Agent skill

Post Draft Review

by agent-substrate in agent-substrate/substrate

Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author.

Apache-2.0Auto-check passedDevelopment

Install Post Draft Review

skills CLI
$ npx skills add agent-substrate/substrate --skill post-draft-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agent-substrate/substrate post-draft-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agent-substrate/substrate.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/post-draft-review .claude/skills/post-draft-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
post-draft-review
GitHub stars
4.5k
Token cost
~2.8k tokens
SKILL.md length
1,472 words
Files
2
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author.

  • Asked to review a pull request
  • SKILL.md covers Inline comments only — the…, Disclose that an agent found it, Keep it tight and Create the draft (PENDING)…, plus 2 more sections
  • Calls gh and jq
  • Leave review comments on one

What it does

Post Draft Review is an agent skill from agent-substrate/substrate. Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author. Use whenever asked to review a pull request or leave review comments on one, including phrasings like "review PR 764" or "take a look at this PR".

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Development, covering Pull requests, Technical documentation and Code review. It works with GitHub. The repository describes itself as: Agent Substrate: the core system. The licence is Apache-2.0.

When your agent uses it

  • Asked to review a pull request
  • Leave review comments on one
  • Including phrasings like review PR 764
  • Take a look at this PR

Example prompts

  • “review PR 764”
  • “take a look at this PR”
  • “Use the post-draft-review skill to post pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit…”
  • “/post-draft-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 296e329. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Post Draft Review loads about 2.8k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 1,472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agent-substrate/substrate at commit 296e329, republished under its Apache-2.0 licence (© agent-substrate). 1,472 words, ~2,825 tokens.

Download SKILL.mdSave it as .claude/skills/post-draft-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
post-draft-review
description
Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author. Use whenever asked to review a pull request or leave review comments on one, including phrasings like "review PR 764" or "take a look at this PR".

Post Draft Review Comments

A "draft review" on GitHub is a review left in the PENDING state. It is visible only to its author, accumulating comments, until the author explicitly submits (publishes) or discards it.

Findings go in as pending inline comments rather than individually published comments, so a human reviews them before anything reaches the PR author.

gh pr review can not create one — it always submits immediately (--approve / --comment / --request-changes). To stay in draft, hit the REST API: POST .../reviews with no event field creates the review PENDING rather than submitting it.

Inline comments only — the human authors the summary

Contribute inline comments only, created with an empty body (body: ""). The top-level summary is written by the human in the UI's "Finish your review" box when they submit. Rationale:

  • The high-level overview (praise, verdict, framing) is the human's voice, not the agent's.
  • The UI's summary box does not prefill an API-set body, so an agent-authored body is silently dropped on UI submit anyway, and can't be restored afterwards: PUT on a submitted review with an empty body is rejected with 422. An empty body sidesteps the whole failure mode.
  • Don't smuggle summary-level content into an inline comment. Top-level content anchored to a code line is poor UX for the reader.

Anything with no inline anchor — what was checked and found clean, issues in files outside the diff — goes in the chat hand-off, for the human to draw on when they write the summary.

Disclose that an agent found it

Each inline finding leads with :robot: followed by the bolded severity name and color (e.g. 🤖 **should-fix** 🟡 – …) to mark it as an AI finding. Keep it generic: don't name the agent, vendor, or model. Disclose only that an agent was involved. The human who finishes the review is accountable for what gets submitted.

Keep it tight

Bias toward brevity. A human reads this, then decides. Concretely:

  • Inline comments: lead with the severity tag and state the problem in a sentence or two, then the fix. Drop preamble, restated context, and pasted command/test output — point at the line and trust the reader.
  • Short sentences. One clause each where possible; no run-ons or long em-dash chains. State the claim and its consequence; leave the derivation (timelines, worked examples, step-by-step traces) out. The author can re-derive it from the claim, and can ask if they can't.
  • Severity tags: blocking 🔴 · should-fix 🟡 · nit 🟢 · question 🟢. Every inline finding opens with the robot marker, then the bolded severity name, then the color: 🤖 **blocking** 🔴 – …, 🤖 **should-fix** 🟡 – …, 🤖 **nit** 🟢 – …, 🤖 **question** 🟢 – …. Leading with 🤖 makes agent comments uniformly recognizable. The severity name is required because the colors alone aren't a standard PR authors know, and a bare 🟢 beside a critique reads like approval.
  • When in doubt, cut. A finding the reader can act on in five seconds beats a paragraph.
  • Brevity comes from cutting content, not compressing prose. Humans read these: keep complete sentences. No telegraphic fragments, abbreviations ("incl.", "w/"), or bare "label: clause" constructions. Drop whole points that don't change what the reader does next; write the surviving ones plainly.

Create the draft (PENDING) review

First check whether a pending review already exists. You post under the human's account, and each author may have only one pending review per PR — so any existing draft is theirs, and it may hold comments they wrote by hand:

bash
gh api repos/<owner>/<repo>/pulls/<num>/reviews \
  --jq '.[] | select(.state == "PENDING") | {id, node_id}'

No output means there's no draft yet; create one as below. If it returns a review, skip to Adding to a draft that already exists and do not delete it.

