SkillAtlasSkill 详情

code-review-excellence

Security audit: baseline 52/52 CLEAN

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年9月20日

Awesome GitHub stars License: CC BY-SA 4.0 PRs Welcome Validate catalog OpenSSF Scorecard Security audit: baseline 52/52 CLEAN Rigor coverage Powered by StatsPAI

Auto-Empirical Research Skills (AERS)

📌 文档结构(2026-07-22 起): 本文件是中文默认入口 —— banner + badges + 信任面 + 9 阶段流水线速览 + 76 行合集总表。 每个合集的完整描述、按用途分组、精确数字、验证方法在 docs/CONTENT_ZH.md(扩展正文,总表行内的 → 直接跳转到对应锚点)。

English version: README-en.md · 中文扩展正文:docs/CONTENT_ZH.md · README-zh-CN.md 已弃用(重定向占位)

🌐 语言: English | 简体中文(默认) | 繁體中文 | 日本語 | 한국어


CoPaper.AI Stanford REAP - Center on China's Economy & Institutions

Stanford REAP × CoPaper.AI · 实证研究 AI 工具的学术工业级产品
由斯坦福实证研究方法论团队打造,覆盖从数据清洗到顶刊投稿的完整工作流



实证研究智能体技能大全封面图

🚀 New here? Open the Skill Search → to filter all 1,096 skills by method, stage, language, and license. The 5-minute tour (make quickstart) prints the same picture in your terminal.

🇨🇳 中文用户从本文件开始(流水线速览 + 76 行总表),每个合集的完整描述见 docs/CONTENT_ZH.md。📖 English readers: see README-en.md.


信任面 · Trust surface (rigor stats)

Rigor laneCountWhere
Numeric benchmark tasks — gold values recomputed from real data each run19benchmark/
Behavioral eval scenarios / rubric items42 / 217eval-harness/
其中已证明能区分对错的场景(pass/fail 双 fixture 自检)9(全部 6 个 critical 场景在内)eval-harness/fixtures/

Full trust overview: docs/TRUST.md · docs/RIGOR_COVERAGE.md

🏁 带上你自己的 agent 来考同一份卷子:pip install -e . 后用 aers-score 给自己打分,成绩发布在 docs/EXTERNAL_SCOREBOARD.md(规则见 docs/SCOREBOARD_RULES.md)。榜上的数字是我们用同一套评分器重算出来的,不是提交者自报的。


⚡ 安装与使用(30 秒上手)

最省事的一招:把 URL 丢给 Agent

把项目 URL 地址 https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills 丢给 Claude Code / Codex,并指定是目录 / 项目 / 全局安装 —— 剩下的让它自己做。例如:

帮我安装 https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills
装到「全局」(~/.claude/skills/),我想在所有项目里都能用

把最后一行换成你要的作用域即可:

作用域说给 Agent 的话落到哪里
目录(当前会话临时用)"只在当前目录用,不要全局安装"当前工作目录下的 .claude/skills/
项目(团队共享,可提交进 git)"装到本项目"项目根目录 .claude/skills/
全局(所有项目可用)"装到全局"~/.claude/skills/(Codex 为 ~/.codex/skills/)

手动安装(两种,任选其一)

A. 插件市场(Claude Code v2.1+,推荐,可升级)

claude plugin marketplace add brycewang-stanford/Auto-Empirical-Research-Skills
claude plugin install aer-skills@auto-empirical-research-skills                 # 顶刊投稿全流程(9 skills)
claude plugin install empirical-analysis-python@auto-empirical-research-skills  # Python 计量流水线
claude plugin install empirical-analysis-stata@auto-empirical-research-skills   # Stata 计量流水线
claude plugin install empirical-analysis-r@auto-empirical-research-skills       # R + Quarto 流水线

B. 只要某一个 skill —— 直接拷文件夹

git clone --recurse-submodules https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
cd Auto-Empirical-Research-Skills

cp -R skills/00.1-Full-empirical-analysis-skill_Python  .claude/skills/   # 项目级
cp -R skills/00.1-Full-empirical-analysis-skill_Python  ~/.claude/skills/ # 全局

拷进去的文件夹必须自带 SKILL.md(部分合集的 SKILL.md 在下一层,拷那一层)。

怎么用

新开一个会话,直接用自然语言说要做什么,Agent 会按 description 自动挑 skill;说不动就点名方法或 skill:

用面板数据跑一个 Callaway–Sant'Anna 事件研究,并出 HonestDiD 稳健性和期刊级表格

完整安装说明(Codex / CodeBuddy 整库导入、--plugin-dir 单次加载、常见故障排查)见 INSTALL.md。


中文文档结构

中文内容分两级维护,各司其职:

