Agent skill

Finn Review

by finna in finna/Finn-loop

Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels.

MITAuto-check passed

Install Finn Review

skills CLI
$ npx skills add finna/Finn-loop --skill finn-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install finna/Finn-loop finn-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/finna/Finn-loop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/finn-review .claude/skills/finn-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
finn-review
GitHub stars
319
Token cost
~1.1k tokens
SKILL.md length
513 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels.

  • Works in 5 steps: Find a PR needing review → Read the contract and code → Check merge evidence → …
  • Asked to run Finn-loops reviewer
  • SKILL.md covers 1. Find a PR needing review, 2. Read the contract and code, 3. Check merge evidence and 4. Post one verdict, plus 1 more section
  • Calls gh

What it does

Finn Review is an agent skill from finna/Finn-loop. Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels. Use when asked to run Finn-loop's reviewer or review its PR queue. Designed for /loop; never merges or pushes code.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub and Linear. The repository describes itself as: The Finn-loop: a 3-skill AI software factory for Claude Code — spec, build, review. Humans merge. The licence is MIT.

When your agent uses it

  • Asked to run Finn-loops reviewer
  • Review its PR queue

Example prompts

  • “/finn-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Find a PR needing review
  2. Read the contract and code
  3. Check merge evidence
  4. Post one verdict
  5. Hard limits

What it can do on your machine

Read from SKILL.md and the folder at commit 7941b62. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Finn Review loads about 1.1k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 513 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from finna/Finn-loop at commit 7941b62, republished under its MIT licence (© finna). 513 words, ~1,106 tokens.

Download SKILL.mdSave it as .claude/skills/finn-review/SKILL.md (or your agent's skills folder).
name
finn-review
description
Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels. Use when asked to run Finn-loop's reviewer or review its PR queue. Designed for /loop; never merges or pushes code.

Finn-loop reviewer

One pass = one PR reviewed. Under /loop, each iteration runs this skill once.

1. Find a PR needing review

bash
gh pr list --state open --json number,title,labels,isDraft,headRefOid,updatedAt,url

Skip drafts. For each PR, find the latest comment whose first line is Finn-loop review of COMMIT_SHA.

Skip a PR when that recorded SHA equals its current headRefOid and it already has loop-approved, loop-changes-requested, or needs-human-review. Review it again when new commits landed after the recorded SHA. If nothing needs review, say so and end the pass.

2. Read the contract and code

  • Parse the linked issue identifier from Closes TEAM-NNN in the PR body and fetch the full Linear issue, including comments and relations. No linked issue is a must-fix finding.
  • Read the full diff and every changed file in context.
  • Review only against the linked issue: acceptance-criteria gaps, defects, broken data flow, unnecessary scope expansion, security problems, missing loading/error states, and code future agents will struggle to modify.
  • Do not suggest unrelated improvements unless they are severe.

Every must-fix code finding starts with one of:

  • [AC-N] — the PR does not satisfy that acceptance criterion
  • [DEFECT] — the implementation is broken while staying inside scope
  • [SECURITY] — a severe security issue blocks shipping
  • [CI] — a required GitHub check failed

Non-goals are binding. If fixing a finding would require behavior excluded by an NG-N, do not prescribe code. Record [SCOPE-CONFLICT AC-N ↔ NG-N] with the exact contradiction and mark the PR for human escalation.

3. Check merge evidence

Inspect the current PR head, mergeability, and required checks:

bash
gh pr view NUMBER --json headRefOid,mergeable,mergeStateStatus
gh pr checks NUMBER --required --json bucket,name,state,link
  • If required checks are pending or mergeability is still unknown, report that the PR is waiting and end without posting a verdict or changing labels. A later loop pass will retry it.
  • Failed required checks are [CI] must-fix findings.
  • A merge conflict is a [DEFECT] must-fix finding.
  • If the repository has no required checks, mark the PR for human escalation; do not apply loop-approved. Finn-loop does not treat missing CI as green.

Review the exact headRefOid used for this evidence. Re-fetch it immediately before posting. If it changed, discard the review and start again on a future pass.

Show full SKILL.md (170 more words)Show less

4. Post one verdict

Post one comment in this structure:

md
Finn-loop review of COMMIT_SHA

CI: required checks passed | failed | not configured
Mergeability: clean | conflicting

## Review

Summary: one or two plain-language sentences on what this PR does.

## 1. Must fix before merge

None.

## 2. Should fix soon

None.

## 3. Safe to merge

Yes — automated review evidence is complete. A human still makes the merge decision.

