Agent skill

Contrib PR Review

by homeassistant-ai in homeassistant-ai/ha-mcp

Review a contribution PR for safety, quality, and readiness.

MITAuto-check: notesTesting & QA

Install Contrib PR Review

skills CLI
$ npx skills add homeassistant-ai/ha-mcp --skill contrib-pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install homeassistant-ai/ha-mcp contrib-pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/homeassistant-ai/ha-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/contrib-pr-review .claude/skills/contrib-pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contrib-pr-review
GitHub stars
5k
Token cost
~3.1k tokens
SKILL.md length
663 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Review a contribution PR for safety, quality, and readiness.

  • Works in 6 steps: Check the Bot Security Reviews → Enable Workflows (If Safe) → Test Coverage Assessment → …
  • Reviewing external contributions
  • SKILL.md covers Context, Review Protocol, Final Review Summary and Important Notes
  • Calls gh and jq

What it does

Contrib PR Review is an agent skill from homeassistant-ai/ha-mcp. Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Pull requests and Test coverage. The repository describes itself as: The Unofficial and Awesome Home Assistant MCP Server. The licence is MIT.

When your agent uses it

  • Reviewing external contributions
  • Tasks that involve Pull requests
  • Tasks that involve Test coverage

Example prompts

  • “/contrib-pr-review”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, WebFetch

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check the Bot Security Reviews
  2. Enable Workflows (If Safe)
  3. Test Coverage Assessment
  4. PR Size & Contributor Experience
  5. Intent & Issue Linkage
  6. Code Quality Overview

What it can do on your machine

Read from SKILL.md and the folder at commit b274a93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contrib PR Review loads about 3.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 663 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from homeassistant-ai/ha-mcp at commit b274a93, republished under its MIT licence (© homeassistant-ai). 663 words, ~3,053 tokens.

Download SKILL.mdSave it as .claude/skills/contrib-pr-review/SKILL.md (or your agent's skills folder).
name
contrib-pr-review
description
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.
allowed-tools
Bash, Read, Grep, Glob, WebFetch
argument-hint
<pr-number>

Contribution PR Review

Review PR #$ARGUMENTS from external contributor for safety, quality, and readiness.

Context

PR Metadata:

!`gh pr view $ARGUMENTS --repo homeassistant-ai/ha-mcp --json author,additions,deletions,files,commits,closingIssuesReferences,isDraft,reviews,url,title,body`

Contributor Stats:

!`gh api /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS --jq '{author: .user.login, user_id: .user.id}' | jq -r '.author' | xargs -I {} gh api /repos/homeassistant-ai/ha-mcp/contributors --jq '.[] | select(.login == "{}") | {login: .login, contributions: .contributions}'`

Files Changed:

!`gh api /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/files --jq '.[] | {filename: .filename, status: .status, additions: .additions, deletions: .deletions, changes: .changes, patch: .patch}' | head -50`

Review Protocol

1. Check the Bot Security Reviews

Note: Codex (chatgpt-codex-connector[bot]) and CodeRabbit (coderabbitai[bot]) both review PRs automatically. Check whether either flagged security concerns.

bash
# Check both bots' reviews and any security-related comments.
# Their findings can be inline-only, so also fetch the pull review comments
# endpoint — review bodies and conversation comments alone can miss them.
# --paginate: both endpoints page at 30, and an iterating PR outruns that.
gh api --paginate /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/reviews --jq '.[] | select(.user.login == "chatgpt-codex-connector[bot]" or .user.login == "coderabbitai[bot]") | {author: .user.login, state: .state, body: .body}'
gh api --paginate /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/comments --jq '.[] | select(.user.login == "chatgpt-codex-connector[bot]" or .user.login == "coderabbitai[bot]") | {author: .user.login, path: .path, line: .line, body: .body}'
# CodeRabbit posts its walkthrough and summary as a top-level comment, which
# neither endpoint above returns — fetch that channel by author too.
gh api --paginate /repos/homeassistant-ai/ha-mcp/issues/$ARGUMENTS/comments --jq '.[] | select(.user.login == "chatgpt-codex-connector[bot]" or .user.login == "coderabbitai[bot]") | {author: .user.login, body: .body}'
# Keyword scan stays, for humans raising security concerns in conversation.
gh pr view $ARGUMENTS --repo homeassistant-ai/ha-mcp --json comments --jq '.comments[] | select(.body | contains("security") or contains("Security")) | {author: .author.login, body: .body}'

If either bot flagged security issues:

  • Review the findings carefully
  • Verify if concerns are valid
  • Do NOT approve until issues addressed or confirmed false positives

If NO bot security flags but you notice concerning patterns:

