Trailmark Graph Evolution
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ffroliva/gflow-cli pr-council-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pr-council-review .claude/skills/pr-council-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .claude/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ffroliva/gflow-cli pr-council-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pr-council-review .agents/skills/pr-council-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .agents/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ffroliva/gflow-cli pr-council-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pr-council-review .cursor/skills/pr-council-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .cursor/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ffroliva/gflow-cli.git --path skills/pr-council-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ffroliva/gflow-cli pr-council-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pr-council-review .gemini/skills/pr-council-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .gemini/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ffroliva/gflow-cli pr-council-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pr-council-review .github/skills/pr-council-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .github/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ffroliva/gflow-cli --skill pr-council-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ffroliva/gflow-cli pr-council-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pr-council-review .opencode/skills/pr-council-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pr-council-review" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/pr-council-review into .opencode/skills/pr-council-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-council-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pr-council-reviewMulti-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).
PR Council Review is an agent skill from ffroliva/gflow-cli. Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review). Five baseline dimensions (correctness, quality, security, tests, memory-hygiene) plus adaptive dimensions per surface (transports / data / CLI / docs / auth / BDD / scripts / release-gate). Each agent invokes specialized skills (security-review, code-review, verify) for its dimension. Reads files via git show <sha:<path to avoid stale-working-tree false positives. Cross-tool…
Its SKILL.md is about 12k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review and AI video generation. It works with Git. The repository describes itself as: Drive Google Flow from the command line: Veo video and Imagen images, scripted, batched and pipeline-ready. Ships an MCP server so coding agents can drive it too, giving you and… The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d44abc8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgituvruffpytestFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
PR Council Review loads about 12k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 5,283 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ffroliva/gflow-cli at commit d44abc8, republished under its MIT licence (© ffroliva). 5,283 words, ~11,833 tokens.
.claude/skills/pr-council-review/SKILL.md (or your agent's skills folder).pr-council-review — PR Council Review skillCouncil-driven PR review. Dispatches 6 baseline + N adaptive parallel reviewers, each scoped to one dimension, each invoking the relevant Claude Code specialized skill (e.g. security-review, code-review, verify), then synthesizes a single consensus verdict.
This skill is the canonical body. The Claude Code slash command at .claude/commands/gflow/pr-council-review.md is a thin wrapper that invokes this skill. Non-Claude tools (Antigravity / Codex / Cursor / Aider) can consume this SKILL.md directly via their own skill loaders.
Three modes:
PR# argument → run the full council on that PR. (See § 2 onward.)/gflow:branch-review wrapper. See § 8 for the PR→branch translation table and pre-flight.Treat YELLOW as soft block — it is advisory in name only; clear it or dismiss it with a logged justification (§ 5 step 8).
All six checks are mandatory. Any failure (except step 6, which records a finding) halts before Phase 1/2.
gh authenticated — run gh auth status. Non-zero exit → stop with: "gh is not authenticated. Run gh auth login and re-invoke."AGENTS.md AND CLAUDE.md exist in the working directory.gh pr view <N> --json number. If error → stop with the error verbatim.gh pr view <N> --json isDraft returns true, surface a banner citing memory [[draft-pr-merge-trap]]: "PR #N is DRAFT. Reviewing is fine, but do NOT merge a draft (the merge API can close it + delete the head ref). Run gh pr ready N first if you intend to merge. Continue review? (yes/no)". Ask the user before dispatching.head_branch=$(gh pr view <N> --json headRefName --jq '.headRefName') and head_sha=$(gh pr view <N> --json headRefOid --jq '.headRefOid'). Pin both to a REVIEWED_SHA variable and pass to every dispatched agent so the council's verdict is anchored to one commit. The local working tree is NOT on the PR head; all file reads must go through git show $REVIEWED_SHA:<path> (or git show origin/$head_branch:<path> if you fetched first). If the author pushes new commits during the review, the council still reports against REVIEWED_SHA; the synthesizer notes any divergence in Phase 5 step 5.ruff format failure in a file the diff only touched went green through 8 agents, then reddened CI and dragged SonarCloud new_coverage to 0). Run the exact CI gate commands (.github/workflows/ci.yml → Lint / Format check / Documentation links / Repo hygiene) against the reviewed tree:# Prefer running at REVIEWED_SHA. If HEAD is already there (reviewing your own
# just-pushed PR, or branch-review mode), run in place:
if [ "$(git rev-parse HEAD)" = "$REVIEWED_SHA" ]; then dir=.; else \
dir=$(mktemp -d); git worktree add --detach "$dir" "$REVIEWED_SHA"; fi
( cd "$dir" && uv run ruff check src tests \
&& uv run ruff format --check src tests \
&& uv run python scripts/ci/check_doc_links.py \
&& uv run python scripts/ci/check_repo_hygiene.py )
# if a worktree was created: git worktree remove --force "$dir" (Windows: prune later if locked)D0 — CI-mechanical RED. This is a hard blocker regardless of the LLM dimensions' verdicts; surface the failing command + output verbatim in the report and do NOT call the PR merge-ready. (Mirrors the SonarCloud-gate rule in the wrapper: the council must not bless a tree CI will reject.)uv, worktree add fails), fall back to gh pr checks <N> and inspect the test job's Lint/Format steps; if they are pending or failing, flag D0 as UNVERIFIED — must be confirmed green before merge, never as GREEN.gh pr checks is not sufficient and the fallback above is blind.
