dmsobtl
dsh-tool-code-review
DSH 插件:结构化代码审查 — Agent 读取 git diff,按 checklist 逐项审查,输出可操作的发现。
- Stars
- 0
- Language
- TypeScript
- Created
- Aug 14, 2026
- Updated
- Aug 14, 2026
Introduction
dsh-tool-code-review
DSH 插件:结构化代码审查 — Agent 读取 git diff,按 checklist 逐项审查,输出可操作的发现。
工具
| 工具 | 功能 |
|---|---|
review_diff | 获取并解析 git diff,返回结构化文件变更摘要 |
review_file | 读取文件指定行范围(带行号,方便定位问题) |
review_checklist | 生成审查 checklist(bugs/security/style/performance/tests/docs) |
使用示例
User: 帮我 review 一下当前的改动
Agent:
→ review_diff({ target: "main" })
// 获取与 main 分支的 diff,了解改了什么
→ review_checklist({ checks: ["bugs", "security"] })
// 生成要检查的点
→ review_file({ path: "src/auth.ts", startLine: 45, endLine: 80 })
// 深入看可疑的代码段
审查结果:
1. [Security] src/auth.ts:52 — 用户输入直接拼接到 SQL,存在注入风险
2. [Bug] src/handler.ts:28 — async 函数缺少 try/catch,错误会被吞掉
3. [Style] src/utils.ts:15 — 未使用的 import
配置
- id: code-review
plugin: dsh-tool-code-review
config:
maxDiffLines: 500
defaultChecks: [bugs, security, style, performance]
审查维度
| 维度 | 检查项 |
|---|---|
| bugs | 越界、空指针、async 错误处理、竞态、资源泄漏 |
| security | SQL 注入、XSS、命令注入、硬编码密钥、路径遍历 |
| style | 命名不一致、死代码、过度复杂、缺少错误消息 |
| performance | N+1 查询、热路径大分配、缺分页、同步 I/O 阻塞 |
| tests | 新代码无测试、边界未覆盖、flaky 模式 |
| docs | API 变更无文档、配置变更未说明、Breaking change 无迁移指南 |
与 dsh-agent-eval 配合
可以定义 eval 任务验证审查质量:
{
"id": "catch-sql-injection",
"prompt": "Review this diff and find the security issue",
"expectedOutcome": { "type": "output_contains", "substring": "SQL injection" }
}
License
MIT