Agent skill

Review PR Lite

by dyoshikawa in dyoshikawa/rulesync

Review a pull request for code quality and security issues without using subagents.

MITAuto-check passedDevelopment

Install Review PR Lite

skills CLI
$ npx skills add dyoshikawa/rulesync --skill review-pr-lite -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dyoshikawa/rulesync review-pr-lite --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dyoshikawa/rulesync.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.rulesync/skills/review-pr-lite .claude/skills/review-pr-lite && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-pr-lite
GitHub stars
1.5k
Token cost
~717 tokens
SKILL.md length
396 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
MIT

At a glance

Review a pull request for code quality and security issues without using subagents.

  • Works in 4 steps: Gather PR Context → Review the Changes → Report Findings → …
  • The user wants a lighter-weight PR review in a single skill
  • SKILL.md covers Important: Do Not Switch the…, Step 1: Gather PR Context, Step 2: Review the Changes and Step 3: Report Findings, plus 2 more sections
  • Calls gh and git

What it does

Review PR Lite is an agent skill from dyoshikawa/rulesync. Review a pull request for code quality and security issues without using subagents. Use when the user wants a lighter-weight PR review in a single skill.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with Git. The repository describes itself as: A Utility CLI for AI Coding Agents. The licence is MIT.

When your agent uses it

  • The user wants a lighter-weight PR review in a single skill
  • Tasks that involve Pull requests

Example prompts

  • “/review-pr-lite”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather PR Context
  2. Review the Changes
  3. Report Findings
  4. Check GitHub Actions Workflows

What it can do on your machine

Read from SKILL.md and the folder at commit 625bf98. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review PR Lite loads about 717 tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 396 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~717

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dyoshikawa/rulesync at commit 625bf98, republished under its MIT licence (© dyoshikawa). 396 words, ~717 tokens.

Download SKILL.mdSave it as .claude/skills/review-pr-lite/SKILL.md (or your agent's skills folder).
name
review-pr-lite
description
Review a pull request for code quality and security issues without using subagents. Use when the user wants a lighter-weight PR review in a single skill.
targets
*

target_pr = the user's request

If target_pr is not provided, use the PR of the current branch.

Important: Do Not Switch the Local Branch

  • Do NOT check out, switch, or otherwise move the local branch (e.g., git checkout, git switch, gh pr checkout).
  • To inspect the PR's changes, use git and gh commands that read remote state without moving the working tree. For example:
    • gh pr view $target_pr to read PR metadata and description.
    • gh pr diff $target_pr to read the diff.
    • gh pr view $target_pr --json files or gh api to list changed files.
    • git fetch origin pull/<PR_NUMBER>/head:refs/remotes/origin/pr-<PR_NUMBER> and git diff origin/main...origin/pr-<PR_NUMBER> if a local read-only ref is needed.

Step 1: Gather PR Context

Run the following in parallel:

  • Get the PR description and metadata via gh pr view $target_pr (do not check out the PR locally).
  • Get the PR diff via gh pr diff $target_pr.
  • If needed, inspect changed files individually for deeper context using gh / git commands (e.g., gh api, git show) — without switching the local branch.

Step 2: Review the Changes

Review the PR directly in this skill without calling any subagents.

Focus on both of the following:

  1. Code Review

    • Bugs or behavioral regressions
    • Incorrect assumptions or edge cases
    • Missing or weak tests
    • Maintainability issues that could cause near-term problems
  2. Security Review

    • Injection risks
    • Auth/authz mistakes
    • Secrets exposure
    • Unsafe file, network, shell, or deserialization behavior
    • Dependency or configuration changes that could weaken security
Show full SKILL.md (158 more words)Show less

Step 3: Report Findings

Integrate all findings into one review result. Please output the PR number in the result so that the user can easily find the PR.

Reporting Rules

  • Assign a severity level to each finding: low, mid, high, or critical.
  • Assign a sequential number to each finding (e.g., #1, #2, #3, ...).
  • Present findings first, ordered by severity.
  • If no findings are discovered, explicitly state that no findings were found.
  • Keep the summary brief and focused on risk and testing gaps.

