Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes.

MITAuto-check: notesDevelopment

Install Review PR

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill review-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace review-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/productivity/claude-workflow-skills/skills/review-pr .claude/skills/review-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-pr
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
386 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes.

  • Works in 5 steps: Pre-flight check → Fetch PR context → Evaluate the diff → …
  • The user says review this PR
  • SKILL.md covers Step 0: Pre-flight check, Step 1: Fetch PR context, Step 2: Evaluate the diff and Step 3: Draft the review body, plus 1 more section
  • Calls gh; reaches github.com

What it does

Review PR is an agent skill from jeremylongshore/tons-of-skills-marketplace. Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes. Use when the user says review this PR, check the PR, look at PR

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, Code quality and Test coverage. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • The user says review this PR
  • Tasks that involve Pull requests
  • Tasks that involve Code quality

Example prompts

  • “Use the review-pr skill to review an open pull request against coding standards, security, and test coverage, then posts a structured review comment…”
  • “/review-pr”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pre-flight check
  2. Fetch PR context
  3. Evaluate the diff
  4. Draft the review body
  5. Post the review

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review PR loads about 1.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 386 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 386 words, ~1,073 tokens.

Download SKILL.mdSave it as .claude/skills/review-pr/SKILL.md (or your agent's skills folder).
name
review-pr
description
Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes. Use when the user says review this PR, check the PR, look at PR
allowed-tools
Read, Glob, Grep, Bash
disable-model-invocation
true
argument-hint
[PR-number]

Review PR

PR: !gh pr view --json number,title --jq '"#\(.number): \(.title)"' 2>/dev/null || echo "none"

Fetches a pull request diff, evaluates it against the project's coding standards, security posture, and test coverage, then posts a structured review and either approves or requests changes.

Step 0: Pre-flight check

bash
gh auth status 2>&1 || { echo "ERROR: gh is not authenticated. Run: gh auth login"; exit 1; }

Determine the PR to review. If the user named a number, use it. Otherwise default to the current branch's open PR:

bash
gh pr view --json number,title 2>/dev/null || echo "No PR for current branch"

If no PR is found, stop and ask the user which PR number to review.

Step 1: Fetch PR context

bash
gh pr view <number> --json number,title,body,headRefName,baseRefName,author,labels,commits,files
bash
gh pr diff <number>

Also read the project files to understand standards and conventions:

  • README.md — stated purpose and feature set
  • CLAUDE.md — current decisions and context, if present
  • ~/.claude/CLAUDE.md — personal development standards already loaded in context

Step 2: Evaluate the diff

Review the diff against the following criteria. Note findings — positive and negative — for each:

Correctness
  • Does the change do what the PR description says?
  • Are there logic errors, off-by-one errors, or incorrect conditionals?
  • Are edge cases handled?
Coding standards (from ~/.claude/CLAUDE.md)
  • Scripts use correct shebang and follow the Bash Style Guide
  • Terminal output uses pfb (Bash) or Rich (Python) with correct visual hierarchy
  • Functions have Google-style documentation headers
  • No hardcoded configuration — environment variables with .env.template
  • Error messages are actionable (say what went wrong and what to do)
Security
  • No secrets, credentials, or tokens in code or comments
  • External input validated at system boundaries
  • No command injection risks (unquoted variables in shell, unsanitised input in queries)
  • File paths handled safely (no unquoted expansions, no eval on external data)
Show full SKILL.md (136 more words)Show less
Test coverage
  • Are new code paths exercised by tests?
  • Do existing tests still pass (check for any test files modified or added)?
  • Are failure paths tested, not just happy paths?
Documentation and markdown
  • New or changed markdown passes markdownlint conventions (blank lines around blocks, language on code fences, line length ≤ 120)
  • Public interfaces, scripts, and functions are documented
Scope
  • Does the PR stay within its stated scope?
  • Are there unrelated changes bundled in?

Step 3: Draft the review body

Write a structured review using this format:

markdown
## Summary

<1–2 sentences on overall quality and whether the PR achieves its stated goal.>

## Findings

### Must fix

- <issue> — <file:line if applicable> — <what to do>

### Suggestions

- <non-blocking improvement or style note>

### Looks good

- <specific thing done well — always include at least one>

## Verdict

<Approve / Request changes> — <one sentence reason>

If there are no must-fix items, the verdict is Approve. If there is at least one must-fix item, the verdict is Request changes.

Step 4: Post the review

For an approval:

bash
gh pr review <number> --approve --body "$(cat <<'REVIEW'
<review body>

🤖 Generated with [claude-workflow-skills:review-pr](https://github.com/ali5ter/claude-workflow-skills) on behalf of [Alister](https://github.com/ali5ter)
REVIEW
)"

For a request-changes review:

bash
gh pr review <number> --request-changes --body "$(cat <<'REVIEW'
<review body>

🤖 Generated with [claude-workflow-skills:review-pr](https://github.com/ali5ter/claude-workflow-skills) on behalf of [Alister](https://github.com/ali5ter)
REVIEW
)"

After posting, output the review verdict and a link to the PR for the user.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/productivity/claude-workflow-skills/skills/review-pr of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Review PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review PR this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: NotesMIT
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Reviewing Changesbitwarden/ios699—~1.1kAutomated safety check: PassGPL-3.0
Aidd Reviewparalleldrive/aidd384—~945Automated safety check: PassMIT
PR ReviewMathews-Tom/armory329—~2.6kAutomated safety check: PassMIT
Code Review AssistantArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    699 GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Aidd Review

    paralleldrive/aidd

    Conduct a thorough code review focusing on code quality, best practices, security, test coverage, and adherence to project standards and functional requirements.

    384 GitHub stars~945 tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • PR Review

    Mathews-Tom/armory

    Diff-based PR review across code quality, test coverage, silent failures, type design, and comment quality with severity-ranked findings.

    329 GitHub stars~2.6k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Code Review Assistant

    ArabelaTso/Skills-4-SE

    Conduct comprehensive code reviews identifying bugs, security issues, performance problems, code quality concerns, and best practice violations.

    253 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    105k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Review PR

What does Review PR do?

Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes. Review PR is an agent skill from jeremylongshore/tons-of-skills-marketplace. Reviews an open pull request against coding standards, security, and test coverage, then posts a structured review comment and either approves or requests changes.

When should I use Review PR?

Review PR fits situations like: the user says review this PR; tasks that involve Pull requests; tasks that involve Code quality.

How do I install Review PR in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill review-pr -a claude-code`. Or copy the skill folder (plugins/productivity/claude-workflow-skills/skills/review-pr in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/review-pr in your project. Claude Code loads it when a task matches its description.

How do I install Review PR in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill review-pr -a codex`. Or copy the skill folder (plugins/productivity/claude-workflow-skills/skills/review-pr in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/review-pr in your project. Codex loads it when a task matches its description.

Can I use Review PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill review-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-pr, .gemini/skills/review-pr, .github/skills/review-pr and .opencode/skills/review-pr in your project.

What does Review PR need to run?

Going by SKILL.md and its folder, Review PR needs the command-line tools its instructions call (gh). Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash.

Does Review PR access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Review PR safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Review PR use?

Review PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review PR use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review PR?

Skills that share tags, products or a category with Review PR: Code Reviewer (Yikai-Liao/symusic, 189 stars), Reviewing Changes (bitwarden/ios, 699 stars), Aidd Review (paralleldrive/aidd, 384 stars) and PR Review (Mathews-Tom/armory, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review PR?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.