  • Unusual AGENTS.md/CLAUDE.md changes unrelated to PR purpose
  • .github/ workflow modifications with pull_request_target
  • .claude/ agent/skill changes that could affect behavior
  • Draft a comment with the specific concerns and show it to the user before posting
2. Enable Workflows (If Safe)

If security assessment passes and PR has workflow changes or new workflows:

bash
# Check current workflow status
gh api /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/requested_reviewers

# Enable workflows if not enabled (requires WRITE permission)
# This command may fail if already enabled - that's OK
gh api -X PUT /repos/homeassistant-ai/ha-mcp/actions/workflows/pr.yml/enable 2>/dev/null || echo "Workflows already enabled or no permission"
3. Test Coverage Assessment

Pre-existing tests (easier review if modified code is already tested):

bash
# For each modified source file, check if tests exist
gh api /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/files --jq '.[] | select(.filename | startswith("src/")) | .filename' | while read file; do
  basename=$(basename "$file" .py)
  echo "Checking tests for: $file"

  # Method 1: Look for test files by naming convention
  find tests/ -name "test_${basename}.py" -o -name "test_*${basename}*.py" 2>/dev/null | head -3

  # Method 2: Grep for function/class names from the modified file
  # Extract function/class names and search for them in tests
  grep -E '^(def|class|async def) [a-zA-Z_]' "$file" 2>/dev/null | head -5 | while read line; do
    name=$(echo "$line" | sed -E 's/.*(def|class) ([a-zA-Z_][a-zA-Z0-9_]*).*/\2/')
    if [ -n "$name" ]; then
      grep -r "$name" tests/ 2>/dev/null | head -1
    fi
  done
done

New tests added:

bash
# Check if PR adds or modifies tests
gh api /repos/homeassistant-ai/ha-mcp/pulls/$ARGUMENTS/files --jq '.[] | select(.filename | startswith("tests/")) | {filename: .filename, status: .status, additions: .additions}'

Output Test Summary:

🧪 Test Coverage:
- Pre-existing tests: ✅ Modified code has tests / ⚠️ No tests for modified code
- New tests: ✅ PR adds X test files / ⚠️ No new tests
- Assessment: [Easy/Medium/Hard to review based on test coverage]
4. PR Size & Contributor Experience

Calculate PR size and assess appropriateness:

bash
# From metadata: additions + deletions
total_lines=$(gh pr view $ARGUMENTS --repo homeassistant-ai/ha-mcp --json additions,deletions --jq '.additions + .deletions')
echo "Total lines changed: $total_lines"

# Get contributor experience
author=$(gh pr view $ARGUMENTS --repo homeassistant-ai/ha-mcp --json author --jq -r '.author.login')

# Check 1: Contributions to this project
project_contributions=$(gh api /repos/homeassistant-ai/ha-mcp/contributors --jq ".[] | select(.login == \"$author\") | .contributions" || echo "0")

# Check 2: Total GitHub commits (overall experience)
total_commits=$(gh api /users/$author --jq '.public_repos + .total_private_repos' 2>/dev/null || echo "unknown")

echo "Contributor: $author"
echo "Project contributions: $project_contributions"
echo "GitHub experience: $total_commits repos"

Assess:

  • First-time to project (0-2 project contributions):

    • Check overall GitHub experience (repos, total commits)
    • < 200 lines: ✅ Excellent size
    • 200-500 lines: ⚠️ Large for first PR - may need extra guidance
    • 500 lines: 🔴 Too large - suggest splitting

  • Regular contributor (3+ project contributions):

    • < 500 lines: ✅ Reasonable
    • 500-1000 lines: ⚠️ Large - ensure good test coverage
    • 1000 lines: 🔴 Very large - suggest splitting

  • Experienced GitHub user (many repos/commits overall):

    • Adjust expectations - they may be new to this project but experienced overall

Output Size Summary:

📏 PR Size:
- Lines changed: [total]
- Contributor: [first-time / regular] ([X] contributions)
- Assessment: [size appropriateness]
5. Intent & Issue Linkage

Check linked issues:

bash
# From metadata: closingIssuesReferences
gh pr view $ARGUMENTS --repo homeassistant-ai/ha-mcp --json closingIssuesReferences --jq '.closingIssuesReferences[] | {number: .number, title: .title}'

If issue linked:

  • Read issue to understand expected outcome
  • Compare PR changes to issue requirements
  • Does PR solve the issue? Check:
    • All requirements addressed
    • No scope creep (extra features not requested)
    • Solution approach aligns with any discussed approaches in issue

If no issue linked:

  • Is this a bug fix? Should reference issue
  • Is this a feature? Should have issue for discussion
  • Is this a typo/docs? OK without issue
  • Recommend creating issue for tracking if it's a substantial change

Output Intent Summary:

🎯 Intent & Linkage:
- Linked issue: #X "title" / ⚠️ No issue linked
- Solves issue: ✅ Fully addresses requirements / ⚠️ Partial / ❌ Doesn't match
- Scope: ✅ Focused / ⚠️ Scope creep detected
6. Code Quality Overview

Note: Codex and CodeRabbit provide automated code review on all PRs. This step focuses on what they cannot assess:

  • Architecture alignment: Does it fit the project structure? (service layer usage, etc.)
  • Breaking changes: Does it remove functionality without replacement? (Tool consolidation/refactoring is NOT breaking)
  • Repo-specific patterns: Context engineering, progressive disclosure, MCP-specific conventions

Breaking change assessment:

  • ✅ NOT Breaking: Tool consolidation, refactoring, parameter changes with same outcome achievable
  • ⚠️ BREAKING: Removes functionality with no alternative, makes previously possible actions impossible

Quick checks:

bash
# ruff and mypy run as steps of the "Fast Checks" job
gh pr checks $ARGUMENTS --repo homeassistant-ai/ha-mcp | grep "Fast Checks"

# Check for common issues in diff
gh pr diff $ARGUMENTS --repo homeassistant-ai/ha-mcp | grep -E "(TODO|FIXME|XXX|HACK)"

Output Quality Summary:

✨ Code Quality:
- Architecture fit: [assessment - service layer, context engineering]
- Breaking changes: ✅ None / ⚠️ Detected - [describe what's genuinely lost]
- Bot reviews: [check if Codex or CodeRabbit flagged anything critical]
Show full SKILL.md (251 more words)Show less

Final Review Summary

Output to User

After completing all steps, present a short summary of what the PR does and the review findings, then ask: "Should I post this comment to the PR?"

Draft PR Comment

After completing the analysis, draft a comment for the PR following these guidelines:

Comment Length: The contributor should be able to read it in one pass: what works, what must change, and what happens next. A good-to-merge comment is shorter than a changes-needed one.

Style:

  • No emojis
  • Markdown formatting OK (bold, lists, code blocks)
  • Present inline in chat (not in a file)
  • Always ask user before posting

Structure for "Good to Merge":

[Positive opening line about the contribution]

[What works well - focus on functionality, tests, architecture]

[Any minor suggestions or notes - optional, technical only]

[Closing line about readiness to merge]

Note: Do NOT mention security assessment in comment unless issues were found. Security checks are internal.

Structure for "Changes Needed":

[Positive opening line acknowledging the work]

[Brief summary of the issue being solved]

**[Concern 1]:**
[Short explanation + suggestion - focus on: tests, functionality, architecture, breaking changes]

**[Concern 2]:** (if applicable)
[Short explanation + suggestion]

**[Concern 3]:** (if applicable)
[Short explanation + suggestion]

[Closing line about next steps]

Note: Raise security concerns with the user as soon as they are found, not in the final structured comment.

Illustrative example - Good to Merge (match the wording to the PR, not to this text):

Thanks for [feature/fix]. [One specific thing it gets right].

The implementation follows existing patterns and the [specific aspect] is well-designed. [Optional: Minor note about something noticed].

Ready to merge once CI passes.

Illustrative example - Changes Needed (match the wording to the PR, not to this text):

Thanks for tackling [problem]. [Metric/impact] shows this addresses a real need.

**Test coverage:**
Missing tests for the new [feature]. Please add a unit test for its logic, and an E2E test for a new tool or for its wiring or Home Assistant behaviour. Performance tests not required.

**[Second concern if applicable]:**
[Brief explanation and request]

Once [change 1] and [change 2] are addressed, this should be good to merge.

Important Notes

  • Security is checked, not publicized: Always check security (step 1), but only mention in comment if issues found
  • Be constructive: Contributors are donating their time - be welcoming
  • Focus on intent: Code quality can be iterated; intent misalignment is harder to fix
  • Consider contributor experience: Adjust expectations based on contribution history
  • The bots already reviewed code: Don't duplicate detailed code review
  • When in doubt: Err on the side of caution and request maintainer review

© homeassistant-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/contrib-pr-review of homeassistant-ai/ha-mcp.

Open the folder on GitHubat commit b274a93

Compare with similar skills

Contrib PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contrib PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contrib PR Review this skillhomeassistant-ai/ha-mcp5k—~3.1kAutomated safety check: NotesMIT
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Review Envoy Gateway PRenvoyproxy/gateway3.1k—~850Automated safety check: PassApache-2.0
Core Components Code Reviewcore-ds/core-components137—~5.4kAutomated safety check: PassMIT
Open PRElite588/AUTOGPT103—~1.3kAutomated safety check: PassCustom licence
Docs Syncmicrosoft/apm4k—~3kAutomated safety check: PassMIT

Similar skills

  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Review Envoy Gateway PR

    envoyproxy/gateway

    Review an Envoy Gateway pull request for essential API, implementation, status, and test coverage requirements.

