cloudbase-code-review
Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse.
Install / Use
npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-reviewInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of cloudbase-code-review
cloudbase-code-review scores 87/100 on our quality scale, 1528th of 2,848 Automation skills we index.
Its SKILL.md is 4.4 KB long, well organised into 23 sections with 2 code examples: a solid amount of guidance for an agent.
With 1,124 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 9 days ago, so cloudbase-code-review is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
cloudbase-code-review compared with similar skills
All 4 of these similar skills score higher than cloudbase-code-review; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cloudbase-code-review (this skill)by TencentCloudBase | 87 | 1.1k | 9d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 89.8k | 18d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.4k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.7k | 8d ago | MCP Server |
Frequently asked questions
- How do I install cloudbase-code-review?
- Run
npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-code-review. The install tabs above show the steps for each supported agent. - Which AI agents does cloudbase-code-review work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is cloudbase-code-review safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cloudbase-code-review still maintained?
- The repository was last updated 9 days ago, so cloudbase-code-review is actively maintained.
Skill content
View source on GitHubname: cloudbase-code-review description: "Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review." version: 2.34.8 alwaysApply: false
Sibling skills (local only)
Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.
If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.
CloudBase Code Review
One-liner: After implementing CloudBase features, call this skill to catch common mistakes before users do.
When to use
Call this skill after completing a CloudBase implementation task, before declaring done:
- You implemented auth (login / register / route guard)
- You created database tables or wrote CRUD (NoSQL / PostgreSQL / MySQL)
- You set up CloudBase Storage (file upload, hosting)
- You configured security rules or RLS policies
- You wrote MCP-dependent code
- You wrote Cloud Function or CloudRun HTTP handlers (check for credential / header echo leaks)
How it works
The skill runs in two layers:
| Layer | Method | Speed | What it catches |
|-------|--------|-------|-----------------|
| Lint (optional) | No executable script is shipped. If the user approves running lint, review the code block in references/lint-rules/README.md, copy it to a temporary local cloudbase-lint.mjs, then run node cloudbase-lint.mjs --project-dir <path> | Seconds | Deterministic regex checks — wrong API calls, missing configs, pattern mismatches |
| LLM review | Read each rule's "LLM 检查" section, inspect code semantically | Variable | Semantic issues — route guard logic, RLS completeness, architecture-level problems |
Rule index
See references/RULES_INDEX.md for the full matrix (module × frontend type → applicable rules).
Rule boundary
Do not promote a single failed run or case-specific workaround into a hard rule. A rule should be backed by stable SDK/API documentation, repeated failures, or deterministic runtime behavior. Case-specific observations belong in attribution reports; only broadly applicable constraints should enter RULES_INDEX.md or the optional lint checklist.
Quick start
# Step 1: Read relevant rules for identified modules
# references/rules/cross-cutting/AUTH001.md
# references/rules/cross-cutting/SEC001.md
# references/rules/postgresql/PG-CR001.md
# ...
# Optional: if the user approves running lint, review the script code block in
# references/lint-rules/README.md, copy it to a temporary cloudbase-lint.mjs,
# then run: node cloudbase-lint.mjs --project-dir .
# Step 2: For each applicable rule, read the "LLM 检查" section
# and manually inspect your code before claiming done.
Rule format
Each rule .md file follows this structure:
# RULE-ID Rule Name
- **Module**: which module (auth / postgresql / storage / ...)
- **Severity**: error | warning
- **Stage**: code-generation | deployment | config
## 正则检查 (Lint)
The condition checked by the optional script code block in `references/lint-rules/README.md`.
## LLM 检查
Semantic review prompt for human or LLM to evaluate.
## 修复指引
How to fix the issue.
Reference index
All packaged reference files (required for skill lint reachability):
- RULES_INDEX.md
- lint-rules/README.md
- rules/cross-cutting/AUTH001.md
- rules/cross-cutting/SEC001.md
- rules/cross-cutting/SKILL001.md
- rules/postgresql/PG-CR001.md
- rules/postgresql/PG-CR002.md
- rules/postgresql/PG-CR003.md
- rules/postgresql/PG-CR004.md
- rules/postgresql/PG-CR005.md
- rules/storage/STORAGE001.md
Related Skills
Agent-Reach
89.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.4k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.7kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
