Agent skill

PR Post Audit

by akitaonrails in akitaonrails/my-skills

Audit the combined default-branch state after one or more PR merges or before deployment/release.

No licenceAuto-check passedDevelopment

Install PR Post Audit

skills CLI
$ npx skills add akitaonrails/my-skills --skill pr-post-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akitaonrails/my-skills pr-post-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akitaonrails/my-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pr-post-audit .claude/skills/pr-post-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-post-audit
GitHub stars
220
Token cost
~3.6k tokens
SKILL.md length
1,777 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
None found

At a glance

Audit the combined default-branch state after one or more PR merges or before deployment/release.

  • Works in 9 steps: Freeze the Boundary → Inventory Provenance and Tickets → Reconcile Individual Audits → …
  • Verify exact merge provenance
  • SKILL.md covers Trust Boundary, Phase 0: Freeze the Boundary, Phase 1: Inventory Provenance… and Phase 2: Reconcile Individual…, plus 6 more sections
  • Calls git

What it does

PR Post Audit is an agent skill from akitaonrails/my-skills. Audit the combined default-branch state after one or more PR merges or before deployment/release. Use to verify exact merge provenance, cross-PR interactions, malicious or prompt-injected contributions, security and supply-chain composition, regressions, compatibility, tests, documentation, changelog completeness, hosted checks, and release readiness after individual PR audits.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Supply chain security, Feature launches and release readiness and Changelog and release notes. The repository describes itself as: akitaonrails' personal skills (not tailored for general usage).

When your agent uses it

  • Verify exact merge provenance
  • Cross-PR interactions
  • Prompt-injected contributions
  • Security and supply-chain composition

Example prompts

  • “/pr-post-audit”

Requirements

  • Docker

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Freeze the Boundary
  2. Inventory Provenance and Tickets
  3. Reconcile Individual Audits
  4. Combined Hostile-Code and Security Sweep
  5. Cross-PR Interaction Sweep
  6. Documentation and Release Ledger
  7. Conditional Verification
  8. Fix Loop
  9. Output and Release Handoff

What it can do on your machine

Read from SKILL.md and the folder at commit 5763b9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Post Audit loads about 3.6k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 1,777 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,777 words (~3,591 tokens).

“Audit the final tree, not a collection of optimistic PR summaries. This is the last code-quality and security gate before deployment or release. It does not release automatically.”

— opening of SKILL.md by akitaonrails
name
pr-post-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in pr-post-audit of akitaonrails/my-skills.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 5763b9e

Compare with similar skills

PR Post Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Post Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Post Audit this skillakitaonrails/my-skills220—~3.6kAutomated safety check: PassNone
Herdr Pre-Release Auditherdrdev/herdr43k—~289Automated safety check: PassApache-2.0
Megaphone ReleaseKuberwastaken/megaphone170—~1.3kAutomated safety check: PassMIT
Create Release Checklistsoftware-mansion/smelter734—~1.9kAutomated safety check: NotesCustom licence
ReleasingOdradekAI/bundles-forge229—~3.3kAutomated safety check: PassApache-2.0
Upgrade Dear Imgui StackLatias94/dear-imgui-rs108—~977Automated safety check: PassApache-2.0

Similar skills

  • Audit herdr release readiness by comparing commits since the base release against next-release changelog and docs. Use when asked to run or apply the repo's…

    43k GitHub stars~289 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Megaphone Release

    Kuberwastaken/megaphone

    Prepare, validate, publish, and verify Megaphone releases. An agent skill from Kuberwastaken/megaphone.

    170 GitHub stars~1.3k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Create Release Checklist

    software-mansion/smelter

    Generate a GitHub release-checklist issue for a full (non-RC) release of the Smelter server and/or the TypeScript SDK.

