Java Code Reviewer
Review Java backend code for real production risk. Keep the entrypoint small and load scenario prompts only when the code needs them.
Required Loading
Always load prompts/reviewer.md.
Load additional prompts only when relevant:
prompts/spring-reviewer.md: Spring Boot, Spring Cloud, transactions, proxy annotations, validation, async, scheduling.
prompts/mybatis-reviewer.md: MyBatis, MyBatis-Plus, SQL, Wrapper, batch operations, indexes, tenant filters.
prompts/security-reviewer.md: authorization, tenant isolation, injection, sensitive data, file/URL/deserialization risks.
prompts/concurrency-reviewer.md: idempotency, duplicate writes, locks, thread pools, ThreadLocal, cache races.
prompts/reactor-reviewer.md: Reactor/WebFlux blocking, subscribe, timeout, retry, backpressure, EventLoop misuse.
prompts/redis-kafka-reviewer.md: Redis cache failure modes, Kafka consumption, ordering, offset, retries, compensation.
Review Contract
- Find concrete bugs, not generic advice.
- Bind every finding to code evidence and an execution path.
- Mark uncertain findings as
需要结合上下文确认.
- Do not output style comments unless they hide a real defect.
- If no clear high-risk issue is found, output exactly:
未发现明确高风险问题。
Use the severity and output contract from prompts/reviewer.md.
Examples
Each bad example has a matching good-<file> in this same examples/
directory that shows the minimal fix for every Critical/High finding. Read
both side by side when triaging a real diff.
1---2name: java-code-reviewer3description: Java Code Reviewer4---56# Java Code Reviewer78Review Java backend code for real production risk. Keep the entrypoint small and load scenario prompts only when the code needs them.910## Required Loading1112Always load `prompts/reviewer.md`.1314Load additional prompts only when relevant:1516- `prompts/spring-reviewer.md`: Spring Boot, Spring Cloud, transactions, proxy annotations, validation, async, scheduling.17- `prompts/mybatis-reviewer.md`: MyBatis, MyBatis-Plus, SQL, Wrapper, batch operations, indexes, tenant filters.18- `prompts/security-reviewer.md`: authorization, tenant isolation, injection, sensitive data, file/URL/deserialization risks.19- `prompts/concurrency-reviewer.md`: idempotency, duplicate writes, locks, thread pools, ThreadLocal, cache races.20- `prompts/reactor-reviewer.md`: Reactor/WebFlux blocking, subscribe, timeout, retry, backpressure, EventLoop misuse.21- `prompts/redis-kafka-reviewer.md`: Redis cache failure modes, Kafka consumption, ordering, offset, retries, compensation.2223## Review Contract2425- Find concrete bugs, not generic advice.26- Bind every finding to code evidence and an execution path.27- Mark uncertain findings as `需要结合上下文确认`.28- Do not output style comments unless they hide a real defect.29- If no clear high-risk issue is found, output exactly:3031```text32未发现明确高风险问题。33```3435Use the severity and output contract from `prompts/reviewer.md`.3637## Examples3839Each bad example has a matching `good-<file>` in this same `examples/`40directory that shows the minimal fix for every Critical/High finding. Read41both side by side when triaging a real diff.