Agent skill

PR Review

by confluentinc in confluentinc/mcp-confluent

Reviews pull requests for the Confluent MCP server. An agent skill from confluentinc/mcp-confluent.

MITAuto-check: notesDevelopment

Install PR Review

skills CLI
$ npx skills add confluentinc/mcp-confluent --skill pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install confluentinc/mcp-confluent pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/confluentinc/mcp-confluent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pr-review .claude/skills/pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review
GitHub stars
167
Token cost
~4.6k tokens
SKILL.md length
1,730 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Reviews pull requests for the Confluent MCP server. An agent skill from confluentinc/mcp-confluent.

  • Works in 6 steps: Gather Information → Filter Files for Review → Categorize the Changes → …
  • Doing self-review before sharing with the team
  • SKILL.md covers Two Review Modes, Review Process, What NOT to Flag and Output Format, plus 3 more sections
  • Calls gh, git and pnpm

What it does

PR Review is an agent skill from confluentinc/mcp-confluent. Reviews pull requests for the Confluent MCP server. Use when reviewing PRs, doing self-review before sharing with the team, or when the user mentions "review PR", "help with PR", "review changes", "self-review", "review local changes", or "check my PR". Focuses on MCP tool wiring, OpenAPI/type coupling, ESM stubbability, transport security, and project-specific patterns.

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, MCP servers and OpenAPI specifications. It works with OpenAPI, Model Context Protocol and TypeScript. The licence is MIT.

When your agent uses it

  • Doing self-review before sharing with the team
  • The user mentions review PR
  • Review local changes

Example prompts

  • “review PR”
  • “help with PR”
  • “review changes”
  • “/pr-review”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Read, Bash, Grep, Glob, Task

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Gather Information
  2. Filter Files for Review
  3. Categorize the Changes
  4. Check Critical Requirements
  5. Check Project-Specific Patterns
  6. Check PR Hygiene

What it can do on your machine

Read from SKILL.md and the folder at commit 76cffd5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Grep
    • Glob
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, git and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review loads about 4.6k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,730 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:100
    `config.example.yaml`, `.env.example`, `.env.integration.example` (user-facing configuration)
  • NoteMentions a .env fileSKILL.md:253
    - [ ] No secrets in the diff: `.env`, `.env.integration`, real API keys, real cluster IDs
  • NoteMentions a .env fileSKILL.md:399
    I key or PEM smuggled into a fixture or `.env.integration` example
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Grep, Glob, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from confluentinc/mcp-confluent at commit 76cffd5, republished under its MIT licence (© confluentinc). 1,730 words, ~4,623 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review/SKILL.md (or your agent's skills folder).
name
pr-review
description
Reviews pull requests for the Confluent MCP server. Use when reviewing PRs, doing self-review before sharing with the team, or when the user mentions "review PR", "help with PR", "review changes", "self-review", "review local changes", or "check my PR". Focuses on MCP tool wiring, OpenAPI/type coupling, ESM stubbability, transport security, and project-specific patterns.
allowed-tools
Read, Bash, Grep, Glob, Task

PR Review Skill

Reviews pull requests for the Confluent MCP (Model Context Protocol) server, focusing on project-specific patterns and the failure modes most likely to slip past TypeScript and lint.

Two Review Modes

The mode is selected by the invocation context, not by the user. If the user supplies a PR number/URL or asks about someone else's PR, run Formal Review Mode. Otherwise (no PR number, working from a local branch, phrases like "self-review" or "check my PR") run Self-Review Mode. When ambiguous, ask which mode to use.

Self-Review Mode (for PR authors)

Use when: the author wants to check their own changes before sharing with the team. Typically used on a draft PR or against local changes before pushing.

Goals:

  • Catch issues early, before formal review
  • Verify MCP tool wiring is complete (enum + handler + registry + predicate)
  • Ensure new external I/O is stubbable
  • Confirm OpenAPI spec and generated types stay in sync
Formal Review Mode (for reviewers)

Use when: a reviewer needs to evaluate a PR from another team member.

