  • Kysely handles automatically

6. Security (OWASP)

CategoryCheck
Injectionparametrized queries
Authguards applied
Data Exposureno secrets in logs
Access Controlfilter by account_id
XSSoutputs sanitized

Multi-tenant:

  • EVERY query filters account_id
  • account_id from JWT, not body

7. SOLID Principles

  • SRP: one class, one responsibility
  • OCP: open for extension, closed for modification
  • LSP: subtypes substitutable
  • ISP: specific interfaces over general
  • DIP: depend on abstractions

8. Code Quality

  • No any type
  • DTOs follow naming
  • No console.log (use logger)
  • No commented code
  • No unused imports
  • Exception handling

9. Database

  • Migration created
  • Has up and down
  • Kysely types updated
  • Entity exported
  • Repository exported

10. Environment

  • New vars in .env.example
  • Example values not real
  • Use IConfigurationService, not process.env

Score

Weights and status (lookup):

{"weights":{"specCompliance":20,"archContract":20,"ioc":15,"restful":10,"contracts":15,"security":15,"solid":10,"quality":10,"database":5}} {"status":{"8-10":"APPROVED","6-7":"NEEDS ATTENTION","4-5":"NEEDS FIXES","0-3":"CRITICAL"}}


Process

Phase 1: Load Context & Create Todos

  1. bash .codeadd/scripts/status.sh
  2. Read reference skills (backend, database, frontend, security)
  3. Read CLAUDE.md
  4. Identify ALL changed files
  5. Create TodoWrite (see MANDATORY RULE) covering each validation category and changed file

Phase 2: Validate

For EACH changed file, validate in order, marking each todo in_progress → completed:

  1. Spec Compliance — see §1
  2. Architecture Contract — see §2 (CRITICAL BLOCKER if violated; fix before continuing)
  3. IoC Configuration — see §3
  4. RESTful Compliance — see §4
  5. Contract Validation — see §5
  6. Security (OWASP) — see §6
  7. SOLID Principles — see §7
  8. Code Quality — see §8
  9. Database — see §9

Phase 3: Fix (autopilot)

  1. For each issue found:
    • Create specific todo: "Fix [issue] in [file]"
    • Mark as in_progress
    • Apply fix
    • Mark as completed
  2. Verify build compiles
  3. Document before/after

Phase 4: Report

Generate the review report at docs/features/${featureId}/review.md. The exact output template (score table, issue format, build status) is owned by the consuming command (add.review) — this skill validates; the command formats.


Rules

Do:

  • Create TodoWrite BEFORE starting review and update it during each phase
  • Load reference skills BEFORE review
  • Run status.sh FIRST
  • Auto-fix in autopilot
  • Verify build
  • Document before/after

Don't:

  • Start review without creating TodoWrite
  • Skip Architecture Contract validation (MOST critical)
  • Skip IoC validation
  • Report without fixing (autopilot)
  • Ignore skill patterns
  • Accept "works" as justification
  • Leave non-compiling code
  • Forget to verify AppModule.imports[] or barrel exports in libs/

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

007

無料

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

10x-team

無料

You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

aibot88 のスキルをすべて見る

このスキルの問題を報告する