winui-code-review

작성자: microsoft

WinUI 3 앱의 코드 품질 검토 — MVVM 준수, x:Bind 정확성, 접근성, 테마, 보안 및 성능. 커밋 전에 사용하여 문제를 발견하세요…

npx skills add https://github.com/microsoft/win-dev-skills --skill winui-code-review

When to Use

Run a code review after the app builds and before committing. This catches quality issues that aren't build errors and aren't visible in UI tests — patterns that compile and run but are wrong, fragile, or slow.

How to Review

Read through the project's XAML and C# files and check each section below. The Microsoft.WindowsAppSDK.Analyzers Roslyn analyzer ships with the winui-dev-workflow skill and is injected when BuildAndRun.ps1 calls project-mode winapp run. The wrapper supplies a temporary file through the environment-backed MSBuild CustomAfterDirectoryBuildProps hook, preserving SDK composition and each project's normal Directory.Build.props discovery (including referenced projects), then restores the environment and removes the temporary file. Plain winapp run, dotnet build, and Visual Studio do not load the analyzer automatically; to enable it outside the wrapper, add the <Analyzer Include="..." /> and <Import Project="..." /> entries to the project's own Directory.Build.props (or wait for the planned NuGet package).

The analyzer catches a curated set of WinUI 3 / Windows App SDK issues with categorized 4-digit IDs:

  • WUI0xxx — UWP → WinUI 3 API compatibility (UwpXamlNamespace, Window.Current, CoreDispatcher, GetForCurrentView)
  • WUI1xxx — Migration-table data-driven hints (UWP API has WinAppSDK equivalent, no equivalent, feature-area hint)
  • WUI2xxx — Runtime / layout / XAML pitfalls (raw TabView content, nested x:Bind without fallback, x:Bind without Mode, null Converter, missing AutomationId, attached-property syntax)
  • WUI3xxx — MVVM patterns (old [ObservableProperty] field syntax)
  • WUI4xxx — Interop (WebView2 not initialized, removed ONNX Runtime GenAI APIs WUI4101-WUI4103)

Every diagnostic ships at Warning severity (no rule is Error) and includes a helpLinkUri. Suppress noise with #pragma warning disable WUIxxxx or <NoWarn> as usual — the analyzer's SuppressionTests verify that pragma suppression round-trips correctly.

MVVM Compliance

  • ViewModels extend ObservableObject, use [ObservableProperty] partial properties (not fields)
  • Commands use [RelayCommand] attribute, not manual ICommand implementations
  • No UI types in ViewModels (SolidColorBrush, Visibility, BitmapImage) — these belong in converters or XAML
  • No business logic in code-behind — only navigation, dialog coordination, and event wiring
  • async Task for async methods, async void only for event handlers
  • Never replace ObservableCollection<T> — use .Clear() + re-add

x:Bind and Data Binding

  • All bindings use {x:Bind}, not {Binding}
  • Mode=OneWay or TwoWay set explicitly — OneTime default causes blank UI for dynamic data
  • x:DataType set on every DataTemplate — required for compiled x:Bind
  • No nested nullable paths (e.g., ViewModel.Selected.Name) without FallbackValue
  • Command bindings can use OneTime (commands don't change) — don't add Mode=OneWay to Command="{x:Bind}"

Accessibility

  • AutomationProperties.AutomationId on every interactive control (Button, TextBox, ComboBox, ToggleSwitch, ListView, NavigationViewItem)
  • AutomationProperties.Name on icon-only buttons and controls without visible text
  • Semantic controls (Button, HyperlinkButton) — not clickable Border/TextBlock
  • No information conveyed by color alone

Theming

  • All colors use {ThemeResource} brushes — no hardcoded #FF0000 or Color="Blue"
  • Typography uses built-in styles (TitleTextBlockStyle, SubtitleTextBlockStyle, BodyTextBlockStyle, CaptionTextBlockStyle) — no raw FontSize
  • Spacing uses 4px grid multiples (4, 8, 12, 16, 24, 32, 48)
  • Corner radius uses ControlCornerRadius / OverlayCornerRadius — not hardcoded values
  • Styles referenced with {StaticResource} not {ThemeResource} (except for brush usage sites)

Security

  • No secrets, API keys, or tokens in source code
  • No Process.Start with unsanitized user input
  • External input validated and sanitized before use
  • File paths from user input not used directly in File.Delete / File.WriteAllText without validation