  • 本文件(README.md,GitHub 默认入口):banner、badges、信任面、9 阶段流水线速览、76 行合集总表。
  • docs/CONTENT_ZH.md(扩展正文):每个合集的完整描述(#skill-NN 锚点)、按用途分组、精确数字、2 分钟验证、三层信任、旗舰流水线详解、贡献与引用。总表行内的 → 直接跳到对应锚点。
  • 其他语言:README-en.md · README-zh-TW.md · README-ja.md · README-ko.md

[!NOTE] 维护规则: 改合集总表 → 本文件与 CONTENT_ZH.md 的锚点表两处同步;改合集详情 / 分组 / 数字 → 只改 docs/CONTENT_ZH.md。统计数字(合集数 / skill 数)以 catalog/skills.json 为准,由 make validate 的 readme-stats 检查器守护。

贡献者(Contributors): 提交前请在本地跑通完整门禁 make check(catalog 校验 + 链接 + 单元测试 + eval-harness + benchmark)。详见 CONTRIBUTING.md。

旧版归档: README-zh-CN.md 已弃用,仅作向后兼容的重定向占位。


🚀 从一个 idea 到一篇论文:社科实证研究 · 端到端流水线(全自动、可介入)

AERS 不只是 76 个散装 skill —— 它能陪你走完一篇论文。 从模糊 idea → 选题精炼 → 文献综述 → 数据获取 → 识别策略 → 估计建模 → 稳健性审计 → 出版级表格 / 图形 → 写作与同行评审 → 降 AIGC → 投稿。端到端、全自动、每一步都可被人介入(中间任何一步你都可以接过去手工改方法、补变量、加稳健性,再让流水线自动接上跑)。

9 阶段流水线 · 每一步都覆盖到具体 skill

#阶段关键 skills(点合集名进目录,→ 进完整说明)
1️⃣选题精炼 — Agent 把模糊想法收紧成"可证伪 + 可执行"的研究问题· 25 Diverga · 33 claude-scholar · 05 research-superpower · 11 compound-science
2️⃣文献综述 — 检索 · 筛选 · PRISMA 流程 · 批判性阅读 · 主题分析· 36 literature-review-skill · 24 academic-research-skills · 59 openalex-skill · 68 research-productivity-skills · 53 thematic-analysis
3️⃣数据获取 — 公开数据库 · API · 网页抓取 · 数据清洗· 33 claude-scholar · 68 research-productivity-skills · 32 stata-skill · 57 edgartools
4️⃣识别策略 — DiD / RD / IV / SCM / DML / matching 全覆盖· ⭐ 00 StatsPAI 🔥 · 10 causal-inference-mixtape · 13 MixtapeTools · 51 CausalPy · 63 scientific-agent-skills
5️⃣估计建模 — Python / Stata / R 三栈,900+ 估计器· ⭐ 00.1 Full Empirical · Python · ⭐ 00.2 Full Empirical · Stata · ⭐ 00.3 Full Empirical · R · 40 pyfixest · 39 marginaleffects · 09 awesome-econ-ai
6️⃣稳健性审计 — 复现包检查 · Honest-DiD · R&R 模拟· 41 sewage-econometrics-check · ⭐ 50 AER-skills · 21 AI-research-feedback
7️⃣表格 & 图形 — 期刊出版级排版 · LaTeX 嵌入· ⭐ 00 StatsPAI · 07 AI-Research-SKILLs · 33 claude-scholar · 08 latex-document-skill
8️⃣写作 & 同行评审 — LaTeX / Quarto · 仿审稿人 · 校对· 06 stats-paper-writing · 04 scientific-writer · 22 christopherkenny-skills · 38 academic-proofreader · 56 econ-writing-skill · 16 clo-author
9️⃣降 AIGC & 去水印 & 投稿 — 知网 / 万方 / Turnitin / 23 类 AI 痕迹模式 / 隐藏字符 · C2PA · docx 元数据清理· ⭐ 48 de-AIGC-skills 🇨🇳🇬🇧 · 44 humanizer_academic · 45 deslop · 46 stop-slop · 47 avoid-ai-writing · 49 humanize-chinese

🎼 元编排:⭐ 69 Paper-WorkFlow —— 一键串起来

Paper-WorkFlow 是 AERS 的"指挥棒",它把上面 9 个阶段的 skill 串成 一条按键即运行的端到端流水线。 你在 IDE 入口给它一句自然语言:

"开一个新论文项目:空气污染与中国劳动力市场,CS 设计 + 省级面板"

它会自动按顺序调:

  1. ⭐ 00 StatsPAI → sp.csdid(...) 给出 CS-DID 估计草案 + 写出估计方程与识别假设
  2. 33 claude-scholar → 抓变量定义 / 数据源候选 / 相关文献
  3. ⭐ 00 StatsPAI → 真跑 sp.feols(...) + sp.honest_did(...)
  4. 41 sewage-econometrics-check → 10 项复现包审计 + 稳健性体检
  5. ⭐ 00 StatsPAI + 07 AI-Research-SKILLs → 出 Table 1–5 + 期刊级图
  6. 38 academic-proofreader → 通读 + §comment 标"审稿人会挑刺的位置"
  7. 56 econ-writing-skill 起草初稿 + ⭐ 48 de-AIGC-skills 🇨🇳🇬🇧 + 45 deslop 过知网 / Turnitin

任何阶段你都可以手动介入 —— 上一阶段的产物全部落盘(产物-幂等 pipeline),你接过去改方法、补控制、加稳健性,再让流水线自动接下去跑。这就是"全自动 + 可介入"。

🏆 7 个 Stanford REAP × CoPaper.AI 自研 skill —— 是整个流水线的主干

⭐ Skill在流水线里的角色
00 StatsPAI 🔥因果引擎:900+ 函数,sp.causal(...) 一行跑闭环(DID / RD / IV / SCM / DML / matching)
00.1 Full Empirical · Python 📘显式 Python 栈(pandas / statsmodels / linearmodels / pyfixest)
00.2 Full Empirical · Stata 📊显式 Stata 栈(reghdfe / ivreg2 / csdid / sdid / rdrobust)
00.3 Full Empirical · R 📗显式 R 栈(tidyverse / fixest / did / HonestDiD)+ Quarto 渲染
48 de-AIGC-skills 🇨🇳🇬🇧中英双语学术降 AIGC + 去水印层(Turnitin AI / GPTZero / 知网 / 万方 · 隐藏字符 / C2PA / docx 元数据)
50 AER-skills 📕Top-5 经济学投稿套件:识别 → 稳健性 → R&R
69 Paper-WorkFlow 🧭元编排器,把上面 9 个阶段串成一键流水线

为什么挑这 7 个?因为它们的行为都被基准钉死了 —— 不是营销口径,是对着已知答案反复跑过验证过的(17 项数值 benchmark + 37 项行为评测 ↗)。

看到这里 —— 完整 76 行合集目录

↴ 直跳到下方 76 行总表(每个合集带 #skill-NN 锚点)。如果你更关心"这些 skill 怎么用"而不是"有哪些 skill",看 📘 中文唯一权威正文 里的「按用途分组」与「旗舰流水线」两节。


🧰 76 个核心 Skills 合集一览(00 → 72,编号连续无空缺)

打开仓库 → 看见整座库。 全部 76 个合集 · 1,096 个 skill,每一个都已 vendor 进本仓库,由 catalog/skills.json 跟踪。⭐ = Stanford REAP × CoPaper.AI 团队自研的 skill;其余为精选、经安全审计的社区作品。

主题图例 — 🚀 全流程与编排器 · 🎯 因果推断与计量经济学 · 📚 文献与研究设计 · ✍️ 写作 / 编辑 / 去 AIGC · 📑 引用 / 复现 / 同行评审 · 🛠️ 数据 / 工具 / 基础设施

点击【→】 跳转到 docs/CONTENT_ZH.md 中该合集的完整描述;点击合集名 直接打开其目录。

🙏 尊重原作者 — 「来源」列直接链回上游原始仓库(owner/repo)。本仓库里的社区合集都是上游快照:请去原仓库点 star、提 issue、看 LICENSE。完整的许可证与来源置信度审计见 docs/LICENSE_AUDIT.md,机器可读版本在 catalog/provenance.json。

