Official agent skill

PR Review

by aws in aws/aws-cdk-cli

AWS CDK CLI general PR reviewer. An agent skill from aws/aws-cdk-cli.

OfficialApache-2.0Auto-check passedDevelopment

Install PR Review

skills CLI
$ npx skills add aws/aws-cdk-cli --skill pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/aws-cdk-cli pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/aws-cdk-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pr-review .claude/skills/pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review
GitHub stars
107
Token cost
~2k tokens
SKILL.md length
931 words
Files
2 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

AWS CDK CLI general PR reviewer. An agent skill from aws/aws-cdk-cli.

  • Works in 3 steps: Orient. Name each changed surface and… → Check the diff in both directions. What… → Rate by harm and stop. Rate each finding…
  • Reviewing any pull request to aws/aws-cdk-cli — the CLI (packages/aws-cdk)
  • SKILL.md covers The review process, Severity — rate by the harm it…, What NOT to flag and Output, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

PR Review is an agent skill from aws/aws-cdk-cli, published by the product's own GitHub organization. AWS CDK CLI general PR reviewer. Use when reviewing any pull request to aws/aws-cdk-cli — the CLI (packages/aws-cdk), toolkit-lib, cloud-assembly-schema, cdk-assets, cloudformation-diff, integ-runner, or the projen/monorepo config. Precision-first: flags only concrete defects the PR introduces, across compatibility, architecture, error handling, testing, correctness, and PR scope.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/review-rules.md`).

It sits in Development, covering Pull requests, Infrastructure as code and Monorepo tooling. It works with Amazon Web Services and AWS CloudFormation. The licence is Apache-2.0.

When your agent uses it

  • Reviewing any pull request to aws/aws-cdk-cli — the CLI (packages/aws-cdk)
  • Cloud-assembly-schema
  • Cloudformation-diff
  • The projen/monorepo config

Example prompts

  • “/pr-review”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Orient. Name each changed surface and its kind: public API of toolkit-lib or cloud-assembly-schema (contract), CLI command/flag wiring…
  2. Check the diff in both directions. What is present and violating, and what is owed but missing: consequential new behavior owes a test, a…
  3. Rate by harm and stop. Rate each finding by the harm when it triggers, per the severity scale below. Consolidate co-located defects into…

What it can do on your machine

Read from SKILL.md and the folder at commit 13877dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review loads about 2k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 931 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/aws-cdk-cli at commit 13877dc, republished under its Apache-2.0 licence (© aws). 931 words, ~1,964 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
pr-review
description
AWS CDK CLI general PR reviewer. Use when reviewing any pull request to aws/aws-cdk-cli — the CLI (packages/aws-cdk), toolkit-lib, cloud-assembly-schema, cdk-assets, cloudformation-diff, integ-runner, or the projen/monorepo config. Precision-first: flags only concrete defects the PR introduces, across compatibility, architecture, error handling, testing, correctness, and PR scope.

AWS CDK CLI PR Review

You review pull requests to aws/aws-cdk-cli as a single general reviewer. The driving question: does this change keep the toolkit's contracts — public APIs, observable CLI behavior, coded IoHost messages, the cloud-assembly schema — intact while doing what it claims? This repo ships a deployment tool installed by the entire CDK user base; toolkit-lib and cloud-assembly-schema have programmatic consumers far beyond the CLI itself.

Precision is the primary constraint. Emit a finding only when this patch introduces a concrete, actionable defect whose harm you can name. A review with zero findings is a valid, good review of a clean PR. Never convert a preference into a finding: the purpose of this skill is better judgment, not a longer checklist.

Scope gate — review ONLY what this PR introduces or changes. A pre-existing problem the diff merely touches, moves, or passes through is not a finding.

You own general engineering review. The rule families in the lookup define your scope; the "What NOT to flag" list below defines its edges. Functional repo requirements remain yours even when they involve credentials — integration-test secret registration and redaction (AGENTS.md § Redacting Secrets) is a correctness concern this skill owns.

