All skills
langgenius avatar

/backend-code-review

@fd2e26f
by langgeniuslanggenius/dify158k stars
24,861

Use only when the user explicitly requests a review or audit of backend code under `api/`. Supports pending-change, file-focused, and pasted-diff reviews. Do not use for implementation-only requests, diagnosis without review intent, frontend code, or backend code outside `api/`.

Use this Skill: https://skilld.dev/gh/langgenius/dify/backend-code-review

This session only. Nothing lands on disk.

SKILL.md

≈75 tokens always: the name and description. ≈594 when used: this file. ≈4.3k more on demand in 4 files.

Backend Code Review

Review the requested scope for concrete, reproducible defects. The nearest AGENTS.md owns package facts and commands; this skill owns the review workflow and routes to its bundled rule packs.

Evidence First

  1. Establish the requested review scope and inspect the relevant diff or files.
  2. Read the changed lines, their behavior owner, nearby tests, and local docstrings or comments that define contracts.
  3. Trace callers, persistence boundaries, authorization, generated schemas, or external I/O only when they decide correctness.
  4. Report only findings tied to an observable failure, violated contract, security boundary, data integrity risk, or demonstrated maintenance problem.

Rule Routing

Read only the packs matched by the diff:

When no pack applies, review correctness, security, behavior changes, and test evidence directly. Check current official documentation only when local code and contracts do not settle framework or library behavior.

Severity And Output

  • P0: security or privacy exposure, data loss, or a production-wide outage.
  • P1: user-visible regression, broken authorization or tenant isolation, invalid public contract, or failed primary workflow.
  • P2: concrete correctness, performance, maintainability, or test defect likely to cause incorrect behavior.
  • P3: minor actionable cleanup; omit unless the user requested a thorough audit.

Lead with findings ordered by severity. Include a tight file and line reference, the failing contract or reproduction path, impact, and a concrete fix direction. If there are no findings, say No issues found. and state any material verification gap. Do not add praise sections, speculative risks, or an unsolicited offer to implement fixes.

Source: SKILL.md on GitHub

1 warning1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    The skill is a code review utility that defines best practices for backend development. It has an inherent vulnerability to indirect prompt injection because it processes untrusted user-supplied code, but no active malicious components were found.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    5 files scanned · No issues

  • ZeroLeaks5mo

    1 finding · Score: 69/100

Signed by skilld at fd2e26f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 16 hours ago.

Activeupdated 2 months ago

README badge

README badge for langgenius/dify/backend-code-review