#合集一句话详情来源
⭐ 00StatsPAI 🔥因果引擎 · Agent-native Python DSL:sp.causal(...) 一行跑闭环(DID/RD/IV/SCM/DML,900+ 函数)→brycewang-stanford/StatsPAI
⭐ 00.1Full Empirical · Python 📘显式栈:pandas · statsmodels · linearmodels · pyfixest→⭐ 本仓库
⭐ 00.2Full Empirical · Stata 📊reghdfe · ivreg2 · csdid · sdid · rdrobust 复现包→⭐ 本仓库
⭐ 00.3Full Empirical · R 📗tidyverse · fixest · did · HonestDiD + Quarto 渲染→⭐ 本仓库
01academic-paper-skills大纲 → 手稿写作 + 7 维审稿人模拟→lishix520/academic-paper-skills
02research-skills医学影像综述、提案、论文转幻灯片→luwill/research-skills
03scientific-skills假设生成 + 28 个科学数据库→K-Dense-AI/claude-scientific-skills
04scientific-writer引用管理 + 科学写作→K-Dense-AI/claude-scientific-writer
05research-superpower系统化检索、筛选与引文溯源→kthorn/research-superpower
06stats-paper-writing端到端 LaTeX 统计论文写作→fuhaoda/stats-paper-writing-agent-skills
07AI-Research-SKILLs发表级 ML 图表、LaTeX、引文核验→Orchestra-Research/AI-Research-SKILLs
08latex-document-skill创建 / 编译任意 LaTeX 文档为 PDF→ndpvt-web/latex-document-skill
09awesome-econ-aiPython 面板数据分析(linearmodels)→meleantonio/awesome-econ-ai-stuff
10causal-inference-mixtapeDID / IV / RDD / SCM 模板(Cunningham)→Jill0099/causal-inference-mixtape
11compound-science面向定量社会科学的贝叶斯估计→James-Traina/compound-science
12claude-code-my-workflow提交 → PR → 合并的研究工作流(Emory)→pedrohcgs/claude-code-my-workflow
13MixtapeToolsCunningham 的因果推断工具集与讲义→scunning1975/MixtapeTools
14research-starterR 中的 IV / DiD / RDD,含完整诊断→luischanci/claude-code-research-starter
15social-science-researchR 或 Python 端到端数据分析→Felpix-Studios/social-science-research
16clo-author多代理数据分析(R / Stata / Python)→hsantanna88/clo-author
17DAAF安全意识代理框架(32 条 deny rule)→DAAF-Contribution-Community/daaf
18stata-accounting来自 126 篇 JAR 论文的实测 Stata 范式→jusi-aalto/stata-accounting-research
19vera-economic-intelligence经济情报 / 政策研究情报工作流→CuellarC05/vera-economic-intelligence
20python-econ-skillDSGE / HANK 与定量经济计算→wenddymacro/python-econ-skill
21AI-research-feedback用 AI 同行评审生成结构化反馈→claesbackman/AI-research-feedback
22christopherkenny-skills面向 Quarto(.qmd)的 APSA 风格检查器→christopherkenny/skills
23baygent带护栏的 PyMC / Arviz 贝叶斯工作流→Learning-Bayesian-Statistics/baygent-skills
24academic-research-skills5 审稿人多视角论文评审→Imbad0202/academic-research-skills
25Diverga研究问题精炼器(抗模式坍缩)→HosungYou/Diverga
26scholar统计算法设计与文档→Data-Wise/claude-plugins
27my_claude_skills经济学摘要写作指南→dariia-m/my_claude_skills
28paper-replicate-agent论文复现代理演示→maxwell2732/paper-replicate-agent-demo
29project20XXy可复现手稿 + notebook 项目→quarcs-lab/project20XXy
30zirui-song-claude-skillsZirui Song 的研究辅助 Claude 技能集→zirui-song/claude-skills
31claude-code-skillsPython 面板数据分析→thalysandratos/claude-code-skills
32stata-skill高性能 Stata C/C++ 插件→dylantmoore/stata-skill
33claude-scholar研究全生命周期:选题 → 综述 → 实验 → 审稿回复→Galaxy-Dawn/claude-scholar
34research-companion头脑风暴、评估并决策研究方向→andrehuang/research-companion
35academic-writing-skills面向投稿场所的工业 AI 文献研究→bahayonghang/academic-writing-skills
36literature-review-skill完整文献综述工作流(中文)→taoyunudt/literature-review-skill
37IlanStrauss-ai-skillsIlan Strauss 经济学研究 AI 工作流→IlanStrauss/ai-skills
38academic-proofreader学术校对→peternka/academic_proofreader
39marginaleffects预测、斜率与比较(R / Python)→vincentarelbundock/marginaleffects
40pyfixestPython 中的快速固定效应估计→py-econometrics/pyfixest
41sewage-econometrics-check10 项复现包审计→sticerd-eee/sewage
42ARIS自主「research-in-sleep」代理,端到端→wanshuiyin/Auto-claude-code-research-in-sleep
43research-plugins478 个研究插件:数据可视化、领域、基础设施→wentorai/research-plugins
44humanizer_academic为医学/学术手稿去 AI 味(23 类模式)→matsuikentaro1/humanizer_academic
45deslop去除 AI 写作痕迹(5 维评分)→stephenturner/skill-deslop
46stop-slop三层 AI 痕迹检测与改写→hardikpandya/stop-slop
47avoid-ai-writing审计 → 改写 → 二次审计 AI 味(留痕)→conorbronsdon/avoid-ai-writing
⭐ 48de-AIGC-skills 🇨🇳🇬🇧中英双语学术降 AIGC + 去水印层(Turnitin AI / GPTZero / 知网 / 万方 · 隐藏字符 / C2PA / docx 元数据)→⭐ 本仓库
49humanize-chinese检测并人性化 AI 生成的中文文本→swaylq/humanize-chinese
⭐ 50AER-skills 📕Top-5 经济学投稿套件:识别 → 稳健性 → R&R→brycewang-stanford/AER-skills
51CausalPy贝叶斯准实验(PyMC Labs)→pymc-labs/CausalPy
52slr-prisma系统文献综述,PRISMA 2020→keemanxp/slr-prisma
53thematic-analysisBraun & Clarke 六阶段定性主题分析→keemanxp/thematic-analysis-skill
54open-science-skills引用一致性、DOI 与论据支撑审计→scdenney/open-science-skills
55r-skillsR 中用 brms 做贝叶斯推断→ab604/claude-code-r-skills
56econ-writing-skill综合 50+ 顶级指南的经济学写作→hanlulong/econ-writing-skill
57edgartools查询与分析 SEC 文件→dgunning/edgartools
58econstack政策简报(UK GES / AU Treasury)→charlescoverdale/econstack
59openalex-skill通过 OpenAlex 查询 2.4 亿+ 学术作品→shiquda/openalex-skill
60superpapers综合性实证研究支持套件→regisely/superpapers
61research-methods与预注册匹配的验证性检验→phdemotions/research-methods
62citation-checker对照 CrossRef / S2 / OpenAlex 核验引用→PHY041/claude-skill-citation-checker
63scientific-agent-skillsDoWhy 识别–估计–反驳框架→tondevrel/scientific-agent-skills
64mcp-stata20 个 Stata 因果推断与复现 skill→tmonk/mcp-stata
65game-theory-paper-writer生成并压力测试博弈论论文→本仓库 PR #17
66empirical-research-skills面向大型面板的 R 性能优化→SiyaoZheng/ai4ss-skills
67econfin-workflow-toolkit中国公司金融实证工作流,从提案到论文→本仓库 PR #22
68research-productivity-skills论文检索、SSRN、DOI 查询、下载→本仓库 PR #21
⭐ 69Paper-WorkFlow 🧭元编排器,串起整个社会科学论文流水线→brycewang-stanford/Paper-WorkFlow
70ssci-polish ✍️SSCI / SCI 英文论文语言润色(语法、可读性、学术语气)→⭐ 本仓库
⭐ 71lit-review-agent-tools 🔍文献综述工具选型 + 一键安装运行(MinerU / PaperQA2 / ASReview / STORM / MCP 服务器)→brycewang-stanford/lit-review-agent-tools
⭐ 72Kaggle Research 🧪通过官方 CLI 安全检索 Kaggle 资源、限界下载公开数据并保留审计证据→⭐ 本仓库