GitHub holds pull_request workflows from forks at conclusion=action_required
until a maintainer clicks Approve and run, and such a run does not appear in
statusCheckRollup at all — so the PR reports every check green while nothing
ran. Measured on 2026-09-15: #781 (approved) showed 16 checks; #793 (held) and
#787 (no run) each showed 2, all green. Run:uv run python scripts/ci/check_fork_pr_ci.py --pr <N>RED — CI never ran. Approve the workflow run, or gate the head
locally, before trusting any green on that PR.gh pr list --state open --json number,title,author,isDraft,headRefName,updatedAt,additions,deletions,labels,reviewDecision,statusCheckRollupEmpty-list short-circuit: if the result is [], print "No open PRs to review." and exit.
Rank with these heuristics (highest priority first):
| Signal | Weight | Why |
|---|---|---|
isDraft == false AND CI all-green | +3 | Ready to merge once approved — highest ROI |
Touched path includes src/gflow_cli/api/transports/ | +2 | UI-automation is the highest-risk surface (memory [[pr-must-verify-on-affected-surface]]) |
Touched path includes src/gflow_cli/auth/ or recaptcha | +2 | Auth changes need security-deep-dive |
Touched path includes src/gflow_cli/api/client.py or src/gflow_cli/api/_sapisidhash.py | +2 | Auth-token plumbing (Bearer / access-token / SAPISID) — lives outside auth/ but is security-material; backtest found 3 historical fixes here |
Touched path includes src/gflow_cli/data/ | +2 | Migration safety + #86 hygiene history |
| Older than 7 days (stale risk) | +1 | Conflict risk grows with age |
additions + deletions <= 300 | +1 | Small PRs ship faster |
Label contains release-blocker, security, hotfix | +5 | Anything labelled urgent jumps the queue |
isDraft == true AND CI red | −2 | Author still iterating; review wastes their time |
Present a numbered table, then stop and ask the user to pick a PR number. Do NOT auto-start on Rank 1 — recommend, do not pre-select.
Pull in parallel via ctx_batch_execute:
PR_META → gh pr view <N> --json title,body,author,baseRefName,headRefName,headRefOid,state,isDraft,additions,deletions,changedFiles,labels,files,statusCheckRollupPR_DIFF → gh pr diff <N>PR_CHECKS → gh pr checks <N>TOUCHED_PATHS → gh pr view <N> --json files --jq '.files[].path' | sort -uRECENT_COMMITS → gh pr view <N> --json commits --jq '.commits[-5:] | .[] | "\(.oid[:7]) \(.messageHeadline)"'PR_COMMENTS → gh pr view <N> --json comments --jq '.comments[] | "\(.createdAt) \(.author.login): \(.body)"'Read the thread before you flag "no evidence".
PR_COMMENTSis not optional colour: a prior council verdict, a maintainer's counter-capture, and the contributor's reply all live there and none of them appear in the diff. On PR #650 the autonomous run posted "reverses a confirmed-live finding with no live evidence attached" as its headline must-fix — 50 minutes after the contributor had posted a machine-generated capability matrix with a SHA-256 and a screenshot in that same thread. Truncate long bodies if you must, but never review a contested PR without reading what has already been said on it.
Reference files (read via git show origin/$head_branch:<path> — NOT local Read, because the working tree is on develop):
CLAUDE.md, AGENTS.md, docs/INDEX.mdSpike traversal (NEW v2.2) — do this BEFORE dispatch, and hand the result to the
reviewers. The council reasons about the diff. A measurement that refutes the diff's
premise does not appear in the diff, so no dimension can find it by reading well. Sweep
docs/superpowers/spikes/ for the surface the PR touches and pass every match into the
prompts of the dimensions that own that surface, as required reading:
total=$(ls docs/superpowers/spikes/*.md | wc -l)
gh pr diff <N> | grep -ohiE '/about|batchexecute|recaptcha|networkidle|SNlM0e|aisandbox[a-z-]*|agent-mode|referenceEntit[a-z]*|SignOutOptions|flow-[a-z-]+|ya29|SAPISID' \
| tr 'A-Z' 'a-z' | sort -u | while read -r t; do
hits=$(grep -rli -- "$t" docs/superpowers/spikes/ 2>/dev/null)
n=$(printf '%s\n' "$hits" | grep -c . )
# A term matching most of the corpus is a topic, not a lead. Skip it.
[ "$n" -gt 0 ] && [ "$n" -le $(( total / 3 )) ] && printf '## %s (%s)\n%s\n' "$t" "$n" "$hits"
doneDo not pipe the loop through sort -u — it separates the headers from their paths,
and the grouping is the readable part.
Selectivity is the whole trick, and it is measurable rather than a matter of taste.
Counted against the 30-spike corpus on 2026-09-16: flow.google.com hits 23 — a topic,
useless as a lead — while /about hits 9, including all three about-redirect spikes.
So filter out any term matching more than a third of the corpus; what remains is short
enough to actually read.
Read the verdict section of each hit, not the whole spike. If one contradicts something the PR asserts, that is a blocking finding before a single agent is dispatched — and it is cheaper than every dimension that would have failed to notice.
