Agent skill

Contributor PR Review Checklist

by different-ai in different-ai/openwork

Checklist for reviewing pull requests from forks before approval: DCO sign-offs on every commit, CLA for ee/ paths, and whether the change is safe to merge.

Custom licenceAuto-check passedDevelopment

Install Contributor PR Review Checklist

skills CLI
$ npx skills add different-ai/openwork --skill review-a-contributor-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install different-ai/openwork review-a-contributor-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/different-ai/openwork.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/review-a-contributor-pr .claude/skills/review-a-contributor-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-a-contributor-pr
GitHub stars
24k
Token cost
~2.9k tokens
SKILL.md length
1,334 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Checklist for reviewing pull requests from forks before approval: DCO sign-offs on every commit, CLA for ee/ paths, and whether the change is safe to merge.

  • Works in 7 steps: Provenance: the code is the… → ee/ paths are covered by the CLA notice → Warden ran on the exact head being merged → …
  • Reviewing a pull request opened from a fork
  • SKILL.md covers 1. Provenance: the code is the…, 2. ee/ paths are covered by…, 3. Warden ran on the exact… and 4. A human read the full diff, plus 3 more sections
  • Calls gh and git

What it does

It applies to every PR whose head sits outside the main repository. Fork PRs get no automatic Warden clearance, and neither DCO nor the `ee/` CLA is enforced by automation yet, so each checklist item must be answered explicitly in the review comment, and `Blocked` on any item means no approval and no merge. A first `gh pr view` query pulls fork status, head repo and commit, author, labels and changed files.

The DCO check requires every non-merge commit to carry a `Signed-off-by` trailer with the author's name and email, verified with a `gh api` query over all commits. The remedy is for the contributor to rebase with `--signoff` and push with `--force-with-lease`; the reviewer never adds the trailer, and squash merging cannot repair it. Anything under `ee/`, including renames out of it, also needs an Individual or Corporate CLA, confirmed through a `cla-signed` label. The skill also covers carrying a fork commit into a same-repo branch.

When your agent uses it

  • Reviewing a pull request opened from a fork
  • Checking every commit on a PR for DCO sign-off
  • Confirming a CLA is on file for changes under ee/
  • Deciding whether an external PR is safe to merge

Example prompts

  • “Review this fork PR with the contributor checklist and tell me what is blocked.”
  • “Check that every commit on the PR has a Signed-off-by trailer.”
  • “This PR touches ee/, so is there a CLA on file for the author?”

Requirements

  • GitHub CLI (`gh`) with access to the repository

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Provenance: the code is the contributor's to give
  2. ee/ paths are covered by the CLA notice
  3. Warden ran on the exact head being merged
  4. A human read the full diff
  5. No new IPC, network, or dependency surface without justification
  6. Carry a fork commit into a same-repo branch
  7. Record the review

What it can do on your machine

Read from SKILL.md and the folder at commit 6325c02. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contributor PR Review Checklist loads about 2.9k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 1,334 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,334 words (~2,913 tokens).

“Use for every PR whose head is not in different-ai/openwork (isCrossRepository: true). Fork PRs get no automatic clearance: warden.yml skips them (head.repo.full_name == github.repository, no secrets on fork heads) and warden-clearance.yml refuses them. As at GitLab, contributing means accepting the…”

— opening of SKILL.md by different-ai, Custom licence
name
review-a-contributor-pr

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .opencode/skills/review-a-contributor-pr of different-ai/openwork.

Open the folder on GitHubat commit 6325c02

Compare with similar skills

Contributor PR Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contributor PR Review Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contributor PR Review Checklist this skilldifferent-ai/openwork24k—~2.9kAutomated safety check: PassCustom licence
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Pre-Release PR Triagejamiepine/voicebox57k—~3.1kAutomated safety check: PassMIT
Verdaccio PR Reviewverdaccio/verdaccio18k—~1.7kAutomated safety check: PassMIT
Ansible Backport Creatoransible/ansible71k—~1.2kAutomated safety check: PassGPL-3.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Pre-Release PR Triage

    jamiepine/voicebox

    Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.

    57k GitHub stars~3.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Verdaccio PR Review

    verdaccio/verdaccio

    Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.