Write each comment body to a file and assemble the payload with jq --rawfile, which escapes markdown, backticks, and newlines correctly. The body is always empty:

bash
commit_id=$(gh pr view <num> --repo <owner>/<repo> --json headRefOid --jq '.headRefOid')

jq -n --arg commit "$commit_id" --rawfile c1 c1.md --rawfile c2 c2.md '{
  body: "",
  commit_id: $commit,
  comments: [
    {path:"cmd/ateapi/internal/store/ateredis/ateredis.go", line:849, side:"RIGHT", body:$c1},
    {path:"cmd/ateapi/main.go", line:57, side:"RIGHT", body:$c2}
  ]
}' > /tmp/review.json

gh api repos/<owner>/<repo>/pulls/<num>/reviews \
  --method POST --input /tmp/review.json --jq '{id, state}'
# => {"id": ..., "state": "PENDING"}

state: PENDING confirms it's a draft: not visible to anyone else, no notifications, until submitted. Keep the returned id to inspect or discard. Omitting event is what keeps it in draft; including event submits immediately.

Inline-comment notes:

  • line is the line number in the file at the PR head. side: "RIGHT" is the new (post-change) version, "LEFT" the base side.
  • Multi-line: use start_line and start_side together with line/side.
  • The line must fall within the PR's diff hunk, or the API rejects the whole review. A file that isn't in the diff at all (for example a caller that wasn't touched) can't take an inline comment. Anchor the point on a changed line nearby, such as the struct field that the untouched caller fails to populate, and reference the real location in prose. Otherwise leave it to the chat hand-off.
  • One bad anchor rejects the whole batch, and the error doesn't say which one. If the POST fails, create the review with a single comment and append the rest one at a time (see below) — the offender is then the one call that fails.
  • Pin exact head line numbers from a checkout of the PR head (gh pr checkout <num>, or fetch pull/<num>/head). Don't eyeball them from the diff.
  • commit_id pins the review to the head you actually read. Without it GitHub anchors against whatever is current when the POST lands, so a push between your fetch and your post silently moves every comment to lines you never looked at. The GraphQL append below has no equivalent field, so re-check the head SHA before appending to an older draft.
Show full SKILL.md (595 more words)Show less
Adding to a draft that already exists

A pending review you didn't create is the human's, and it may already hold comments they wrote themselves. Never delete it. Deleting takes their comments with it, they aren't recoverable, and drafts are exactly where someone parks a half-finished thought.

Append instead, one mutation per finding, using the review's node_id (the PRR_… value, not the numeric id):

bash
gh api graphql -f query='
mutation($review: ID!, $path: String!, $line: Int!, $body: String!) {
  addPullRequestReviewThread(input: {
    pullRequestReviewId: $review,
    path: $path, line: $line, side: RIGHT, body: $body
  }) { thread { id } }
}' -f review="PRR_kwDO..." \
   -f path="cmd/ateom-microvm/restore.go" -F line=214 \
   -F body=@c1.md

-F body=@c1.md reads the body straight from the file, keeping the file-per-comment discipline that --rawfile gives the batch path. Prefer it over -f body="$(cat c1.md)": command substitution strips trailing newlines, so the last line of the comment loses its break. For a multi-line anchor, add startLine and startSide.

Leave the review body alone whether it's empty or not. If the human started the draft, that text is theirs.

Appending this way is verified: the review keeps its id, stays pending, and the human's own comments come through untouched. The single-comment delete below hasn't been exercised — read the review back the first time you use it.

Revising your own findings

Delete your own comments one at a time. Don't delete the review — recreating it is only safe when you know the draft is entirely yours, and in a shared draft you don't:

bash
# your findings are the 🤖-tagged ones
gh api repos/<owner>/<repo>/pulls/<num>/reviews/<id>/comments \
  --jq '.[] | select(.body | startswith("🤖")) | .id'

gh api repos/<owner>/<repo>/pulls/comments/<comment_id> --method DELETE

This is the second job the 🤖 marker does. In a shared draft it's the only thing that tells your comments apart from the human's.

A finding the human has already edited may no longer start with 🤖, so the filter skips it. That's the safe direction — they've taken it over — but don't read a missing marker as proof a comment was never yours.

Verify anchors landed correctly

line and original_line come back null while a review is PENDING (they resolve on submit), and position is a legacy cumulative diff offset. Neither tells you the file line at a glance. Instead, check the last line of each comment's diff_hunk, which is the line the comment is attached to:

bash
gh api repos/<owner>/<repo>/pulls/<num>/reviews/<id>/comments \
  --jq '.[] | "\(.path)\n   ↳ \(.diff_hunk | split("\n") | last)\n"'

Hand-off, then the human finishes

The hand-off in chat should give the human what they need to write the summary and decide: a short findings table (severity, one-line claim, file:line anchor) and the checked-and-found-clean notes, meaning the verification work with no inline anchor. No paste-ready summary text — the summary is the human's to write.

