All skills
langgenius avatar

/backend-code-review

@fd2e26f
by langgeniuslanggenius/dify158k stars
24,861

Use only when the user explicitly requests a review or audit of backend code under `api/`. Supports pending-change, file-focused, and pasted-diff reviews. Do not use for implementation-only requests, diagnosis without review intent, frontend code, or backend code outside `api/`.

Use this Skill: https://skilld.dev/gh/langgenius/dify/backend-code-review

This session only. Nothing lands on disk.

referencesarchitecture-rule.md

≈285 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Architecture review

The API agent guide owns package boundaries. In particular, api/core/ is migration-only: do not propose new files or extracted implementations there.

Transport and domain boundaries

Controllers own request parsing, service calls, and response serialization. Trace business decisions to their service or domain owner; flag controller policy when it duplicates or bypasses that owner. Move extracted behavior to an appropriate owner outside core/.

Dependency direction

Transport layers may depend on services and domain contracts. Domain code must not import controller or request context. Pass validated actor, tenant, and resource data explicitly instead of reaching upward for it. Check existing owners and import-linter contracts before proposing a shared abstraction.

Business-agnostic libraries

api/libs/ must not own product policy or orchestration. Flag service/controller dependencies and domain-specific decisions in library helpers. Move that behavior to its existing service or domain owner outside core/; retain only reusable infrastructure in libs/.

Source: SKILL.md on GitHub

1 warning1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    The skill is a code review utility that defines best practices for backend development. It has an inherent vulnerability to indirect prompt injection because it processes untrusted user-supplied code, but no active malicious components were found.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    5 files scanned · No issues

  • ZeroLeaks5mo

    1 finding · Score: 69/100

Signed by skilld at fd2e26f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 2 months ago

README badge

README badge for langgenius/dify/backend-code-review