Skip to main content
Back to AI
Review3 min

Prompt patterns for code review

Structured prompts that ask for risks, line references, behavioral regressions, missing tests, and migration fallout.

Takeaway

A useful AI review prompt asks for concrete, falsifiable findings before summaries, style suggestions, or praise.

01

Define the review stance

Ask the assistant to prioritize bugs, regressions, security risks, accessibility gaps, migration fallout, and missing tests. That framing keeps the response closer to what a human reviewer needs.

A good stance also tells the assistant what not to optimize for. General praise, broad rewrites, and style-only suggestions should come after concrete findings, if they appear at all.

  • Ask for findings first, ordered by severity.
  • Require file paths, line references, or user-visible behavior for every blocking issue.
  • Tell the reviewer to call out uncertainty instead of filling gaps with assumptions.

02

Require evidence

Good findings cite files, line references, user-visible behavior, and a test or manual flow that would catch the issue. Feedback without evidence should be treated as an idea, not a blocker.

Evidence requirements make review output easier to triage. The developer can reproduce, fix, or reject each point without debating vague impressions.

  • Provide the diff, affected routes, and relevant tests as context.
  • Ask which check would have caught each finding.
  • Separate confirmed behavior from inferred risk.

review instruction

text

Lead with bugs and regressions. Cite files and behavior.
Do not include praise until after findings.
Say when a concern is speculative.

03

Keep the final pass factual

After fixes, ask for a verification-focused review that lists what changed, what passed, and what remains untested. That output is easier to trust in a pull request.

The final pass should be short enough to act as release or review evidence. It should not re-open the whole design discussion unless verification exposes a new risk.

  • List commands that passed and commands that were not run.
  • Mention manual flows checked after the patch.
  • Keep unresolved risks visible without overstating them.