Goals:

  • Quickly understand the scope and purpose of changes
  • Identify potential issues or concerns
  • Provide constructive feedback grounded in MCP/Confluent conventions
  • Verify the PR template checklist is honored

Review Process

Step 1: Gather Information

For local changes (self-review):

bash
# files changed since divergence from main
git diff main --name-only

# overview and full diff
git diff main --stat
git diff main

For GitHub PRs:

bash
# PR metadata
gh pr view <PR_NUMBER> --json number,title,body,author,baseRefName,headRefName,additions,deletions,changedFiles,state,reviewDecision

# if no PR number is given, try the current branch
gh pr view --json number,title,body,author,baseRefName,headRefName,additions,deletions,changedFiles,state,reviewDecision

# diff
gh pr diff <PR_NUMBER>

# existing reviews and inline comments
gh pr view <PR_NUMBER> --json reviews,comments

# referenced issues
gh issue view <ISSUE_NUMBER> --json body,comments
Step 2: Filter Files for Review

SKIP these paths entirely (auto-generated or vendored):

  • dist/** (compiled output)
  • node_modules/**
  • coverage/**
  • src/confluent/openapi-schema.d.ts (generated by pnpm run generate:openapi-types)
  • pnpm-lock.yaml (review only top-level dependency changes via package.json)
  • TEST-result.xml

DO review carefully (small file, big blast radius):

  • openapi.json (paired with the regenerated .d.ts)
  • package.json (new deps, scripts, engine bumps)
  • config.example.yaml, .env.example, .env.integration.example (user-facing configuration)
  • vitest.config.ts, tsconfig.json, tsconfig.build.json, eslint.config.mjs
  • .semaphore/** (CI configuration)
  • Dockerfile, docker-compose.yml
Step 3: Categorize the Changes
CategoryFile patternsWhat to check
Tool handlerssrc/confluent/tools/handlers/<domain>/**Enum entry, registry entry, enabledConnectionIds, Zod schema
Tool registrysrc/confluent/tools/tool-registry.tsNew handler imported and added to handlers map
Tool name enumsrc/confluent/tools/tool-name.tsNew enum member with stable string value
Connection predicatessrc/confluent/tools/connection-predicates.tsNew predicate composes existing service-block checks
Domain base classessrc/confluent/tools/handlers/<domain>/*-tool-handlerDomain-wide gating still correct after edits
Client managerssrc/confluent/{base-,direct-,}client-manager.tsClient lifecycle, single source of truth per connection
Configurationsrc/config/**, src/env-schema.tsZod schema, YAML interpolation, both config paths covered
Transportssrc/mcp/transports/**API-key auth, DNS rebinding protection, port handling
OpenAPI surfaceopenapi.jsonRegenerated .d.ts is committed in the same PR
Unit tests**/*.test.ts (excluding *.integration.test.ts)Vitest patterns, node-deps.ts indirection, no vi.mock
Integration tests**/*.integration.test.ts, tests/harness/**Credential gating via early-return, tags, startServer
CI / release.semaphore/**, scripts/**, DockerfileNo skipped checks, no smuggled secrets
DocsREADME.md, docs/**, CHANGELOG.md, telemetry.mdAccuracy, MCP-tool inventory, user-facing wording
Project rules / skills.claude/rules/**, .claude/skills/**Frontmatter, path globs, trigger phrases
Step 4: Check Critical Requirements

IMPORTANT: only review lines that were actually changed in the PR diff. Context lines from the diff are for understanding, not for review. Do not flag pre-existing issues in unchanged code.

1. Tool Wiring Completeness (MANDATORY for new tools)

A new MCP tool needs all four of:

  • Entry in ToolName enum (src/confluent/tools/tool-name.ts)
  • Handler class extending BaseToolHandler (or a domain subclass like FlinkToolHandler)
  • enabledConnectionIds(runtime) using a predicate from connection-predicates.ts
  • Registration in ToolHandlerRegistry.handlers (src/confluent/tools/tool-registry.ts)

Red flags:

  • New handler class but no tool-registry.ts change → tool will not be loaded
  • New enum entry but no handler → runtime error when iterating enabled tools
  • Wrong predicate (e.g., hasKafka for a Schema Registry tool) → tool enables on the wrong connections and silently no-ops or errors

The canonical wiring lives in .claude/rules/tool-handlers.md, which auto-loads when files under src/confluent/tools/**/*.ts are touched.

2. OpenAPI / Generated Types Coupling

If openapi.json changed:

  • src/confluent/openapi-schema.d.ts is regenerated and committed in the same PR
  • The diff in the .d.ts reflects the spec change (no stale paths or schemas)

If openapi-schema.d.ts changed without openapi.json changing, the file was hand-edited - flag it. The generator is pnpm run generate:openapi-types; the file should never be edited manually.

3. ESM Stubbability via node-deps.ts

ESM named imports are read-only from outside the defining module, so vi.spyOn cannot intercept direct named imports. This project's workaround is src/confluent/node-deps.ts: external I/O (filesystem, env, network not via openapi-fetch/Kafka clients, third-party constructors) routes through that namespace, and tests spy on the wrapper.

