本文へ移動
cccskills
無料GitHub で公開

auto-code-review

Security scan + code quality + auto-fix on git push.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Auto Code Review Agent

Push-getriggerter Code-Review-Agent der Security-Scans, Code-Qualitätsprüfungen und Style-Checks automatisch durchführt und behebbare Issues patchen kann.

Verwendung

# Letzten Commit prüfen
python scripts/auto-code-review.py --repo /pfad/zum/repo

# Letzte 5 Commits prüfen
python scripts/auto-code-review.py --diff HEAD~5

# Nur JSON-Report ausgeben
python scripts/auto-code-review.py --json

# Mit Auto-Fix (trailing whitespace, BOM, EOF)
python scripts/auto-code-review.py --fix

# Still (nur Exit-Code)
python scripts/auto-code-review.py --quiet

Exit-Codes

CodeBedeutung
0Keine Issues gefunden
1Warnungen (Quality/Style)
2Security Issues gefunden

Security-Scan

Sucht nach:

  • Secrets: Hardcodierte Passwörter, API-Keys, Tokens, Private Keys, AWS-Keys, Connection-Strings, JWT-Tokens
  • SQL-Injection: f-string/format in execute(), String-Konkatenation in SQL-Queries
  • Dangerous APIs: os.system(), shell=True, eval(), exec(), pickle.load(), yaml.load() ohne SafeLoader, verify=False

Code-Qualität

  • Leere except: Blöcke
  • TODO / FIXME / HACK / XXX Kommentare
  • Funktionen > 50 Zeilen
  • Fehlende Return-Type-Hints
  • print() in Produktionscode
  • Auskommentierter Code

Style

  • Trailing Whitespace (auto-fixable)
  • Tabs statt Spaces (auto-fixable)
  • BOM-Marker (auto-fixable)
  • Fehlende Newline am EOF (auto-fixable)

Cron-Job

Der Cron auto-code-review-60m läuft alle 60 Minuten und prüft --diff HEAD~1 im OpenAmer-Repo.

Integration

# Als Git-Pre-Push-Hook
echo 'python scripts/auto-code-review.py --quiet --repo "$PWD"' >> .git/hooks/pre-push
chmod +x .git/hooks/pre-push

Exit-Code-Logik

  • exit 0 = sauber
  • exit 1 = Warnungen (Quality/Style Issues vorhanden)
  • exit 2 = Security Issues gefunden → sofort handeln

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Build integrated IS/BS/CF financial workbooks in Excel.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

a2a-swarm

無料

Run and grow the OpenAmer Agent-to-Agent swarm: identity, trust, node-to-node ask, signed skill/insight sharing, and the autonomous self-learning loop.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

Use for A/B experiments on OpenAmer configs and skills.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

Roleplay a hostile user to find and triage UX pain points.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

Agent mesh: master/worker nodes, HTTP delegation, heartbeat.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

Use for agentic commerce payments tasks. Candidate synthesized from trend radar; awaiting trial promotion.

日本語の概要は準備中です。原文の説明を表示しています。

openamer/openamer52026年10月11日 更新

openamer のスキルをすべて見る

このスキルの問題を報告する