Agent skill

GitHub Code Review

by AlexAI-MCP in AlexAI-MCP/hermes-CCC

Review GitHub pull requests with a findings-first engineering mindset.

MITAuto-check passedDevelopment

Install GitHub Code Review

skills CLI
$ npx skills add AlexAI-MCP/hermes-CCC --skill github-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AlexAI-MCP/hermes-CCC github-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github-code-review .claude/skills/github-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-code-review
GitHub stars
135
Token cost
~1.3k tokens
SKILL.md length
623 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Review GitHub pull requests with a findings-first engineering mindset.

  • Works in 7 steps: Read PR metadata. → Read changed-file list. → Identify risky files first. → …
  • Auditing diffs for bugs
  • SKILL.md covers Purpose, Activation Signals, Review Order and High-Risk Change Types, plus 15 more sections
  • Calls gh and git

What it does

GitHub Code Review is an agent skill from AlexAI-MCP/hermes-CCC. Review GitHub pull requests with a findings-first engineering mindset. Use when auditing diffs for bugs, regressions, security issues, missing tests, or risky design choices, and when producing actionable review comments instead of generic summaries.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests and Code review. It works with GitHub. The repository describes itself as: Hermes Agent ported to Claude Code Channel — 46 native skills, no OAuth, no external process. The licence is MIT.

When your agent uses it

  • Auditing diffs for bugs
  • Security issues
  • Risky design choices
  • When producing actionable review comments instead of generic summaries

Example prompts

  • “/github-code-review”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read PR metadata.
  2. Read changed-file list.
  3. Identify risky files first.
  4. Read the diff with behavioral intent in mind.
  5. Check tests and verification claims.
  6. Produce findings ordered by severity.
  7. Add a brief summary only after the findings.

What it can do on your machine

Read from SKILL.md and the folder at commit 8107e89. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Code Review loads about 1.3k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 623 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from AlexAI-MCP/hermes-CCC at commit 8107e89, republished under its MIT licence (© AlexAI-MCP). 623 words, ~1,332 tokens.

Download SKILL.mdSave it as .claude/skills/github-code-review/SKILL.md (or your agent's skills folder).
name
github-code-review
description
Review GitHub pull requests with a findings-first engineering mindset. Use when auditing diffs for bugs, regressions, security issues, missing tests, or risky design choices, and when producing actionable review comments instead of generic summaries.
version
0.1.0
author
OpenAI Codex
license
MIT
metadata.category
github
metadata.ported_from
NousResearch Hermes Agent
metadata.tags
github, code-review, pull-requests, risk
metadata.tools
github, git, diff
metadata.maturity
beta

GitHub Code Review

Purpose

  • Find real defects and risks before merge.
  • Prioritize correctness, security, and regressions over style nits.
  • Produce review comments that are concrete and defensible.
  • Keep summaries brief and findings primary.
  • Tie each concern to evidence in the diff.

Activation Signals

  • Use this skill when the user asks for a review.
  • Use this skill when a PR must be audited before merge.
  • Use this skill when code changes touch critical systems.
  • Use this skill when a team needs structured findings with severity.
  • Use this skill when review comments should map cleanly onto changed files.

Review Order

  1. Read PR metadata.
  2. Read changed-file list.
  3. Identify risky files first.
  4. Read the diff with behavioral intent in mind.
  5. Check tests and verification claims.
  6. Produce findings ordered by severity.
  7. Add a brief summary only after the findings.

High-Risk Change Types

  • auth or session logic
  • data migrations
  • concurrency changes
  • caching invalidation
  • payment or billing logic
  • permission checks
  • serialization or schema changes
  • error handling rewrites

Evidence Sources

  • file diffs
  • PR description
  • CI status
  • changed filenames
  • related issue text
  • existing review comments
  • nearby tests

Finding Categories

  • correctness bug
  • regression risk
  • security issue
  • missing validation
  • missing test coverage
  • maintainability risk
  • performance regression

Severity Guidelines

  • high when merge could cause data loss, security exposure, or broken primary flows
  • medium when likely behavior is wrong under realistic conditions
  • low when risk is limited but still worth fixing before merge

Comment Structure

  • Start with the risk, not praise.
  • Name the exact behavior at risk.
  • Point to the file and line.
  • Explain why the current diff is unsafe or incomplete.
  • Suggest the minimal corrective direction when possible.

Example Finding

markdown
High: The new session guard treats a missing cache entry as "guest" even during token refresh, which can incorrectly revoke authenticated users during normal refresh windows. This path appears in `auth/middleware.ts` and does not have matching regression coverage.

Review Questions

  • What behavior changed?
  • What assumptions does the change introduce?
  • Where could the new logic be called unexpectedly?
  • What happens on failure paths, not just the happy path?
  • What tests prove the changed behavior?
  • What edge case is still uncovered?

Test Review Rules

  • Do not trust "tests added" without reading what they assert.
  • Check whether tests cover the risky branch or only the happy path.
  • Check whether the test would have failed before the change.
  • Note when the code change outscopes the tests.
Show full SKILL.md (264 more words)Show less

Anti-Patterns

  • summarizing the PR without surfacing defects
  • focusing on naming while skipping broken behavior
  • making speculative comments with no evidence
  • reviewing only one changed file in a large risky PR
  • assuming CI passing means behavior is correct

Connector And CLI Paths

  • Use GitHub connector metadata and diff tools when available.
  • Use gh pr view, gh pr diff, or local git diff when working from CLI.
  • Prefer file-by-file patch review for large PRs.
  • Read inline comment threads before duplicating the same concern.

