cann-reviewCANN 代码审查技能。用于审查 GitCode 上的 CANN 项目 PR。 当用户提到"审查 PR"、"代码审查"、"cann review"或提供 GitCode PR 链接时触发。 自动分析代码变更,检查内存泄漏、安全漏洞和可读性,生成结构化报告并发布评论。
Install via ClawdBot CLI:
clawdbot install hzrky/cann-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → http://localhost:3000/api/cron/addAccesses system directories or attempts privilege escalation
/var/log/Calls external URL not in known-safe list
https://gitcode.com/setting/token-classicAI Analysis
The skill contains multiple concerning patterns including: 1) Instructions to send data to localhost:3000 (potential data exfiltration endpoint), 2) References to accessing system directories like /var/log/, 3) Hardcoded API token example in documentation, and 4) Instructions for credential configuration that could be exploited. While the skill's stated purpose is legitimate code review, these embedded signals suggest potential for misuse or hidden functionality.
Generated Mar 21, 2026
Development teams working on CANN (Compute Architecture for Neural Networks) projects use this skill to automate code reviews for pull requests on GitCode. It helps ensure code quality by checking for memory leaks, security vulnerabilities, and readability issues before merging changes, reducing manual review effort and improving software reliability.
Maintainers of open-source projects, especially those involving C/C++/Python codebases, utilize this skill to streamline code review processes. It automatically analyzes PRs, generates structured reports, and posts comments, enabling efficient collaboration and adherence to coding standards in distributed teams.
DevOps engineers integrate this skill into continuous integration and delivery pipelines to automate code quality checks. It triggers on PR submissions, performs automated reviews via GitCode API, and provides feedback, enhancing development workflows and ensuring consistent code standards across deployments.
Security teams employ this skill to conduct automated security audits on code changes in CANN projects. It scans for vulnerabilities like buffer overflows and null pointer dereferences, generating reports that help prioritize fixes and maintain secure codebases in high-stakes AI environments.
Offer this skill as a cloud-based service with tiered subscriptions based on usage volume (e.g., number of PRs reviewed per month). Provide additional features like custom rule sets, team collaboration tools, and premium support to attract enterprise clients in AI and software development sectors.
Sell on-premise or private cloud licenses to large organizations, such as tech companies and research institutions, for integration into their internal development platforms. Include customization options, dedicated training, and ongoing maintenance contracts to ensure long-term partnerships and revenue stability.
Provide a free basic version with limited reviews per month to attract individual developers and small teams. Monetize through premium upgrades offering advanced features like detailed analytics, priority support, and integration with other tools, converting free users into paying customers over time.
💬 Integration Tip
Ensure GitCode API token is properly configured with write_repository permissions to enable automated commenting and LGTM posting, and test the skill in a staging environment before full deployment.
Scored Jun 19, 2026
Audited Apr 17, 2026 · audit v1.0
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.