Agent skill

Review PR

by linuxfoundation in linuxfoundation/insights

Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards…

MITAuto-check: notesDevelopment

Install Review PR

skills CLI
$ npx skills add linuxfoundation/insights --skill review-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install linuxfoundation/insights review-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/linuxfoundation/insights.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review-pr .claude/skills/review-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-pr
GitHub stars
280
Token cost
~2.7k tokens
SKILL.md length
1,094 words
Files
3 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards…

  • Works in 6 steps: Input & Context Gathering → Launch Code Enforcer (background) → Verify Previous Review Comments → …
  • Checking PR quality
  • SKILL.md covers Phase 1: Input & Context…, Phase 2: Launch Code Enforcer…, Phase 3: Verify Previous… and Phase 4: PR Metadata Validation, plus 3 more sections
  • Calls gh, git and jq

What it does

Review PR is an agent skill from linuxfoundation/insights. Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards check against every file in .claude/rules/ and .claude/hooks/guard-protected-files.sh, and drafts inline review comments with suggested fixes. NEVER auto-posts comments or submits reviews — always presents a draft in the terminal for user approval before any comment lands on the PR. Use when reviewing PRs, checking PR…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/backend-checklist.md` and `references/frontend-checklist.md`).

It sits in Development, covering Pull requests and Social publishing and cross-posting. It works with Jira. The repository describes itself as: Insights into the world's most critical open source software. The licence is MIT.

When your agent uses it

  • Checking PR quality
  • Validating code changes
  • The user says review

Example prompts

  • “review”
  • “check this PR”
  • “audit code”
  • “/review-pr”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Glob, Grep, Agent, AskUserQuestion, Skill

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Input & Context Gathering
  2. Launch Code Enforcer (background)
  3. Verify Previous Review Comments
  4. PR Metadata Validation
  5. Compile Context
  6. Present Draft Review for Approval (NEVER auto-post)

What it can do on your machine

Read from SKILL.md and the folder at commit 3df53b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob
    • Grep
    • Agent
    • AskUserQuestion
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review PR loads about 2.7k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 157 tokens; SKILL.md has 1,094 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~157
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob, Grep, Agent, AskUserQuestion, Skill

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from linuxfoundation/insights at commit 3df53b5, republished under its MIT licence (© linuxfoundation). 1,094 words, ~2,674 tokens.

Download SKILL.mdSave it as .claude/skills/review-pr/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
review-pr
description
Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards check against every file in `.claude/rules/` and `.claude/hooks/guard-protected-files.sh`, and drafts inline review comments with suggested fixes. NEVER auto-posts comments or submits reviews — always presents a draft in the terminal for user approval before any comment lands on the PR. Use when reviewing PRs, checking PR quality, validating code changes, or when the user says "review", "check this PR", or "audit code".
allowed-tools
Bash, Read, Glob, Grep, Agent, AskUserQuestion, Skill

Insights PR Review

You are reviewing a pull request against the Insights architecture standards and project conventions. Walk through each phase in order.

The review is backed by these living sources of truth — always pull current contents rather than relying on memory:

  • .claude/rules/*.md — all project rules
  • .claude/hooks/guard-protected-files.sh — the authoritative protected-files list
  • CLAUDE.md — project conventions

Phase 1: Input & Context Gathering

Parse arguments

The args string follows this format: <PR number> [extra instructions].

  • First token is the PR number if numeric.
  • Everything after it is extra instructions (e.g. "focus on backend", "check that previous comments were addressed").
  • If no PR number is provided, use AskUserQuestion to ask for one.
Determine repository
bash
gh repo view --json nameWithOwner --jq '.nameWithOwner'
Fetch PR metadata (parallel)

Run all of the following in a single turn:

bash
# PR details
gh pr view <N> --json title,body,headRefName,baseRefName,author,files,additions,deletions,state,number

# Full diff
gh pr diff <N>

# Previous inline review comments
gh api repos/{owner}/{repo}/pulls/{N}/comments --paginate

# Previous review summaries
gh api repos/{owner}/{repo}/pulls/{N}/reviews --paginate

# Commit messages
gh api repos/{owner}/{repo}/pulls/{N}/commits --paginate --jq '.[].commit.message'

# Fetch both branches for merge-base check
git fetch origin <baseRefName> <headRefName>

If the diff is too large, save it to /tmp/pr-<N>.diff and read only changed .ts, .vue, .scss, .md files with Read.