想看更详细的描述(主题分类、字段、统计)? 见 docs/CONTENT_ZH.md 中标注 #skill-NN 锚点的同一张表 —— 它是每个合集的完整描述所在的扩展正文。

📈 项目历程

自 2026-04 首次发布以来的主干里程碑(完整提交记录见 Commits 与 CHANGELOG.md):

---
config:
  gitGraph:
    rotateCommitLabel: false
---
gitGraph TB:
   commit id: "2026-04 首次发布"
   branch community
   commit id: "2026-05 首个社区 PR"
   checkout main
   merge community
   commit id: "2026-05 更名 AERS"
   commit id: "2026-06 插件市场"
   commit id: "2026-06 全库路由器"
   commit id: "2026-07 首个 tag" tag: "v2026.07"
   branch kaggle
   commit id: "2026-07 Kaggle 集成"
   checkout main
   merge kaggle
   commit id: "2026-08 de-AIGC 双语"
   commit id: "2026-08 来源链接全覆盖"
   branch evidence
   commit id: "2026-08 aers-score CLI"
   commit id: "2026-08 外部成绩单"
   checkout main
   merge evidence
   commit id: "2026-08 结构估计 = 方法族 18"
   commit id: "2026-08 NSW 基准从引用变推导"
   commit id: "2026-09 de-AIGC 去水印层"
Star History Chart

