spring-kotlin-code-review

bởi kotlin

Xem xét các thay đổi Kotlin + Spring để phát hiện hồi quy hành vi, lỗi giao dịch và proxy, sai sót API và tuần tự hóa, rủi ro về bền vững dữ liệu, vấn đề bảo mật,…

npx skills add https://github.com/kotlin/kotlin-backend-agent-skills --skill spring-kotlin-code-review

Spring Kotlin Code Review

Source mapping: Tier 1 critical skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-21).

Mission

Review changes the way a strong Kotlin plus Spring teammate would review them: behavior first, risk first, evidence first. Optimize for catching bugs, regressions, and missing tests, not for polishing style.

Read In This Order

  • Diff or changed files.
  • Related tests.
  • Configuration or build file changes.
  • Impacted controllers, services, repositories, security config, and migrations.
  • Project conventions from project-context-ingestion if available.

Review Dimensions

Check every relevant change for:

  • transaction boundaries and rollback behavior
  • proxy compatibility and self-invocation traps
  • bean wiring and configuration safety
  • API contract, validation, and serialization correctness
  • JPA or repository correctness and performance
  • security exposure and authorization drift
  • concurrency, retries, and idempotency risks
  • observability regressions
  • test adequacy and missing failure-path coverage
  • Kotlin-specific problems such as !!, unsafe platform types, and misuse of lateinit

Output Contract

Return findings first and order them by severity. Use this structure:

  • Findings: each finding should name the risk, explain the consequence, and point to the relevant file and line when available.
  • Open questions or assumptions: only where uncertainty changes the review outcome.
  • Summary: only after findings, and only briefly.

If no material findings exist, say so explicitly and still note residual risk or testing gaps.

What Counts As A Real Finding

  • A correctness bug.
  • A production-risking design choice.
  • A likely regression.
  • A security or data-consistency hole.
  • Missing coverage for a meaningful failure path.

Minor style suggestions are secondary and should never drown out real risk.

Review Heuristics

  • Prefer a smaller number of well-supported findings over a long list of weak suspicions.
  • Tie every finding to behavior, not only to taste.
  • Verify whether the repository's existing conventions intentionally justify an unusual pattern before flagging it.
  • Distinguish must fix concerns from consider improving concerns.

Advanced Review Checklist

  • Check deploy-order safety. A code change, config change, and migration may each be correct alone but unsafe in rolling deployment order.
  • Check backward compatibility of JSON contracts, event schemas, database writes, and feature flags. Additive changes are safer than semantic changes hidden behind the same shape.
  • Check cache invalidation, deduplication, retry semantics, and idempotency whenever writes or integrations change.
  • Check whether observability changed with the behavior. A new critical path without metrics, logs, or trace propagation is a real operational regression.
  • Check whether new repository queries need supporting indexes or whether an innocuous loop creates N+1 behavior.
  • Check whether any new async, scheduled, or concurrent path changes transaction scope, MDC propagation, or security context.
  • Check build and dependency changes for BOM drift, plugin mismatches, or silent classpath changes.
  • Check what was removed, not only what was added. Missing validation, logging, or authorization is often the real regression.

Expert Heuristics

  • Read the change as a workflow, not as isolated files. Many Spring bugs live in the seam between controller, service, repository, and config.
  • If a finding depends on an assumption, state the assumption and the fastest way to confirm it.
  • Prefer findings that are expensive for the team to rediscover in production.
  • Use style comments only when they prevent future correctness bugs or materially improve maintainability.

Guardrails

  • Do not nitpick naming or formatting when the change contains higher-severity risk.
  • Do not invent risks without code evidence.
  • Do not praise or summarize before surfacing findings.
  • Do not ignore missing tests just because the code "looks straightforward."
  • Do not apply generic Java advice without checking Kotlin and Spring specifics.

Quality Bar

A good run of this skill gives the author a short list of concrete, high-signal risks to address. A bad run reads like a generic lint pass and misses the transactional, proxy, security, or persistence behavior that actually matters.

Thêm skills từ kotlin

kotlin-backend-jpa-entity-mapping
kotlin
Lớp dữ liệu (data class) của Kotlin rất tự nhiên cho DTO nhưng nguy hiểm cho thực thể JPA. Hibernate dựa vào ngữ nghĩa định danh mà lớp dữ liệu phá vỡ: equals / hashCode trên tất cả các trường làm hỏng tư cách thành viên Set / Map sau khi thay đổi trạng thái, và copy() được tạo tự động tạo ra các bản sao tách rời của các thực thể được quản lý.
kotlin-tooling-agp9-migration
kotlin
Plugin Android Gradle 9.0 khiến các plugin ứng dụng và thư viện Android không tương thích với plugin Kotlin Multiplatform trong cùng một module. Kỹ năng này hướng dẫn bạn thực hiện quá trình di chuyển.
kotlin-tooling-cocoapods-spm-migration
kotlin
Di chuyển dự án KMP từ CocoaPods (kotlin("native.cocoapods")) sang Swift Package Manager (swiftPMDependencies DSL) — thay thế pod() bằng swiftPackage(),…
kotlin-tooling-immutable-collections-0-5-x-migration
kotlin
Di chuyển mã Kotlin (và Java) từ kotlinx.collections.immutable 0.3.x / 0.4.x lên phiên bản 0.5.x mới nhất. Dòng 0.5.x đổi tên mọi phương thức trả về bản sao trên…
kotlin-tooling-java-to-kotlin
kotlin
Chuyển đổi các tệp nguồn Java sang Kotlin tự nhiên bằng phương pháp chuyển đổi 4 bước có kỷ luật với 5 bất biến được kiểm tra ở mỗi bước. Hỗ trợ chuyển đổi nhận biết framework, xử lý các mục tiêu vị trí chú thích, thành ngữ thư viện và bảo toàn API.
kotlin-tooling-native-build-performance
kotlin
Chẩn đoán và khắc phục tình trạng biên dịch và liên kết Kotlin/Native chậm trong các dự án Kotlin Multiplatform nhắm mục tiêu iOS. Sử dụng khi người dùng báo cáo iOS chậm hoặc…
kotlin-spring-proxy-compatibility
kotlin
Diagnose and prevent Kotlin plus Spring proxy failures around `@Transactional`, `@Cacheable`, `@Async`, method security, retry, configuration proxies, and JPA…
ci-cd-containerization-advisor
kotlin
Thiết kế các pipeline build, image và triển khai có thể tái tạo cho ứng dụng Kotlin và Spring, bao gồm xác minh CI, container phân lớp, an toàn khi triển khai,…