Load all project rules (dynamic — do not hardcode)

Glob .claude/rules/*.md and read every rule file. At time of writing this includes:

  • always-use-uikit.md — uikit component usage rules
  • pnpm-workspace-commands.md — pnpm workspace conventions
  • commit-workflow.md — PR title format, branch naming, JIRA, signing
Load the protected-files hook

Read .claude/hooks/guard-protected-files.sh. Parse its case statements and if conditions to build the authoritative protected-files list. Never maintain it by hand — parse the hook so it stays in sync.


Phase 2: Launch Code Enforcer (background)

Spawn a background Agent subagent with run_in_background: true. Proceed to Phase 3 immediately while it runs in parallel.

Prompt for the agent:

You are a code-standards enforcer for the Insights codebase (Nuxt 4 / Vue 3 / TypeScript).

Branch: origin/<headRefName> Changed files: (include the full list from Phase 1)

For each file, read it with git show origin/<headRefName>:<path> and check against:

  1. .claude/rules/*.md — glob and read all rule files
  2. .claude/skills/review-pr/references/frontend-checklist.md — for files under frontend/app/
  3. .claude/skills/review-pr/references/backend-checklist.md — for files under frontend/server/
  4. CLAUDE.md — project conventions

Also read .claude/hooks/guard-protected-files.sh and parse its case/if patterns. For every changed file matching a protected pattern, emit a NIT finding with the hook's warning reason.

Severity calibration:

  • CRITICAL — runtime bugs, security issues, secrets in code, broken auth, missing createError for HTTP errors
  • SHOULD_FIX — documented style/structure violations (raw HTML instead of uikit, Options API, missing license headers, space-y-* instead of gap-*, any type, inline DB queries instead of repo pattern)
  • NIT — minor improvements, naming, protected-file awareness

Return findings as JSON: [{ "file": "...", "line": N, "severity": "CRITICAL|SHOULD_FIX|NIT", "rule": "<rule-file>:<section>", "message": "...", "suggestion": "..." }]

If you cannot quote the rule from a loaded rule file or checklist, drop the finding. Hallucinated rules are worse than missed ones.


Phase 3: Verify Previous Review Comments

Check whether previously raised review comments were actually addressed in code. Do NOT trust "resolved" status — read the actual code.

  1. Gather all inline comments and review bodies from Phase 1.
  2. Skip trivial comments: nits, "+1", bot auto-comments, purely informational remarks.
  3. For every CRITICAL or SHOULD FIX comment:
    1. Read the file on the PR branch: git show origin/<headRefName>:<file>
    2. Compare current code against what the comment requested.
    3. Classify: FIXED / NOT FIXED / PARTIALLY FIXED / N/A
  4. Build a markdown table:
markdown
| #   | Comment Summary           | File                       | Status    | Evidence                    |
| --- | ------------------------- | -------------------------- | --------- | --------------------------- |
| 1   | Use lfx-button not button | app/components/Foo.vue     | FIXED     | Line 12 now uses lfx-button |
| 2   | Missing license header    | server/api/projects.get.ts | NOT FIXED | File still has no header    |

If no previous review comments, note "No previous review comments found" and move on.


Phase 4: PR Metadata Validation

Validates PR metadata against commit-workflow.md.

Checks
  1. PR title format — must match type: description (Conventional Commits), all lowercase, no JIRA ticket in title. A scope is optional.

    • Valid types: feat, fix, docs, style, refactor, perf, test, build, ci, chore, revert
  2. Branch name format — should match <type>/IN-<number> (e.g. feat/IN-123). Flag as NIT if non-conforming but otherwise well-formed.

  3. JIRA ticket reference — at least one commit message or the PR body should reference an IN-XXX ticket. Extract with grep -oE 'IN-[0-9]+'. If none, flag SHOULD FIX.

  4. Branch rebased on main:

    bash
    git merge-base --is-ancestor origin/main origin/<headRefName>

    If non-zero exit code, flag SHOULD FIX: branch needs a rebase.

