Agent skill

PR Triage

by ChanningLua in ChanningLua/prax-agent

给单个 PR 做代码感知 triage —— 分类 / 跑测试 / 扫依赖 / 产出审查笔记. An agent skill from ChanningLua/prax-agent.

MITAuto-check: notesDevelopment

Install PR Triage

skills CLI
$ npx skills add ChanningLua/prax-agent --skill pr-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ChanningLua/prax-agent pr-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ChanningLua/prax-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/prax/skills/pr-triage .claude/skills/pr-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-triage
GitHub stars
273
Token cost
~1.4k tokens
SKILL.md length
305 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

给单个 PR 做代码感知 triage —— 分类 / 跑测试 / 扫依赖 / 产出审查笔记. An agent skill from ChanningLua/prax-agent.

  • Works in 8 steps: :拿 PR metadata → :拿 diff 本体 → :分类(硬枚举) → …
  • Development work in your project
  • SKILL.md covers 何时触发, 输入, 预检(不满足就停) and 输出, plus 5 more sections
  • Calls git, jq and gh

What it does

PR Triage is an agent skill from ChanningLua/prax-agent. 给单个 PR 做代码感知 triage —— 分类 / 跑测试 / 扫依赖 / 产出审查笔记

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Git and GitHub. The repository describes itself as: Self-improving agent runtime that learns from experience — test-verify-fix loops, correction detection, cross-project memory, multi-model orchestration. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/pr-triage”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, VerifyCommand, Notify

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. :拿 PR metadata
  2. :拿 diff 本体
  3. :分类(硬枚举)
  4. :风险评分
  5. :真跑测试(Prax 核心)
  6. :依赖扫描
  7. :写审查笔记
  8. :通知

What it can do on your machine

Read from SKILL.md and the folder at commit 19d016b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • VerifyCommand
    • Notify

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • jq
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Triage loads about 1.4k tokens when it runs. Until then it costs about 14 tokens; SKILL.md has 305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~14
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, VerifyCommand, Notify

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ChanningLua/prax-agent at commit 19d016b, republished under its MIT licence (© ChanningLua). 305 words, ~1,396 tokens.

Download SKILL.mdSave it as .claude/skills/pr-triage/SKILL.md (or your agent's skills folder).
name
pr-triage
description
给单个 PR 做代码感知 triage —— 分类 / 跑测试 / 扫依赖 / 产出审查笔记
allowed-tools
Bash, Read, Write, Grep, Glob, VerifyCommand, Notify
triggers
pr triage, 审 pr, 审查 pr, pr review, 分类 pr, triage pr, pull request review
tags
pull-request, code-review, ci, devex, verify-first
priority
8

PR Triage Bot

Prax 的杀手锏在这:不只"让 LLM 看 diff 给点评",而是真的 checkout 出来、真的跑测试、真的看新增依赖有没有 CVE。结果比纯 LLM 评论可信一个量级。

何时触发

  • 用户粘 PR URL 或说"triage #42"
  • cron 每天早上 8 点扫 open PRs
  • GitHub webhook 触发(需要额外 hook 配置,本 skill 不负责触发)

输入

  • 必需:PR URL 或 #NNN(本仓库的话)或 PR 分支名
  • 可选:仓库路径(默认当前 cwd)

预检(不满足就停)

bash
# 1. 在 git 仓库里
git rev-parse --show-toplevel

# 2. 有 gh CLI 吗?
command -v gh && gh auth status 2>/dev/null

没 gh 时走 降级路径(见 Step 2b)。没 git 仓库直接报错。

输出

一份 markdown 审查笔记:

.prax/pr-triage/pr-<NNN>-<YYYYMMDD-HHMMSS>.md

不自动 approve / merge / close / comment 到 GitHub。所有外部动作都必须用户明确再触发一次。

工作流程

Step 1:拿 PR metadata
bash
# 完整路径
gh pr view <url> --json number,title,body,files,author,baseRefName,headRefName,additions,deletions,commits

# 提炼
NUM=$(echo $JSON | jq -r '.number')
TITLE=$(echo $JSON | jq -r '.title')
BASE=$(echo $JSON | jq -r '.baseRefName')
HEAD=$(echo $JSON | jq -r '.headRefName')
STATS="+$(echo $JSON | jq -r '.additions'),-$(echo $JSON | jq -r '.deletions')"
FILES=$(echo $JSON | jq -r '.files | length')
Step 2:拿 diff 本体
bash
gh pr diff <url> > /tmp/pr-<NUM>.diff
wc -l /tmp/pr-<NUM>.diff
Step 2b:gh 不可用的降级

没 gh CLI 时:

bash
# 本仓库的 PR:如果本地 remotes 里有 pull/<num>/head refspec
git fetch origin pull/<NUM>/head:pr-<NUM> 2>/dev/null
git diff origin/<base>...pr-<NUM> > /tmp/pr-<NUM>.diff

如果连 fetch 也不行(外网受限)→ 退化成只读远端分支名模式,不跑测试,只产出分类 + 手动审查清单。

Step 3:分类(硬枚举)

