feat: add unified-review workflow (scoring tools + skill)

Adds the unified-review integration that fuses CRG graph context with the
ai-code-review scoring methodology and gstack-review fix-first workflow:

- scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage,
  redundancy_rate, high_risk_density, vulnerability_risk) with
  good/warn/fail grades, plus dedupe_findings (fingerprint merge,
  multi-source confidence boost, PR quality score) and report data builder
- tools/scoring_tools.py + main.py: three new MCP tools
  (score_review_tool, dedupe_findings_tool, generate_report_tool)
- assets/report-template.html: self-contained HTML report template
- skills.py + skills/unified-review/: new read-only unified-review skill
  with language/manual-review/specialist checklists
- docs and CHANGELOG updated; tests added (test_scoring, test_report,
  test_unified_review) and test_skills updated for 5 skills
This commit is contained in:
dev
2026-08-05 13:31:55 +08:00
parent 82b7c6dc9e
commit 84ae9b817e
32 changed files with 2229 additions and 19 deletions
+11
View File
@@ -4,6 +4,17 @@
### Added
- Added the **unified-review** skill that fuses CRG graph context with the
ai-code-review three-layer scoring methodology and the gstack-review
fix-first workflow. The skill is read-only: every finding waits for a
manual fix decision. Ships with language / manual-review / specialist
checklists under `skills/unified-review/references/`.
- Added three MCP tools backing the unified-review workflow:
`score_review_tool` (objective Layer-2 metrics with good/warn/fail grades),
`dedupe_findings_tool` (fingerprint dedup, multi-source confidence boost,
PR quality score), and `generate_report_tool` (standalone
`code-review-report.html`). See `code_review_graph/scoring.py`.
- Added a Voyage AI embedding provider (`--provider voyage`, key from
`VOYAGE_API_KEY`, opt-in request throttling via
`CRG_VOYAGE_MIN_INTERVAL_SEC`). Embeddings are now persisted after each