    18k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Creates backports of a merged Ansible devel pull request onto the right stable branches by cherry-picking its merge commit onto new backport branches.

    71k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Greploop Apps

    michaelshimeles/skills

    Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.

    1.3k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed

More from different-ai/openwork

All 33 skills in this repo
  • OpenWork Desktop CDP Driver

    different-ai/openwork

    Drives a running OpenWork desktop window over CDP from the shell to evaluate JS, take screenshots, start sessions and send prompts for hand checks.

    24k GitHub stars~465 tokensUpdated today
    Auto-check passed
  • Fake Model Provider Faults

    different-ai/openwork

    Makes the desktop app's model provider fail on demand, with refused connections, resets, stalls and HTTP 4xx and 5xx errors, so error and retry states can be reproduced.

    24k GitHub stars~642 tokensUpdated today
    Auto-check passed
  • OpenWork Model Alias Manager

    different-ai/openwork

    Manages OpenWork's inference model aliases, discounts and overlays over the upstream OpenRouter catalog, and triggers the GitHub workflow that refreshes base models.

    24k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Reproduce Chat States

    different-ai/openwork

    Fires known chat states in the running OpenWork desktop app, such as provider errors, retries and tool steps, so you can check how each renders.

    24k GitHub stars~673 tokensUpdated today
    Auto-check passed
  • Attaches OpenCode browser tools to the OpenWork Electron dev app through CDP to explore its UI, send a composer task and debug, not to give test verdicts.

    24k GitHub stars~780 tokensUpdated today
    Auto-check passed
  • Daytona Sandbox Operations

    different-ai/openwork

    Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.

    24k GitHub stars~917 tokensUpdated today
    Auto-check passed

Works with

Questions about Contributor PR Review Checklist

What does Contributor PR Review Checklist do?

Checklist for reviewing pull requests from forks before approval: DCO sign-offs on every commit, CLA for ee/ paths, and whether the change is safe to merge. It applies to every PR whose head sits outside the main repository. Fork PRs get no automatic Warden clearance, and neither DCO nor the `ee/` CLA is enforced by automation yet, so each checklist item must be answered explicitly in the review comment, and `Blocked` on any item means no approval and no merge.

When should I use Contributor PR Review Checklist?

Contributor PR Review Checklist fits situations like: reviewing a pull request opened from a fork; checking every commit on a PR for DCO sign-off; confirming a CLA is on file for changes under ee/; deciding whether an external PR is safe to merge.

How do I install Contributor PR Review Checklist in Claude Code?

Run `npx skills add different-ai/openwork --skill review-a-contributor-pr -a claude-code`. Or copy the skill folder (.opencode/skills/review-a-contributor-pr in different-ai/openwork) into .claude/skills/review-a-contributor-pr in your project. Claude Code loads it when a task matches its description.

How do I install Contributor PR Review Checklist in Codex?

Run `npx skills add different-ai/openwork --skill review-a-contributor-pr -a codex`. Or copy the skill folder (.opencode/skills/review-a-contributor-pr in different-ai/openwork) into .agents/skills/review-a-contributor-pr in your project. Codex loads it when a task matches its description.

Can I use Contributor PR Review Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add different-ai/openwork --skill review-a-contributor-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-a-contributor-pr, .gemini/skills/review-a-contributor-pr, .github/skills/review-a-contributor-pr and .opencode/skills/review-a-contributor-pr in your project.

What does Contributor PR Review Checklist need to run?

Going by SKILL.md and its folder, Contributor PR Review Checklist needs the command-line tools its instructions call (gh and git). Our summary lists: GitHub CLI (`gh`) with access to the repository.

Does Contributor PR Review Checklist access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Contributor PR Review Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Contributor PR Review Checklist use?

Contributor PR Review Checklist has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Contributor PR Review Checklist use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Contributor PR Review Checklist?

Skills that share tags, products or a category with Contributor PR Review Checklist: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), PR Review State Fetch (prisma/orm, 48k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars) and Verdaccio PR Review (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contributor PR Review Checklist?

different-ai (a GitHub organization) maintains it in different-ai/openwork, which has 23,987 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 10, 2026.

Source: different-ai/openwork on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.