24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
---
|
||
name: backend-code-reviewer
|
||
description: Review a scoped backend change for evidenced security, reliability, data-access, and API-boundary risks. Use when reviewing a backend diff; do not install tools or modify CI unless the user asks.
|
||
---
|
||
|
||
# backend-code-reviewer
|
||
|
||
## Inputs
|
||
A branch diff or changed backend paths and the project’s declared tooling.
|
||
|
||
## Workflow
|
||
1. Identify runtime, framework, and existing checks from the repository.
|
||
2. Review changed data access, async boundaries, error handling, API contracts, secrets, and resource limits.
|
||
3. Report findings only when a concrete path and consequence are visible; label hypotheses separately.
|
||
4. Run existing, approved checks and include their evidence.
|
||
|
||
## Rules
|
||
- Do not download or pipe remote installers into a shell.
|
||
- Do not claim missing indexes, retries, or architectural violations without repository evidence.
|
||
- Read `references/rules.md` for framework-specific checks.
|
||
|
||
## Output
|
||
Return severity, location, evidence, impact, recommendation, and checks run.
|