Written from PR #835. It added a migrated-host auth oracle that read the rendered DOM and claimed the signal was server-attested. Eight dimensions passed it — D1, D3, D6, D10 all read the auth path closely and none objected to the premise. The refutation was five days old and already in this repository:
2026-09-11-about-redirect-is-decided-client-side.mdmeasured that Flow's/abouthop is decided client-side with zero requests to Flow, and states outright that "the backend grants access while the frontend declines to open it." That single sentence invalidates the oracle. The diff touchedflow.google.comin fourteen places; a grep would have put the spike in front of D6 and D10 as required reading. The e2e caught it instead — by going red on a live account whose state moved mid-session. This is a routing failure, not a reviewer failure, and routing is fixable.
Memory traversal: for each TOUCHED_PATH, look up relevant slugs:
transports/ → [[migrated-host-driver-wire-lessons]], [[pr-must-verify-on-affected-surface]], [[flow-locale-leak-icon-ligatures]], [[ligature-carrier-differs-by-host]], [[playwright-click-no-downstream-event-signature]], [[rest-transports-drop-ui-fields]], [[image-video-mode-switch-symmetry]], [[ui-selector-drift-error-exit-23]]data/ → [[data-layer-overview]], [[data-layer-test-pollution-trap]], [[exit-code-16-data-store]], [[on-started-callback-recorder-safety]]auth/ → [[real-browser-auth-mandatory]], [[release-signing]]cli → [[release-back-merge-gap-recovery]], [[wheel-build-sanity-gate]]tests/ (any) → [[bdd-stubs-mirror-runtime-signatures]], [[background-e2e-pytest-pattern]], [[full-test-suite-ooms]], [[stale-test-discovery]], [[structlog-cache-logger-off-for-tests]]tests/features/ (BDD) → also [[bdd-stubs-mirror-runtime-signatures]]scripts/ → [[wheel-build-sanity-gate]], [[release-back-merge-gap-recovery]].planning/, docs/superpowers/ → [[release-spec-plan-memory-consolidation]]docs/, *.md → [[readme-hybrid-router-pattern]], [[doc-examples-are-untested-fixtures]], [[agents-md-vs-llms-txt]], [[pypi-readme-staleness-fix]]pyproject.toml, .github/ → [[release-spec-plan-memory-consolidation]], [[pr-hygiene-revert-and-multi-commit]], [[draft-pr-merge-trap]], [[pypi-rejected-filename-reusable]]| Dimension | Always? | Activates when… |
|---|---|---|
| D1 — Correctness & completeness | ✅ baseline | always |
| D2 — Code quality & best practices | ✅ baseline | always |
| D3 — Security | ✅ baseline | always |
| D4 — Tests & coverage | ✅ baseline | always |
| D5 — Memory hygiene & consolidation | ✅ baseline (NEW v2) | always |
| D6 — UI / live-verification | adaptive | any path under src/gflow_cli/api/transports/ or tests/e2e/ |
| D7 — Data-migration safety | adaptive | any path under src/gflow_cli/data/ or *.sql |
| D8 — CLI UX & help-text consistency | adaptive | any path matching src/gflow_cli/cli*.py or src/gflow_cli/commands/ |
| D9 — Docs cross-reference & drift | adaptive | ≥2 of: README.md, docs/**, CHANGELOG.md, AGENTS.md, CLAUDE.md, PLAN.md |
| D10 — Auth / reCAPTCHA / Chrome-profile | adaptive | any path under src/gflow_cli/auth/ or label security |
| D11 — Release-gate compliance | adaptive | pyproject.toml, src/gflow_cli/__init__.py, .github/workflows/, release/* branch |
| D12 — BDD step-stub signatures | adaptive | any path under tests/features/ |
| D13 — Dev / release scripts | adaptive | any path under scripts/ |
| D14 — Over-engineering / YAGNI | ✅ baseline (NEW v3) | always |
| D15 — Surface parity (CLI ↔ MCP ↔ docs) | adaptive (NEW v4) | any path matching src/gflow_cli/cli*.py, src/gflow_cli/mcp/**, src/gflow_cli/worker/**, or a changed --help/remediation string |
D15 specifics. gflow ships every capability twice, and no automated gate can see the two
copies drift: tests/mcp/test_cli_parity.py is command-level (a new leaf needs a mapping),
so an unmirrored option, an unread queued-payload key, or a docstring asserting removed
behaviour is green everywhere. Walk the six mirror axes in skills/check/SKILL.md step 1b
against the diff and report each as satisfied or drifted. Highest-yield check: for every
param the PR touches, confirm the key mcp/tools.py writes into the queue payload is the key
worker/codec.py reads — they are matched by string, so a mismatch type-checks and silently
no-ops. This dimension exists because #626 unlocked a CLI combination while mcp/tools.py
and docs/MCP.md went on telling agents it was rejected, through a fully green pipeline.
Baseline floor is non-negotiable. D1–D5 and D14 ALWAYS run. Docs-only PRs (100% paths under *.md, docs/**, CHANGELOG.md, README.md, LICENSE, AUTHORS) → D4 reframes from "test code coverage" to "docs-verification"; D5 still runs unchanged.