Performance

  • Long or dynamic lists use ListView/GridView (virtualized), not StackPanel with foreach
  • x:Load for content that's not always visible (e.g., dialogs, secondary panels)
  • Heavy work off UI thread via Task.Run or async/await — never block UI
  • No .Result / .Wait() / .GetAwaiter().GetResult() — these deadlock the UI thread
  • using statements on all disposable objects (Model, Tokenizer, InferenceSession, Generator)

Globalization

  • User-facing strings use x:Uid in XAML and ResourceLoader in C# — not hardcoded
  • String resources in Strings/en-us/Resources.resw (not .resx)
  • Date/number formatting uses CultureInfo.CurrentCulture — not hardcoded formats
  • Layout supports RTL (FlowDirection inherited from root, no absolute positioning that breaks in RTL)
  • No string concatenation for user-facing messages — use string.Format or interpolation with resource strings

Review Report

After reviewing, summarize:

  1. Issues found: List each with file, line, and what's wrong
  2. Severity: Error (must fix), Warning (should fix), or Note (could improve)
  3. Suggested fixes: Specific code changes for each issue

References

For detailed rules with code examples, see references/quality-rules.md — covers performance deep dives (x:Phase, layout optimization), security (PasswordVault, DPAPI, WebView2 hardening), accessibility (keyboard nav, screen readers), code quality (.editorconfig, naming), and globalization (x:Uid patterns, RTL, pluralization).

microsoft의 다른 스킬

oss-growth
microsoft
OSS 성장 해커 페르소나
agent-framework-azure-ai-py
microsoft
Microsoft Agent Framework Python SDK(agent-framework-azure-ai)를 사용하여 Azure AI Foundry 에이전트를 구축합니다. AzureAIAgentsProvider로 지속적 에이전트를 만들 때, 호스팅 도구(코드 인터프리터, 파일 검색, 웹 검색)를 사용할 때, MCP 서버를 통합할 때, 대화 스레드를 관리할 때, 또는 스트리밍 응답을 구현할 때 사용합니다. 함수 도구, 구조화된 출력, 다중 도구 에이전트를 다룹니다.
development
airunway-aks-setup
microsoft
AKS에서 AI Runway 설정 — 빈 클러스터에서 실행 중인 모델까지. 클러스터 검증, 컨트롤러 설치, GPU 평가, 공급자 설정, 첫 배포를 다룹니다. 시기: "AI Runway 설정", "AKS 클러스터 온보딩", "AI Runway 설치", "airunway 설정", "AKS에 모델 배포", "AKS에서 GPU 추론", "AKS에서 KAITO 설정", "AKS에서 LLM 실행", "AKS에서 vLLM", "AKS에서 모델 서빙 설정", "AI Runway 컨트롤러".
devops
appinsights-instrumentation
microsoft
Azure Application Insights로 웹앱을 계측하기 위한 지침입니다. 원격 분석 패턴, SDK 설정, 구성 참조를 제공합니다. WHEN: 앱 계측 방법, App Insights SDK, 원격 분석 패턴, App Insights란 무엇인가, Application Insights 지침, 계측 예시, APM 모범 사례.
devops
applicationinsights-web-ts
microsoft
브라우저/웹 앱을 Application Insights JavaScript SDK(@microsoft/applicationinsights-web)로 계측합니다. Real User Monitoring(RUM) — 페이지 뷰, 클릭, AJAX/fetch 종속성, 예외, 사용자 지정 이벤트, 백엔드 OpenTelemetry 트레이스와 상관관계가 있는 브라우저 측 GenAI 에이전트 트레이스에 사용합니다. SDK Loader Script 및 npm 설정, 프레임워크 확장(React, React Native, Angular), Click Analytics, 텔레메트리 이니셜라이저, 브라우저에서 생성된 에이전트/도구/모델 스팬에 대한 OTel GenAI 의미론적 규칙을 다룹니다.
devops
azure-ai-anomalydetector-java
microsoft
Azure AI Anomaly Detector SDK for Java로 이상 탐지 애플리케이션을 구축하세요. 단변량/다변량 이상 탐지, 시계열 분석 또는 AI 기반 모니터링을 구현할 때 사용하세요.
development
azure-ai-language-conversations-py
microsoft
azure-ai-language-conversations Python SDK를 사용하여 대화형 언어 이해(CLU)를 구현합니다. ConversationAnalysisClient로 대화 의도와 엔터티를 분석하거나, NLP 기능을 구축하거나, 애플리케이션에 언어 이해를 통합할 때 사용합니다.
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 for Python. ML 작업 영역, 작업, 모델, 데이터 세트, 컴퓨팅 및 파이프라인에 사용합니다. 트리거: "azure-ai-ml", "MLClient", "workspace", "model registry", "training jobs", "datasets".
development