Output Contract

Return:

  • numbered findings first
  • each finding with severity and concise evidence
  • open questions or assumptions second
  • short overall summary last

Example Review Skeleton

markdown
1. High: ...
2. Medium: ...

Open questions:
- ...

Summary:
The PR is close, but the auth refresh path and missing regression coverage should be addressed before merge.

Decision Rules

  • If there are no findings, say so explicitly.
  • If a concern is speculative, present it as an open question rather than a finding.
  • If the diff is too large to fully trust, call out residual risk.
  • If review scope is partial, say what you did and did not inspect.

Common Failure Modes

  • reviewing intent instead of actual code
  • missing transitive risk in adjacent files
  • underweighting missing tests
  • overproducing nitpicks and hiding serious issues
  • skipping residual risk when certainty is limited

Recovery Moves

  • Re-read the highest-risk file after forming a first opinion.
  • Compare changed tests against changed production branches.
  • Re-check assumptions against the actual code path.
  • Collapse low-value nitpicks so important findings stand out.

Checklist

  1. Read PR metadata.
  2. Scan risky files first.
  3. Review diffs for behavior changes.
  4. Inspect tests and CI claims.
  5. Write findings ordered by severity.
  6. Separate findings from open questions.
  7. Keep summary short.
  8. State residual risk honestly.

© AlexAI-MCP, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/github-code-review of AlexAI-MCP/hermes-CCC.

Open the folder on GitHubat commit 8107e89

Compare with similar skills

GitHub Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Code Review this skillAlexAI-MCP/hermes-CCC135—~1.3kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Fastlane Pull Request Reviewfastlane/fastlane42k—~550Automated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Reviews a fastlane pull request against its linked issue and the project guides, separating blocking from non-blocking findings and handling vulnerabilities privately.

    42k GitHub stars~550 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Reviews open pull requests in the daisyUI repository using read-only GitHub data and isolated base-versus-PR checks, then writes a merge verdict report.

    43k GitHub stars~766 tokensUpdated 8 days ago
    DevelopmentAuto-check passed

More from AlexAI-MCP/hermes-CCC

All 44 skills in this repo
  • GitHub PR Workflow

    AlexAI-MCP/hermes-CCC

    Run a disciplined GitHub pull request workflow from branch creation through merge.

    135 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Hermes Memory

    AlexAI-MCP/hermes-CCC

    Manage durable project memory for Claude Code. An agent skill from AlexAI-MCP/hermes-CCC.

    135 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Hermes Route

    AlexAI-MCP/hermes-CCC

    Route Claude Code work by complexity, risk, and tool needs. An agent skill from AlexAI-MCP/hermes-CCC.

    135 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Hermes Skill

    AlexAI-MCP/hermes-CCC

    Create, improve, inventory, and audit Claude Code skills. An agent skill from AlexAI-MCP/hermes-CCC.

    135 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Hermes Traj

    AlexAI-MCP/hermes-CCC

    Capture Claude Code interaction trajectories in training-friendly formats.

    135 GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • Subagent Driven Development

    AlexAI-MCP/hermes-CCC

    Decompose Claude Code work into parallel subagent-friendly streams when the environment permits delegation.

    135 GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about GitHub Code Review

What does GitHub Code Review do?

Review GitHub pull requests with a findings-first engineering mindset. GitHub Code Review is an agent skill from AlexAI-MCP/hermes-CCC. Review GitHub pull requests with a findings-first engineering mindset.

When should I use GitHub Code Review?

GitHub Code Review fits situations like: auditing diffs for bugs; security issues; risky design choices; when producing actionable review comments instead of generic summaries.

How do I install GitHub Code Review in Claude Code?

Run `npx skills add AlexAI-MCP/hermes-CCC --skill github-code-review -a claude-code`. Or copy the skill folder (skills/github-code-review in AlexAI-MCP/hermes-CCC) into .claude/skills/github-code-review in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Code Review in Codex?

Run `npx skills add AlexAI-MCP/hermes-CCC --skill github-code-review -a codex`. Or copy the skill folder (skills/github-code-review in AlexAI-MCP/hermes-CCC) into .agents/skills/github-code-review in your project. Codex loads it when a task matches its description.

Can I use GitHub Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexAI-MCP/hermes-CCC --skill github-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-code-review, .gemini/skills/github-code-review, .github/skills/github-code-review and .opencode/skills/github-code-review in your project.

What does GitHub Code Review need to run?

Going by SKILL.md and its folder, GitHub Code Review needs the command-line tools its instructions call (gh and git).

Does GitHub Code Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Code Review use?

GitHub Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Code Review use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Code Review?

Skills that share tags, products or a category with GitHub Code Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), GitHub Review Iteration (prisma/orm, 48k stars), PR Finalize Review (microsoft/garnet, 12k stars) and PR Review State Fetch (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Code Review?

AlexAI-MCP (a GitHub user) maintains it in AlexAI-MCP/hermes-CCC, which has 135 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on April 8, 2026.

Source: AlexAI-MCP/hermes-CCC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.