claude-skills/engineering-team/skills/code-reviewer/rules/universal.md
fouad 14c645ba16 refactor(code-reviewer): — universal rules + per-language files
- Extract commun languages rules in a separate rules/universal.md containing all cross-language rules in one place
- Move language-specific rules inline into each languages/*.md file,
  organised into consistent sections: Security / Async / Resource
  Management / Exception Handling / Performance / Idioms
- Add Java support: languages/java.md with full section coverage
- Every review now requires exactly 2 file reads: universal.md +
  one language file
- Add "Adding a new language" guide to SKILL.md: one file to create,
  nothing else changes
2026-05-25 13:15:37 +01:00

2.1 KiB

Universal Rules — All Languages

These rules apply regardless of language. Load this file for every review, alongside the relevant languages/*.md file.


Security

  • Flag any string interpolation or concatenation used to build SQL, shell, or LDAP queries — require parameterized queries or a safe API
  • Flag hardcoded credentials, API keys, tokens, or secrets anywhere in source — require environment variables or a secrets manager
  • Flag user-controlled input passed to file system, process execution, or URL redirect APIs without validation
  • Flag overly broad CORS or CSP policies

Async / Concurrency

  • Flag shared mutable state accessed from multiple threads/coroutines/tasks without synchronization
  • Flag fire-and-forget async operations with no error handling path
  • Flag timeouts missing on any network or I/O call
  • Flag unbounded queues or thread pools with no backpressure mechanism

Resource Management

  • Flag any resource (file, socket, DB connection, HTTP connection) acquired without a guaranteed release path
  • Flag connection pools not returned to the pool on all code paths (including exceptions)
  • Flag unbounded collections that grow without eviction — potential memory leak
  • Flag resources held open longer than the operation they serve

Exception Handling

  • Flag empty catch/except blocks — swallowed exceptions hide bugs silently
  • Flag catching the broadest possible exception type (Exception, Throwable, error) where a specific type is appropriate
  • Flag exceptions used for normal control flow (signaling "not found", etc.) — use return values or Optional
  • Flag error context lost when re-throwing — always wrap with the original cause

Performance

  • Flag N+1 query patterns — loading a collection then querying for each item individually
  • Flag unbounded queries or API calls with no pagination or limit
  • Flag synchronous I/O on a thread or event loop that serves concurrent requests
  • Flag large objects serialized/deserialized repeatedly when they could be cached
  • Flag string concatenation in tight loops — use a builder or join