Use the superpowers:dispatching-parallel-agents skill. Send all agents in one message — they must run concurrently.
Each agent is a general-purpose agent (only subagent type that supports arbitrary parallel dispatch), but the prompt instructs it to invoke the relevant Claude Code skill inside the agent for specialized capability. Mapping:
| Dim | Agent invokes skill (via Skill tool) | Rationale |
|---|---|---|
| D1 Correctness | review (single-agent PR review built-in) | Provides PR-review framing for free |
| D2 Code quality | code-review | Reuse-and-quality lens |
| D3 Security | security-review | Built-in security-review skill — the most important specialization |
| D4 Tests | superpowers:test-driven-development (informed) | TDD principles + verification mindset |
| D5 Memory hygiene | (none — direct memory inspection) | Inspect memory files via git show + filesystem |
| D6 UI/live-verify | verify (if live-verify approved) | Runs the app to confirm behavior |
| D7 Data-migration | (none — direct code inspection) | |
| D8 CLI UX | (none — direct help-text inspection) | |
| D9 Docs drift | (none — direct doc-cross-ref) | |
| D10 Auth | security-review (subset of D3 with auth-specific lens) | |
| D11 Release-gate | (none — direct config inspection) | |
| D12 BDD | (none — direct stub-signature inspection) | |
| D13 Scripts | (none — direct script inspection) | |
| D14 Over-engineering | ponytail:ponytail-review (soft dep — invoke if installed; else apply the inline YAGNI rubric in § Per-dimension specifics) | "Should this code exist at all?" — the lens D1–D2 don't cover |
On the D14 soft dependency: ponytail:ponytail-review is a user-local plugin, not shipped with this repo, so it is optional (same pattern as the agy extra reviewer in issue-resolve). The over-engineering lens is owned by this skill (the rubric below); the plugin only accelerates it. An agent without the plugin applies the rubric directly and still produces a D14 verdict — never skip D14 because the plugin is absent.
You are one of <N> parallel reviewers on a council reviewing PR #<N> of `gflow-cli` at C:\development\github\gflow-cli.
Your dimension is **<DIMENSION NAME>**. Other agents handle <other dimensions> — do NOT duplicate their work.
**PR head branch:** `<head_branch>` (head SHA: `<head_sha>`).
**Base branch:** `<base_branch>`.
**🚨 CRITICAL — file reading + verification rules (v2 stale-tree-reads fix + v2.1 verify-before-claim):**
The orchestrator's working tree is on `<base_branch>` (typically `develop`), NOT the PR head. If you `Read` a file in `C:\development\github\gflow-cli\`, you get the PRE-PR copy and will produce FALSE POSITIVES like "file X doesn't exist" or "claim Y not applied" when in fact X and Y are present on the PR head.
**Mandatory rules:**
1. **For file inspection** — ALWAYS use `ctx_execute(language="shell", code="git show <REVIEWED_SHA>:<path>")` (or `git show origin/<head_branch>:<path>`). For the diff itself, `gh pr diff <N>`. For metadata, `gh pr view <N> --json ...`. NEVER use `Read` on a repo file unless you have verified `git branch --show-current` returns `<head_branch>`.
2. **Verify-before-claim — applies to BEHAVIOR claims, not just file existence (v2.1 NEW):** any "feature/setting/marker/env-var is NOT present" or "is missing" or "is wrong" claim MUST be backed by an explicit `git show <REVIEWED_SHA>:<path> | grep <expected>` (or equivalent) that you ran. Quote the exact command + its output in your report. Do NOT rely on memory or summary; the v2 council had a real false-negative where D5 claimed "PR doesn't add addopts filter" because the agent assumed-not-verified — the addopts WAS added but the agent never ran `git show <SHA>:pyproject.toml`. Treat your own claims like a code reviewer: would this assertion survive a hostile re-review? If yes, ship it; if uncertain, re-verify.
3. **SHA pinning verification (v2.1 NEW):** before reporting findings, run `git rev-parse $REVIEWED_SHA` (or `git ls-remote origin <head_branch>`) and confirm your reads were against `<REVIEWED_SHA>`. If the author has pushed new commits during your dispatch, your findings still apply to `<REVIEWED_SHA>` — the synthesizer will note any divergence at Phase 5 step 5.
**Specialized skill (if listed for your dimension):** before deep analysis, invoke the Skill tool for `<skill_name>` to load specialized review guidance. Apply that skill's checklists in addition to the dimension-specific questions below.
Assess specifically:
1. <dimension-specific question 1, with code citation hooks>
2. <…>
**Mandatory memory you MUST consult and cite if relevant:** <fixed slug list from the Dimension → Slugs table>.
Output a structured report under 500 words:
- Verdict: GREEN / YELLOW / RED
- Must-fix (numbered, file:line refs)
- Nice-to-have (numbered)
- Confirmed-<good/safe/correct> (1-line bullets)
If you have nothing to flag, say so explicitly and state GREEN with a one-line justification — do NOT manufacture findings.
