INNER CODE UNIT · Python
build_review_prompt
panther-labs/panther-analysis · .scripts/claude_review.py:79
def build_review_prompt(changed_files, file_contents, style_guides):
"""Build the review prompt."""
has_queries = any(f.startswith("queries/") for f in changed_files)
has_correlation = any(f.startswith("correlation_rules/") for f in changed_files)
query_section = (
"""Query files detected — review these:
- Filename format: `<LogProvider>.<QueryTitle>.Query.yml`
- DisplayName format: "LogProvider QueryTitle"
- Snowflake SQL syntax correctness
- LIMIT clause present where sensible
- Time range filter (p_event_time or similar)
- Use `p_any_*` fields when possible
- Select specific fields, not `SELECT *`
- Readable and performant"""
if has_queries
else "No query files in this change — skip this section."
)