# Node Code Reviewer

> Node Code Reviewer

- Skill: `liyown/node-code-reviewer` (Agent Skill, multi-file: 20 files)
- Install (CLI): `npx skillmds@latest add liyown/node-code-reviewer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/liyown/node-code-reviewer/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: liyown (https://skillmd.com/u/liyown)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/liyown/node-code-reviewer

---


# Node Code Reviewer

Review Node.js backend code for real production risk. Keep the entrypoint small and load scenario prompts only when the code needs them.

## Required Loading

Always load `prompts/reviewer.md`.

Load additional prompts only when relevant:

- `prompts/async-reviewer.md`: async/await, event loop, blocking calls, unhandled rejection, AbortController, worker threads, unref.
- `prompts/error-reviewer.md`: error types, Promise rejection, async stack traces, error middleware order, structured logging.
- `prompts/sql-reviewer.md`: Prisma, TypeORM, Sequelize, Knex, raw SQL, transactions, N+1, connection pool.
- `prompts/http-reviewer.md`: Fastify, Express, Koa, Hono, middleware order, timeouts, body limits, request lifecycle, streaming.
- `prompts/security-reviewer.md`: authorization, tenant isolation, injection, prototype pollution, deserialization, secrets, SSRF.

## Review Contract

- Find concrete bugs, not generic advice.
- Bind every finding to code evidence and an execution path.
- Mark uncertain findings as `需要结合上下文确认`.
- Do not output style comments unless they hide a real defect.
- If no clear high-risk issue is found, output exactly:

```text
未发现明确高风险问题。
```

Use the severity and output contract from `prompts/reviewer.md`.

## Examples

Each bad example has a matching `good-<file>` in this same `examples/`
directory that shows the minimal fix for every Critical/High finding. Read
both side by side when triaging a real diff.