If you are NOT sure a finding is real because it depends on file content, VERIFY via `git show origin/<head_branch>:<path>` before reporting it. Stale-tree false positives are a documented v1 council bug.Slugs resolve directly:
[[<slug>]]→docs/superpowers/memory/<slug>.md. Open exactly the files your dimension's row names — no searching, no judgement call about what is relevant. The directory is in the repo, so it is available to every agent that can read the tree, including the sandboxed autonomous runs that have no access to a maintainer's local store.
scripts/ci/check_council_memory.pyenforces the round trip both ways: a citation with no file fails CI, and a file no dimension cites fails CI too. So a gap announces itself instead of quietly degrading routing back into a search — which is what this table previously did, when the slugs were "conceptual anchors" that resolved to nothing.These files are a published subset of the maintainer's working memory, not a mirror of it: review-relevant facts only, with private identifiers stripped. If a slug's file is missing, say so in your report and move on — never fabricate its contents.
| Dim | Mandatory memory slugs |
|---|---|
| D1 | [[pr-must-verify-on-affected-surface]], [[video-model-capability-matrix]], [[flow-capabilities-are-cohort-dependent]], [[migrated-refusal-is-a-dom-card-not-a-wire-record]] |
| D2 | [[ruff-format-scope-is-src-tests]], [[git-add-all-sweeps-scratch-files]] |
| D3 | [[real-browser-auth-mandatory]], [[release-signing]] |
| D4 | [[e2e-evidence-is-a-contributor-deliverable]], [[force-color-breaks-cli-tests]], [[pr-must-verify-on-affected-surface]], [[full-test-suite-ooms]], [[stale-test-discovery]], [[structlog-cache-logger-off-for-tests]], [[windows-running-launcher-blocks-uv-upgrade]] |
| D5 | [[memory-is-working-dir-keyed]], [[release-spec-plan-memory-consolidation]], [[pr-council-review-stale-tree-reads]] (this very bug, as the council should self-improve) |
| D6 | [[ui-selector-drift-error-exit-23]], [[credit-free-route-abort-verification]], [[flow-credits-videos-only]], [[flow-recon-must-run-on-denon82-ffroliva-migrated]], [[flow-locale-leak-icon-ligatures]], [[ligature-carrier-differs-by-host]], [[playwright-click-no-downstream-event-signature]], [[rest-transports-drop-ui-fields]], [[image-video-mode-switch-symmetry]], [[verification-ledger-5-layer]], [[migrated-host-driver-wire-lessons]], [[content-policy-text-scan-false-positives-on-page-chrome]] |
| D7 | [[on-started-callback-recorder-safety]], [[data-layer-test-pollution-trap]], [[exit-code-16-data-store]] |
| D8 | (none mandatory) |
| D9 | [[prose-conflicts-hide-in-disjoint-files]], [[doc-examples-are-untested-fixtures]], [[readme-hybrid-router-pattern]], [[agents-md-vs-llms-txt]], [[pypi-readme-staleness-fix]] |
| D10 | [[real-browser-auth-mandatory]] |
| D11 | [[release-back-merge-gap-recovery]], [[wheel-build-sanity-gate]], [[pypi-rejected-filename-reusable]], [[draft-pr-merge-trap]], [[windows-running-launcher-blocks-uv-upgrade]] |
| D12 | [[bdd-stubs-mirror-runtime-signatures]] |
| D13 | [[wheel-build-sanity-gate]] |
| D14 | (none mandatory; apply the YAGNI rubric below) |
| D15 | [[mcp-is-first-class-across-skill-chain]] |
Closes #N acceptance criteria met)?--no-verify / signature-bypass?Mandatory affected-surface check: identify the runtime surface (T2V / I2V / data / CLI / auth / etc.). If the suite doesn't exercise that exact surface → automatically YELLOW. Cite the test file:line proving coverage, or state explicitly no such test exists.
Mandatory e2e-evidence check (since PR #675). If the PR touches a Flow surface, it owes an e2e test — one the author ran, with its result, or a new one under tests/e2e/. Offline-green is structurally incapable of proving a blackbox still behaves as captured ([[e2e-evidence-is-a-contributor-deliverable]]). Score it:
tests/e2e/ file:line, confirm it exists at REVIEWED_SHA (git show $REVIEWED_SHA:<path>), and confirm it exercises the surface this PR changed. A named test that passes but never touches the changed code path is the [[pr-must-verify-on-affected-surface]] failure with an e2e label on it.Three traps to avoid:
[[verification-ledger-5-layer]], not this. It is a narrative record of one run; an e2e test is a re-runnable regression. Never record live evidence as satisfying the e2e rule — that substitution was attempted on #669 within an hour of the rule landing..feature file is not an e2e test. It runs offline against fakes.e7a09d8, 2026-09-05 19:15Z) predate the rule — flag it forward-looking, do not hold it against them. Anchor on the merge, not the calendar day: #669 (11:28Z) and #671 (13:38Z) were both opened that same day, hours before the rule existed, and are exactly the PRs this clause protects.Test pyramid placement? Behavior vs shape? Coverage delta meaningful vs dead?
~/.claude/projects/C--development-github-gflow-cli/memory/ (file-based memory — primary source).mcp__*memory*, mcp__*mempalace*, mcp__*mem0*, mcp__*context-mode* (for indexed KB), or any tool the user explicitly mentioned. If found, invoke its "list" / "search" / "stats" tool to enumerate stored items. If no such tool is loaded in-session, state explicitly "no MCP memory server loaded; D5 scope = file-based memory only".UNAVAILABLE, never GREEN. Verify you can
actually read it (ls the path, quote the file count) before any verdict. Memory is keyed
by working-directory path, not repo identity, so a fresh clone — every autonomous
sandbox run — starts with an empty namespace unless the store was synced to that host.
