npx skills add ...
npx skills add coreylyn/harmonyos-skills --skill harmonyos-review
Review native HarmonyOS ArkTS and ArkUI repositories for concrete, source-evidenced defects in correctness, security, lifecycle and resource ownership, state management, concurrency, persistence, permissions, compatibility, and performance. Use for code review, bug hunting, release readiness, migration audits, or review of a diff, PR, module, or whole project. Report only findings demonstrated by reachable code and project configuration, with precise file and line references; use current official Huawei documentation for version-sensitive claims.
npx skills add coreylyn/harmonyos-skills --skill harmonyos-review
Find real defects, not checklist-shaped speculation. Repository code and configuration establish what the application does; official Huawei documentation establishes version-sensitive platform contracts.
build-profile.json5, oh-package.json5, module.json5, and related configuration to establish SDK levels, application model, devices, permissions, dependencies, and build variants.Start broad, then follow evidence:
Example reconnaissance commands:
Adapt patterns to the repository. Exclude generated, dependency, build-output, fixture, and test-data directories when they create noise.
Load references/checklist.md and select categories supported by the scope:
For platform-dependent claims, consult references/official-docs.md and verify against current official Huawei documentation. Do not hard-code “current” API versions or infer a requirement from another framework.
A reportable finding needs all of the following:
Before reporting, try to disprove the candidate:
Do not report style preferences, arbitrary size limits, generic “could be” risks, or scanner matches without demonstrated impact.
Severity reflects impact and likelihood, not fix difficulty.
Unless the user requests a repository document, respond in the conversation. Use references/report-template.md only when a full Markdown artifact is requested.
Order findings by severity. Each finding should contain:
[severity] concise titlepath/to/file.ets:lineIf no findings meet the evidence bar, say so explicitly. Then note coverage gaps and unrun validation separately; do not inflate them into findings.