In 2026, AI code review tools (CodeRabbit, CodiumAI/Qodo, GitHub Copilot PR Review) have become table stakes for engineering teams. Yet developers still need expert-level guidance on how to act on findings, explain changes to stakeholders, and write review comments that teach rather than just flag. This skill:
Reviews code snippets or diffs for bugs, security issues, performance problems, and style violations
Generates actionable PR review comments in the style of senior engineers
Explains WHY a change is problematic — not just "this is wrong"
Suggests concrete fixes with alternative code implementations
Enforces team coding standards when you provide a style guide or tech stack
// 反例:多个 goroutine 并发写,触发 fatal error: concurrent map writes
for _, u := range users { go func(u User){ cache[u.ID] = u }(u) }
// 正例
var mu sync.Mutex
for _, u := range users { go func(u User){ mu.Lock(); cache[u.ID] = u; mu.Unlock() }(u) }
// 或改用 sync.Map / 单写入 goroutine + channel
# 反例:每篇博客一次查询作者
posts = session.query(Post).all()
for p in posts: print(p.author.name)
# 正例:预加载
posts = session.query(Post).options(joinedload(Post.author)).all()
## Code Review Summary
**Reviewed by:** AI Code Review Expert
**Date:** [today]
**Overall:** [4/5] — Minor issues found
### Critical Issues (0)
No blocking issues found.
### Warnings (2)
- `user_service.py:45` — Potential SQL injection via raw query concatenation
- `auth.py:12` — JWT secret read from environment variable without validation
### Suggestions (3)
- Consider extracting the validation logic into a shared utility
- Add docstrings to public methods
- Use `dataclasses` instead of plain dicts for `UserProfile`
### Positive Highlights
- Excellent use of dependency injection in `UserController`
- Clear separation of concerns between service and repository layers
第二示例 — Java/Spring 安全修复 PR(含 Critical)
markdown
## Code Review Summary
**Reviewed by:** AI Code Review Expert
**Date:** [today]
**Overall:** [2/5] — Blocking security issues found
### Critical Issues (1)
- `UserController.java:72` — Missing authorization on `deleteUser`; any authenticated user can delete any account (A01)
### Warnings (2)
- `JwtUtil.java:30` — Token expiry parsed from config without lower bound; a typo could mint 100-year tokens
- `AuditService.java:15` — Deletion event not written to audit log (A09)
### Suggestions (2)
- Extract role-check logic into a reusable annotation to avoid per-endpoint drift
- Add integration test asserting 403 for non-admin callers
### Positive Highlights
- Consistent use of constructor injection; easy to unit test
Example Interactions
User:
python
def get_user(user_id):
query = "SELECT * FROM users WHERE id = " + user_id
return db.execute(query)
def get_user(user_id: int) -> dict | None:
query = "SELECT * FROM users WHERE id = %s"
return db.execute(query, (user_id,))
User: "Review this TypeScript React component for performance issues"
Skill response: Identifies missing useMemo/useCallback wrappers, unnecessary re-renders, missing key props in lists, and suggests a refactor to a presentational/container pattern.
User: "这段 Go 代码在压测时偶发 panic,帮我看看" + 并发写 map 的片段
Skill response: 定位为 concurrent map writes([Critical]),给出 sync.Mutex 与 sync.Map 两种修法,并说明各自适用门槛:写多读少用 Mutex,读多写少且 key 稳定用 sync.Map;同时提示用 go test -race 在 CI 中固化回归。