Agent skill

PR Review Expert

by borghei in borghei/Claude-Skills

Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas.

MITAuto-check passedDevelopment

Install PR Review Expert

skills CLI
$ npx skills add borghei/Claude-Skills --skill pr-review-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills pr-review-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/pr-review-expert .claude/skills/pr-review-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review-expert
GitHub stars
886
Token cost
~1.5k tokens
SKILL.md length
618 words
Files
7 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas.

  • Reviewing PRs that touch shared libraries
  • SKILL.md covers Core Capabilities, When to Use, Tools and References, plus 2 more sections
  • Runs Python scripts from its folder; calls python, git and gh
  • Database schemas

What it does

PR Review Expert is an agent skill from borghei/Claude-Skills. Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas. Use when reviewing PRs that touch shared libraries, APIs, database schemas, auth, or security-sensitive code.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/best-practices-and-troubleshooting.md`, `references/review-workflow-commands.md` and `references/writeup-format-and-checklist.md`).

It sits in Development, covering Pull requests, Test coverage and Database schema design. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Reviewing PRs that touch shared libraries
  • Database schemas
  • Security-sensitive code

Example prompts

  • “/pr-review-expert”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review Expert loads about 1.5k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 618 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 618 words, ~1,520 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review-expert/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
pr-review-expert
description
Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas. Use when reviewing PRs that touch shared libraries, APIs, database schemas, auth, or security-sensitive code.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
code-review
metadata.tier
POWERFUL
metadata.updated
2026-06-17
metadata.frameworks
github, gitlab, review-checklist

PR Review Expert

Structured, systematic code review for GitHub PRs and GitLab MRs. Goes beyond style nits to perform blast-radius analysis, security vulnerability scanning, breaking-change detection, test-coverage delta calculation, and performance impact assessment. Produces reviewer-ready reports with prioritized findings categorized as must-fix, should-fix, and suggestions.

Keywords: PR review, code review, pull request, merge request, blast radius, security scan, breaking changes, test coverage, review checklist, code quality

Core Capabilities

  • Blast radius analysis — trace which files, services, and downstream consumers a diff could break; quantify severity CRITICAL/HIGH/MEDIUM/LOW.
  • Security scanning — detect SQL injection, XSS vectors, hardcoded secrets, auth bypass, insecure crypto, path traversal, and prototype pollution in the diff.
  • Breaking-change detection — flag API removals/renames, response-schema and required-field changes, DB column removals, env-var changes, and TS interface edits.
  • Test coverage analysis — new-code vs new-test ratio, missing tests for new public functions, deleted tests without deleted code, coverage delta.
  • Performance assessment — N+1 query patterns, bundle-size regressions, unbounded queries, missing indexes.
  • Reviewer-ready output — prioritized must-fix / should-fix / suggestion report, a 35-item checklist, and consistent comment labels.

When to Use

  • Before merging any PR that touches shared libraries, APIs, or database schemas.
  • When a PR is large (>200 lines changed) and needs structured review.
  • For PRs in security-sensitive code paths (auth, payments, PII handling).
  • After an incident, to proactively review similar code changes.
  • For onboarding new contributors whose PRs need thorough feedback.

Tools

ToolPurposeCommand
blast_radius_calculator.pyCalculate PR blast radius from import chains / dependency trees of changed filesgit diff --name-only main...HEAD | python scripts/blast_radius_calculator.py --root src
diff_analyzer.pyAnalyze a diff for risk indicators (large files, sensitive paths, config/breaking/security patterns)gh pr diff $PR | python scripts/diff_analyzer.py --json
review_checklist_generator.pyGenerate a tailored review checklist from changed file types/patternsgit diff --name-only main...HEAD | python scripts/review_checklist_generator.py

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/review-workflow-commands.md — the 6-step review workflow with the exact gh/grep command catalog for context gathering, blast radius, security scan, breaking-change detection, coverage delta, and performance impact (plus the blast-radius severity table and coverage rules). Read when actually performing a review.
  • references/writeup-format-and-checklist.md — the review report template with worked examples, the complete 35-item review checklist, and the comment-label taxonomy. Read when writing up findings.
  • references/best-practices-and-troubleshooting.md — common reviewer pitfalls, best-practice habits, the troubleshooting table, and the success-criteria bar. Read before and after a review for quality control.
Show full SKILL.md (233 more words)Show less

Scope & Limitations

This skill covers:

  • Structured review of GitHub PRs and GitLab MRs using a 35+ item checklist
  • Blast radius analysis for monorepo and multi-service architectures
  • Static security scanning of diffs for common vulnerability patterns (SQLi, XSS, secrets, auth bypass)
  • Breaking change detection for APIs, database schemas, TypeScript interfaces, and environment variables

This skill does NOT cover:

  • Automated code fixes or refactoring — use engineering/saas-scaffolder or engineering/migration-architect for code generation
  • Runtime security analysis, SAST/DAST tool orchestration, or CVE database lookups — use engineering/dependency-auditor for dependency-level vulnerability scanning
  • CI/CD pipeline configuration or build failure triage — use engineering/ci-cd-pipeline-builder for pipeline design
  • Performance benchmarking or load testing — use engineering/performance-profiler for profiling and optimization guidance

Integration Points

SkillIntegrationData Flow
engineering/dependency-auditorRun dependency audit before reviewing PRs that add or upgrade packagesAudit report feeds into the Security section of the review report
engineering/ci-cd-pipeline-builderEmbed review checklist gates into CI pipelines as automated PR checksChecklist items become pass/fail signals in the pipeline
engineering/performance-profilerEscalate N+1 and unbounded query findings for detailed profilingFlagged code paths from review become profiling targets
engineering/migration-architectValidate database migration safety for PRs that include schema changesMigration risk assessment supplements the Breaking Changes section
engineering/release-managerFeed breaking change detection results into release notes and changelogsDetected breaking changes auto-populate release documentation
engineering/api-design-reviewerCross-reference API endpoint changes with API design standardsAPI review findings merge into the Blast Radius and Breaking Changes sections

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in engineering/pr-review-expert of borghei/Claude-Skills.

  • SKILL.md
  • references/best-practices-and-troubleshooting.md
  • references/review-workflow-commands.md
  • references/writeup-format-and-checklist.md
  • scripts/blast_radius_calculator.py
  • scripts/diff_analyzer.py
  • scripts/review_checklist_generator.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

PR Review Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review Expert this skillborghei/Claude-Skills886—~1.5kAutomated safety check: PassMIT
Review Envoy Gateway PRenvoyproxy/gateway3.1k—~850Automated safety check: PassApache-2.0
Core Components Code Reviewcore-ds/core-components137—~5.4kAutomated safety check: PassMIT
Open PRElite588/AUTOGPT103—~1.3kAutomated safety check: PassCustom licence
Docs Syncmicrosoft/apm4k—~3kAutomated safety check: PassMIT
Review PRjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: NotesMIT

Similar skills

  • Review Envoy Gateway PR

    envoyproxy/gateway

    Review an Envoy Gateway pull request for essential API, implementation, status, and test coverage requirements.

    3.1k GitHub stars~850 tokensUpdated today
    DevelopmentAuto-check passed
  • Core Components Code Review

    core-ds/core-components

    Review a Pull Request or diff in the @alfalab/core-components UI library — correctness bugs, public API/breaking changes, accessibility, keyboard/focus/pointer interaction, component states…

    137 GitHub stars~5.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Open PR

    Elite588/AUTOGPT

    Open a pull request with proper PR template, test coverage, and review workflow.

    103 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Docs Sync

    microsoft/apm

    Official

    A skill your agent uses whenever a pull request is opened, reopened, or synchronized in microsoft/apm to assess whether and how the documentation corpus must change to stay truthful with the…

    4k GitHub stars~3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Review PR

    jeremylongshore/tons-of-skills-marketplace

    Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes.

    2.8k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check: notes
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about PR Review Expert

What does PR Review Expert do?

Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas. PR Review Expert is an agent skill from borghei/Claude-Skills. Systematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas.

When should I use PR Review Expert?

PR Review Expert fits situations like: reviewing PRs that touch shared libraries; database schemas; security-sensitive code.

How do I install PR Review Expert in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill pr-review-expert -a claude-code`. Or copy the skill folder (engineering/pr-review-expert in borghei/Claude-Skills) into .claude/skills/pr-review-expert in your project. Claude Code loads it when a task matches its description.

How do I install PR Review Expert in Codex?

Run `npx skills add borghei/Claude-Skills --skill pr-review-expert -a codex`. Or copy the skill folder (engineering/pr-review-expert in borghei/Claude-Skills) into .agents/skills/pr-review-expert in your project. Codex loads it when a task matches its description.

Can I use PR Review Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill pr-review-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review-expert, .gemini/skills/pr-review-expert, .github/skills/pr-review-expert and .opencode/skills/pr-review-expert in your project.

What does PR Review Expert need to run?

Going by SKILL.md and its folder, PR Review Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python, git and gh). Our summary lists: Python 3.

Does PR Review Expert access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Review Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does PR Review Expert use?

PR Review Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review Expert use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to PR Review Expert?

Skills that share tags, products or a category with PR Review Expert: Review Envoy Gateway PR (envoyproxy/gateway, 3.1k stars), Core Components Code Review (core-ds/core-components, 137 stars), Open PR (Elite588/AUTOGPT, 103 stars) and Docs Sync (microsoft/apm, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review Expert?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.