Memory

AI Code Review RiskRadar

Try it

AI Code Review and Code Risk Review quality gate for Git Diff, release readiness, regression testing, security testing, dependency impact, runtime risk, LLM...

What it does

AI Code Review and Code Risk Review quality gate for Git Diff, release readiness, regression testing, security testing, dependency impact, runtime risk, LLM testing, Agentic AI risk, and RAG security.

The skill document

RiskRadar AI

RiskRadar AI is a general-purpose code risk review and release-quality gate skill for software teams. It turns code changes into actionable engineering and QA evidence: exact code locations, impact, severity, confidence, test strategy, and release recommendation.

It works for backend, frontend, mobile, platform, data, AI, LLM, Agent, RAG, API, infrastructure, and integration-heavy systems.

When To Use

Use this skill when you need to:

  • Review a pull request or Git Diff before release.
  • Find functional, runtime, dependency, security, performance, compatibility, and regression risks.
  • Review AI-enabled workflows such as LLM calls, agents, RAG retrieval, prompt templates, tool calling, and model fallback logic.
  • Build a release quality gate with concrete verification steps.
  • Generate unit, integration, E2E, adversarial, resilience, and monitoring test recommendations.

Core Workflow

  1. Scope the change: identify repositories, files, Git Diff, affected modules, user flows, APIs, data flows, and runtime boundaries.
  2. Map critical paths: trace state transitions, external dependencies, persistence, network calls, async jobs, permissions, and user-visible impact.
  3. Identify AI dependencies: detect LLM calls, agents, RAG, prompt templates, model routing, tool calls, feature flags, and fallback behavior when applicable.
  4. Analyze risks: classify functional, runtime, dependency, security, performance, AI, privacy, resilience, and regression risks.
  5. Validate evidence: link every finding to code, configuration, data flow, logs, tests, or product behavior.
  6. Design tests: produce targeted unit, integration, E2E, adversarial, resilience, and monitoring tests.
  7. Write the report: include severity, confidence, exact location, impact, verification steps, and release recommendation.

Reference Guides

TopicReferenceLoad When
Code risk reviewreferences/code-risk-review-playbook.mdAlways use for risk classification, evidence requirements, and report table

Required Output

Produce a Markdown report with:

  • Executive summary and release recommendation.
  • Risk table with severity, confidence, exact code location, impact, and fix/test recommendation.
  • AI workflow risk section when LLM, Agent, RAG, model, or tool-calling logic is involved.
  • Test strategy by layer: unit, integration, E2E, adversarial, resilience, monitoring.
  • Evidence checklist and open questions.

AI Workflow Risk Section

## AI Workflow Risk Review

| Risk | Code Location | User/System Impact | AI/Model/Agent Link | Evidence Needed | Verification | Priority |
| --- | --- | --- | --- | --- | --- | --- |

Quality Bar

  • Do not invent risks without code or configuration evidence.
  • Every high-severity risk must include a concrete reproduction or verification path.
  • Separate facts, assumptions, and inferred risks.
  • Prefer actionable, release-blocking findings over generic advice.
  • If evidence is insufficient, state exactly what is missing.

Related skills

当用户需要扫描代码安全漏洞、审计代码、分析 C/Python 风险、检查依赖漏洞、或生成安全报告时触发。支持云端 LLM 语义分析和本地 GPU 回退。

1 installs

Scan AI-generated code for bugs before deploying — 8 static analysis checks from critical (hardcoded secrets, unsafe eval) to low (unused imports). Productio...

4 installs

Generate HTML code review pages with risk tags, diff highlights, and file-level annotations. 当用户需要代码审查可视化、PR审查报告、代码diff高亮、风险标签标注、审查页面生成时使用。

3 installs

金融AI + Code Review / Git Diff 代码风险分析与质量门禁 Skill:定位LLM/Agent/RAG金融业务风险、运行时异常、依赖影响、安全合规和回归测试缺口,生成上线前测试策略、审计证据、单元测试建议和标准报告。

12 installs1 stars

Get senior-engineer-level code reviews with severity ratings, security checks, and ready-to-paste PR comments.

25 installs1 stars

Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.