    3.1k GitHub stars~850 tokensUpdated today
    DevelopmentAuto-check passed
  • Core Components Code Review

    core-ds/core-components

    Review a Pull Request or diff in the @alfalab/core-components UI library — correctness bugs, public API/breaking changes, accessibility, keyboard/focus/pointer interaction, component states…

    137 GitHub stars~5.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Open PR

    Elite588/AUTOGPT

    Open a pull request with proper PR template, test coverage, and review workflow.

    103 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Docs Sync

    microsoft/apm

    Official

    A skill your agent uses whenever a pull request is opened, reopened, or synchronized in microsoft/apm to assess whether and how the documentation corpus must change to stay truthful with the…

    4k GitHub stars~3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Test Reviewer

    axelixlabs/axelix

    Reviews test code in GitHub pull requests for isolation, public-API contract coverage, AAA structure, and correct exception assertions.

    148 GitHub stars~3.2k tokensUpdated today
    MobileAuto-check passed

More from homeassistant-ai/ha-mcp

All 8 skills in this repo
  • Bat Adhoc

    homeassistant-ai/ha-mcp

    Run bot acceptance tests to validate MCP tools work correctly from a real AI agent's perspective.

    5k GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Issue Analysis

    homeassistant-ai/ha-mcp

    Deep analysis of a single GitHub issue with codebase exploration, implementation planning, and architectural assessment.

    5k GitHub stars~753 tokensUpdated today
    Auto-check: notes
  • Issue To PR Resolver

    homeassistant-ai/ha-mcp

    Implement a GitHub issue end-to-end — create a worktree branch, implement the feature with tests, create a draft PR, then iteratively resolve all CI failures and review comments until the PR is clean.

    5k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • My PR Checker

    homeassistant-ai/ha-mcp

    Manage your own GitHub pull requests — check CI status, inline review comments, PR-level comments, resolve review threads, fix issues, and iterate until all checks pass and threads are resolved.

    5k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Bat Story Eval

    homeassistant-ai/ha-mcp

    Compare MCP tool behavior between target and baseline versions using pre-built and custom stories with diff-based triage.

    5k GitHub stars~3.4k tokensUpdated today
    Auto-check: notes
  • Contributors Update

    homeassistant-ai/ha-mcp

    Find merged PR authors missing from README and update the contributors list after approval

    5k GitHub stars~983 tokensUpdated today
    Auto-check passed

Questions about Contrib PR Review

What does Contrib PR Review do?

Review a contribution PR for safety, quality, and readiness. Contrib PR Review is an agent skill from homeassistant-ai/ha-mcp. Review a contribution PR for safety, quality, and readiness.

When should I use Contrib PR Review?

Contrib PR Review fits situations like: reviewing external contributions; tasks that involve Pull requests; tasks that involve Test coverage.

How do I install Contrib PR Review in Claude Code?

Run `npx skills add homeassistant-ai/ha-mcp --skill contrib-pr-review -a claude-code`. Or copy the skill folder (.claude/skills/contrib-pr-review in homeassistant-ai/ha-mcp) into .claude/skills/contrib-pr-review in your project. Claude Code loads it when a task matches its description.

How do I install Contrib PR Review in Codex?

Run `npx skills add homeassistant-ai/ha-mcp --skill contrib-pr-review -a codex`. Or copy the skill folder (.claude/skills/contrib-pr-review in homeassistant-ai/ha-mcp) into .agents/skills/contrib-pr-review in your project. Codex loads it when a task matches its description.

Can I use Contrib PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add homeassistant-ai/ha-mcp --skill contrib-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contrib-pr-review, .gemini/skills/contrib-pr-review, .github/skills/contrib-pr-review and .opencode/skills/contrib-pr-review in your project.

What does Contrib PR Review need to run?

Going by SKILL.md and its folder, Contrib PR Review needs the command-line tools its instructions call (gh and jq). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, WebFetch.

Does Contrib PR Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Contrib PR Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Contrib PR Review use?

Contrib PR Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Contrib PR Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Contrib PR Review?

Skills that share tags, products or a category with Contrib PR Review: Evaluate PR Tests (dotnet/maui, 23k stars), Review Envoy Gateway PR (envoyproxy/gateway, 3.1k stars), Core Components Code Review (core-ds/core-components, 137 stars) and Open PR (Elite588/AUTOGPT, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contrib PR Review?

homeassistant-ai (a GitHub organization) maintains it in homeassistant-ai/ha-mcp, which has 5,015 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 11, 2026.

Source: homeassistant-ai/ha-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.