Reporting "no memory entry contradicts this PR" from a directory you could not read is a
false negative dressed as a pass: it is the assumed-not-verified failure this dimension
already forbids, and it happened on PR #650, where video-model-capability-matrix.md
recorded that exact PR as REJECTED while D5 reported GREEN from an empty mount.MEMORY.md index still in sync (entries listed correspond to existing files)? Flag drift.[[release-spec-plan-memory-consolidation]]: any spec/plan in docs/superpowers/ or .planning/ that's now post-ship should be deleted on merge, with durable bits extracted to memory. When D5 fires RED on consolidation, D9 (Docs drift) defers to D5 — do not double-list the same plan-file finding in both dimensions.git show or filesystem cat) and the line range. The v2 run had a real false-claim here.new_project_clicked/submit_clicked/frame_attached/image_mode_entered/count_setter_completed/reference_attached) in PR body? Absent → YELLOW per [[pr-must-verify-on-affected-surface]].try/except DataStoreError — bare callback in paid-generation path = RED). Schema compat. Migration idempotent. DataStoreError vs DataMigrationError vs DataIntegrityError semantics.--kebab-case? --help golden-snapshot tests updated? Docstring examples runnable?[[real-browser-auth-mandatory]])? Profile-dir SecurityError boundary intact? No new secret-shaped strings?pyproject.toml ↔ src/gflow_cli/__init__.py (RED if drift). [Unreleased] emptied + new version added. Wheel build clean. Back-merge gap addressed._run_* kwarg → mirror in tests/features/_fake_* stubs (silent TypeError trap).[[windows-dev-quirks]]); release scripts include wheel-build sanity gate.ponytail:ponytail-review is installed, invoke it; otherwise apply this rubric directly to the added lines:file:Lline: delete/inline/shrink — what replaces it) and, when meaningful, net: -N lines possible. A single smoke test / assert-based self-check is the minimum, never flag it as bloat. RED only for genuinely dead/unreachable code; over-generality is Nice-to-have unless it's load-bearing.UNKNOWN, downgrade consensus by one step (GREEN→YELLOW, YELLOW→YELLOW, RED→RED). Never wait indefinitely.D0 (mechanical CI gate, Pre-flight step 6) RED or UNVERIFIED → the overall verdict cannot be GREEN. A D0 RED forces RED even if every LLM dimension is GREEN — CI will reject the tree. A D0 UNVERIFIED caps the verdict at YELLOW with an explicit "confirm CI green before merge" action.git show <REVIEWED_SHA>:<path> (NOT git show origin/<head>:<path> — the remote may have moved since dispatch). If any agent claim contradicts <REVIEWED_SHA>, mark it FALSE POSITIVE in the report — do not silently drop, so accuracy is auditable.git show verification. The v2 council had a real false-claim here from D5 (assumed-not-verified).gh pr view <N> --json headRefOid --jq '.headRefOid'. If the current head differs from <REVIEWED_SHA>, note this prominently in the report: "Author pushed N new commits during the review. This verdict reports against <REVIEWED_SHA>; the new commits may have resolved findings (re-run the council to confirm)." Do NOT try to re-review the new commits silently.AskUserQuestion with three options — Run now (~1 Flow credit per locale), Block merge — add to PR body as required reviewer action, Skip and accept risk. Cite [[verification-ledger-5-layer]]. Do NOT spend credits without affirmative click.AskUserQuestion offering to APPLY the memory edits/additions/deletions in the same PR or as a follow-up.AskUserQuestion MUST include a "Dismiss YELLOW with justification (logged)" option. Dismissal requires a one-line reason appended to the PR body or comment, so the override is auditable.# PR #<N> — Council Review Verdict
## Consensus: <emoji> <GREEN | YELLOW | RED>
| Dimension | Verdict | Headline |
|---|---|---|
| <D1> | … | <one-line summary> |
| <D2> | … | … |
## Must-fix (<N>)
1. **<short title>** — `<file>:<line>`. <description>. <which dimension flagged>.
2. …
## Nice-to-have (<N>)
1. …
## False positives (filtered out — agents misread stale tree)
- D<n> claim about <…>: verified absent on PR HEAD via `git show origin/<head>:<path>` — dropping.
## Confirmed-good (high-confidence positives)
- …
## Memory actions (D5)
- ADD: <slug> capturing <pattern>
- UPDATE: <slug> — claim X is now stale because <…>
- DELETE: <slug> — superseded by <…>
## How to proceed
<AskUserQuestion>Always end with an AskUserQuestion.
