@estebanforge/pi-js-review
JavaScript code-review tool for Pi. Grades your git diffs against a focused JS flaws rubric (5 sections, 18 entries: equality/coercion, async, mutation/scope, globals/prototypes, security). Each entry has a bad/good pair; the LLM proposes a corrected snip
Package details
Install @estebanforge/pi-js-review from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@estebanforge/pi-js-review- Package
@estebanforge/pi-js-review- Version
1.0.1- Published
- Jun 30, 2026
- Downloads
- 290/mo · 20/wk
- Author
- estebanforge
- License
- MIT
- Types
- extension
- Size
- 27.7 KB
- Dependencies
- 0 dependencies · 0 peers
Pi manifest JSON
{
"extensions": [
"./extensions"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
@estebanforge/pi-js-review
JavaScript code review against a focused JS flaws rubric. Registers a js_review tool that reads git diffs, filters to .js/.mjs/.cjs, and attaches the rubric (18 entries across 5 sections, each a one-line rationale plus a bad→good pair). The rubric targets semantic and security flaws Biome / ESLint do not reliably catch. Every rule is grounded in a confirmed online source — see Sources.
Sibling to @estebanforge/pi-go-review, pi-php-review, and pi-rust-review. Pair with biome check (or eslint) for compiler-grade lint coverage; this tool focuses on mistakes static analyzers may not flag.
Install
pi install npm:@estebanforge/pi-js-review
Usage
Ask Pi: "review my JS changes."
The tool runs git in one of five modes:
| Mode | Description | Needs ref |
|---|---|---|
working |
Unstaged changes | No |
staged |
Staged (cached) changes | No |
all |
All changes vs HEAD | No |
commit |
A specific commit | Yes (SHA) |
range |
A commit range | Yes (e.g. main..HEAD) |
Narrow scope with path (a file or directory). The tool runs git from that path — so path can point into a nested repo (e.g. a package inside a workspace whose root is not itself a git repo).
What it does
- Reads the git diff filtered to
*.js/*.mjs/*.cjs. - Attaches the JS flaws rubric (18 entries, 5 sections).
- The LLM reviews the diff and returns findings that propose a corrected snippet:
| Severity | Meaning |
|---|---|
| Bug / Critical | Must fix |
| Suggestion | Should consider |
| Nit | Minor improvement |
| Good pattern | Well done |
Each finding cites the entry number (e.g. #10), the file + code fragment, and a corrected snippet. Ends with a Verdict: Approve / Request Changes / Needs Discussion.
Rubric sections
| Section | Entries |
|---|---|
| 1. Equality & Coercion | #1 - #2 |
| 2. Async | #3 - #5 |
| 3. Mutation & Scope | #6 - #7 |
| 4. Globals & Prototypes | #8 - #9 |
| 5. Security | #10 - #18 |
Security-weighted: 9 of 18 entries are injection / access-control / crypto flaws — #10 eval, #11 innerHTML XSS, #12 ReDoS, #13 hardcoded secrets, #14 open redirect/SSRF, #16 command injection, #17 insecure randomness, #18 path traversal, plus #9 prototype pollution. #15 covers event-loop (availability). The rest are the async and coercion bugs that cause real outages.
Sources
The rubric's rules were validated against confirmed online sources during research. The sources live here in the README (not embedded in the rubric) to keep the per-call prompt lean.
| # | Entry | Source |
|---|---|---|
| 1 | Loose equality == |
MDN — Equality comparisons and sameness |
| 2 | Falsy conditional trap | MDN — Falsy |
| 3 | Missing await |
eslint-plugin-promise no-floating-promises |
| 4 | Unhandled rejection | nodebestpractices — Catch unhandled promise rejections |
| 5 | forEach with async |
MDN — Array.prototype.forEach |
| 6 | Mutating arguments | clean-code-javascript — Avoid Side Effects |
| 7 | Detached this |
MDN — this |
| 8 | Extending natives | Why extending built-in objects is not a good idea |
| 9 | Prototype pollution | OWASP — Prototype Pollution Prevention |
| 10 | eval |
MDN — eval() |
| 11 | innerHTML XSS |
OWASP — DOM based XSS Prevention |
| 12 | ReDoS | OWASP — Regular expression Denial of Service |
| 13 | Hardcoded secrets | OWASP — Secrets Management |
| 14 | Open redirect / SSRF | OWASP — Unvalidated Redirects and Forwards |
| 15 | Event-loop blocking | Node.js — Don't Block the Event Loop |
| 16 | Command injection | OWASP — OS Command Injection Defense |
| 17 | Insecure randomness | MDN — Math.random() / Crypto.randomUUID() |
| 18 | Path traversal | OWASP — Path Traversal |
Primary authorities: MDN Web Docs, OWASP Cheat Sheet Series, nodebestpractices, clean-code-javascript (MIT).
Note: Azat Mardan's 100 JavaScript and TypeScript Mistakes and How to Avoid Them (Manning) exists but is paywalled (MEAP), with no free checklist; this rubric is therefore a curated hybrid rather than book-primary, like the PHP extension.
TUI rendering
Custom rendering for both the tool call and its result: mode, file count, insertions/deletions, and truncation status at a glance.
License
MIT