Coding

Code Review Gate

Try it

AI 代码审查门禁 — 对 git diff 执行全面的静态分析,覆盖功能正确性、安全性、 性能、可读性、可维护性、测试覆盖、文档同步 7 个维度。按 Critical / Important / Minor 三级严重度输出结构化报告,存在 Critical 问题时门禁阻塞(exit code 1)。

What it does

AI 代码审查门禁 — 对 git diff 执行全面的静态分析,覆盖功能正确性、安全性、 性能、可读性、可维护性、测试覆盖、文档同步 7 个维度。按 Critical / Important / Minor 三级严重度输出结构化报告,存在 Critical 问题时门禁阻塞(exit code 1)。

The skill document

Code Review Gate — AI 代码审查门禁 Skill

OpenClaw Skill: 自动对 git diff 执行结构化代码审查,输出分级报告并阻塞 Critical 问题。

场景描述 (When to Use)

  • 开发者完成一轮代码修改,准备合并到主分支前
  • CI/CD 流水线中需要自动化代码审查门禁
  • Pull Request 提交后,需要 AI 先做一轮预审
  • 任何需要确保代码质量、安全性和设计一致性的场景

决策规则 (Decision Rules)

  1. 阻塞条件: 任何 Critical 级别问题(安全漏洞/功能错误/数据风险)未修复 → 门禁不通过,禁止进入下一阶段
  2. 警告条件: Important 级别问题存在但无不阻塞,记录并建议修复
  3. 通过条件: 所有 mandatory 检查项均通过 AND blocking_issues == 0
  4. 跳过条件: 变更规模为 docs/config/prompt/chore 且风险 ≤ low 时,本门禁可跳过(由上游流程判断)

审查维度 (Check Categories)

维度严重级别说明
功能正确性 (functional)Critical逻辑错误、边界条件、错误处理、并发问题
安全性 (security)CriticalSQL注入、XSS、命令注入、敏感信息泄露、权限控制
性能 (performance)ImportantO(n²)复杂度、N+1查询、正则回溯、资源泄漏
可读性 (readability)Important命名规范、职责单一、注释质量、代码简洁
可维护性 (maintainability)ImportantSOLID原则、依赖关系、配置外部化、日志规范
测试覆盖 (testing)Critical单元测试、边界测试、异常测试、断言清晰
文档同步 (documentation)MinorAPI文档、变更记录、README同步

使用示例 (Usage)

基础用法 — 审查当前未提交的改动

openclaw run code-review-gate --base HEAD~1 --head HEAD

审查指定 commit 范围

openclaw run code-review-gate --base abc1234 --head def5678

审查指定文件

openclaw run code-review-gate --files "src/api/*.py,src/services/*.py" --design design.md

传入设计文档做一致性校验

openclaw run code-review-gate --base main --head feature-branch --design openspec/changes/feat-001/design.md

参数说明

参数必需说明
--base是*git diff 基准 commit/branch
--head是*git diff 目标 commit/branch
--files限定审查的文件路径(glob 模式)
--design设计文档路径,用于对比实现一致性
--severity最低报告级别: critical / important / minor (默认 important)
--format输出格式: markdown / json / terminal (默认 markdown)
--max-lines单次审查最大行数限制 (默认 1000)

* --base + --head--files 二选一

输出格式 (Output)

审查完成后生成结构化报告:

## Code Review Report — [timestamp]

**Range:** abc1234..def5678
**Files Changed:** 12 | **Lines:** +345 -120
**Design Doc:** openspec/changes/feat-001/design.md

---

### Strengths
- Clean separation of concerns in service layer
- Comprehensive error handling with proper fallbacks
- Well-structured test cases covering edge scenarios

### Issues

#### Critical (Must Fix — 2 issues)
1. **SQL Injection in user query** [src/api/users.py:45]
   - What: Raw string formatting used in SQL WHERE clause
   - Risk: Allows arbitrary SQL execution via crafted input
   - Fix: Use parameterized queries with `?` placeholders