Star 增长曲线(非提交数)· 由 scripts/build-star-history.py 从 GitHub API 生成并提交入库

如果 AERS 对你的工作有帮助,请引用它(CITATION.cff)并点个 Star,让更多研究者看到。


AI 是放大器,不是替代品。它替你做最耗时的"搬砖",你保留最核心的"判断"。


CoPaper.AI Stanford REAP

Stanford REAP × CoPaper.AI · 实证研究 AI 工具的学术工业级产品


扫码访问 copaper.ai
扫码访问 copaper.ai
CoPaper.AI 公众号
关注公众号「CoPaper.AI」

内置 20 个方法论 skill · 20 分钟完成实证论文 · 自研 StatsPAI(900+ 函数 / MIT 开源)

开发与工程Agent / MCP / Skill 创作

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
  3. 将 "skills/33-Galaxy-Dawn-claude-scholar/skills/code-review-excellence" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
  3. 将 "skills/33-Galaxy-Dawn-claude-scholar/skills/code-review-excellence" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
  3. 将 "skills/33-Galaxy-Dawn-claude-scholar/skills/code-review-excellence" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
  3. 将 "skills/33-Galaxy-Dawn-claude-scholar/skills/code-review-excellence" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills.git
  3. 将 "skills/33-Galaxy-Dawn-claude-scholar/skills/code-review-excellence" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: code-review-excellence
description: This skill should be used when the user asks to review a diff or pull request, write review comments, audit code quality, establish review standards, or improve how a team performs code review.
version: 0.1.0

Code Review Excellence

Transform code reviews from gatekeeping to knowledge sharing through constructive feedback, systematic analysis, and collaborative improvement.

When to Use This Skill

  • Reviewing pull requests and code changes
  • Establishing code review standards for teams
  • Mentoring junior developers through reviews
  • Conducting architecture reviews
  • Creating review checklists and guidelines
  • Improving team collaboration
  • Reducing code review cycle time
  • Maintaining code quality standards

Core Principles

1. The Review Mindset

Goals of Code Review:

  • Catch bugs and edge cases
  • Ensure code maintainability
  • Share knowledge across team
  • Enforce coding standards
  • Improve design and architecture
  • Build team culture

Not the Goals:

  • Show off knowledge
  • Nitpick formatting (use linters)
  • Block progress unnecessarily
  • Rewrite to your preference

2. Effective Feedback

Good Feedback is:

  • Specific and actionable
  • Educational, not judgmental
  • Focused on the code, not the person
  • Balanced (praise good work too)
  • Prioritized (critical vs nice-to-have)
❌ Bad: "This is wrong."
✅ Good: "This could cause a race condition when multiple users
         access simultaneously. Consider using a mutex here."

❌ Bad: "Why didn't you use X pattern?"
✅ Good: "Have you considered the Repository pattern? It would
         make this easier to test. Here's an example: [link]"

❌ Bad: "Rename this variable."
✅ Good: "[nit] Consider `userCount` instead of `uc` for
         clarity. Not blocking if you prefer to keep it."

3. Review Scope

What to Review:

  • Logic correctness and edge cases
  • Security vulnerabilities
  • Performance implications
  • Test coverage and quality
  • Error handling
  • Documentation and comments
  • API design and naming
  • Architectural fit

What Not to Review Manually:

  • Code formatting (use Prettier, Black, etc.)
  • Import organization
  • Linting violations
  • Simple typos

Review Process

Phase 1: Context Gathering (2-3 minutes)

Before diving into code, understand:

1. Read PR description and linked issue
2. Check PR size (>400 lines? Ask to split)
3. Review CI/CD status (tests passing?)
4. Understand the business requirement
5. Note any relevant architectural decisions

Phase 2: High-Level Review (5-10 minutes)

1. **Architecture & Design**
   - Does the solution fit the problem?
   - Are there simpler approaches?
   - Is it consistent with existing patterns?
   - Will it scale?

2. **File Organization**
   - Are new files in the right places?
   - Is code grouped logically?
   - Are there duplicate files?

3. **Testing Strategy**
   - Are there tests?
   - Do tests cover edge cases?
   - Are tests readable?

Phase 3: Line-by-Line Review (10-20 minutes)

For each file:

1. **Logic & Correctness**
   - Edge cases handled?
   - Off-by-one errors?
   - Null/undefined checks?
   - Race conditions?

2. **Security**
   - Input validation?
   - SQL injection risks?
   - XSS vulnerabilities?
   - Sensitive data exposure?

3. **Performance**
   - N+1 queries?
   - Unnecessary loops?
   - Memory leaks?
   - Blocking operations?

4. **Maintainability**
   - Clear variable names?
   - Functions doing one thing?
   - Complex code commented?
   - Magic numbers extracted?

