Agent skill

GitHub Code Review

by jackfranklin in jackfranklin/dotfiles

Perform a thorough, read-only review of one GitHub pull request.

MITAuto-check passedDevelopment

Install GitHub Code Review

skills CLI
$ npx skills add jackfranklin/dotfiles --skill github-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jackfranklin/dotfiles github-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jackfranklin/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/skills/github-code-review .claude/skills/github-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-code-review
GitHub stars
255
Token cost
~1.8k tokens
SKILL.md length
690 words
Files
2 (incl. scripts)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Perform a thorough, read-only review of one GitHub pull request.

  • Works in 6 steps: Establish GitHub context → Read linked issues → Read all prior PR feedback → …
  • Given a GitHub PR number and you need to understand its linked issue(s)
  • SKILL.md covers Invocation and Workflow
  • Calls gh, git and bash

What it does

GitHub Code Review is an agent skill from jackfranklin/dotfiles. Perform a thorough, read-only review of one GitHub pull request. Use when given a GitHub PR number and you need to understand its linked issue(s), all existing discussion and review feedback, and independently apply the code-review skill to the exact PR code.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts. Compatibility notes: Requires gh authenticated for the target repository, git, and a local clone of that repository.

It sits in Development, covering Code review. It works with GitHub. The repository describes itself as: My dotfiles for my dev environment, compromising of tmux, vim, zsh and git. The licence is MIT.

When your agent uses it

  • Given a GitHub PR number and you need to understand its linked issue(s)
  • All existing discussion and review feedback
  • Independently apply the code-review skill to the exact PR code

Example prompts

  • “/github-code-review”

Requirements

  • Compatibility (from SKILL.md): Requires gh authenticated for the target repository, git, and a local clone of that repository.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish GitHub context
  2. Read linked issues
  3. Read all prior PR feedback
  4. Create an isolated PR worktree
  5. Perform the implementation review
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 7ec4998. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires gh authenticated for the target repository, git, and a local clone of that repository.

    From compatibility in the SKILL.md frontmatter.

Context cost

GitHub Code Review loads about 1.8k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 690 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jackfranklin/dotfiles at commit 7ec4998, republished under its MIT licence (© jackfranklin). 690 words, ~1,816 tokens.

Download SKILL.mdSave it as .claude/skills/github-code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-code-review
description
Perform a thorough, read-only review of one GitHub pull request. Use when given a GitHub PR number and you need to understand its linked issue(s), all existing discussion and review feedback, and independently apply the code-review skill to the exact PR code.
compatibility
Requires gh authenticated for the target repository, git, and a local clone of that repository.
disable-model-invocation
true

GitHub Code Review

Review exactly one GitHub pull request. This skill supplies GitHub context and an isolated checkout; code-review remains the governing implementation review standard. Be direct and evidence-based. Do not praise, approve, post GitHub comments, modify the active checkout, or run tests unless the user separately asks.

Invocation

text
/github-code-review 42

Require one positive integer PR number. If it is missing or invalid, ask for it. Do not review every open PR as a fallback.

Workflow

1. Establish GitHub context

From the repository containing the active checkout, collect the PR metadata and its patch. Use the explicit repository argument in later gh commands so changing directories cannot change the target repository.

bash
repo="$(gh repo view --json nameWithOwner --jq .nameWithOwner)"
gh pr view <number> -R "$repo" --json number,title,url,body,state,author,baseRefName,baseRefOid,headRefName,headRefOid,commits,files,additions,deletions,changedFiles,closingIssuesReferences,comments,reviews
gh pr diff <number> -R "$repo" --patch

Read the title and body before inspecting the implementation. Identify the claimed problem, expected outcome, scope, and any unstated assumptions. A missing or vague description is relevant context, but is not automatically a blocking finding.

2. Read linked issues

Use the structured closingIssuesReferences returned by the PR metadata. Read every linked issue, including its title, body, state, labels, and comments:

bash
gh issue view <issue-url> --json number,title,url,state,labels,body,comments

A closing reference is authoritative; do not guess linked issues by grepping arbitrary #123 text in prose. If no issues are linked, report that limitation rather than inventing one.

