Files
code-review-graph/skills/unified-review/references/common-mistakes.md
T
dev 84ae9b817e feat: add unified-review workflow (scoring tools + skill)
Adds the unified-review integration that fuses CRG graph context with the
ai-code-review scoring methodology and gstack-review fix-first workflow:

- scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage,
  redundancy_rate, high_risk_density, vulnerability_risk) with
  good/warn/fail grades, plus dedupe_findings (fingerprint merge,
  multi-source confidence boost, PR quality score) and report data builder
- tools/scoring_tools.py + main.py: three new MCP tools
  (score_review_tool, dedupe_findings_tool, generate_report_tool)
- assets/report-template.html: self-contained HTML report template
- skills.py + skills/unified-review/: new read-only unified-review skill
  with language/manual-review/specialist checklists
- docs and CHANGELOG updated; tests added (test_scoring, test_report,
  test_unified_review) and test_skills updated for 5 skills
2026-08-05 13:31:55 +08:00

1.2 KiB

Unified Review — Common Mistakes

  • Skipping graph context — always run get_minimal_context first; CRG context is what makes the review token-efficient and blast-radius aware.
  • Rushing to fix — this skill is READ-ONLY. Present findings, wait for user decision. Never apply fixes, commit, or push.
  • Ignoring tier — read .code-review.yaml. fast skips Layer 2/3; strict requires per-item confirmation for every blocker/major.
  • Judging metrics without evidencescore_review_tool outputs are heuristics. Cite the evidence, and let the LLM confirm SQL/exception/vuln findings before presenting them as facts.
  • Missing manual-review modules — payment, order, inventory, permission, distributed-lock, data-migration always require a manual review checklist.
  • Forgetting enum completeness reads OUTSIDE the diff — grep sibling values, then read each consumer; in-diff review alone is insufficient.
  • Batch-skipping blockers🔴 blockers cannot be batch-skipped; each needs an explicit user decision.
  • Not producing the report — always call generate_report_tool at the end and present the text report inline.