INNER CODE UNIT · Python

build_review_prompt

panther-labs/panther-analysis · .scripts/claude_review.py:79

def build_review_prompt(changed_files, file_contents, style_guides):
    """Build the review prompt."""
    has_queries = any(f.startswith("queries/") for f in changed_files)
    has_correlation = any(f.startswith("correlation_rules/") for f in changed_files)

    query_section = (
        """Query files detected — review these:
- Filename format: `<LogProvider>.<QueryTitle>.Query.yml`
- DisplayName format: "LogProvider QueryTitle"
- Snowflake SQL syntax correctness
- LIMIT clause present where sensible
- Time range filter (p_event_time or similar)
- Use `p_any_*` fields when possible
- Select specific fields, not `SELECT *`
- Readable and performant"""
        if has_queries
        else "No query files in this change — skip this section."
    )

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…