3. Read all prior PR feedback

Read all three categories of feedback:

  1. PR conversation comments (comments from gh pr view);
  2. submitted reviews and their bodies (reviews from gh pr view);
  3. inline review threads, including their resolved and outdated state.

For inline threads, query GitHub's reviewThreads GraphQL connection. Request the thread path, current/original line, isResolved, isOutdated, and every comment's author, body, URL, and timestamp:

bash
owner="${repo%%/*}"
name="${repo##*/}"
query='query($owner: String!, $name: String!, $number: Int!, $cursor: String) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100, after: $cursor) {
        nodes {
          isResolved isOutdated path line originalLine
          comments(first: 100) {
            nodes { author { login } body url createdAt }
          }
        }
        pageInfo { hasNextPage endCursor }
      }
    }
  }
}'
gh api graphql -f query="$query" -F owner="$owner" -F name="$name" -F number=<number>

Use each returned endCursor in the next request until hasNextPage is false. Do not substitute the REST pull-request-comments endpoint: it cannot reliably report thread resolution state.

Treat existing feedback as input to verify, not as conclusions to repeat. For each substantive concern, classify it as one of:

  • Still open — the current PR still has the problem.
  • Resolved — the current code addresses it.
  • Stale or not applicable — the code changed, the thread is outdated, or the concern is unsupported by the current implementation.
  • Needs author decision — it is a product or design question that cannot be settled from the code and issue.
Show full SKILL.md (325 more words)Show less
4. Create an isolated PR worktree

Review the actual PR head in a temporary detached Git worktree, never in the user's active checkout. First obtain the PR's baseRefName from step 1, then invoke the skill's trusted helper. It owns the temporary refs, worktree, state, and cleanup lifecycle:

bash
bash /home/jack/.claude/skills/github-code-review/scripts/github-code-review-worktree \
  start <number> <baseRefName-from-step-1> origin

It prints WORKTREE, BASE_REF, HEAD_REF, and STATE_FILE. Preserve all four values. Use git -C "$WORKTREE" ... for every worktree command: each Bash tool call starts from the active checkout, so cd in a previous call does not persist. Do not recreate this logic in an inline shell script.

If origin is not the GitHub remote for the PR, identify the matching remote first and pass its name as the optional final argument. If setup fails, explain the failure and do not silently review the active checkout instead. Always request cleanup when the review is finished or cannot continue:

bash
bash /home/jack/.claude/skills/github-code-review/scripts/github-code-review-worktree \
  finish "$STATE_FILE"

Never use git checkout, git switch, git reset, git stash, git clean, or gh pr checkout in the active checkout. The temporary refs and worktree must be removed through the helper's finish command even if the review cannot finish.

5. Perform the implementation review

Load and apply the sibling code-review skill now. It defines the review principles and full implementation checklist. For its context/diff step, use the isolated worktree and this exact PR range instead of staged or unstaged changes:

bash
git diff "$base_ref...HEAD"

Read relevant unchanged code in the worktree: callers, types, constants, existing utilities, tests, and local repository instructions. Review the code independently; prior reviewer comments may guide investigation but never replace it.

6. Report

Use this format. Findings must identify a current location where possible, explain the concrete consequence, and recommend a correction. Do not duplicate existing feedback as a new finding; cross-reference it under existing feedback instead.

md
# GitHub Code Review — PR #<number>: <title>

## Intent
- PR: <your concise interpretation of the PR's intended change>
- Linked issue(s): <issue number/title and relevant acceptance criteria, or none>
- Scope assessed: <notable files or areas>

## Existing feedback reconciled
- **Still open** — <author and concern> (`path:line`)
- **Resolved** — <author and concern>
- **Stale or not applicable** — <author and reason>
- **Needs author decision** — <question>

## New findings
### Critical
- `path:line` — <problem, consequence, and correction>

### Important
- `path:line` — <problem, consequence, and correction>

### Minor
- `path:line` — <problem, consequence, and correction>

## Review limits
- <only genuine limitations, such as no linked issue or unavailable content>

Omit empty severity sections. If no new findings exist, say No new findings. Do not claim that the PR is mergeable or approved: the output is a thorough code review, not a merge-decision shortcut.