Upon completing a Branch / Council Review:
/gflow:live-verify)/gflow:issue-resolve <N>)Provenance: v1 protocol validated on PR #93 (locale selectors, 2026-05-26). v2 evolved 2026-05-27 after running on PR #95 surfaced two real defects: (a) sub-agents read stale working-tree files producing 5+ false positives (memory
[[pr-council-review-stale-tree-reads]]), (b) baseline missed memory-hygiene as a dimension. Both fixed in v2.
general-purpose agents that invoke specialized skills (security-review, code-review, verify, review) inside their prompt for dimension-specific capability.gh pr merge, no git push, no gh pr close./review is the single-agent Claude-Code built-in (one-pass, cheap) — use for spot-checks or draft iteration. /gflow:pr-council-review is the council version for pre-merge audits and high-risk surfaces..claude/commands/gflow/pr-council-review.md is a thin wrapper. Other tools (Antigravity / Codex / Cursor / Aider) consume this file directly via their own skill-loading mechanism./gflow:branch-review)Same council, but run against a local feature branch instead of an open PR — pre-PR review. The slash command /gflow:branch-review invokes this skill in branch mode.
AGENTS.md + CLAUDE.md) is kept.All other sections (§ 3 Detect adaptive dimensions, § 4 Dispatch, § 5 Synthesize, § 6 Report, § 7 Provenance) apply unchanged.
--base <ref> — base reference to diff against. Default: develop.
| Step | PR mode | Branch mode |
|---|---|---|
| Reviewed SHA | gh pr view <N> --json headRefOid --jq '.headRefOid' | git rev-parse HEAD |
| Head branch name | gh pr view <N> --json headRefName --jq '.headRefName' | git branch --show-current |
| Diff | gh pr diff <N> | git diff <base>..HEAD |
| Changed files | gh pr view <N> --json files --jq '.files[].path' | git diff --name-only <base>..HEAD |
| Recent commits | gh pr view <N> --json commits … | git log --oneline <base>..HEAD |
| PR metadata (title, body, labels, CI checks) | gh pr view <N> --json … | N/A — skip; use git log <base>..HEAD for narrative |
| Output channel | terminal | terminal + optional .planning/branch-review-<branch>-<ts>.md (gitignored). Never posts to a PR. |
Steps that stay: § 0 step 2 (AGENTS.md AND CLAUDE.md exist). Step 5 (REVIEWED_SHA capture) is replaced as below.
git rev-parse --is-inside-work-tree returns true. Otherwise: "Not in a git repo."current_branch = git branch --show-current. Must be non-empty AND not main AND not develop. If empty (detached HEAD) or matches a protected branch, refuse with: "Branch-review is for feature branches. For a PR, run /gflow:pr-council-review <N>. For ad-hoc audit, check out a feature branch first."git diff --quiet <base>..HEAD — exit code MUST be non-zero (there must be a diff). If exit code is zero (no diff), exit with: "No commits ahead of <base> — nothing to review."REVIEWED_SHA = git rev-parse HEAD — pin up front and pass to every dispatched agent.Same rule as PR mode (§ 4 mandatory rule 1): read via git show $REVIEWED_SHA:<path>. Even though the working tree is ON the reviewed branch, pinning to REVIEWED_SHA keeps the verdict stable if the branch moves mid-review.
release/* branch downgradeIf current_branch matches release/*, D11 (Release-gate compliance) will RED-flag the in-progress CHANGELOG / version bump as expected for a release-in-progress. The synthesizer auto-downgrades D11 RED → YELLOW when git tag --list "v*" --contains HEAD returns empty (release tag not yet cut). Surface the downgrade in the verdict so users don't chase a false negative. Per memory [[release-back-merge-gap-recovery]] + [[wheel-build-sanity-gate]], this downgrade does NOT suppress findings about missing back-merge or skipped wheel-sanity.
At Phase 5 (Synthesize), compare git rev-parse HEAD to REVIEWED_SHA. If diverged (user committed mid-review, ran git stash pop, rebased, etc.), prepend the report with: "Local HEAD moved during review (was <X>, now <Y>). Findings apply to <X>." Do NOT silently re-review the new commits.
.planning/branch-review-<branch>-<ts>.md (path is gitignored per the repo's .gitignore for .planning/).gh pr comment, no gh pr review, no gh pr merge. Branch mode is local-only and read-only.Dimension detection (§ 3), memory traversal (§ 2 — same Dimension → Slugs table), agent dispatch (§ 4), synthesis rules (§ 5), and report shape (§ 6). Same baseline D1–D5 + adaptive D6–D13. Same per-dimension specialized-skill mapping. Same false-positive filter and YELLOW soft-block treatment.
Single source of truth. ~90% of the council protocol is shared between PR mode and branch mode; only the input channel (PR vs git diff) and the output channel (terminal vs terminal + .planning/) differ. A sibling skill would drift over time.