2. **Missing auth check** [src/api/admin.py:120]
   - What: Admin endpoint lacks authentication middleware
   - Risk: Unauthenticated access to sensitive admin operations
   - Fix: Add `@require_auth` decorator

#### Important (Should Fix — 3 issues)
1. **N+1 query in list endpoint** [src/services/order.py:78]
   - ...

#### Minor (Nice to Have — 2 issues)
1. **Inconsistent variable naming** [src/utils/parser.py:33]
   - ...

### Design Consistency Check
- ✅ API signature matches design doc
- ⚠️ One endpoint (`GET /api/v2/users`) not documented in design
- ✅ Data model matches schema definition

### Recommendations
- Add input sanitization middleware
- Consider query batching for list endpoints

### Assessment

**Gate: ❌ BLOCKED**

**Reasoning:** 2 critical issues must be resolved before merge — SQL injection and missing authentication. Important issues should be addressed but do not block.

门禁结果码

退出码含义CI 行为
0通过 — 无 Critical 问题允许合并
1阻塞 — 存在 Critical 问题阻止合并
2错误 — 工具自身异常标记为 CI 失败
3跳过 — 变更不符合审查条件允许合并

依赖

  • git — 命令行工具,用于获取 diff
  • Python ≥ 3.10
  • bandit — Python 安全扫描 (可选,增强安全检测)
  • radon — 代码复杂度分析 (可选)

与 OpenClaw 框架的集成

本 Skill 可作为 OpenClaw 流水线中的独立阶段:

import { defineAgent } from "openclaw";
import { CodeReviewGateSkill } from "@community/code-review-gate";

const agent = defineAgent({
  name: "dev-workflow-agent",
  description: "Development workflow with code review gate",
  model: "claude-sonnet-4-20250514",
  skills: [
    new CodeReviewGateSkill({
      severity: "critical",
      maxLines: 1000,
    }),
  ],
});

配置选项

通过 gate.config.yaml 自定义检查项:

# gate.config.yaml — 可选配置文件
severity_threshold: critical       # 阻塞级别
max_diff_lines: 1000              # 单次最大审查行数
skip_patterns:                    # 跳过审查的文件模式
  - "*.md"
  - "*.json"
  - "docs/**"
  - "*.lock"
require_design_doc: true          # 是否强制要求设计文档
enabled_checks:                   # 启用的检查维度
  - functional
  - security
  - performance
  - testing
  - documentation
auto_fix_suggestions: true        # 是否生成修复建议

Related skills

Get senior-engineer-level code reviews with severity ratings, security checks, and ready-to-paste PR comments.

25 installs1 stars

Conducts multi-axis code review. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Use when you need to assess code quality across multiple dimensi Use when 需要Development领域自动化处理、数据分析和流程编排时使用。不适用于无明确需求的模糊场景。

代码审查与质量检测:检查代码规范、潜在Bug、性能问题、安全漏洞,输出审查报告与改进建议。Invoke when user asks 代码审查、Code Review、代码质量、代码检查、代码优化.

1 installs

コードレビューを実施する際に使用。プルリクエストのレビュー、コード品質チェック、 セキュリティ検査、パフォーマンス分析を行う。「レビューして」「コードをチェック」 「品質を確認」などの指示で起動。

by terrycarter1985

AI Code Review and Code Risk Review quality gate for Git Diff, release readiness, regression testing, security testing, dependency impact, runtime risk, LLM...

3 installs

用AI写代码一时爽,项目越写越乱火葬场?Superpowers方法论5道Gate卡住质量:设计没想清楚不准动手、没写测试不准提交。把「能跑就行」升级成工程级交付,让AI帮你写出可维护的代码。支持全栈项目(Web/移动端/API/数据)、团队协作规范、CI/CD集成指南。从需求到上线的完整工程化流水线,杜绝"AI生...

4 installs