Phase 4: Summary & Decision (2-3 minutes)

1. Summarize key concerns
2. Highlight what you liked
3. Make clear decision:
   - ✅ Approve
   - 💬 Comment (minor suggestions)
   - 🔄 Request Changes (must address)
4. Offer to pair if complex

Review Techniques

Technique 1: The Checklist Method

## Security Checklist
- [ ] User input validated and sanitized
- [ ] SQL queries use parameterization
- [ ] Authentication/authorization checked
- [ ] Secrets not hardcoded
- [ ] Error messages don't leak info

## Performance Checklist
- [ ] No N+1 queries
- [ ] Database queries indexed
- [ ] Large lists paginated
- [ ] Expensive operations cached
- [ ] No blocking I/O in hot paths

## Testing Checklist
- [ ] Happy path tested
- [ ] Edge cases covered
- [ ] Error cases tested
- [ ] Test names are descriptive
- [ ] Tests are deterministic

Technique 2: The Question Approach

Instead of stating problems, ask questions to encourage thinking:

❌ "This will fail if the list is empty."
✅ "What happens if `items` is an empty array?"

❌ "You need error handling here."
✅ "How should this behave if the API call fails?"

❌ "This is inefficient."
✅ "I see this loops through all users. Have we considered
    the performance impact with 100k users?"

Technique 3: Suggest, Don't Command

## Use Collaborative Language

❌ "You must change this to use async/await"
✅ "Suggestion: async/await might make this more readable:
    ```typescript
    async function fetchUser(id: string) {
        const user = await db.query('SELECT * FROM users WHERE id = ?', id);
        return user;
    }
    ```
    What do you think?"

❌ "Extract this into a function"
✅ "This logic appears in 3 places. Would it make sense to
    extract it into a shared utility function?"

Technique 4: Differentiate Severity

Use labels to indicate priority:

🔴 [blocking] - Must fix before merge
🟡 [important] - Should fix, discuss if disagree
🟢 [nit] - Nice to have, not blocking
💡 [suggestion] - Alternative approach to consider
📚 [learning] - Educational comment, no action needed
🎉 [praise] - Good work, keep it up!

Example:
"🔴 [blocking] This SQL query is vulnerable to injection.
 Please use parameterized queries."

"🟢 [nit] Consider renaming `data` to `userData` for clarity."

"🎉 [praise] Excellent test coverage! This will catch edge cases."

Language-Specific Patterns

Python Code Review

# Check for Python-specific issues

# ❌ Mutable default arguments
def add_item(item, items=[]):  # Bug! Shared across calls
    items.append(item)
    return items

# ✅ Use None as default
def add_item(item, items=None):
    if items is None:
        items = []
    items.append(item)
    return items

# ❌ Catching too broad
try:
    result = risky_operation()
except:  # Catches everything, even KeyboardInterrupt!
    pass

# ✅ Catch specific exceptions
try:
    result = risky_operation()
except ValueError as e:
    logger.error(f"Invalid value: {e}")
    raise

# ❌ Using mutable class attributes
class User:
    permissions = []  # Shared across all instances!

# ✅ Initialize in __init__
class User:
    def __init__(self):
        self.permissions = []

TypeScript/JavaScript Code Review

// Check for TypeScript-specific issues

// ❌ Using any defeats type safety
function processData(data: any) {  // Avoid any
    return data.value;
}

// ✅ Use proper types
interface DataPayload {
    value: string;
}
function processData(data: DataPayload) {
    return data.value;
}

// ❌ Not handling async errors
async function fetchUser(id: string) {
    const response = await fetch(`/api/users/${id}`);
    return response.json();  // What if network fails?
}

// ✅ Handle errors properly
async function fetchUser(id: string): Promise<User> {
    try {
        const response = await fetch(`/api/users/${id}`);
        if (!response.ok) {
            throw new Error(`HTTP ${response.status}`);
        }
        return await response.json();
    } catch (error) {
        console.error('Failed to fetch user:', error);
        throw error;
    }
}

// ❌ Mutation of props
function UserProfile({ user }: Props) {
    user.lastViewed = new Date();  // Mutating prop!
    return <div>{user.name}</div>;
}

// ✅ Don't mutate props
function UserProfile({ user, onView }: Props) {
    useEffect(() => {
        onView(user.id);  // Notify parent to update
    }, [user.id]);
    return <div>{user.name}</div>;
}

Advanced Review Patterns

Pattern 1: Architectural Review

When reviewing significant changes:

1. **Design Document First**
   - For large features, request design doc before code
   - Review design with team before implementation
   - Agree on approach to avoid rework

2. **Review in Stages**
   - First PR: Core abstractions and interfaces
   - Second PR: Implementation
   - Third PR: Integration and tests
   - Easier to review, faster to iterate

3. **Consider Alternatives**
   - "Have we considered using [pattern/library]?"
   - "What's the tradeoff vs. the simpler approach?"
   - "How will this evolve as requirements change?"