The review process

  1. Orient. Name each changed surface and its kind: public API of toolkit-lib or cloud-assembly-schema (contract), CLI command/flag wiring (frontend), toolkit-lib internals (logic), generated file (regenerate-only), test, docs, projen config. Read references/review-rules.md — its rows are your checklist. The repo's AGENTS.md is the authority most rules cite; read the section a rule names before flagging on it.
  2. Check the diff in both directions. What is present and violating, and what is owed but missing: consequential new behavior owes a test, a new option owes an @default, a PR-description claim owes the code that makes it true (claim "now raises DeploymentError" → find the throw site).
  3. Rate by harm and stop. Rate each finding by the harm when it triggers, per the severity scale below. Consolidate co-located defects into one finding. Stop once you can name the mechanism and cite its rule.

Verify before you cite. When a finding turns on whether a behavior, default, helper, or convention is REAL, read the authoritative doc or the actual source first — never post from memory. An unverified "X isn't supported" or "the default is Y" is a false-positive risk.

Severity — rate by the harm it does when it triggers

  • BLOCKING — demonstrated damage: a public contract breaks under a consumer, a customer's deployment fails or silently does the wrong thing, an error is swallowed while state is corrupt, a secret can reach a public log. Must be fixed before merge.
  • RECOMMENDED — decay: nothing breaks today, but the change leaves a latent trap or maintainability cost. Should be fixed; does not block.
  • OPTIONAL — negligible: pure polish.

Calibrate honestly: confidence is not severity (rate the harm when the path is reached, not how sure you are it is reached); no harm, no finding; test preferences, type casts in tests or mocks, naming, and maintainability concerns are never BLOCKING by themselves. When a finding rests on the repo's own guides, let the rule's stated harm set the tier and cite it by file + section.

Show full SKILL.md (405 more words)Show less

What NOT to flag

  • Pre-existing / not introduced by this PR.
  • Best-effort subsystems working as designed — notices, telemetry, version checks, caching, and cleanup intentionally catch-and-continue; that is correct design, not a swallowed error. Flag only a catch that lets the requested operation continue on corrupt state or report success falsely.
  • CI-owned checks — title format, PR size, coverage thresholds, automated license/attribution checks, and the bootstrap template's required version bump/security-review label. Deterministic gates enforce these; repeating them is noise.
  • Test scaffolding — casts in tests/mocks, expect.anything() where concrete values are asserted elsewhere, multi-assertion tests, snapshot assertions. These are not defects.
  • Unstable-command design latitude — commands behind the unstable gate may iterate on their surface; hold them to correctness, not frozen-contract strictness.
  • Projen-regenerated diffs accompanying their source change (.projenrc.ts / cli-config.ts) — expected, not a finding.
  • Cosmetics and lint-enforced style — typos, wording, formatting, import order; prose that merely "feels" AI-generated. Only objective artifacts (dead code, debug leftovers) are findings, per the rules.

Output

Produce structured findings, not hand-authored markdown:

  • file — repo-relative path. lineRange: { startLine, endLine } — single-line findings set both.
  • category — one of: compatibility, architecture, errors-and-ux, testing, code-quality, verification, process.
  • severity — BLOCKING / RECOMMENDED / OPTIONAL. The only vocabulary.
  • ruleId — the stable [CLI-*] id that fired, verbatim from the rules lookup.
  • message — the complete standalone comment: observation → impact → concrete fix, citing the guideline by file + section where one backs the finding.
  • reference — the authoritative source cited, or null. evidence — the supporting detail. suggestedFix — ready-to-commit code where the fix is small, or null.

The review as a whole carries a summary with its text. Every finding meets the evidence bar: the changed code, the concrete triggering scenario, the resulting harm, the repo contract or verified source behavior, and a practical correction. Cite formally when asserting external facts, service behavior, defaults, or repo precedent; a self-evident defect needs no citation essay.

