Node Code Reviewer
Review Node.js backend code for real production risk. Keep the entrypoint small and load scenario prompts only when the code needs them.
Required Loading
Always load prompts/reviewer.md.
Load additional prompts only when relevant:
prompts/async-reviewer.md: async/await, event loop, blocking calls, unhandled rejection, AbortController, worker threads, unref.
prompts/error-reviewer.md: error types, Promise rejection, async stack traces, error middleware order, structured logging.
prompts/sql-reviewer.md: Prisma, TypeORM, Sequelize, Knex, raw SQL, transactions, N+1, connection pool.
prompts/http-reviewer.md: Fastify, Express, Koa, Hono, middleware order, timeouts, body limits, request lifecycle, streaming.
prompts/security-reviewer.md: authorization, tenant isolation, injection, prototype pollution, deserialization, secrets, SSRF.
Review Contract
- Find concrete bugs, not generic advice.
- Bind every finding to code evidence and an execution path.
- Mark uncertain findings as
需要结合上下文确认.
- Do not output style comments unless they hide a real defect.
- If no clear high-risk issue is found, output exactly:
未发现明确高风险问题。
Use the severity and output contract from prompts/reviewer.md.
Examples
Each bad example has a matching good-<file> in this same examples/
directory that shows the minimal fix for every Critical/High finding. Read
both side by side when triaging a real diff.
1---2name: node-code-reviewer3description: Node Code Reviewer4---56# Node Code Reviewer78Review Node.js backend code for real production risk. Keep the entrypoint small and load scenario prompts only when the code needs them.910## Required Loading1112Always load `prompts/reviewer.md`.1314Load additional prompts only when relevant:1516- `prompts/async-reviewer.md`: async/await, event loop, blocking calls, unhandled rejection, AbortController, worker threads, unref.17- `prompts/error-reviewer.md`: error types, Promise rejection, async stack traces, error middleware order, structured logging.18- `prompts/sql-reviewer.md`: Prisma, TypeORM, Sequelize, Knex, raw SQL, transactions, N+1, connection pool.19- `prompts/http-reviewer.md`: Fastify, Express, Koa, Hono, middleware order, timeouts, body limits, request lifecycle, streaming.20- `prompts/security-reviewer.md`: authorization, tenant isolation, injection, prototype pollution, deserialization, secrets, SSRF.2122## Review Contract2324- Find concrete bugs, not generic advice.25- Bind every finding to code evidence and an execution path.26- Mark uncertain findings as `需要结合上下文确认`.27- Do not output style comments unless they hide a real defect.28- If no clear high-risk issue is found, output exactly:2930```text31未发现明确高风险问题。32```3334Use the severity and output contract from `prompts/reviewer.md`.3536## Examples3738Each bad example has a matching `good-<file>` in this same `examples/`39directory that shows the minimal fix for every Critical/High finding. Read40both side by side when triaging a real diff.