  5. PR size — if additions > 1000, note per commit-workflow.md's 1000-line target.

Build a findings table:

markdown
| Check           | Status | Detail                          |
| --------------- | ------ | ------------------------------- |
| PR title format | PASS   | `feat(auth): add token refresh` |
| Branch name     | PASS   | `feat/IN-1234`                  |
| JIRA ticket     | PASS   | Found IN-1234 in commits        |
| Branch rebased  | PASS   | origin/main is an ancestor      |
| PR size         | PASS   | 342 additions                   |

Phase 5: Compile Context

Wait for the Phase 2 enforcer Agent to complete. Then compile all findings.

Show full SKILL.md (440 more words)Show less
Apply false-positive filter

Before surfacing any finding, drop it if:

  • The rule field cannot be matched by string search in the loaded rule files, checklists, or hook
  • It relates to a pattern that doesn't exist in this codebase (e.g. Angular-specific rules)
Assemble the context block
  1. Previous comment verification — Phase 3 table (or "No previous review comments found")
  2. PR metadata validation — Phase 4 table
  3. Protected files touched — list any matching .claude/hooks/guard-protected-files.sh, with the hook's warning reason
  4. Code enforcer findings — filtered JSON results from Phase 2
  5. Domain checklists applied — note which checklists were checked:
    • Frontend files (frontend/app/**) → references/frontend-checklist.md
    • Backend files (frontend/server/**) → references/backend-checklist.md
  6. Extra user instructions — any additional instructions from the args

Phase 6: Present Draft Review for Approval (NEVER auto-post)

You MUST NOT post inline comments, submit a review, or request changes without the user's explicit approval. Always present the draft first and wait for a clear go-ahead. This applies every time, with no exceptions.

Step 1 — Show the draft

Print the compiled context as a draft review summary:

  1. PR summary — number, title, author, size, branch
  2. Phase 3 table — previous comments and whether they were addressed
  3. Phase 4 table — PR metadata validation
  4. Protected files touched — list with hook reasons
  5. Proposed inline comments — one block per finding: file:line, severity, rule citation, message, suggested fix. Number them so the user can reference individual items.
  6. Proposed review body — summary text for the top of the review
  7. Proposed review verdict — COMMENT / APPROVE / REQUEST_CHANGES, with reasoning
Step 2 — Ask for approval

Use AskUserQuestion with options:

  • "Post all comments as drafted"
  • "Post with changes — I'll tell you which comments to drop or edit"
  • "Don't post — just keep the summary here"

Do NOT proceed until the user explicitly picks an option. Treat silence or ambiguous replies as "don't post".

Step 3 — Only after approval: invoke /review

Once the user approves (with or without edits), apply their edits and use the Skill tool to invoke review with the PR number and compiled context:

text
<PR number> -- <compiled context from Phase 5, with user's edits applied>

If the user said "don't post", stop here — do not invoke /review or any PR-mutating gh command.


Additional Rules

PR size check

If additions > 1000, include in the review body:

Note: This PR has {additions} additions, which exceeds the recommended 1000-line target per commit-workflow.md. Consider splitting into smaller, independently reviewable PRs.

New contributor awareness
bash
gh pr list --author <author> --state merged --limit 5 --json number | jq 'length'

If the author has fewer than 5 merged PRs to this repo, be more educational in inline comments — explain the why behind each rule, not just the what.

Extra instructions

If the user passed extra instructions after the PR number, prioritize those areas but still execute the full review pipeline.

© linuxfoundation, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/review-pr of linuxfoundation/insights.

  • SKILL.md
  • references/backend-checklist.md
  • references/frontend-checklist.md

Open the folder on GitHubat commit 3df53b5

Compare with similar skills

Review PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review PR this skilllinuxfoundation/insights280—~2.7kAutomated safety check: NotesMIT
PR BodySAP/spartacus784—~499Automated safety check: PassApache-2.0
Link Ticket To SessionJayantDevkar/claude-code-karma329—~1.8kAutomated safety check: NotesApache-2.0
Dynamo PR DescriptionDynamoDS/Dynamo2k—~880Automated safety check: PassApache-2.0
Adhoc PRshopsys/shopsys350—~2.3kAutomated safety check: PassCustom licence
Code Reviewsortie-ai/sortie196—~2.9kAutomated safety check: PassMIT

Similar skills

  • PR Body

    SAP/spartacus

    Official

    A skill your agent uses when the user asks to generate, write, or draft a pull request (PR) body or description for the current branch.