Red flags in non-test code:

ts
// BAD: direct named import at use site → not stubbable
import { readFile } from "node:fs/promises";
const config = await readFile(path, "utf8");

// GOOD: route through node-deps for stubbability
import { nodeDeps } from "@src/confluent/node-deps.js";
const config = await nodeDeps.readFile(path, "utf8");

Red flag in tests: vi.mock(...) calls. The project does not use vi.mock; wrap the dependency in node-deps.ts and use vi.spyOn(nodeDeps, "readFile") instead. The /vitest skill confirms the patterns.

4. Type Safety
  • No new explicit any (the project disables noImplicitAny for OpenAPI types, but explicit any at use sites is still a code smell)
  • Tool input schemas are Zod schemas, not loose object types
  • REST calls use openapi-fetch with typed paths from the generated schema, not raw fetch
  • Imports use .js extensions (ESM requirement) and @src/* for internal modules
  • No @ts-ignore / @ts-expect-error without a comment explaining why
5. Single Responsibility
  • Handlers do one tool's worth of work; cross-domain logic moves to a shared helper
  • No "god clients" - BaseClientManager owns REST and Schema Registry; DirectClientManager adds Kafka admin/producer/consumer. New client kinds extend, not inflate, these.
Step 5: Check Project-Specific Patterns
Predicate-Based Tool Gating
  • enabledConnectionIds(runtime) uses an existing predicate where one fits
  • If a brand-new predicate is introduced, it composes existing service-block checks rather than re-walking runtime.connections ad hoc
  • Domain base classes (e.g., FlinkToolHandler) implement enabledConnectionIds once for the whole domain; per-handler overrides should be rare and well-justified
Configuration Surface (two paths must stay in sync)

MCPServerConfiguration is produced by either loadConfigFromYaml() (-c <path>) or buildConfigFromEnvAndCli() (legacy env+CLI). Both produce the same Zod-validated shape.

  • New configuration fields are added to the Zod schema in src/config/models.ts AND honored by buildConfigFromEnvAndCli (or explicitly excluded from the legacy path with a note)
  • config.example.yaml and .env.example are updated when user-facing config changes
  • ${VAR} interpolation continues to work for any new YAML fields
Transport Security
  • HTTP/SSE handlers preserve API-key auth and DNS rebinding protection
  • No new endpoint added without authentication unless explicitly intended (and called out in the PR description)
  • Secrets never go through Pino at info level or above; sensitive fields are redacted (Pino's redact option, configured in src/logger.ts)
Logger Usage
  • Uses the project logger from src/logger.ts (Pino), not console.log / console.error
  • Errors use logger.error({ err }) so Pino's serializer captures stack traces
  • No log lines that include credentials, tokens, or full request bodies that may contain secrets
Show full SKILL.md (711 more words)Show less
Testing
  • Unit tests follow .claude/rules/unit-tests.md (assertion style, stubbing patterns, handler test structure, fake timers)
  • Integration tests follow .claude/rules/integration-tests.md: colocated *.integration.test.ts, tags on outer describe, credential gating via early-return (NOT describe.skipIf, which still runs nested hooks in vitest 4)
  • Class-instance mocks use createMockInstance(Class) from @tests/stubs/index.js
  • No .only left in test files
  • No vi.mock (the project pattern is node-deps.ts + vi.spyOn)

Use the /vitest skill to verify spy/mock APIs against current Vitest docs.

Step 6: Check PR Hygiene
  • PR description follows the template: Summary of Changes, manual testing instructions (transports exercised, sample inputs/outputs, env vars), additional context
  • Tests checkbox is honored: new behavior has new tests; updated behavior has updated tests
  • CHANGELOG entry added when the change is user-facing (new tool, new config field, breaking change, security fix). Internal refactors do not need an entry.
  • No unrelated changes bundled in (formatting passes, dependency bumps, etc., should ride their own PR unless they directly support the change)
  • No secrets in the diff: .env, .env.integration, real API keys, real cluster IDs

What NOT to Flag

Style Preferences (avoid nitpicking)
  • Import statements: import type { } vs import { } - both valid
  • Formatting issues - Prettier and ESLint enforce these via the pre-commit hook
  • Auto-removed unused imports during a refactor - handled by eslint-plugin-unused-imports
  • Trailing-comma, single-quote, semi-colon preferences - Prettier owns these
  • Minor naming preferences when the existing name is reasonable
Comment Preservation
  • Never suggest deleting existing comments unless they are now actively misleading
  • Comments explain "why" not "what"; they may look redundant but provide context the reviewer may not have
  • When code is updated, preserve or update the comments rather than removing them