Budget: at most 7 posted findings — every BLOCKING first, then the highest-harm RECOMMENDED, OPTIONAL only if room remains. This is a cap, not a quota. Tone: "we" and "consider" over "you should"; questions for uncertain findings ("Intentional?"), but require an answer before approval.

Sources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/pr-review of aws/aws-cdk-cli.

  • SKILL.md
  • references/review-rules.md

Open the folder on GitHubat commit 13877dc

Compare with similar skills

PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review this skillaws/aws-cdk-cli107—~2kAutomated safety check: PassApache-2.0
Review PRhashicorp/terraform-provider-aws11k—~1.1kAutomated safety check: PassMPL-2.0
Create PRgo-to-k/cdkd143—~873Automated safety check: PassApache-2.0
Review PRgo-to-k/cdkd143—~793Automated safety check: PassApache-2.0
AWS Architecture Diagramawslabs/agent-plugins915—~3.8kAutomated safety check: NotesApache-2.0
Document Serviceawslabs/agent-plugins915—~4.4kAutomated safety check: PassApache-2.0

Similar skills

  • Review PR

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider pull request for correctness and conventions.

    11k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Create PR

    go-to-k/cdkd

    Run /verify-pr checks, then create a GitHub PR if all pass. An agent skill from go-to-k/cdkd.

    143 GitHub stars~873 tokensUpdated today
    DevelopmentAuto-check passed
  • Review PR

    go-to-k/cdkd

    Recommend the right reviewer set for a PR from what it touches.

    143 GitHub stars~793 tokensUpdated today
    DevelopmentAuto-check passed
  • AWS Architecture Diagram

    awslabs/agent-plugins

    Official

    Generate validated AWS architecture diagrams as draw.io XML using official AWS4 icon libraries.

    915 GitHub stars~3.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Document Service

    awslabs/agent-plugins

    Official

    This skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs…

    915 GitHub stars~4.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • AWS Sam Bootstrap

    giuseppe-trisciuoglio/developer-kit

    Provides AWS SAM bootstrap patterns: generates template.yaml and samconfig.toml for new projects via sam init, creates SAM templates for existing Lambda/CloudFormation code migration, validates…

    355 GitHub stars~954 tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes

Categories

Questions about PR Review

What does PR Review do?

AWS CDK CLI general PR reviewer. An agent skill from aws/aws-cdk-cli. PR Review is an agent skill from aws/aws-cdk-cli, published by the product's own GitHub organization. AWS CDK CLI general PR reviewer.

When should I use PR Review?

PR Review fits situations like: reviewing any pull request to aws/aws-cdk-cli — the CLI (packages/aws-cdk); cloud-assembly-schema; cloudformation-diff; the projen/monorepo config.

How do I install PR Review in Claude Code?

Run `npx skills add aws/aws-cdk-cli --skill pr-review -a claude-code`. Or copy the skill folder (skills/pr-review in aws/aws-cdk-cli) into .claude/skills/pr-review in your project. Claude Code loads it when a task matches its description.

How do I install PR Review in Codex?

Run `npx skills add aws/aws-cdk-cli --skill pr-review -a codex`. Or copy the skill folder (skills/pr-review in aws/aws-cdk-cli) into .agents/skills/pr-review in your project. Codex loads it when a task matches its description.

Can I use PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/aws-cdk-cli --skill pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review, .gemini/skills/pr-review, .github/skills/pr-review and .opencode/skills/pr-review in your project.

What does PR Review need to run?

SKILL.md names no scripts, command-line tools or credentials: PR Review is instructions for the agent only.

Does PR Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Review use?

PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to PR Review?

Skills that share tags, products or a category with PR Review: Review PR (hashicorp/terraform-provider-aws, 11k stars), Create PR (go-to-k/cdkd, 143 stars), Review PR (go-to-k/cdkd, 143 stars) and AWS Architecture Diagram (awslabs/agent-plugins, 915 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review?

aws (a GitHub organization, an official publisher) maintains it in aws/aws-cdk-cli, which has 107 GitHub stars. The repository was last updated on October 8, 2026.

Source: aws/aws-cdk-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.