Agent skill

PR Review

by fossasia in fossasia/eventyay-interpretation

A skill your agent uses to review pull requests for VoxBento.

Apache-2.0Auto-check passedDevelopment

Install PR Review

skills CLI
$ npx skills add fossasia/eventyay-interpretation --skill pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay-interpretation pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay-interpretation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pr-review .claude/skills/pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review
GitHub stars
1.6k
Token cost
~1.1k tokens
SKILL.md length
458 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to review pull requests for VoxBento.

  • Works in 9 steps: Invariant Compliance → Auth & Security → Database Changes → …
  • Review pull requests for VoxBento
  • SKILL.md covers PR Review Checklist, High-Risk Patterns to Flag and Running Validation Locally
  • Calls uv and node

What it does

PR Review is an agent skill from fossasia/eventyay-interpretation. Use this skill to review pull requests for VoxBento. Covers correctness, security, architecture compliance, and testing.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with Python. The repository describes itself as: A plugin for live interpretation of video streams. The licence is Apache-2.0.

When your agent uses it

  • Review pull requests for VoxBento
  • Tasks that involve Pull requests

Example prompts

  • “/pr-review”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Invariant Compliance
  2. Auth & Security
  3. Database Changes
  4. Route Changes
  5. WebSocket Protocol
  6. Transcription Changes
  7. Frontend Changes
  8. Tests
  9. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 1ca0139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review loads about 1.1k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay-interpretation at commit 1ca0139, republished under its Apache-2.0 licence (© fossasia). 458 words, ~1,124 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review/SKILL.md (or your agent's skills folder).
name
pr-review
description
Use this skill to review pull requests for VoxBento. Covers correctness, security, architecture compliance, and testing.

Skill: PR Review

Use this skill to review pull requests for VoxBento. Covers correctness, security, architecture compliance, and testing.


PR Review Checklist

1. Invariant Compliance
  • No Vue, React, jQuery, inline <script> blocks.
  • No Flask, Socket.IO, aiortc.
  • No AudioContext.destination for interpreter mic audio.
  • from __future__ import annotations at top of every new/modified Python file.
  • New Python code uses portal.* imports (not relative imports or new top-level modules).
  • uv.lock only changed if uv sync --python 3.13 --dev was run.
  • Role is never trusted from client data in WS handlers.
2. Auth & Security
  • All redirects use safe_redirect() — no raw RedirectResponse(url=user_input).
  • No open redirect: next_url / next query params validated before use.
  • Admin routes have dependencies=[Depends(require_admin)].
  • API keys stored encrypted via portal.crypto.encrypt_val; never stored plaintext.
  • No secrets logged or returned in API responses.
  • JWT tokens use settings.effective_jwt_secret; no hardcoded secrets.
  • New form inputs validated before DB write.
3. Database Changes
  • Model changes in portal/models.py have a corresponding Alembic migration.
  • Migration uses batch_alter_table for column operations on SQLite (see migration 008 as reference).
  • New DB columns have appropriate defaults and nullability.
  • Relationships that need mediamtx_path use joinedload(DBBooth.event).
  • CRUD functions use async with get_session() as session: pattern.
4. Route Changes
  • New routes have correct auth dependency.
  • Error cases raise HTTPException with appropriate status codes.
  • New page routes redirect to login if unauthenticated (using safe_redirect).
  • New API routes respect _require_access(credentials, token) if applicable.
5. WebSocket Protocol
  • New WS message types have a handler in fastapi_app.py ws_booth loop.
  • session.granted_role used, not data['role'].
  • New Booth.as_public_dict() fields are intentional (broadcast to all clients).
6. Transcription Changes
  • New provider implements TranscriptionProvider ABC.
  • New provider added to PROVIDERS dict in worker.py.
  • New provider registered in ProviderEnum and ALLOWED_MODELS.
  • New API key column follows Fernet encryption pattern.
  • Worker lifecycle handles CancelledError and cleans up ffmpeg process.
Show full SKILL.md (166 more words)Show less
7. Frontend Changes
  • Plain ES modules — no import maps, no build step, no npm.
  • node --check static/js/*.js passes.
  • No AudioContext.destination for mic audio.
  • New UI elements have IDs/data attributes expected by JS (not hardcoded strings).
  • WHIP/WHEP URLs constructed from portal.dataset.* — not hardcoded.
8. Tests
  • New functionality has at least one test.
  • Tests use anyio + pytest.mark.anyio fixture (see conftest.py).
  • DB tests use configure('sqlite+aiosqlite:///:memory:') + init_db().
  • No test uses production DB URL.
  • uv run pytest tests/ -v passes.
9. Documentation
  • README.md updated if user-facing behavior changed.
  • docs/how-it-works.mdx updated if system design changed.
  • Relevant context file in .github/.agents/context/ updated.
  • agents.md updated if invariants changed.