Output Format

For Self-Review
markdown
## Self-Review Summary

### Changes Overview

[Brief summary of what changed]

### Critical Requirements Checklist

- [ ] Tool Wiring (enum + handler + predicate + registry): [status, location of any gap]
- [ ] OpenAPI / Types Coupling: [status]
- [ ] ESM Stubbability (node-deps): [status]
- [ ] Type Safety: [status]
- [ ] Transport Security: [status, if applicable]

### Issues to Address Before PR

1. [High-priority issue with file:line]
2. [Medium-priority issue with file:line]

### Suggestions (Optional)

- [Nice-to-have improvements]

### Ready for Review?

[Yes / Not yet, with reasoning]
For Formal Review
markdown
## PR Review: #{number} - {title}

**Author:** {author}
**Branch:** {headRefName} → {baseRefName}
**Changes:** +{additions} / -{deletions} across {changedFiles} files

### Summary

[2-3 sentence summary of what the PR does and why]

### Changed Components

- [Categorized list of changed files, excluding auto-generated]

### Findings

#### Issues (Must Fix)

- [ ] **[category]**: [description] - `file:line`

#### Suggestions (Consider)

- [ ] **[category]**: [description] - `file:line`

#### Positive Observations

- [Good patterns, thorough tests, well-written code]

### Test Coverage Assessment

- **New tests added:** [Yes/No, list test files]
- **Coverage gaps:** [Untested paths or edge cases]
- **Unit vs integration balance:** [Assessment]

### Configuration & Security Notes

[Any concerns about transport security, secret handling, config surface, or CCloud auth]

### Recommendation

**[APPROVE / REQUEST CHANGES / NEEDS DISCUSSION]**

[Brief rationale]

Review Categories

Use these labels in findings:

CategoryDescription
tool-wiringMissing enum / handler / registry / predicate hookup
openapiopenapi.json and .d.ts out of sync, or hand-edited generated file
stubbabilityNew external I/O bypasses node-deps.ts; vi.mock introduced
typesExplicit any, missing Zod schema, raw fetch over openapi-fetch
configYAML and env-var paths drift; missing example-file update
transportAuth or DNS-rebinding regression; unauthenticated endpoint
secretsCredentials in diff, logs, or fixtures
testingMissing tests, wrong mocking pattern, .only left in
loggingconsole.* in src code, secret leaks in log lines
docsCHANGELOG missing for user-facing change; stale README example
styleNaming, conventions where Prettier/ESLint do not already enforce
performanceSynchronous I/O in hot paths, unbounded fetches

Common Issues to Watch For

Tool Wiring Gaps
  • Handler class added but never imported into tool-registry.ts
  • New enum entry never instantiated → unused enum value
  • enabledConnectionIds returns [] unconditionally → tool never enables
OpenAPI Drift
  • openapi.json updated, openapi-schema.d.ts not regenerated → callers still see the old type
  • openapi-schema.d.ts hand-edited because regeneration "broke things" - fix the spec instead
Test-Time Surprises
  • vi.mock(...) introduced as a shortcut → maintenance landmine; use node-deps.ts instead
  • describe.skipIf(!hasCreds) in integration tests → nested hooks still run on vitest 4
  • New external I/O imported directly at use site → tests cannot stub it without restructuring
Configuration Drift
  • New field added to YAML schema but not to buildConfigFromEnvAndCli - env-var users get a silently incomplete config
  • .env.example / config.example.yaml not updated → onboarding breakage
Security
  • API key or PEM smuggled into a fixture or .env.integration example
  • Pino log line that JSON-stringifies an object containing Authorization headers
  • New transport endpoint without auth or with auth bypassed under NODE_ENV=test
Performance
  • await in a tight loop where Promise.all would do
  • Unbounded list endpoints (no pagination, no limit) returning the full Confluent Cloud surface to a model context

Tips

  • Start with the PR description and the PR template checklist
  • Look at the test changes first to understand the intended behavior
  • For new tools, trace ToolName enum → handler → registry → predicate; if any link is missing, the tool is dead code
  • Use Task with the Explore agent for deeper codebase context (for example, "find all callers of nodeDeps.readFile to estimate the blast radius of a signature change")
  • Use companion project skills to ground review in current docs:
    • /mcp-docs for MCP protocol questions (tool annotations, resource shapes, transport spec)
    • /vitest for spy/mock APIs and Vitest 4 behavior
  • When the diff touches src/confluent/tools/**, **/*.test.ts, or tests/**, the matching .claude/rules/ files (tool-handlers.md, unit-tests.md, integration-tests.md) auto-load with the canonical conventions - consult them rather than re-deriving the rules from the diff.
  • When suggesting a simplification, verify it with the relevant doc skill before posting - saves a back-and-forth when the "simpler" alternative does not actually exist on the current SDK version

© confluentinc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pr-review of confluentinc/mcp-confluent.

