Backend code review for Dify's api: evidence-first findings with a severity ladder
Evidence-first backend reviews — inspect the diff, route to rule packs (DB schema, architecture, repositories, SQLAlchemy), report P0–P3 findings tied to observable failures
- What
- Evidence-first backend reviews — inspect the diff, route to rule packs (DB schema, architecture, repositories, SQLAlchemy), report P0–P3 findings tied to observable failures
- Cost
- Free
- Needs
- a backend change to review (best suited to Dify's own api/ layout, since the rule packs are Dify-specific) — the skill is a review methodology, not software
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Selected by Skill Harbor — short listing (the repo states no license, so no content is reproduced): @langgenius's backend code review skill, written for the Dify project's own backend (reviews target code under `api/`). The discipline: evidence first — inspect the requested diff or files, read the changed lines plus their behavior owners and nearby tests, trace callers and boundaries only where they decide correctness, and report ONLY findings tied to an observable failure, violated contract, security boundary, data-integrity risk, or demonstrated maintenance problem. Reviews route to bundled rule packs read by diff type: DB schema, architecture, repositories, and SQLAlchemy; when no pack applies, correctness/security/behavior are reviewed directly against local contracts. Findings come on a severity ladder (P0 security/data-loss/outage, P1 user-visible regression or broken auth, P2 concrete correctness defect, P3 minor cleanup only on explicit request), ordered by severity with file:line references, failing contracts and fix directions — no praise sections, no speculative risks. Honest caveats: written for Dify's own repo layout (the `api/` scope and bundled rule packs are Dify-specific) — less useful as a generic reviewer; license not stated by the source repo — short listing with a link only, nothing copied. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a backend change to review (best suited to Dify's own api/ layout, since the rule packs are Dify-specific) — the skill is a review methodology, not software Install "Backend code review for Dify's api: evidence-first findings with a severity ladder" for me. It gives my agent @langgenius's review workflow: establish scope and inspect the diff, read changed lines with their behavior owners and nearby tests, route to the matching rule packs (DB schema, architecture, repositories, SQLAlchemy), and report only evidence-backed findings on the P0–P3 severity ladder — no praise, no speculation. IMPORTANT: the repo states no license — fetch from the link only, and reproduce nothing beyond the link. Repository: https://github.com/langgenius/dify/blob/main/.agents/skills/backend-code-review/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "backend-code-review". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. hand the agent the diff or files to review; nothing else — it's a methodology). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.