本文へ移動
cccskills
無料GitHub で公開

cloudbase-code-review

Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review.

インストール方法を見る

含まれるファイル(13)

  • SKILL.md4.4 KB
  • LICENSE.md1.0 KB
  • references/lint-rules/README.md17.3 KB
  • references/RULES_INDEX.md12.9 KB
  • references/rules/cross-cutting/AUTH001.md2.4 KB
  • references/rules/cross-cutting/SEC001.md2.3 KB
  • references/rules/cross-cutting/SKILL001.md1.5 KB
  • references/rules/postgresql/PG-CR001.md2.7 KB
  • references/rules/postgresql/PG-CR002.md2.8 KB
  • references/rules/postgresql/PG-CR003.md1.9 KB
  • references/rules/postgresql/PG-CR004.md2.9 KB
  • references/rules/postgresql/PG-CR005.md2.3 KB
  • references/rules/storage/STORAGE001.md1.9 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Sibling skills (local only)

Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.

If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.

CloudBase Code Review

One-liner: After implementing CloudBase features, call this skill to catch common mistakes before users do.

When to use

Call this skill after completing a CloudBase implementation task, before declaring done:

  • You implemented auth (login / register / route guard)
  • You created database tables or wrote CRUD (NoSQL / PostgreSQL / MySQL)
  • You set up CloudBase Storage (file upload, hosting)
  • You configured security rules or RLS policies
  • You wrote MCP-dependent code
  • You wrote Cloud Function or CloudRun HTTP handlers (check for credential / header echo leaks)

How it works

The skill runs in two layers:

LayerMethodSpeedWhat it catches
Lint (optional)No executable script is shipped. If the user approves running lint, review the code block in references/lint-rules/README.md, copy it to a temporary local cloudbase-lint.mjs, then run node cloudbase-lint.mjs --project-dir <path>SecondsDeterministic regex checks — wrong API calls, missing configs, pattern mismatches
LLM reviewRead each rule's "LLM 检查" section, inspect code semanticallyVariableSemantic issues — route guard logic, RLS completeness, architecture-level problems

Rule index

See references/RULES_INDEX.md for the full matrix (module × frontend type → applicable rules).

Rule boundary

Do not promote a single failed run or case-specific workaround into a hard rule. A rule should be backed by stable SDK/API documentation, repeated failures, or deterministic runtime behavior. Case-specific observations belong in attribution reports; only broadly applicable constraints should enter RULES_INDEX.md or the optional lint checklist.

Quick start

# Step 1: Read relevant rules for identified modules
#   references/rules/cross-cutting/AUTH001.md
#   references/rules/cross-cutting/SEC001.md
#   references/rules/postgresql/PG-CR001.md
#   ...

# Optional: if the user approves running lint, review the script code block in
# references/lint-rules/README.md, copy it to a temporary cloudbase-lint.mjs,
# then run: node cloudbase-lint.mjs --project-dir .

# Step 2: For each applicable rule, read the "LLM 检查" section
#         and manually inspect your code before claiming done.

Rule format

Each rule .md file follows this structure:

# RULE-ID Rule Name

- **Module**: which module (auth / postgresql / storage / ...)
- **Severity**: error | warning
- **Stage**: code-generation | deployment | config

## 正则检查 (Lint)

The condition checked by the optional script code block in `references/lint-rules/README.md`.

## LLM 检查

Semantic review prompt for human or LLM to evaluate.

## 修复指引

How to fix the issue.

Reference index

All packaged reference files (required for skill lint reachability):

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the `model` field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*, model id in the `model` field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper `model` field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

Use when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes, or missing contract tests, especially during periodic quality review or before preparing corrective PRs.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月10日 更新

TencentCloudBase のスキルをすべて見る

このスキルの問題を報告する