Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server).

Apache-2.0Auto-check passedDevelopment

Install Review PR

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill review-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins review-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/mimfort/rag_for_git/plugin/skills/review-pr .claude/skills/review-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-pr
GitHub stars
1.3k
Token cost
~2.5k tokens
SKILL.md length
1,203 words
Files
6 (incl. references)
Skills in repo
714
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server).

  • Works in 6 steps: Prepare. Call prepare_review(repo, pr).… → Task context (optional). Only if… → Analyze (fan-out). The Python per-unit… → …
  • The user asks to review a PR (review PR 123
  • SKILL.md covers Inputs, Pipeline, Failure handling and Reporting a reviewer defect
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review PR is an agent skill from hashgraph-online/awesome-codex-plugins. Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server). Use when the user asks to review a PR ("review PR 123", "заревьюй PR", a PR URL). Requires ParadeDB/Neo4j running and a built base index.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/analyze-prompt.md`, `references/blast-radius-prompt.md` and `references/requirements-prompt.md`).

It sits in Development, covering Pull requests. It works with Model Context Protocol, GitHub and Neo4j. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • The user asks to review a PR (review PR 123
  • Tasks that involve Pull requests

Example prompts

  • “review PR 123”
  • “заревьюй PR”
  • “/review-pr”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Prepare. Call prepare_review(repo, pr). The payload contains
  2. Task context (optional). Only if task_board is non-null. Resolve the task key: an
  3. Analyze (fan-out). The Python per-unit fan-out remains based only on units.
  4. Dimensions (parallel with step 3). Dispatch whole-diff subagents
  5. Verify. Dispatch one subagent with references/verify-prompt.md and the
  6. Publish. Compose a short review summary (2-5 sentences, in

What it can do on your machine

Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review PR loads about 2.5k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 1,203 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its Apache-2.0 licence (© hashgraph-online). 1,203 words, ~2,521 tokens.

Download SKILL.mdSave it as .claude/skills/review-pr/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
review-pr
description
Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server). Use when the user asks to review a PR ("review PR 123", "заревьюй PR", a PR URL). Requires ParadeDB/Neo4j running and a built base index.

PR Review Pipeline

Orchestrate a full PR review using the reviewer MCP server tools. The deterministic tail (policy gate, line grounding, dedup, idempotency, comment cap, publishing) is handled by publish_review — your job is analysis quality, not formatting rules.

Inputs

Parse from $ARGUMENTS: target PR as owner/repo#N, owner/repo N, or a GitHub PR URL. --dry-run flag → pass dry_run=true to publish_review and show the report instead of posting.

Include resolution (applies to all steps below). When you read any references/*-prompt.md file to dispatch a subagent (steps 3, 4, and 5 — analyze, requirements, risk changes, blast-radius, verify), it may contain <!-- include: _common/<file>.md --> markers. Before putting the prompt into the subagent, replace each marker with the verbatim contents of that file (path is relative to plugin/skills/). These _common/*.md files are the single source of the shared findings-schema / anti-hallucination / tool-usage blocks.

Pipeline

  1. Prepare. Call prepare_review(repo, pr). The payload contains:

    • pr: {number, title, body, base_sha, head_sha, base_ref, draft}
    • policy: {severity_threshold, min_confidence, max_comments, categories, ignore, output_language}
    • units: list of {path, patch, commentable_right, commentable_left}
    • task_board: {type, project, key_pattern, create_target, done_target, options} or null — non-secret generic board metadata from .review.yml
    • task_keys: {primary, others} or null — task keys extracted from the PR by the server
    • risk_paths: bounded non-Python items with {path, status, reasons, patch, commentable_right, commentable_left}
    • risk_skipped_paths: classified paths omitted by the deterministic cap
    • skipped_paths, skip_drafts, suggestions_mode

    If the payload has status: "skipped", this is NOT an error but an expected skip (the PR's target branch is not in REVIEW_BRANCHES). Tell the user the reason value and stop: do not run analyze/publish, and do not treat it as a failure.

    If pr.draft is true and skip_drafts is true, stop and tell the user. Note policy.output_language — ALL finding messages, suggestions and the summary MUST be written in that language.

  2. Task context (optional). Only if task_board is non-null. Resolve the task key: an explicit key in $ARGUMENTS wins; otherwise use task_keys.primary. If no key is available, skip this step and note in the summary that no task key was found.

    Task reads are scoped to this repo's project: pass project=<task_board.project> (from the target branch .review.yml, see step with task_board) to get_task/get_task_context/search_tasks (PRI-170; empty project = unscoped).

