spring-kotlin-code-review

작성자: kotlin

Kotlin + Spring 변경 사항에서 동작 회귀, 트랜잭션 및 프록시 버그, API 및 직렬화 오류, 지속성 위험, 보안 문제 등을 검토합니다.

npx skills add https://github.com/kotlin/kotlin-backend-agent-skills --skill spring-kotlin-code-review

Spring Kotlin Code Review

Source mapping: Tier 1 critical skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-21).

Mission

Review changes the way a strong Kotlin plus Spring teammate would review them: behavior first, risk first, evidence first. Optimize for catching bugs, regressions, and missing tests, not for polishing style.

Read In This Order

  • Diff or changed files.
  • Related tests.
  • Configuration or build file changes.
  • Impacted controllers, services, repositories, security config, and migrations.
  • Project conventions from project-context-ingestion if available.

Review Dimensions

Check every relevant change for:

  • transaction boundaries and rollback behavior
  • proxy compatibility and self-invocation traps
  • bean wiring and configuration safety
  • API contract, validation, and serialization correctness
  • JPA or repository correctness and performance
  • security exposure and authorization drift
  • concurrency, retries, and idempotency risks
  • observability regressions
  • test adequacy and missing failure-path coverage
  • Kotlin-specific problems such as !!, unsafe platform types, and misuse of lateinit

Output Contract

Return findings first and order them by severity. Use this structure:

  • Findings: each finding should name the risk, explain the consequence, and point to the relevant file and line when available.
  • Open questions or assumptions: only where uncertainty changes the review outcome.
  • Summary: only after findings, and only briefly.

If no material findings exist, say so explicitly and still note residual risk or testing gaps.

What Counts As A Real Finding

  • A correctness bug.
  • A production-risking design choice.
  • A likely regression.
  • A security or data-consistency hole.
  • Missing coverage for a meaningful failure path.

Minor style suggestions are secondary and should never drown out real risk.

Review Heuristics

  • Prefer a smaller number of well-supported findings over a long list of weak suspicions.
  • Tie every finding to behavior, not only to taste.
  • Verify whether the repository's existing conventions intentionally justify an unusual pattern before flagging it.
  • Distinguish must fix concerns from consider improving concerns.

Advanced Review Checklist

  • Check deploy-order safety. A code change, config change, and migration may each be correct alone but unsafe in rolling deployment order.
  • Check backward compatibility of JSON contracts, event schemas, database writes, and feature flags. Additive changes are safer than semantic changes hidden behind the same shape.
  • Check cache invalidation, deduplication, retry semantics, and idempotency whenever writes or integrations change.
  • Check whether observability changed with the behavior. A new critical path without metrics, logs, or trace propagation is a real operational regression.
  • Check whether new repository queries need supporting indexes or whether an innocuous loop creates N+1 behavior.
  • Check whether any new async, scheduled, or concurrent path changes transaction scope, MDC propagation, or security context.
  • Check build and dependency changes for BOM drift, plugin mismatches, or silent classpath changes.
  • Check what was removed, not only what was added. Missing validation, logging, or authorization is often the real regression.

Expert Heuristics

  • Read the change as a workflow, not as isolated files. Many Spring bugs live in the seam between controller, service, repository, and config.
  • If a finding depends on an assumption, state the assumption and the fastest way to confirm it.
  • Prefer findings that are expensive for the team to rediscover in production.
  • Use style comments only when they prevent future correctness bugs or materially improve maintainability.

Guardrails

  • Do not nitpick naming or formatting when the change contains higher-severity risk.
  • Do not invent risks without code evidence.
  • Do not praise or summarize before surfacing findings.
  • Do not ignore missing tests just because the code "looks straightforward."
  • Do not apply generic Java advice without checking Kotlin and Spring specifics.

Quality Bar

A good run of this skill gives the author a short list of concrete, high-signal risks to address. A bad run reads like a generic lint pass and misses the transactional, proxy, security, or persistence behavior that actually matters.

kotlin의 다른 스킬

kotlin-backend-jpa-entity-mapping
kotlin
Kotlin의 data class는 DTO에 자연스럽지만 JPA 엔티티에는 위험합니다. Hibernate는 data class가 깨뜨리는 identity 의미론에 의존합니다. 모든 필드에 대한 equals/hashCode는 상태 변경 후 Set/Map 멤버십을 손상시키고, 자동 생성된 copy()는 관리되는 엔티티의 분리된 복제본을 만듭니다.
kotlin-tooling-agp9-migration
kotlin
Android Gradle Plugin 9.0은 동일한 모듈에서 Android 애플리케이션 및 라이브러리 플러그인을 Kotlin Multiplatform 플러그인과 호환되지 않게 만듭니다. 이 스킬은 마이그레이션 과정을 안내합니다.
kotlin-tooling-cocoapods-spm-migration
kotlin
KMP 프로젝트를 CocoaPods(kotlin("native.cocoapods"))에서 Swift Package Manager(swiftPMDependencies DSL)로 마이그레이션 — pod()를 swiftPackage()로 대체,…
kotlin-tooling-immutable-collections-0-5-x-migration
kotlin
Kotlin(및 Java) 코드를 kotlinx.collections.immutable 0.3.x / 0.4.x에서 최신 0.5.x로 마이그레이션합니다. 0.5.x 라인은 모든 복사본을 반환하는 메서드의 이름을 변경합니다…
kotlin-tooling-java-to-kotlin
kotlin
Java 소스 파일을 체계적인 4단계 변환 방법론을 사용하여 관용적인 Kotlin으로 변환하며, 각 단계에서 5가지 불변 조건을 확인합니다. 애노테이션 사이트 대상, 라이브러리 관용구, API 보존을 처리하는 프레임워크 인식 변환을 지원합니다.
kotlin-tooling-native-build-performance
kotlin
Kotlin Multiplatform 프로젝트에서 iOS를 대상으로 할 때 느린 Kotlin/Native 컴파일 및 링크를 진단하고 수정합니다. 사용자가 느린 iOS 또는…을 보고할 때 사용하세요.
kotlin-spring-proxy-compatibility
kotlin
Diagnose and prevent Kotlin plus Spring proxy failures around `@Transactional`, `@Cacheable`, `@Async`, method security, retry, configuration proxies, and JPA…
ci-cd-containerization-advisor
kotlin
재현 가능한 빌드, 이미지 및 배포 파이프라인을 설계합니다. Kotlin 및 Spring 애플리케이션을 대상으로 하며, CI 검증, 계층형 컨테이너, 롤아웃 안전성 등을 포함합니다.