Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

MITAuto-check: notesDevelopment

Install PR Review Comments

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill pr-review-comments -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit pr-review-comments --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-core/skills/pr-review-comments .claude/skills/pr-review-comments && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review-comments
GitHub stars
357
Token cost
~1k tokens
SKILL.md length
404 words
Files
3 (incl. scripts, references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

  • Works in 5 steps: Confirm the JSON path and the PR number.… → Dry-run first to see what will be posted… → Review the "Postable" / "Skipped" counts… → …
  • You have a list/JSON of review findings (each with a file path
  • SKILL.md covers Prerequisites, Key constraint: only diff…, Workflow and Choosing the mode, plus 2 more sections
  • Runs Python scripts from its folder; calls gh

What it does

PR Review Comments is an agent skill from giuseppe-trisciuoglio/developer-kit. Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line. Use when you have a list/JSON of review findings (each with a file path, line number, and a message such as summary/failurescenario) and want them published on a PR as inline review comments. Triggers include "post these review comments on the PR", "associate comments to files in the PR", "publish review findings to PR

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/json-schema.md` and `scripts/post_pr_comments.py`).

It sits in Development, covering Pull requests, Code review and Technical documentation. It works with GitHub. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • You have a list/JSON of review findings (each with a file path
  • A message such as summary/failurescenario) and want them published on a PR as inline review comments
  • Include post these review comments on the PR
  • Associate comments to files in the PR

Example prompts

  • “post these review comments on the PR”
  • “associate comments to files in the PR”
  • “Use the pr-review-comments skill to post review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its…”
  • “/pr-review-comments”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the JSON path and the PR number. If the repo isn't obvious, run gh repo view.
  2. Dry-run first to see what will be posted and what gets skipped
  3. Review the "Postable" / "Skipped" counts with the user. If lines were skipped because
  4. Post for real, choosing the mode (see below)
  5. Report back the created review/comment URLs and the list of any skipped findings.

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review Comments loads about 1k tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 404 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 404 words, ~1,040 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review-comments/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
pr-review-comments
description
Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line. Use when you have a list/JSON of review findings (each with a file path, line number, and a message such as summary/failure_scenario) and want them published on a PR as inline review comments. Triggers include "post these review comments on the PR", "associate comments to files in the PR", "publish review findings to PR
allowed-tools
Read, Write, Bash

PR Review Comments

Publish a JSON array of review findings as inline comments on a GitHub Pull Request, each anchored to its file and line. Uses the GitHub API through the authenticated gh CLI, so no token handling is needed.

Prerequisites

  • gh CLI installed and authenticated (gh auth status). The script auto-detects the repo with gh repo view; pass --repo OWNER/REPO to override.
  • The PR number to comment on.
  • A JSON file: an array of objects. Required keys per object: file, line. Message comes from summary and/or failure_scenario (combined into the body), or an explicit body. See references/json-schema.md for the full schema and a sample.

Key constraint: only diff lines are commentable

GitHub only accepts an inline comment if the target line is part of the PR's diff. line is the line number in the new file (use side: "LEFT" for removed lines). The script fetches the PR diff, validates every finding against the actual hunks, and skips any whose line is outside the diff — reporting them at the end so nothing is lost silently. There is no way to attach a line comment to an unchanged, undiffed line.

Workflow

  1. Confirm the JSON path and the PR number. If the repo isn't obvious, run gh repo view.
  2. Dry-run first to see what will be posted and what gets skipped:
    bash
    scripts/post_pr_comments.py --pr <N> --json <path> --dry-run
  3. Review the "Postable" / "Skipped" counts with the user. If lines were skipped because the diff moved, the line numbers in the JSON may be stale — reconcile before posting.
  4. Post for real, choosing the mode (see below):
    bash
    # Grouped (default): one PR review bundling all comments
    scripts/post_pr_comments.py --pr <N> --json <path> --event COMMENT
    
    # Individual: one separate inline comment per finding
    scripts/post_pr_comments.py --pr <N> --json <path> --mode individual
  5. Report back the created review/comment URLs and the list of any skipped findings.
Show full SKILL.md (131 more words)Show less

Choosing the mode

ModeEndpointUse when
grouped (default)POST /pulls/{n}/reviewsPublishing a set of findings as one review. One notification; can set --event APPROVE | REQUEST_CHANGES | COMMENT.
individualPOST /pulls/{n}/commentsAdding standalone comments incrementally, or when each finding should be its own thread/notification.