Pattern 2: Test Quality Review

// ❌ Poor test: Implementation detail testing
test('increments counter variable', () => {
    const component = render(<Counter />);
    const button = component.getByRole('button');
    fireEvent.click(button);
    expect(component.state.counter).toBe(1);  // Testing internal state
});

// ✅ Good test: Behavior testing
test('displays incremented count when clicked', () => {
    render(<Counter />);
    const button = screen.getByRole('button', { name: /increment/i });
    fireEvent.click(button);
    expect(screen.getByText('Count: 1')).toBeInTheDocument();
});

// Review questions for tests:
// - Do tests describe behavior, not implementation?
// - Are test names clear and descriptive?
// - Do tests cover edge cases?
// - Are tests independent (no shared state)?
// - Can tests run in any order?

Pattern 3: Security Review

## Security Review Checklist

### Authentication & Authorization
- [ ] Is authentication required where needed?
- [ ] Are authorization checks before every action?
- [ ] Is JWT validation proper (signature, expiry)?
- [ ] Are API keys/secrets properly secured?

### Input Validation
- [ ] All user inputs validated?
- [ ] File uploads restricted (size, type)?
- [ ] SQL queries parameterized?
- [ ] XSS protection (escape output)?

### Data Protection
- [ ] Passwords hashed (bcrypt/argon2)?
- [ ] Sensitive data encrypted at rest?
- [ ] HTTPS enforced for sensitive data?
- [ ] PII handled according to regulations?

### Common Vulnerabilities
- [ ] No eval() or similar dynamic execution?
- [ ] No hardcoded secrets?
- [ ] CSRF protection for state-changing operations?
- [ ] Rate limiting on public endpoints?

Giving Difficult Feedback

Pattern: The Sandwich Method (Modified)

Traditional: Praise + Criticism + Praise (feels fake)

Better: Context + Specific Issue + Helpful Solution

Example:
"I noticed the payment processing logic is inline in the
controller. This makes it harder to test and reuse.

[Specific Issue]
The calculateTotal() function mixes tax calculation,
discount logic, and database queries, making it difficult
to unit test and reason about.

[Helpful Solution]
Could we extract this into a PaymentService class? That
would make it testable and reusable. I can pair with you
on this if helpful."

Handling Disagreements

When author disagrees with your feedback:

1. **Seek to Understand**
   "Help me understand your approach. What led you to
    choose this pattern?"

2. **Acknowledge Valid Points**
   "That's a good point about X. I hadn't considered that."

3. **Provide Data**
   "I'm concerned about performance. Can we add a benchmark
    to validate the approach?"

4. **Escalate if Needed**
   "Let's get [architect/senior dev] to weigh in on this."

5. **Know When to Let Go**
   If it's working and not a critical issue, approve it.
   Perfection is the enemy of progress.

Best Practices

  1. Review Promptly: Within 24 hours, ideally same day
  2. Limit PR Size: 200-400 lines max for effective review
  3. Review in Time Blocks: 60 minutes max, take breaks
  4. Use Review Tools: GitHub, GitLab, or dedicated tools
  5. Automate What You Can: Linters, formatters, security scans
  6. Build Rapport: Emoji, praise, and empathy matter
  7. Be Available: Offer to pair on complex issues
  8. Learn from Others: Review others' review comments

Common Pitfalls

  • Perfectionism: Blocking PRs for minor style preferences
  • Scope Creep: "While you're at it, can you also..."
  • Inconsistency: Different standards for different people
  • Delayed Reviews: Letting PRs sit for days
  • Ghosting: Requesting changes then disappearing
  • Rubber Stamping: Approving without actually reviewing
  • Bike Shedding: Debating trivial details extensively

Templates

PR Review Comment Template

## Summary
[Brief overview of what was reviewed]

## Strengths
- [What was done well]
- [Good patterns or approaches]

## Required Changes
🔴 [Blocking issue 1]
🔴 [Blocking issue 2]

## Suggestions
💡 [Improvement 1]
💡 [Improvement 2]

## Questions
❓ [Clarification needed on X]
❓ [Alternative approach consideration]

## Verdict
✅ Approve after addressing required changes

Resources

  • references/code-review-best-practices.md: Comprehensive review guidelines
  • references/common-bugs-checklist.md: Language-specific bugs to watch for
  • references/security-review-guide.md: Security-focused review checklist
  • assets/pr-review-template.md: Standard review comment template
  • assets/review-checklist.md: Quick reference checklist
  • scripts/pr-analyzer.py: Analyze PR complexity and suggest reviewers

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!