    734 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Releasing

    OdradekAI/bundles-forge

    A skill your agent uses when releasing a bundle-plugin, bumping versions, fixing version drift across manifests, setting up version sync infrastructure, updating CHANGELOG, publishing to…

    229 GitHub stars~3.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Upgrade Dear Imgui Stack

    Latias94/dear-imgui-rs

    A skill your agent uses when a user asks to upgrade Dear ImGui, cimgui, ImPlot, ImPlot3D, ImNodes, ImGuizmo, Dear ImGui Test Engine, or related bindings in this repository.

    108 GitHub stars~977 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Check

    Thank-you-Linus/Linus-Dashboard

    Check if project is ready for release with comprehensive pre-release validation.

    211 GitHub stars~637 tokensUpdated today
    DevelopmentAuto-check passed

More from akitaonrails/my-skills

All 18 skills in this repo
  • Fact Check

    akitaonrails/my-skills

    Adversarial fact-checking of the user's articles and essays (typically blog posts from akitaonrails-hugo, any markdown/text file), verifying every claim against online primary sources via cheap…

    220 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Blog Cost Charts

    akitaonrails/my-skills

    Generate dark-themed cost-vs-score bubble scatter charts and score/(costtime) value-ranking bar charts for a blog post comparing LLM benchmark results (or any dataset with a score/cost/time shape)…

    220 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Codemap

    akitaonrails/my-skills

    Generate comprehensive hierarchical codemaps for UNFAMILIAR repositories.

    220 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Clonedeps

    akitaonrails/my-skills

    Clone important project dependency source code into an ignored local workspace so OpenCode can inspect library internals.

    220 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • GitHub Resolution

    akitaonrails/my-skills

    Execute the approved outcomes of a pr-audit and/or iss-audit — fix or adjust everything the audit found necessary before merging, verify no regressions, cover every new behavior with unit tests…

    220 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Post Refactor

    akitaonrails/my-skills

    Post-refactor clean-code check after recent refactors or a few merged PRs.

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes

Questions about PR Post Audit

What does PR Post Audit do?

Audit the combined default-branch state after one or more PR merges or before deployment/release. PR Post Audit is an agent skill from akitaonrails/my-skills. Audit the combined default-branch state after one or more PR merges or before deployment/release.

When should I use PR Post Audit?

PR Post Audit fits situations like: verify exact merge provenance; cross-PR interactions; prompt-injected contributions; security and supply-chain composition.

How do I install PR Post Audit in Claude Code?

Run `npx skills add akitaonrails/my-skills --skill pr-post-audit -a claude-code`. Or copy the skill folder (pr-post-audit in akitaonrails/my-skills) into .claude/skills/pr-post-audit in your project. Claude Code loads it when a task matches its description.

How do I install PR Post Audit in Codex?

Run `npx skills add akitaonrails/my-skills --skill pr-post-audit -a codex`. Or copy the skill folder (pr-post-audit in akitaonrails/my-skills) into .agents/skills/pr-post-audit in your project. Codex loads it when a task matches its description.

Can I use PR Post Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akitaonrails/my-skills --skill pr-post-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-post-audit, .gemini/skills/pr-post-audit, .github/skills/pr-post-audit and .opencode/skills/pr-post-audit in your project.

What does PR Post Audit need to run?

Going by SKILL.md and its folder, PR Post Audit needs the command-line tools its instructions call (git). Our summary lists: Docker.

Does PR Post Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Post Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Post Audit use?

No licence was found for PR Post Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does PR Post Audit use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Post Audit?

Skills that share tags, products or a category with PR Post Audit: Herdr Pre-Release Audit (herdrdev/herdr, 43k stars), Megaphone Release (Kuberwastaken/megaphone, 170 stars), Create Release Checklist (software-mansion/smelter, 734 stars) and Releasing (OdradekAI/bundles-forge, 229 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Post Audit?

akitaonrails (a GitHub user) maintains it in akitaonrails/my-skills, which has 220 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 11, 2026.

Source: akitaonrails/my-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.