Close the hand-off with the review id, the comment count, and these three points. A human who doesn't know them can publish the whole thing unread:

  • Nothing is published yet. The review is PENDING and visible only to them.
  • They should read each finding against the code before submitting, and delete anything they don't stand behind. Deleting a pending comment costs nothing.
  • Submitting publishes every remaining comment at once, under their name. There is no partial submit.

Point them at README.md, which is the full version of the above and the authoritative instructions for the human — keep it in sync if you change this section. Don't imply the review is finished. It isn't, and it can't be until someone has read the findings.

To discard the whole draft instead:

bash
gh api repos/<owner>/<repo>/pulls/<num>/reviews/<review_id> --method DELETE

This removes every comment in the review, including any the human wrote. Only reach for it on a draft you created and know is entirely yours.

Gotchas

  • Each author may have only one pending review per PR at a time, and you post as the human, so a second POST .../reviews errors out. Append to the existing draft rather than clearing it — see Adding to a draft that already exists.
  • Relative markdown links in comment bodies (for example [x](cmd/.../foo.go#L1)) render oddly on GitHub. Prefer plain `path:line` in backticks for code references.

© agent-substrate, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/post-draft-review of agent-substrate/substrate.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 296e329

Compare with similar skills

Post Draft Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Post Draft Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Post Draft Review this skillagent-substrate/substrate4.5k—~2.8kAutomated safety check: PassApache-2.0
Inline PR Commentshyperlane-xyz/hyperlane-explorer102—~1.1kAutomated safety check: PassCustom licence
PR Review Commentsgiuseppe-trisciuoglio/developer-kit3551 repos~1kAutomated safety check: NotesMIT
Code Reviewtestdouble/han279—~8.7kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Inline PR Comments

    hyperlane-xyz/hyperlane-explorer

    Post a single consolidated PR review with summary and inline comments.

    102 GitHub stars~1.1k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    355 GitHub starsUsed in 1 repo~1k tokens
    DevelopmentAuto-check: notes
  • Code Review

    testdouble/han

    Run a comprehensive code review on local source files. An agent skill from testdouble/han.

    279 GitHub stars~8.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed

More from agent-substrate/substrate

  • Triage Issues

    agent-substrate/substrate

    Triages open GitHub issues by applying the correct labels. An agent skill from agent-substrate/substrate.

    4.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Detect Flaky Tests

    agent-substrate/substrate

    Detects flaky Go tests by analyzing GitHub Actions workflow runs across the last 7 days and all PRs — covering both the run-tests job (unit/integration) and the e2e-test job (gVisor and microVM…

    4.5k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Review Crds

    agent-substrate/substrate

    Reviews CRDs for compliance with Kubernetes API conventions.

    4.5k GitHub stars~228 tokensUpdated today
    Auto-check passed
  • Security Status Report

    agent-substrate/substrate

    Generates a security status report based on docs/threats.json by spinning up sub-agents for each threat to compute a quality score.

    4.5k GitHub stars~524 tokensUpdated today
    Auto-check passed
  • Agents Md

    agent-substrate/substrate

    Generates or updates an AGENTS.md file

    4.5k GitHub stars~635 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Post Draft Review

What does Post Draft Review do?

Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author. Post Draft Review is an agent skill from agent-substrate/substrate. Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author.

When should I use Post Draft Review?

Post Draft Review fits situations like: asked to review a pull request; leave review comments on one; including phrasings like review PR 764; take a look at this PR.

How do I install Post Draft Review in Claude Code?

Run `npx skills add agent-substrate/substrate --skill post-draft-review -a claude-code`. Or copy the skill folder (.agents/skills/post-draft-review in agent-substrate/substrate) into .claude/skills/post-draft-review in your project. Claude Code loads it when a task matches its description.

How do I install Post Draft Review in Codex?

Run `npx skills add agent-substrate/substrate --skill post-draft-review -a codex`. Or copy the skill folder (.agents/skills/post-draft-review in agent-substrate/substrate) into .agents/skills/post-draft-review in your project. Codex loads it when a task matches its description.

Can I use Post Draft Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agent-substrate/substrate --skill post-draft-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/post-draft-review, .gemini/skills/post-draft-review, .github/skills/post-draft-review and .opencode/skills/post-draft-review in your project.

What does Post Draft Review need to run?

Going by SKILL.md and its folder, Post Draft Review needs the command-line tools its instructions call (gh and jq).

Does Post Draft Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Post Draft Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Post Draft Review use?

Post Draft Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Post Draft Review use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Post Draft Review?

Skills that share tags, products or a category with Post Draft Review: Inline PR Comments (hyperlane-xyz/hyperlane-explorer, 102 stars), PR Review Comments (giuseppe-trisciuoglio/developer-kit, 355 stars), Code Review (testdouble/han, 279 stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Post Draft Review?

agent-substrate (a GitHub organization) maintains it in agent-substrate/substrate, which has 4,536 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: agent-substrate/substrate on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.