Default to grouped with --event COMMENT unless the user wants a verdict or separate threads.

Options reference

--pr N              PR number (required)
--json PATH         JSON array of findings (required)
--repo OWNER/REPO   Override auto-detected repo
--mode grouped|individual   Default: grouped
--event COMMENT|APPROVE|REQUEST_CHANGES   Grouped-mode verdict (default COMMENT)
--review-body TEXT  Top-level summary body for the grouped review
--commit SHA        Commit to anchor to (default: PR head SHA)
--dry-run           Validate and print payloads without posting

Notes

  • Multi-line range comments: include start_line (and optional start_side) in the JSON object alongside line; the script passes them through.
  • Always --dry-run before a real post on an unfamiliar PR — stale line numbers are the most common failure and the dry-run surfaces them as "skipped" without side effects.
  • The script is the reliable path; don't hand-roll gh api calls for this — it handles diff validation, repo/commit detection, and body assembly consistently.

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in plugins/developer-kit-core/skills/pr-review-comments of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/json-schema.md
  • scripts/post_pr_comments.py

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

PR Review Comments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review Comments compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review Comments this skillgiuseppe-trisciuoglio/developer-kit357—~1kAutomated safety check: NotesMIT
Post Draft Reviewagent-substrate/substrate4.8k—~2.8kAutomated safety check: PassApache-2.0
Inline PR Commentshyperlane-xyz/hyperlane-explorer102—~1.1kAutomated safety check: PassCustom licence
Code Reviewtestdouble/han281—~8.7kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Post Draft Review

    agent-substrate/substrate

    Posts pull request review findings as GitHub draft (pending) inline comments for a human to edit and submit, instead of publishing them straight to the PR author.

    4.8k GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Inline PR Comments

    hyperlane-xyz/hyperlane-explorer

    Post a single consolidated PR review with summary and inline comments.

    102 GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    testdouble/han

    Run a comprehensive code review on local source files. An agent skill from testdouble/han.

    281 GitHub stars~8.7k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS SDK Java V2 Secrets Manager

    giuseppe-trisciuoglio/developer-kit

    Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

    357 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about PR Review Comments

What does PR Review Comments do?

Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line. PR Review Comments is an agent skill from giuseppe-trisciuoglio/developer-kit. Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

When should I use PR Review Comments?

PR Review Comments fits situations like: you have a list/JSON of review findings (each with a file path; A message such as summary/failurescenario) and want them published on a PR as inline review comments; include post these review comments on the PR; associate comments to files in the PR.

How do I install PR Review Comments in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill pr-review-comments -a claude-code`. Or copy the skill folder (plugins/developer-kit-core/skills/pr-review-comments in giuseppe-trisciuoglio/developer-kit) into .claude/skills/pr-review-comments in your project. Claude Code loads it when a task matches its description.

How do I install PR Review Comments in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill pr-review-comments -a codex`. Or copy the skill folder (plugins/developer-kit-core/skills/pr-review-comments in giuseppe-trisciuoglio/developer-kit) into .agents/skills/pr-review-comments in your project. Codex loads it when a task matches its description.

Can I use PR Review Comments in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill pr-review-comments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review-comments, .gemini/skills/pr-review-comments, .github/skills/pr-review-comments and .opencode/skills/pr-review-comments in your project.

What does PR Review Comments need to run?

Going by SKILL.md and its folder, PR Review Comments needs Python for the scripts in its folder and the command-line tools its instructions call (gh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash.

Does PR Review Comments access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Review Comments safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does PR Review Comments use?

PR Review Comments is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review Comments use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 576 tokens, read only when the agent opens those files.

What are the alternatives to PR Review Comments?

Skills that share tags, products or a category with PR Review Comments: Post Draft Review (agent-substrate/substrate, 4.8k stars), Inline PR Comments (hyperlane-xyz/hyperlane-explorer, 102 stars), Code Review (testdouble/han, 281 stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review Comments?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.