Open the folder on GitHubat commit 76cffd5

Compare with similar skills

PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review this skillconfluentinc/mcp-confluent167—~4.6kAutomated safety check: NotesMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Frontmcp Developmentagentfront/frontmcp146—~11kAutomated safety check: PassApache-2.0
MCP Server Builderalirezarezvani/claude-skills28k—~985Automated safety check: PassMIT
MCP Server Builderborghei/Claude-Skills886—~1.9kAutomated safety check: PassMIT
Dashclaw Shipucsandman/DashClaw310—~7.2kAutomated safety check: PassMIT

Similar skills

  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Development

    agentfront/frontmcp

    A skill your agent uses when building any FrontMCP server component other than a tool (for tools, use create-tool).

    146 GitHub stars~11k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • MCP Server Builder

    alirezarezvani/claude-skills

    Design and ship production-ready MCP (Model Context Protocol) servers from OpenAPI contracts instead of hand-written tool wrappers.

    28k GitHub stars~985 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    borghei/Claude-Skills

    Build MCP (Model Context Protocol) servers with tool definitions, resource providers, prompt templates, and transports.

    886 GitHub stars~1.9k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Dashclaw Ship

    ucsandman/DashClaw

    The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.

    310 GitHub stars~7.2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Generate MCP Server

    trycompai/comp

    A skill your agent uses when generating an MCP server from an OpenAPI spec with Speakeasy.

    2k GitHub stars~2.7k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed

More from confluentinc/mcp-confluent

  • Vitest

    confluentinc/mcp-confluent

    A skill your agent uses when the user asks about Vitest mocking, spies, stubs, fake timers, config, or test runner behavior.

    167 GitHub stars~1.7k tokensUpdated today
    Auto-check: notes
  • MCP Docs

    confluentinc/mcp-confluent

    A skill your agent uses when the user asks about Model Context Protocol details (protocol spec, transports, authorization, tools/resources/prompts, sampling/elicitation/roots, server/client…

    167 GitHub stars~604 tokensUpdated today
    Auto-check passed

Questions about PR Review

What does PR Review do?

Reviews pull requests for the Confluent MCP server. An agent skill from confluentinc/mcp-confluent. PR Review is an agent skill from confluentinc/mcp-confluent. Reviews pull requests for the Confluent MCP server.

When should I use PR Review?

PR Review fits situations like: doing self-review before sharing with the team; the user mentions review PR; review local changes.

How do I install PR Review in Claude Code?

Run `npx skills add confluentinc/mcp-confluent --skill pr-review -a claude-code`. Or copy the skill folder (.claude/skills/pr-review in confluentinc/mcp-confluent) into .claude/skills/pr-review in your project. Claude Code loads it when a task matches its description.

How do I install PR Review in Codex?

Run `npx skills add confluentinc/mcp-confluent --skill pr-review -a codex`. Or copy the skill folder (.claude/skills/pr-review in confluentinc/mcp-confluent) into .agents/skills/pr-review in your project. Codex loads it when a task matches its description.

Can I use PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add confluentinc/mcp-confluent --skill pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review, .gemini/skills/pr-review, .github/skills/pr-review and .opencode/skills/pr-review in your project.

What does PR Review need to run?

Going by SKILL.md and its folder, PR Review needs the command-line tools its instructions call (gh, git and pnpm). Our summary lists: Docker. Its frontmatter pre-approves these tools: Read, Bash, Grep, Glob, Task.

Does PR Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does PR Review use?

PR Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review use?

About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Review?

Skills that share tags, products or a category with PR Review: OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars), Frontmcp Development (agentfront/frontmcp, 146 stars), MCP Server Builder (alirezarezvani/claude-skills, 28k stars) and MCP Server Builder (borghei/Claude-Skills, 886 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review?

confluentinc (a GitHub organization) maintains it in confluentinc/mcp-confluent, which has 167 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.

Source: confluentinc/mcp-confluent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.