Code review checklist your agent applies to every pull request
Generic checklists get ignored because half the items don't fit your project. This prompt has your todo.is agent build a code review checklist for your language, framework and team rules, then use it on a real diff: findings grouped by severity, each with the file, the line and a suggested fix.
The prompt
- Make a code review checklist for a [LANGUAGE AND FRAMEWORK] project where [WHAT MATTERS MOST]. Group it into correctness, security, performance, readability, tests and team rules ([TEAM RULES]). Keep each item a yes/no question, 30 items max. Then review the attached diff ([DIFF OR FILES]) against it: list findings as blocker, should fix or nit, each with file, line, why it matters and a suggested change. Send the checklist as a Markdown file I can add to our pull request template.
What to change
- [LANGUAGE AND FRAMEWORK]: E.g. "TypeScript with Next.js and Prisma", "Django REST", "Go microservices".
- [WHAT MATTERS MOST]: E.g. "we handle payments", "it's a public API", "juniors write most of the code".
- [TEAM RULES]: E.g. "no direct SQL, feature flags for new features, every PR updates the changelog". Or "none yet".
- [DIFF OR FILES]: Paste git diff output or attach the changed files or a .patch.
Example result
- Code review checklist: Next.js + Prisma, payments
- Correctness
- • Does the change do what the ticket asks, including the edge cases listed?
- • Are null, empty and loading states handled in every new component?
- • Do database writes that belong together run in one prisma.$transaction?
- Security
- • Is every new API route checking the session and the user's role on the server, not only in the UI?
- • Is user input validated with the shared zod schema before it reaches Prisma?
- • Are secrets read from environment variables and absent from client bundles (no NEXT_PUBLIC_ prefix)?
- • Are amounts handled in integer cents, never floats?
- Performance
- • Are there queries inside loops that should be one findMany with include or in?
- • Do new list queries use pagination (take/cursor)?
- Readability
- • Are names clear without comments? Are functions under about 40 lines?
- • Is dead code and debug logging removed?
- Tests
- • Is there a test for the main path and for at least one failure path?
- • For payment changes, is there a test with a declined card from the provider's test mode?
- Team rules
- • Is the new feature behind a flag? Is CHANGELOG.md updated?
- Review of your diff
- • Blocker, app/api/refund/route.ts line 14: the route reads orderId from the body and refunds it without checking that the order belongs to the logged-in user. Any user could refund any order. Load the order with where: { id, userId: session.user.id } first
- • Should fix, lib/orders.ts line 52: prisma.orderItem.findMany runs inside a for loop over orders, about 1 query per order. Use one query with orderId: { in: ids }
- • Should fix, components/RefundButton.tsx line 9: no loading state, so a double click sends two refund requests. Disable the button while pending
- • Should fix: no test for the refund route's failure path
- • Nits: an unused import, a console.log on line 33, and two names (data2, tmp) that could be clearer
How to do it with todo.is
- Copy the prompt and fill in your stack, what matters most and your team rules.
- Attach the diff or changed files in todo.is, or paste git diff output in a message to your agent.
- Your agent builds the checklist, applies it and sends findings ranked by severity.
- Add pull_request_template.md to your repo's .github folder so the checklist shows on every PR.
- Send each new diff with "review against our checklist"; your agent remembers it.
Tips for a better result
- Keep the checklist short. Thirty sharp, project-specific questions beat a hundred generic ones.
- Put automated checks (formatting, lint, types) in CI so human reviewers focus on logic and security.
- Review in small pieces. Diffs over about 400 lines get skimmed, so ask authors to split big PRs.
- Separate blockers from nits clearly. Authors need to know what must change before merging.
- AI review is a second pair of eyes, not a replacement for a teammate who knows the system.
code review checklist: FAQ
- What should a code review checklist include? Correctness, security, performance, readability, tests and your team's own rules. The most useful items are specific to your stack, like checking authorization in every API route.
- How long should a code review take? Many teams aim for reviews of under 400 lines that take less than an hour. Longer reviews catch fewer problems per line.
- Can the agent comment directly on my GitHub pull request? No. It sends the findings to you with file and line references. You or your team post them on the PR.
- Is it okay to share private code for review? Your code stays in your own agent workspace and only your agent uses it. Check your company's policy on AI tools before sharing proprietary code.
JavaScript is required to use the todo.is app.