Library · Team · n8n · coding-review
Coding Review — n8n
Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (n8n workflow recipe (Manual Trigger → LLM → output).)
Id: n8n/coding-review · Slug: coding-review · Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.
What is this
Workflow for n8n. Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (n8n workflow recipe (Manual Trigger → LLM → output).)
How this runtime fits
This n8n implementation is primarily an AI workflow / agentic workflow for the parent AI Team. Call it a multi-agent workflow only when the graph actually splits agent-like steps.
Parent AI Team: coding-review · What is an AI Team?
What it does
Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (n8n workflow recipe (Manual Trigger → LLM → output).)
Who for
Builders working on Engineering jobs who can run n8n themselves.
Need to run
- You will run this locally or on infra you control.
- No production credentials in prompts or committed files.
- n8n instance you control
- Optional local LLM HTTP endpoint
How to use
- In n8n: Import from File → workflow.json (or recreate nodes from the sketch).
- Add your local LLM credential/HTTP node in place of the placeholder.
- Paste the full system prompt into the LLM node.
- Execute once with Example in as input. Inspect output; no schedule yet.
Limitations
- Not a substitute for professional legal, medical, or investment advice.
- Outputs can be wrong; human review required before publish or spend.
- Stage-1 Library items are free recipes — marketplace ready-to-use teams remain separate.
- Do not attach billing cloud LLM nodes without a human budget check.
Test status
Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.
Files
workflow.json— Importable n8n workflow sketchREADME.md— Safe import notes
Full prompt / config / code
# n8n Recipe — Coding Review
## Full system prompt (put in your LLM node)
You are a code review specialist. Goal: find bugs and risks in the pasted diff/file.
RULES:
- Do not rewrite the whole codebase. Comment on the provided snippet only.
- Flag: correctness, security, missing tests, irreversible ops, secrets.
- Never suggest committing secrets, force-push, or rm -rf style cleanup.
- Propose patches as unified-diff style snippets when useful.
- Stop with a severity-ordered list. Human decides merges.
OUTPUT:
1) Summary (2-4 sentences)
2) Issues table: severity | location | issue | suggested fix
3) Tests to add
4) What looks fine
## workflow.json
```json
{
"name": "BotShelf Library \u2014 Coding Review",
"nodes": [
{
"parameters": {},
"id": "1",
"name": "Manual Trigger",
"type": "n8n-nodes-base.manualTrigger",
"typeVersion": 1,
"position": [
0,
0
]
},
{
"parameters": {
"values": {
"string": [
{
"name": "system",
"value": "You are a code review specialist. Goal: find bugs and risks in the pasted diff/file.\n\nRULES:\n- Do not rewrite the whole codebase. Comment on the provided snippet only.\n- Flag: correctness, security, missing tests, irreversible ops, secrets.\n- Never suggest committing secrets, force-push, or rm -rf style cleanup.\n- Propose patches as unified-diff style snippets when useful.\n- Stop with a severity-ordered list. Human decides merges.\n\nOUTPUT:\n1) Summary (2-4 sentences)\n2) Issues table: severity | l\u2026"
},
{
"name": "user_input",
"value": "={{$json.input}}"
}
]
}
},
"id": "2",
"name": "Prepare Prompt",
"type": "n8n-nodes-base.set",
"typeVersion": 3,
"position": [
260,
0
]
},
{
"parameters": {
"notice": "Attach your own local LLM node (Ollama/LM Studio HTTP). Do not enable billing cloud nodes without a human budget check."
},
"id": "3",
"name": "LLM Placeholder",
"type": "n8n-nodes-base.noOp",
"typeVersion": 1,
"position": [
520,
0
]
}
],
"connections": {
"Manual Trigger": {
"main": [
[
{
"node": "Prepare Prompt",
"type": "main",
"index": 0
}
]
]
},
"Prepare Prompt": {
"main": [
[
{
"node": "LLM Placeholder",
"type": "main",
"index": 0
}
]
]
}
},
"meta": {
"botshelf_job": "coding-review",
"safety": "manual-trigger-only"
}
}
```
## README safety
- Trigger is Manual only (no cron spend loops in stage 1).
- Replace LLM Placeholder with a local HTTP node to Ollama/LM Studio when ready.
- Do not store API keys in the workflow JSON committed to git; use n8n credentials store.
- No shell nodes that delete files or push to production.
Example in
Review this Python snippet:
```
def pay(user, amount):
charge(user.card, amount)
send_receipt(user.email)
```
Context: internal tool, no retries yet.Example out
Summary: Charge-then-receipt with no idempotency or failure handling. Issues: - high | charge() | no idempotency key | add key + status check - med | send_receipt | may fire after partial failure | gate on success Tests: simulate charge timeout; duplicate submit. Looks fine: clear happy-path shape.
Model / runtime notes
Stage-1 recipe is manual-trigger only. Add schedules only after you confirm cost controls.
Canonical Team
Parent: coding-review
· implementation_id: n8n/coding-review
GitHub source
teams/coding-review/n8n · commit eb87e8e049fdf9908e438305ff827c7b617505b5
· license: free-use-at-own-risk
Structural check: PASS · env: structural (structural only — does not set Verified)
Related Library items
Related marketplace Team pages
Soft thematic links only — not identity merges. Marketplace Teams ≠ Library AI Team records.
- Claude Review (marketplace Team page — separate entity)
- Claude PR (marketplace Team page — separate entity)