    Read the task store-first (unifies with solve-task):

    • Call reviewer get_task(key, project=<task_board.project>) first. Hit (object with a key) → use it as the TaskBrief directly; it is already indexed by the server-side sync, so do NOT call index_task.
    • Miss (null) → call generic incremental sync_board(board=<task_board.project or null>, board_type=<task_board.type>, provider_options=<task_board.options or {}>, limit=null, purge_orphaned=false), then call get_task(key, project=<task_board.project>) once more. A sync error or second miss is fail-open: skip the requirements dimension and note the reason in the summary — NEVER abort the review.

    The TaskBrief schema is {key, aliases[], title, description, criteria[], status, url, links[]} (phase 3 adds aliases[] and uses links[]). On either store hit the brief is already indexed — do NOT re-index. Then gather task context to sharpen the requirements check:

    • get_task_context(TaskBrief.key, project=<task_board.project>) → linked tasks, their PRs, and the code those PRs touched;
    • search_tasks("<TaskBrief.title>. <first lines of description>", project=<task_board.project>) → semantically similar tasks. Keep ONLY the related/similar items that look relevant; you will pass them to the requirements dimension in step 4. All of this is best-effort: if index_task/get_task_context/search_tasks return a "(… unavailable)" note or error, continue — never abort the review.
  3. Analyze (fan-out). The Python per-unit fan-out remains based only on units. For each unit in units, dispatch a subagent (Task tool, run independent subagents in parallel; batch units if there are more than ~10) with:

    • the contents of references/analyze-prompt.md (read it once, resolve includes, include verbatim);
    • the unit's path, patch, commentable_right (sorted list of new-file line numbers available for inline), commentable_left (sorted list of old-file line numbers available for inline), and the PR title/body;
    • the repo/pr identifiers so the subagent can call the reviewer MCP tools (search_code, get_related_symbols, read_file, get_definition, find_callers, get_changed_file_diff);
    • the target output language. Each subagent submits findings via submit_findings(repo, pr, findings=[...]) (schema-enforced; the server assigns ids).
  4. Dimensions (parallel with step 3). Dispatch whole-diff subagents:

    • performance: follow the methodology of ../performance-review/SKILL.md (Goal, Method, Severity sections);
    • maintainability: follow ../maintainability-review/SKILL.md;
    • requirements (ONLY if a TaskBrief was built in step 2): dispatch one subagent with references/requirements-prompt.md, the diffs of all units (path + patch), the TaskBrief, plus the related/similar task context gathered in step 2 (linked tasks, their PRs, touched code, similar tasks) as an optional "Related context" block, the repo/pr identifiers (so it can call the reviewer MCP tools), and the target output language. It submits findings via submit_findings with category requirements.
    • risk changes (ONLY if risk_paths is non-empty): dispatch one subagent with references/risk-changes-prompt.md, every risk item, the PR title/body, repo/pr identifiers, and output language. It submits only grounded correctness/security findings via submit_findings.
    • blast-radius: dispatch one subagent with references/blast-radius-prompt.md, the diffs of all units (path + patch), each unit's commentable_right/commentable_left (the line numbers where inline comments are allowed), the PR title/body, the repo/pr identifiers, and the target output language. It runs two checks — changed signatures breaking callers (via get_impact) and interface expansion (a changed Protocol/ABC whose implementations must all be updated, via get_related_symbols/search_code) — and submits findings via submit_findings with category correctness. Give the performance/maintainability subagents: the diffs of all units (path + patch), the repo/pr identifiers so they can call the reviewer MCP tools, and the target output language. They must submit findings via submit_findings (category performance / maintainability).
  5. Verify. Dispatch one subagent with references/verify-prompt.md and the repo/pr identifiers. It reads candidates via get_candidate_findings(repo, pr) and submits verdicts via submit_verdicts(repo, pr, verdicts=[{id, is_real}]). A finding with is_real=false is dropped at publish; a finding with no verdict is kept (recall-safe — no orchestrator action needed if verify fails).

  6. Publish. Compose a short review summary (2-5 sentences, in policy.output_language): what the PR does, overall assessment, key risks. If a task was read, state whether the PR meets the task's requirements; if the task context was requested but unavailable (no key, sync error, task not found), say so briefly. Mention files that were not analyzed: failed subagents and skipped_paths from the prepare payload. Name a failed risk subagent in the summary, and report every risk_skipped_paths entry as not inspected. Call publish_review(repo, pr, summary, dry_run, task_key) where task_key is the canonical TaskBrief.key if a task was read (else omit / null). Review cost is captured automatically by the plugin's PreToolUse hook (plugin/hooks/review_cost.py) into a sidecar file that publish_review reads server-side — no action needed here. If the CLI separately provides model/usage/cost metadata, pass it via the optional keyword arguments model, usage, and total_cost to publish_review anyway: explicit arguments take priority over the sidecar on a per-field basis, so pass whatever the CLI can give you. When published, this links the PR to the task in the graph for future reviews. Report to the user: posted/dry-run, inline count, and the report counters (dropped_by_gate/deduped/invalid/already_posted/moved_to_summary/capped/verify_rejected), run_id.