    784 GitHub stars~499 tokensUpdated today
    DevelopmentAuto-check passed
  • Link Ticket To Session

    JayantDevkar/claude-code-karma

    Link the current Claude Code session to a ticket (Linear, Jira, GitHub Issues, or GitHub Pull Requests) and cache its title/status in karma.

    329 GitHub stars~1.8k tokensUpdated 9 days ago
    DevelopmentAuto-check: notes
  • Dynamo PR Description

    DynamoDS/Dynamo

    Generate PR descriptions for Dynamo that align with the team template section names and order.

    2k GitHub stars~880 tokensUpdated today
    DevelopmentAuto-check passed
  • Adhoc PR

    shopsys/shopsys

    Ad-hoc Pull Request Publisher — commits the current changes, pushes the branch, opens a GitHub pull request against the repository's default branch, and creates a matching SSP Jira issue in the…

    350 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    sortie-ai/sortie

    Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

    196 GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Review Release Notes

    chef/chef-web-docs

    Read a release notes file and edit it using Jira release data and GitHub pull requests as co-equal, optional sources.

    143 GitHub stars~5.2k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from linuxfoundation/insights

All 9 skills in this repo
  • Event Tracking

    linuxfoundation/insights

    Add event tracking calls to Vue/Nuxt components in the Insights app using the useTrackEvent composable.

    280 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check passed
  • Adr

    linuxfoundation/insights

    Record an architecture decision as an ADR in api/docs/arch/adr/.

    280 GitHub stars~1k tokensUpdated 6 days ago
    Auto-check passed
  • Dco

    linuxfoundation/insights

    Recover from missing DCO sign-off on commits. An agent skill from linuxfoundation/insights.

    280 GitHub stars~696 tokensUpdated 6 days ago
    Auto-check: notes
  • Fix Vulns

    linuxfoundation/insights

    Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).

    280 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check: notes
  • Setup

    linuxfoundation/insights

    Full development environment setup from scratch — prerequisites, dependencies, .env file, optional local PostgreSQL database (for auth/collections/chat work), and dev server.

    280 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check: notes
  • Setup Docs

    linuxfoundation/insights

    Run the docs site, blog, or Storybook locally. An agent skill from linuxfoundation/insights.

    280 GitHub stars~383 tokensUpdated 6 days ago
    Auto-check: notes

Works with

Categories

Questions about Review PR

What does Review PR do?

Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards…. Review PR is an agent skill from linuxfoundation/insights.sh, and drafts inline review comments with suggested fixes.

When should I use Review PR?

Review PR fits situations like: checking PR quality; validating code changes; the user says review.

How do I install Review PR in Claude Code?

Run `npx skills add linuxfoundation/insights --skill review-pr -a claude-code`. Or copy the skill folder (.claude/skills/review-pr in linuxfoundation/insights) into .claude/skills/review-pr in your project. Claude Code loads it when a task matches its description.

How do I install Review PR in Codex?

Run `npx skills add linuxfoundation/insights --skill review-pr -a codex`. Or copy the skill folder (.claude/skills/review-pr in linuxfoundation/insights) into .agents/skills/review-pr in your project. Codex loads it when a task matches its description.

Can I use Review PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add linuxfoundation/insights --skill review-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-pr, .gemini/skills/review-pr, .github/skills/review-pr and .opencode/skills/review-pr in your project.

What does Review PR need to run?

Going by SKILL.md and its folder, Review PR needs the command-line tools its instructions call (gh, git and jq). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Agent, AskUserQuestion, Skill.

Does Review PR access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review PR safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Review PR use?

Review PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review PR use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Review PR?

Skills that share tags, products or a category with Review PR: PR Body (SAP/spartacus, 784 stars), Link Ticket To Session (JayantDevkar/claude-code-karma, 329 stars), Dynamo PR Description (DynamoDS/Dynamo, 2k stars) and Adhoc PR (shopsys/shopsys, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review PR?

linuxfoundation (a GitHub organization) maintains it in linuxfoundation/insights, which has 280 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 1, 2026.

Source: linuxfoundation/insights on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.