
Backend Code Review Assistant
Catch bugs, performance issues, and security gaps before they hit production
What You Can Do
This skill systematically reviews backend code to uncover bugs, performance bottlenecks, security vulnerabilities, and architectural debt before deployment. You provide code (functions, diffs, or full files), and it delivers prioritized findings with detailed explanations and actionable fixes. Every review includes severity assessment, code examples, and concrete recommendations to improve quality and safety.
Features
detects SQL injection, authentication flaws, input validation gaps, hardcoded secrets, and OWASP Top 10 risks
identifies N+1 queries, inefficient algorithms, memory leaks, missing indexes, and bottlenecks in critical paths
checks for privilege escalation, unsafe dependencies, session management flaws, and compliance violations
evaluates code organization, separation of concerns, design patterns, and technical debt accumulation
flags outdated libraries, known vulnerabilities, version conflicts, and unsafe transitive dependencies
checks index coverage, query efficiency, constraint correctness, and scalability concerns
ensures testability, readability, style consistency, and alignment with team standards
Example Output
Finding 1: SQL Injection (Critical)
Location: Line 42 in getUserData()
Issue: Direct string interpolation in SQL query
// ❌ Vulnerable
db.query("SELECT * FROM users WHERE id = " + userId)
// ✅ Fixed
db.query("SELECT * FROM users WHERE id = $1", [userId])
Impact: Attacker can bypass authentication and exfiltrate database
Finding 2: N+1 Query Problem (High)
Location: Lines 18-22 in listUserOrders()
Issue: Loop executes query per user instead of batch
// ❌ 1000 queries for 1000 users
users.forEach(user => db.query("SELECT * FROM orders WHERE user_id = " + user.id))
// ✅ Fixed: 1 query
const orders = db.query("SELECT * FROM orders WHERE user_id = ANY($1)", [userIds])
Impact: API response time > 10 seconds for 1000 users
Finding 3: Missing Authorization (Critical)
Location: Line 15 in DELETE /api/users/:id
Issue: Endpoint lacks role check; any user can delete anyone
Fix: Add middleware requireRole('admin') before handler
What's Included
- SKILL.md file with complete review workflow and decision trees:
- Backend code review checklist (security, performance, architecture, testing):
- Vulnerability pattern library (SQL injection, XSS, CSRF, authentication bypasses):
- Performance antipattern detection guide (N+1 queries, inefficient loops, memory waste):
- Security hardening checklist (secrets, dependencies, privilege escalation):
- Architectural review framework (design patterns, separation of concerns, modularity):
- Template feedback responses for common issues:
- Before/after code examples for 20+ common fixes:
Who It's For
- Backend engineers and full-stack developers conducting peer reviews
- Senior developers and tech leads ensuring code quality before deployment
- Engineering managers overseeing team standards and architectural decisions
- DevOps and platform engineers auditing critical infrastructure code
- Security teams performing pre-release vulnerability assessments
Best For
- Pre-deployment code review of microservices and APIs
- Security audit of authentication, authorization, and data handling layers
- Performance optimization before production scaling events
- Technical debt assessment and remediation roadmap planning
- Dependency and vulnerability audits before releasing new versions