用 PR title + 首个 commit message + files-changed 启发式:

分类证据
featuretitle 含 feat(...) / 新文件多 / +100 以上
bugtitle 含 fix(...) / 行数均衡增删
refactortitle 含 refactor / 纯结构调整
choretitle 含 chore / 仅 config/yaml
docs仅 *.md 变更
hotfix含 hotfix 或 urgent

一个 PR 可以多标签,取最强一个作为主分类。

Step 4:风险评分

硬规则,每触发一条加一分:

规则分数
patch > 500 行+2
patch > 1000 行+3(累加)
触达 >10 个文件+2
改 package.json/requirements.txt/Cargo.toml/go.mod 且有新增依赖+2
改 auth/security/permission/middleware 相关文件+2
改 CI / .github/workflows/+2
改数据库迁移文件+3
PR body 空+1
没测试伴随(仅 src 没 test)+2

0-2 分:低;3-5:中;6+:高。

Step 5:真跑测试(Prax 核心)
bash
git fetch origin pull/<NUM>/head:prax-triage-<NUM>
git checkout prax-triage-<NUM>

# 用 VerifyCommand 跑,限时 5 分钟
VerifyCommand(command="pytest -q", timeout=300)
# 或 npm test / cargo test / go test — 从 Step 2 的 files 推断

失败不代表 PR 坏——可能是仓库本身坏的。拿 base 做对照:

bash
git checkout <BASE>
VerifyCommand(command="pytest -q", timeout=300)
  • PR 失败 + base 通过 → PR 引入了问题(明确)
  • PR 失败 + base 也失败 → 仓库本身坏(标 "baseline broken")
  • PR 通过 + base 通过 → ✅
  • PR 通过 + base 失败 → PR 修好了问题(可能)

跑完必须 checkout 回原分支,避免污染用户工作区:

bash
git checkout -
git branch -D prax-triage-<NUM>
Step 6:依赖扫描
bash
# 对 diff 找新增 import / require
grep -E '^\+[[:space:]]*(import|from|require|use )' /tmp/pr-<NUM>.diff | head -30

# package.json / requirements.txt / Cargo.toml 新增条目
git diff origin/<base>...<head> -- package.json requirements.txt Cargo.toml go.mod

列出来不代表有漏洞——只列给 reviewer,让 reviewer 决定要不要查 CVE。

Step 7:写审查笔记
markdown
---
pr: 42
title: feat(notify): add NotifyTool
author: @foo
generated_at: 2026-04-22T10:05:00+08:00
stats: "+320, -15, 4 files"
---

# PR #42 Triage

## 分类
- 主:**feature**
- 副:docs

## 风险评分:3(中)

触发规则:
- patch = 305 行 (+1)
- 新增依赖:httpx (+2)

## 测试结果
- PR 分支 pytest -q:✅ 1929 passed
- 基线 base `main` pytest -q:✅ 1922 passed
- **结论**:PR 引入 7 个新通过的测试,无回归

## 新增依赖
- Python: `httpx` (已有 dep)
- 无 package.json 变更

## 审查要点
1. `tools/notify.py:38` Provider 基类 — 检查是否预留扩展点
2. `tools/notify.py:105` SMTP 密码从 env 读 — 确认无 YAML 硬编码
3. `tests/unit/test_notify.py` 23 个测试 — 覆盖所有 provider 分支

## 推荐动作
- [ ] 人工审 `tools/notify.py:__init__` 的接口稳定性
- [ ] 确认 `notify.yaml` schema 文档已更新

(Prax pr-triage 不自动 approve/merge/close — 所有 GitHub 动作由人触发)
Step 8:通知

若 .prax/notify.yaml 有 eng-leads channel:

Notify(
  channel = "eng-leads",
  title = "PR #<NUM> triage: <level>",
  body = <笔记的分类 + 风险评分 + 测试结果段>,
  level = "error" if tests_failed else ("warn" if risk >= 6 else "info"),
)

硬约束

  1. 不 approve / 不 merge / 不 close / 不 comment 到 GitHub——只本地写笔记
  2. 跑完测试必须 checkout 回原分支,-D 临时分支
  3. 外部 API 不触达(CVE 扫描、依赖版本查询都只列出,让人去查)
  4. 失败路径必须有降级——gh 不可用、网络不通、测试跑不起来,都要能产出部分笔记
  5. patch > 2000 行时(硬上限)直接标记 level=warn,笔记里写"PR 过大,建议拆分,本工具不对此类 PR 跑完整测试",跳过 Step 5

工具选择(很关键)

  • 审查笔记 .prax/pr-triage/pr-<N>-<ts>.md 每次都是新文件:用 Write(自动建目录)。
  • 跑 gh pr view / gh pr diff / git fetch / git checkout / VerifyCommand:都要 Bash,默认权限模式不够,需要 --permission-mode danger-full-access。
  • HashlineEdit / Edit 对不存在路径会 File not found——新笔记必须走 Write。