Then set labels based on the verdict, checking existing labels before removing them so an absent label does not fail the command:

  • No must-fix and no new escalation: add loop-approved; remove loop-changes-requested. Preserve a pre-existing needs-human-review label because it may represent a separate high-risk human gate.
  • Must-fix present: add loop-changes-requested; remove loop-approved.
  • Scope conflict or no required CI: add needs-human-review; remove both loop-approved and loop-changes-requested; set "Safe to merge" to No — human decision required.

The escalation path deliberately leaves the automated repair queue. A human must resolve the reason, change the issue or repository configuration as needed, and remove needs-human-review before Finn-loop reviews that unchanged commit again.

5. Hard limits

  • Never merge or enable auto-merge.
  • Never push commits to the PR branch.
  • Never approve or request changes through a formal GitHub review. Use one comment plus labels because the loop may run on the PR author's token and GitHub rejects self-reviews.
  • loop-approved is evidence for a human, not merge authorization.

© finna, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/finn-review of finna/Finn-loop.

Open the folder on GitHubat commit 7941b62

Compare with similar skills

Finn Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Finn Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Finn Review this skillfinna/Finn-loop319—~1.1kAutomated safety check: PassMIT
Draft Pull Request Creatorwordpress-mobile/WordPress-Android3.2k—~881Automated safety check: NotesGPL-2.0
Superset Automatesuperset-sh/superset15k—~1.4kAutomated safety check: PassCustom licence
Cursor Agents Workflowlangfuse/langfuse36k—~1.7kAutomated safety check: PassCustom licence
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Specgetsentry/sentry-react-native1.8k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Draft Pull Request Creator

    wordpress-mobile/WordPress-Android

    Commits and pushes current changes, writes a pull request title and body from the branch history and template, and opens a draft PR on GitHub after you approve it.

    3.2k GitHub stars~881 tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Superset Automate

    superset-sh/superset

    Turns a recurring chore into a scheduled or event-triggered Superset agent, drafting its prompt, picking a target and trigger, and reviewing the first run.

    15k GitHub stars~1.4k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Cursor Agents Workflow

    langfuse/langfuse

    Human handoff, Linear branch names, reviewable (non-draft) PRs, the cursor GitHub label, Claude, Greptile, and Codex review comments, preview test steps, proof of work posted on the GitHub PR, and…

    36k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Spec

    getsentry/sentry-react-native

    Official

    Produce a verified spec — problem, desired outcome, and acceptance criteria — before building.

    1.8k GitHub stars~1.1k tokensUpdated 2 days ago
    Product & Project ManagementAuto-check passed
  • Managing Git Workflow

    hashintel/hash

    Git and pull-request workflow for HASH, including conditional Linear conventions and merge-queue diagnostics.

    1.7k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed

More from finna/Finn-loop

  • Finn Build

    finna/Finn-loop

    Claim the next safe agent-ready issue from Linear, implement it, and open a PR.

    319 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Finn Spec

    finna/Finn-loop

    Interview the user about a raw idea until confident, then file a build-ready issue in Linear.

    319 GitHub stars~824 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Finn Review

What does Finn Review do?

Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels. Finn Review is an agent skill from finna/Finn-loop. Review open PRs against their linked Linear issues and required GitHub checks, then post a three-group verdict with Finn-loop labels.

When should I use Finn Review?

Finn Review fits situations like: asked to run Finn-loops reviewer; review its PR queue.

How do I install Finn Review in Claude Code?

Run `npx skills add finna/Finn-loop --skill finn-review -a claude-code`. Or copy the skill folder (skills/finn-review in finna/Finn-loop) into .claude/skills/finn-review in your project. Claude Code loads it when a task matches its description.

How do I install Finn Review in Codex?

Run `npx skills add finna/Finn-loop --skill finn-review -a codex`. Or copy the skill folder (skills/finn-review in finna/Finn-loop) into .agents/skills/finn-review in your project. Codex loads it when a task matches its description.

Can I use Finn Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add finna/Finn-loop --skill finn-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/finn-review, .gemini/skills/finn-review, .github/skills/finn-review and .opencode/skills/finn-review in your project.

What does Finn Review need to run?

Going by SKILL.md and its folder, Finn Review needs the command-line tools its instructions call (gh).

Does Finn Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Finn Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Finn Review use?

Finn Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Finn Review use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Finn Review?

Skills that share tags, products or a category with Finn Review: Draft Pull Request Creator (wordpress-mobile/WordPress-Android, 3.2k stars), Superset Automate (superset-sh/superset, 15k stars), Cursor Agents Workflow (langfuse/langfuse, 36k stars) and Warp Vulnerability Triage (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Finn Review?

finna (a GitHub user) maintains it in finna/Finn-loop, which has 319 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on July 23, 2026.

Source: finna/Finn-loop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.