High-Risk Patterns to Flag

PatternRiskAction
RedirectResponse(url=request.query_params['next'])Open redirectReplace with safe_redirect
role = data.get('role') in WS handlerRole injectionUse session.granted_role
session.execute(f"... {user_input} ...")SQL injectionUse parameterized queries
event.openai_api_key = openai_key (plaintext)API key exposureUse encrypt_val
logger.info(f"Key: {api_key}")Secret leakageRemove log line
New npm/yarn/vite configViolates no-build constraintRemove
New <script> tag in templateInline scriptMove to ES module file

Running Validation Locally

bash
uv sync --python 3.13 --dev
uv run pytest tests/ -v
node --check static/js/interpreter-booth.js
node --check static/js/whep-listener.js
uv run alembic upgrade head   # if migration added

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/pr-review of fossasia/eventyay-interpretation.

Open the folder on GitHubat commit 1ca0139

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in fossasia/eventyay-interpretation, which our catalogue first saw on October 7, 2026.

Compare with similar skills

PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review this skillfossasia/eventyay-interpretation1.6k—~1.1kAutomated safety check: PassApache-2.0
Skyvern Version BumpSkyvern-AI/skyvern23k—~1kAutomated safety check: NotesAGPL-3.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Create Cuda Python Pull RequestNVIDIA/cuda-python3.4k—~1.1kAutomated safety check: PassApache-2.0
pybind11 Release Preparationpybind/pybind1118k—~1.7kAutomated safety check: PassCustom licence
Docling Pull Request Reviewdocling-project/docling69k—~1kAutomated safety check: PassMIT

Similar skills

  • Skyvern Version Bump

    Skyvern-AI/skyvern

    Walks through a Skyvern open-source release bump: update the version, rebuild the Python and TypeScript SDKs with Fern, commit, and open a pull request.

    23k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Official

    Create a CUDA Python pull request from an approved personal or organization-owned fork, including the GitHub CLI GraphQL fallback for renamed organization-owned forks.

    3.4k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Opens the pybind11 release-preparation pull request: picking the release base, bumping the version in common.h and integrating the changelog, following docs/release.rst.

    18k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Docling Pull Request Review

    docling-project/docling

    Reviews or re-reviews a Docling pull request in fixed stages, with findings that can be reproduced and an explicit record of every check that was run.

    69k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes

More from fossasia/eventyay-interpretation

All 38 skills in this repo
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    Auto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Auto-check passed
  • Domain Modeling

    fossasia/eventyay-interpretation

    Build and sharpen a project's domain model. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 30 repos~821 tokens
    Auto-check passed
  • Improve

    fossasia/eventyay-interpretation

    Survey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to execute.

    1.6k GitHub starsUsed in 10 repos~3.7k tokens
    Auto-check: warnings
  • Migrate To Shoehorn

    fossasia/eventyay-interpretation

    Migrate test files from as type assertions to @total-typescript/shoehorn.

    1.6k GitHub starsUsed in 12 repos~698 tokens
    Auto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    Auto-check passed

Works with

Categories

Questions about PR Review

What does PR Review do?

A skill your agent uses to review pull requests for VoxBento. PR Review is an agent skill from fossasia/eventyay-interpretation. Use this skill to review pull requests for VoxBento.

When should I use PR Review?

PR Review fits situations like: review pull requests for VoxBento; tasks that involve Pull requests.

How do I install PR Review in Claude Code?

Run `npx skills add fossasia/eventyay-interpretation --skill pr-review -a claude-code`. Or copy the skill folder (.agents/skills/pr-review in fossasia/eventyay-interpretation) into .claude/skills/pr-review in your project. Claude Code loads it when a task matches its description.

How do I install PR Review in Codex?

Run `npx skills add fossasia/eventyay-interpretation --skill pr-review -a codex`. Or copy the skill folder (.agents/skills/pr-review in fossasia/eventyay-interpretation) into .agents/skills/pr-review in your project. Codex loads it when a task matches its description.

Can I use PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay-interpretation --skill pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review, .gemini/skills/pr-review, .github/skills/pr-review and .opencode/skills/pr-review in your project.

What does PR Review need to run?

Going by SKILL.md and its folder, PR Review needs the command-line tools its instructions call (uv and node). Our summary lists: Python 3.

Does PR Review access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Review use?

PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Review?

Skills that share tags, products or a category with PR Review: Skyvern Version Bump (Skyvern-AI/skyvern, 23k stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Create Cuda Python Pull Request (NVIDIA/cuda-python, 3.4k stars) and pybind11 Release Preparation (pybind/pybind11, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review?

fossasia (a GitHub organization) maintains it in fossasia/eventyay-interpretation, which has 1,551 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 5, 2026.

Source: fossasia/eventyay-interpretation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.