和其他 skill 的接力

  • docs-audit:PR 改 src/ 没改 docs/ 时,triage 笔记里引用 docs-audit 的输出
  • release-notes:triage 过的 PR 在发版时能直接落入 release-notes 的 commit 分类

典型调用

用户:triage #42

→ skill 跑 gh pr view + gh pr diff
→ 分类 = feature,risk = 3 (patch 320 行 + 新增 httpx 依赖)
→ git fetch pull/42/head → pytest -q → 1929 pass
→ git checkout main → pytest -q → 1922 pass
→ 结论:PR 无回归,引入 7 个新测试
→ 写 .prax/pr-triage/pr-42-20260422-100500.md
→ Notify eng-leads channel (info)
→ 回用户:分类 feature,风险中,测试通过,笔记在 .prax/pr-triage/pr-42-...md

© ChanningLua, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/prax/skills/pr-triage of ChanningLua/prax-agent.

Open the folder on GitHubat commit 19d016b

Compare with similar skills

PR Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Triage this skillChanningLua/prax-agent273—~1.4kAutomated safety check: NotesMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0
Draft Release Notesjamiepine/voicebox57k—~941Automated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Draft Release Notes

    jamiepine/voicebox

    Writes or refreshes the Unreleased section of CHANGELOG.md as a themed narrative built from the commits, PRs and diff since the last version tag.

    57k GitHub stars~941 tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.

    69k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from ChanningLua/prax-agent

All 12 skills in this repo
  • Prax Shift

    ChanningLua/prax-agent

    Hand coding work or explicitly authorized one-shot verification to Prax Shift, inspect a shift, or schedule supported coding work with Claude as the worker.

    273 GitHub stars~1.4k tokensUpdated 26 days ago
    Auto-check passed
  • Prax Shift

    ChanningLua/prax-agent

    Hand coding work or explicitly authorized one-shot verification to Prax Shift, inspect a shift, or schedule supported coding work with Codex as the worker.

    273 GitHub stars~1.6k tokensUpdated 26 days ago
    Auto-check passed
  • AI News Daily

    ChanningLua/prax-agent

    端到端 pipeline —— 抓 X/知乎/Bilibili AI 相关热门 → 整理成 wiki → 推送飞书日报. An agent skill from ChanningLua/prax-agent.

    273 GitHub stars~1.3k tokensUpdated 26 days ago
    Auto-check: notes
  • Browser Scrape

    ChanningLua/prax-agent

    用 AutoCLI 二进制驱动用户已登录的 Chrome 抓取 Twitter/X、知乎、Bilibili、Reddit 等 55+ 站点

    273 GitHub stars~587 tokensUpdated 26 days ago
    Auto-check: notes
  • Hotspot Article

    ChanningLua/prax-agent

    从近期大事件、真实需求和常青决策中选题,完成多源研究、业务落地、实测、事实核验和精选文章. An agent skill from ChanningLua/prax-agent.

    273 GitHub stars~2.7k tokensUpdated 26 days ago
    Auto-check: notes
  • Knowledge Compile

    ChanningLua/prax-agent

    把一堆 raw markdown(抓取/笔记/文章)压成 Obsidian 风格 wiki —— 有 TOC、有按主题聚合、有日简报

    273 GitHub stars~914 tokensUpdated 26 days ago
    Auto-check: notes

Works with

Categories

Questions about PR Triage

What does PR Triage do?

给单个 PR 做代码感知 triage —— 分类 / 跑测试 / 扫依赖 / 产出审查笔记. An agent skill from ChanningLua/prax-agent. PR Triage is an agent skill from ChanningLua/prax-agent.

When should I use PR Triage?

PR Triage fits situations like: development work in your project.

How do I install PR Triage in Claude Code?

Run `npx skills add ChanningLua/prax-agent --skill pr-triage -a claude-code`. Or copy the skill folder (src/prax/skills/pr-triage in ChanningLua/prax-agent) into .claude/skills/pr-triage in your project. Claude Code loads it when a task matches its description.

How do I install PR Triage in Codex?

Run `npx skills add ChanningLua/prax-agent --skill pr-triage -a codex`. Or copy the skill folder (src/prax/skills/pr-triage in ChanningLua/prax-agent) into .agents/skills/pr-triage in your project. Codex loads it when a task matches its description.

Can I use PR Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ChanningLua/prax-agent --skill pr-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-triage, .gemini/skills/pr-triage, .github/skills/pr-triage and .opencode/skills/pr-triage in your project.

What does PR Triage need to run?

Going by SKILL.md and its folder, PR Triage needs the command-line tools its instructions call (git, jq and gh). Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, VerifyCommand, Notify.

Does PR Triage access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Triage safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does PR Triage use?

PR Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Triage use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Triage?

Skills that share tags, products or a category with PR Triage: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Pull Request Title and Body Writer (openinterpreter/openinterpreter, 69k stars) and Draft Release Notes (jamiepine/voicebox, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Triage?

ChanningLua (a GitHub user) maintains it in ChanningLua/prax-agent, which has 273 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 11, 2026.

Source: ChanningLua/prax-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.