Show full SKILL.md (100 more words)Show less

Failure handling

  • A failed analyze subagent must not abort the run: continue with the other units and mention the skipped file in the summary.
  • A failed risk changes subagent is fail-open: continue with the review and name it in the summary.
  • A prepare_review payload with status: "skipped" is not a failure: report its reason (target branch not tracked in REVIEW_BRANCHES) and stop without analyze/publish.
  • If prepare_review fails, surface its error text to the user as-is (it contains the remediation hint, e.g. "docker compose up -d").
  • Never post comments yourself via gh/git — only through publish_review.

Reporting a reviewer defect

<!-- include: _common/bug-reporting.md -->

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in plugins/mimfort/rag_for_git/plugin/skills/review-pr of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/analyze-prompt.md
  • references/blast-radius-prompt.md
  • references/requirements-prompt.md
  • references/risk-changes-prompt.md
  • references/verify-prompt.md

Open the folder on GitHubat commit 9e7b281

Compare with similar skills

Review PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review PR this skillhashgraph-online/awesome-codex-plugins1.3k—~2.5kAutomated safety check: PassApache-2.0
GitHub Commentingjuspay/neurolink144—~698Automated safety check: PassMIT
Plane Release Notes Generatormakeplane/plane61k—~2.5kAutomated safety check: PassAGPL-3.0
Mariadb Operator PR Reviewmariadb-operator/mariadb-operator1k—~3.3kAutomated safety check: PassApache-2.0
Link Ticket To SessionJayantDevkar/claude-code-karma329—~1.8kAutomated safety check: NotesApache-2.0
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • GitHub Commenting

    juspay/neurolink

    How to post clean, rich, deduplicated GitHub PR review comments — suggestion blocks, multi-line anchors, markers, formatting rules.

    144 GitHub stars~698 tokensUpdated today
    DevelopmentAuto-check passed
  • Builds categorized release notes for a Plane release pull request from its commits and writes them into the PR description, for both the plane-cloud and plane-ee repos.

    61k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Mariadb Operator PR Review

    mariadb-operator/mariadb-operator

    Perform a structured maintainer-style PR review for the mariadb-operator repository.

    1k GitHub stars~3.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Link Ticket To Session

    JayantDevkar/claude-code-karma

    Link the current Claude Code session to a ticket (Linear, Jira, GitHub Issues, or GitHub Pull Requests) and cache its title/status in karma.

    329 GitHub stars~1.8k tokensUpdated 11 days ago
    DevelopmentAuto-check: notes
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review Feedback Handler

    gittower/git-flow-next

    Fetches review comments on a pull request, judges each one, writes the evaluation to a plan file and implements accepted changes, waiting for approval before anything public.

    457 GitHub stars~2.9k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes

More from hashgraph-online/awesome-codex-plugins

All 714 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Questions about Review PR

What does Review PR do?

Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server). Review PR is an agent skill from hashgraph-online/awesome-codex-plugins. Review a GitHub pull request with the RAG + code-graph pipeline (reviewer MCP server).

When should I use Review PR?

Review PR fits situations like: the user asks to review a PR (review PR 123; tasks that involve Pull requests.

How do I install Review PR in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill review-pr -a claude-code`. Or copy the skill folder (plugins/mimfort/rag_for_git/plugin/skills/review-pr in hashgraph-online/awesome-codex-plugins) into .claude/skills/review-pr in your project. Claude Code loads it when a task matches its description.

How do I install Review PR in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill review-pr -a codex`. Or copy the skill folder (plugins/mimfort/rag_for_git/plugin/skills/review-pr in hashgraph-online/awesome-codex-plugins) into .agents/skills/review-pr in your project. Codex loads it when a task matches its description.

Can I use Review PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill review-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-pr, .gemini/skills/review-pr, .github/skills/review-pr and .opencode/skills/review-pr in your project.

What does Review PR need to run?

SKILL.md names no scripts, command-line tools or credentials: Review PR is instructions for the agent only. Our summary lists: Python 3; Docker.

Does Review PR access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review PR safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review PR use?

Review PR is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review PR use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Review PR?

Skills that share tags, products or a category with Review PR: GitHub Commenting (juspay/neurolink, 144 stars), Plane Release Notes Generator (makeplane/plane, 61k stars), Mariadb Operator PR Review (mariadb-operator/mariadb-operator, 1k stars) and Link Ticket To Session (JayantDevkar/claude-code-karma, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review PR?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.