© jackfranklin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in claude/skills/github-code-review of jackfranklin/dotfiles.

  • SKILL.md
  • scripts/github-code-review-worktree

Open the folder on GitHubat commit 7ec4998

Compare with similar skills

GitHub Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Code Review this skilljackfranklin/dotfiles255—~1.8kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Fastlane Pull Request Reviewfastlane/fastlane42k—~550Automated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Reviews a fastlane pull request against its linked issue and the project guides, separating blocking from non-blocking findings and handling vulnerabilities privately.

    42k GitHub stars~550 tokensUpdated today
    DevelopmentAuto-check passed
  • Reviews open pull requests in the daisyUI repository using read-only GitHub data and isolated base-versus-PR checks, then writes a merge verdict report.

    43k GitHub stars~766 tokensUpdated 7 days ago
    DevelopmentAuto-check passed

More from jackfranklin/dotfiles

All 19 skills in this repo
  • Adr

    jackfranklin/dotfiles

    Capture an Architecture Decision Record (ADR) for a significant decision made in the current project.

    255 GitHub stars~962 tokensUpdated today
    Auto-check passed
  • Jack References

    jackfranklin/dotfiles

    Manage Jack's personal technical reference library at ~/git/references.

    255 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Later

    jackfranklin/dotfiles

    Log items to come back to later — bugs found mid-task, feature ideas, project feedback — as GitHub Issues.

    255 GitHub stars~767 tokensUpdated today
    Auto-check passed
  • New Deno App

    jackfranklin/dotfiles

    Scaffold a new Deno 2 + Hono + Deno KV + Eta + HTMX app with password auth and PWA support.

    255 GitHub stars~3.6k tokensUpdated today
    Auto-check: notes
  • Resolve Merge Conflict

    jackfranklin/dotfiles

    A skill your agent uses when you need to resolve an in-progress git merge/rebase conflict.

    255 GitHub starsUsed in 21 repos~427 tokens
    Auto-check passed
  • Writing Great Skills

    jackfranklin/dotfiles

    Reference for writing and editing skills well — the vocabulary and principles that make a skill predictable.

    255 GitHub starsUsed in 15 repos~2.2k tokens
    Auto-check passed

Works with

Categories

Questions about GitHub Code Review

What does GitHub Code Review do?

Perform a thorough, read-only review of one GitHub pull request. GitHub Code Review is an agent skill from jackfranklin/dotfiles. Perform a thorough, read-only review of one GitHub pull request.

When should I use GitHub Code Review?

GitHub Code Review fits situations like: given a GitHub PR number and you need to understand its linked issue(s); all existing discussion and review feedback; independently apply the code-review skill to the exact PR code.

How do I install GitHub Code Review in Claude Code?

Run `npx skills add jackfranklin/dotfiles --skill github-code-review -a claude-code`. Or copy the skill folder (claude/skills/github-code-review in jackfranklin/dotfiles) into .claude/skills/github-code-review in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Code Review in Codex?

Run `npx skills add jackfranklin/dotfiles --skill github-code-review -a codex`. Or copy the skill folder (claude/skills/github-code-review in jackfranklin/dotfiles) into .agents/skills/github-code-review in your project. Codex loads it when a task matches its description.

Can I use GitHub Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jackfranklin/dotfiles --skill github-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-code-review, .gemini/skills/github-code-review, .github/skills/github-code-review and .opencode/skills/github-code-review in your project.

What does GitHub Code Review need to run?

Going by SKILL.md and its folder, GitHub Code Review needs the command-line tools its instructions call (gh, git and bash). Compatibility (from SKILL.md): Requires gh authenticated for the target repository, git, and a local clone of that repository..

Does GitHub Code Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does GitHub Code Review use?

GitHub Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Code Review use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Code Review?

Skills that share tags, products or a category with GitHub Code Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), GitHub Review Iteration (prisma/orm, 48k stars), PR Finalize Review (microsoft/garnet, 12k stars) and PR Review State Fetch (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Code Review?

jackfranklin (a GitHub user) maintains it in jackfranklin/dotfiles, which has 255 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: jackfranklin/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.