Step 4: Check GitHub Actions Workflows

After completing the content review, check the status of the GitHub Actions workflows for $target_pr (for example, using gh pr checks or gh run list).

  • Report the status of every workflow run to the user, including runs that are still in progress.
  • For each failing workflow, also report:
    • The likely cause of the failure (based on the relevant logs or job output).
    • Candidate solutions or next steps to resolve it.

© dyoshikawa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .rulesync/skills/review-pr-lite of dyoshikawa/rulesync.

Open the folder on GitHubat commit 625bf98

Compare with similar skills

Review PR Lite next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review PR Lite compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review PR Lite this skilldyoshikawa/rulesync1.5k—~717Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from dyoshikawa/rulesync

All 40 skills in this repo
  • Rulesync Feature Research

    dyoshikawa/rulesync

    Maps rulesync feature implementations to upstream coding-agent documentation.

    1.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Babysit Dependabot PR

    dyoshikawa/rulesync

    Babysit a Dependabot dependency-bump PR all the way to merge: verify the author is the genuine Dependabot bot, diagnose and resolve any CI failure (excluding or fixing a breaking bump when needed)…

    1.5k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Commit Push PR

    dyoshikawa/rulesync

    Commit current changes, push to remote, and create or update a pull request.

    1.5k GitHub stars~458 tokensUpdated today
    Auto-check passed
  • Git Worktree Runner

    dyoshikawa/rulesync

    Manages git worktrees using git-worktree-runner (gtr). An agent skill from dyoshikawa/rulesync.

    1.5k GitHub stars~1.3k tokensUpdated today
    Auto-check: notes
  • Goal PR

    dyoshikawa/rulesync

    Drive a pull request to a clean state and merge it: run the review-pr skill, fix every mid-or-above finding, and repeat until no mid-or-above findings remain, then merge.

    1.5k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Goal Release

    dyoshikawa/rulesync

    Cut a release end to end: use the draft-release skill to open the release PR and draft GitHub release, wait for CI to turn green, run the merge-pr skill to merge the release PR, then update the…

    1.5k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Review PR Lite

What does Review PR Lite do?

Review a pull request for code quality and security issues without using subagents. Review PR Lite is an agent skill from dyoshikawa/rulesync. Review a pull request for code quality and security issues without using subagents.

When should I use Review PR Lite?

Review PR Lite fits situations like: the user wants a lighter-weight PR review in a single skill; tasks that involve Pull requests.

How do I install Review PR Lite in Claude Code?

Run `npx skills add dyoshikawa/rulesync --skill review-pr-lite -a claude-code`. Or copy the skill folder (.rulesync/skills/review-pr-lite in dyoshikawa/rulesync) into .claude/skills/review-pr-lite in your project. Claude Code loads it when a task matches its description.

How do I install Review PR Lite in Codex?

Run `npx skills add dyoshikawa/rulesync --skill review-pr-lite -a codex`. Or copy the skill folder (.rulesync/skills/review-pr-lite in dyoshikawa/rulesync) into .agents/skills/review-pr-lite in your project. Codex loads it when a task matches its description.

Can I use Review PR Lite in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dyoshikawa/rulesync --skill review-pr-lite -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-pr-lite, .gemini/skills/review-pr-lite, .github/skills/review-pr-lite and .opencode/skills/review-pr-lite in your project.

What does Review PR Lite need to run?

Going by SKILL.md and its folder, Review PR Lite needs the command-line tools its instructions call (gh and git).

Does Review PR Lite access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review PR Lite safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review PR Lite use?

Review PR Lite is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review PR Lite use?

About 717 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review PR Lite?

Skills that share tags, products or a category with Review PR Lite: Finishing a Development Branch (obra/superpowers, 297k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Open Code Review CLI (alibaba/open-code-review, 46k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review PR Lite?

dyoshikawa (a GitHub user) maintains it in dyoshikawa/rulesync, which has 1,509 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 9, 2026.

Source: dyoshikawa/rulesync on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.