Review a new or open pull request for this repository with an adversarial security and quality lens.

Custom licenceAuto-check passedDevelopment

Install PR

skills CLI
$ npx skills add jtenniswood/espcontrol --skill pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jtenniswood/espcontrol pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jtenniswood/espcontrol.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pr .claude/skills/pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr
GitHub stars
1.1k
Token cost
~1.4k tokens
SKILL.md length
583 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
Custom licence

At a glance

Review a new or open pull request for this repository with an adversarial security and quality lens.

  • Works in 6 steps: Identify the PR → Protect Local Work → Inspect for Malicious or Suspicious… → …
  • The user says /pr
  • SKILL.md covers Overview, Workflow and Output Format
  • Calls gh, python3 and npm

What it does

PR is an agent skill from jtenniswood/espcontrol. Review a new or open pull request for this repository with an adversarial security and quality lens. Use when the user says "/pr", "/pr-review", "check the new PR", "is this PR safe to merge", "look for malicious code", "review outside contribution", "should I merge this PR", or asks for reasons not to merge a pull request.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Pull requests. It works with Home Assistant. The repository describes itself as: Esphome based smart home control panel.

When your agent uses it

  • The user says /pr
  • Check the new PR
  • Is this PR safe to merge
  • Look for malicious code

Example prompts

  • “/pr-review”
  • “check the new PR”
  • “is this PR safe to merge”
  • “/pr”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the PR
  2. Protect Local Work
  3. Inspect for Malicious or Suspicious Changes
  4. Review Correctness and Fit
  5. Run Focused Checks
  6. Decide Whether to Merge

What it can do on your machine

Read from SKILL.md and the folder at commit 72cf82c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • python3
    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR loads about 1.4k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 583 words (~1,409 tokens).

“Assess a pull request before merge. Focus on bugs, suspicious behavior, malicious code, supply-chain risk, broken project conventions, missing tests, and any reason the repo owner should wait before merging.”

— opening of SKILL.md by jtenniswood, Custom licence
name
pr

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in .agents/skills/pr of jtenniswood/espcontrol.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 72cf82c

Compare with similar skills

PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR this skilljtenniswood/espcontrol1.1k—~1.4kAutomated safety check: PassCustom licence
Community Triageroryeckel/wyoming_openai219—~2.9kAutomated safety check: PassApache-2.0
simon42 Dashboard Strategy Dev GuideTheRealSimon42/simon42-dashboard-strategy265—~3.6kAutomated safety check: PassCustom licence
PR Descriptiongduteil/cozytouch128—~539Automated safety check: PassNone
PR Bodyandrew-blake/melcloudhome142—~4.5kAutomated safety check: PassMIT
Huawei PRxiasi0/ha-huawei-smarthome135—~501Automated safety check: PassGPL-3.0

Similar skills

  • Community Triage

    roryeckel/wyoming_openai

    GitHub issues, pull requests, bug reports, scope questions, and support threads.

    219 GitHub stars~2.9k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • simon42 Dashboard Strategy Dev Guide

    TheRealSimon42/simon42-dashboard-strategy

    Working rules for developing the simon42 Home Assistant dashboard strategy: verify before assuming, protect existing behavior, test on a real system and handle community PRs with care.

    265 GitHub stars~3.6k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • PR Description

    gduteil/cozytouch

    Write or rewrite a pull request description so it is short and actually readable.

    128 GitHub stars~539 tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • PR Body

    andrew-blake/melcloudhome

    A skill your agent uses when composing or revising a pull request description in this repo, including PRs that sit in a stack.

    142 GitHub stars~4.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Huawei PR

    xiasi0/ha-huawei-smarthome

    Standardize pull request titles and descriptions for the ha-huawei-smarthome repository.

    135 GitHub stars~501 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Verify Cozytouch

    gduteil/cozytouch

    Prove a change to the Cozytouch Home Assistant integration in a real Home Assistant — a throwaway instance against a fake Atlantic cloud served from a diagnostics dump (a fixture or a reporter's)…

    128 GitHub stars~2.2k tokensUpdated 4 days ago
    DevelopmentAuto-check passed

More from jtenniswood/espcontrol

All 14 skills in this repo
  • Clean Complete Branches

    jtenniswood/espcontrol

    Clean up completed Git branches and worktrees for this repository both locally and on GitHub.

    1.1k GitHub stars~820 tokensUpdated today
    Auto-check passed
  • Clean Merged Branch Folders

    jtenniswood/espcontrol

    Clean up local branch worktree folders for this repository after their branches or pull requests have merged to main.

    1.1k GitHub stars~813 tokensUpdated today
    Auto-check passed
  • Flash Displays

    jtenniswood/espcontrol

    Flash EspControl display firmware from this repository using ESPHome.

    1.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Release

    jtenniswood/espcontrol

    Create and safely publish a new GitHub release for this repository through a verified draft build, then confirm the related GitHub Actions run.

    1.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Review All

    jtenniswood/espcontrol

    Review every open pull request authored by the user in this repository and address actionable unresolved review feedback.

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Tech Debt Scan

    jtenniswood/espcontrol

    Research-only technical debt scan for this EspControl repository.

    1.1k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about PR

What does PR do?

Review a new or open pull request for this repository with an adversarial security and quality lens. PR is an agent skill from jtenniswood/espcontrol. Review a new or open pull request for this repository with an adversarial security and quality lens.

When should I use PR?

PR fits situations like: the user says /pr; check the new PR; is this PR safe to merge; look for malicious code.

How do I install PR in Claude Code?

Run `npx skills add jtenniswood/espcontrol --skill pr -a claude-code`. Or copy the skill folder (.agents/skills/pr in jtenniswood/espcontrol) into .claude/skills/pr in your project. Claude Code loads it when a task matches its description.

How do I install PR in Codex?

Run `npx skills add jtenniswood/espcontrol --skill pr -a codex`. Or copy the skill folder (.agents/skills/pr in jtenniswood/espcontrol) into .agents/skills/pr in your project. Codex loads it when a task matches its description.

Can I use PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jtenniswood/espcontrol --skill pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr, .gemini/skills/pr, .github/skills/pr and .opencode/skills/pr in your project.

What does PR need to run?

Going by SKILL.md and its folder, PR needs the command-line tools its instructions call (gh, python3, npm and git). Our summary lists: Python 3.

Does PR access the network?

SKILL.md contains no URLs. Its commands use gh, npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR use?

PR has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does PR use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR?

Skills that share tags, products or a category with PR: Community Triage (roryeckel/wyoming_openai, 219 stars), simon42 Dashboard Strategy Dev Guide (TheRealSimon42/simon42-dashboard-strategy, 265 stars), PR Description (gduteil/cozytouch, 128 stars) and PR Body (andrew-blake/melcloudhome, 142 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR?

jtenniswood (a GitHub user) maintains it in jtenniswood/espcontrol, which has 1,091 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 11, 2026.

Source: jtenniswood/espcontrol on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.