pr-triage-autopilot)When invoked unattended by hermes-ops's automated triage runner, the agent and the reviewer sub-agents resolve all interactive gates and feedback loops with the following fixed resolutions:
| Interactive gate (existing protocol) | Autonomous-mode resolution |
|---|---|
| § 0 step 4, draft-PR confirmation | N/A — draft PRs are filtered out upstream by the Stage 0 gate. |
| § 5 step 6, live-verify credit-spend gate | Always skip; never run live e2e tests or spend Flow/Veo credits. On a GREEN verdict, carry this in the mandatory "Next step — live validation" report section (see Live-validation ceiling below), not as a loose informational note. |
| § 5 step 7, memory-action gate | Report the suggested memory actions in the text, but never auto-apply or write them. |
| § 5 step 8, YELLOW-dismiss escape valve | Never auto-dismiss or override. Report the consensus verdict (YELLOW/RED) exactly as-is. |
| § 6, final "How to proceed" User Question | Omit the interactive question. Print the compiled markdown report directly to stdout. |
| SonarCloud required-gate (CI policy) | Fork PR + skipped/missing SonarCloud check -> treat as informational note, not a block. |
| D4 e2e-evidence check (§ Per-dimension specifics) | Report, never run. The sandbox has no Flow auth and must not spend credits, so the agent judges only whether the PR carries e2e evidence — it never executes pytest -m e2e. Missing evidence on a Flow surface is still reported as a must-fix; a GREEN verdict here means "evidence present and plausible", never "e2e passed". |
The sandbox cannot exercise the code live (network egress restricted, no Flow auth mounted, credit spend forbidden above), so the e2e suite and /gflow:benchmark are never run in this mode. An autonomous GREEN means "static review green, live validation outstanding" — never merge-ready. Rules:
/gflow:benchmark (operator-run, outside the sandbox, with real credentials/credits) is the final triage gate; it runs deliberately last, only once everything else is green, so credits are never spent on a PR that static review would have bounced; and it is expected to surface issues and return the PR to development — a bounce there is the process working, not a review miss.The final report must end with a single, machine-parseable structured line printed to stdout. This allows the host orchestrator script to parse the outcome without parsing free-form markdown:
SUMMARY_VERDICT: [GREEN|YELLOW|RED] | MUST_FIX_COUNT: [count] | PR_URL: [url]
write_file, replace_file_content, run_command) are forbidden.PR_TRIAGE_ENGINE — review-engine seam on the host orchestrator. Default council-claude (this skill); any other value refuses to start (council-multi-cli is reserved). The ledger records the engine used for each verdict.$HERMES_OPS_DIR/scripts/notify/email_notify.py (hermes-ops' Resend notifier) for four events only: council verdict COMPLETED, NEEDS-HUMAN flag, DEFERRED_SIZE, and FAILED_PERMANENT. Notifier failure or absence never blocks the run — the ledger and the GitHub-posted report remain the source of truth.© ffroliva, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/pr-council-review of ffroliva/gflow-cli.
Open the folder on GitHubat commit d44abc8
PR Council Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| PR Council Review this skillffroliva/gflow-cli | 269 | — | ~12k | Automated safety check: Pass | MIT | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.5k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Fix Vulnslinuxfoundation/insights | 282 | — | ~3.8k | Automated safety check: Notes | MIT | |
| Claude Securityanthropics/claude-plugins-official | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Trailmark Review Gatetrailofbits/skills | 7.5k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Differential Security Reviewtrailofbits/skills | 7.5k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 |
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
linuxfoundation/insights
Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).
anthropics/claude-plugins-official
Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.
trailofbits/skills
Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.
trailofbits/skills
Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.
aws/agent-toolkit-for-aws
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
ffroliva/gflow-cli
A skill your agent uses when the user wants to drive Google Flow (Veo image-to-video, Veo text-to-video, Imagen / Nano Banana image generation) from the terminal or a script — including…
ffroliva/gflow-cli
A skill your agent uses when triaging a GitHub issue for gflow-cli — a reporter's bug claim, a freshly-filed issue, or deciding whether and how to act on one.
ffroliva/gflow-cli
A skill your agent uses when an assessed gflow-cli issue (verdict CONFIRMED-BUG or LIKELY-BUG) has localized, verifiable scope and should be driven to a fix.
ffroliva/gflow-cli
Two-part gate for gflow-cli feature/fix work. An agent skill from ffroliva/gflow-cli.
ffroliva/gflow-cli
A skill your agent uses when the user wants a finished video out of gflow rather than a single clip — a scripted scene, a talking-head or dialogue piece, an explainer, a product montage, a story…
ffroliva/gflow-cli
Auto-fix lint and formatting, then report types and tests. An agent skill from ffroliva/gflow-cli.
Works with
Categories
Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review). PR Council Review is an agent skill from ffroliva/gflow-cli. Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).
PR Council Review fits situations like: tasks that involve Security review; tasks that involve AI video generation.
Run `npx skills add ffroliva/gflow-cli --skill pr-council-review -a claude-code`. Or copy the skill folder (skills/pr-council-review in ffroliva/gflow-cli) into .claude/skills/pr-council-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ffroliva/gflow-cli --skill pr-council-review -a codex`. Or copy the skill folder (skills/pr-council-review in ffroliva/gflow-cli) into .agents/skills/pr-council-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ffroliva/gflow-cli --skill pr-council-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-council-review, .gemini/skills/pr-council-review, .github/skills/pr-council-review and .opencode/skills/pr-council-review in your project.
Going by SKILL.md and its folder, PR Council Review needs the command-line tools its instructions call (gh, git, uv, ruff and pytest). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use gh, git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
PR Council Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 12k tokens (SKILL.md is roughly 47k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with PR Council Review: Trailmark Graph Evolution (trailofbits/skills, 7.5k stars), Fix Vulns (linuxfoundation/insights, 282 stars), Claude Security (anthropics/claude-plugins-official, 38k stars) and Trailmark Review Gate (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ffroliva (a GitHub user) maintains it in ffroliva/gflow-cli, which has 269 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.
Source: ffroliva/gflow-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.