Copilot PR Autopilot
github/awesome-copilot
Copilot left 14 review comments on your PR — half are nits. An agent skill from github/awesome-copilot.
Malloy semantic-model code review. An agent skill from malloydata/publisher.
$ npx skills add malloydata/publisher --skill malloy-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install malloydata/publisher malloy-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-review .claude/skills/malloy-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .claude/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/malloydata/publisher/tree/main/skills/malloy-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add malloydata/publisher --skill malloy-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install malloydata/publisher malloy-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/malloy-review .agents/skills/malloy-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .agents/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install malloydata/publisher malloy-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/malloy-review .cursor/skills/malloy-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .cursor/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/malloydata/publisher.git --path skills/malloy-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add malloydata/publisher --skill malloy-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install malloydata/publisher malloy-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/malloy-review .gemini/skills/malloy-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .gemini/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install malloydata/publisher malloy-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add malloydata/publisher --skill malloy-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/malloy-review .github/skills/malloy-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .github/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install malloydata/publisher malloy-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/malloy-review .opencode/skills/malloy-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malloy-review" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-review into .opencode/skills/malloy-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malloy-reviewMalloy semantic-model code review. An agent skill from malloydata/publisher.
Malloy Review is an agent skill from malloydata/publisher. Malloy semantic-model code review. Invoke when the user asks to review, audit, or critique a .malloy file, a folder of Malloy models, or a GitHub PR that touches Malloy. Enforces project modeling standards and emits a navigable review file.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files (for example `reference/output-template.md`, `reference/rubric-correctness.md` and `reference/rubric-documentation.md`).
It sits in Education, covering Code review and Quizzes and assessments. It works with GitHub. The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c43a052. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malloy Review loads about 2.5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,187 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from malloydata/publisher at commit c43a052, republished under its MIT licence (© malloydata). 1,187 words, ~2,471 tokens.
.claude/skills/malloy-review/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.<!--
Copyright (c) Credible Data Inc.
SPDX-License-Identifier: MIT
-->
Single-pass code reviewer for .malloy files. The deliverable is one Markdown file in the canonical shape (see reference/output-template.md). Findings cite the project's standards file (e.g., CLAUDE.md) where it applies; otherwise they cite rubric IDs (reference/rubric-*.md).
Tool names are written bare here -
get_context,execute_query,search_malloy_docs. The exact prefixed name depends on the host surface; match each against the tools you actually have.
Read these in order:
CLAUDE.md, AGENTS.md, etc.). Treat as the higher-priority source of truth; rubric rules defer to it where they overlap.reference/severity-taxonomy.md: the vocabulary every finding uses.reference/rubric-*.md: the seven dimension rubrics. Don't re-read for every review; load them on demand based on what's in scope.reference/output-template.md: the shape of the review file you produce..malloy-review.local.md in the scope folder, if present, project-specific severity overrides or extra rules.Make sure the Malloy MCP tools are configured before running: this skill uses execute_query for data checks and search_malloy_docs for verifying Malloy capabilities. Both are optional; the review degrades gracefully if either is unavailable.
/malloy-review [<path>] [--pr <n>] [--out <file>] [--comment]| Argument | Effect |
|---|---|
| (no arg) | Auto-detect scope per reference/scope-resolution.md |
<path> | Review that file or directory |
--pr <n> | Review the .malloy files changed in GitHub PR <n> (see PR mode below) |
--out <file> | Write review to this path. Default is ./malloy-review-<YYYYMMDD-HHMMSS>.md |
--comment | PR mode only: post the review as a PR comment via gh pr comment |
If scope is ambiguous (multiple packages, wrong file type, empty result), stop and ask: don't guess. See reference/scope-resolution.md for the rules.
resolve scope → read files → verify PKs → apply rubrics → write outputPer reference/scope-resolution.md. Echo the resolved scope to the user before doing anything expensive. Multi-package repos → present packages as A/B/C and let the user pick. Never auto-fan-out across packages: different packages may target different database connections.
For each in-scope .malloy file, read the full content. As you read, track each source's primary_key: and its join_one/join_many/join_cross targets, you'll use this for the PK uniqueness check (C-12) and join-style consistency (Y-03).
If mcp__ide__getDiagnostics is available, call it on the in-scope files and promote each diagnostic to a finding: errors → blocker (confidence 95), warnings → major (confidence 85), info/hint → minor (confidence 75), all with source: "diagnostic". Skip rubric rules these already cover. If unavailable, skip, the LLM rubric pass still runs.
execute_query is available)For every source with a declared primary_key:, run a uniqueness check and store the result on source_index.<src>.pk_verified:
run: <source> -> {
aggregate:
rows is count()
distinct_pk is count(<pk_col>)
}| Result | pk_verified |
|---|---|
rows == distinct_pk | true |
rows != distinct_pk | false |
execute_query is unavailable for the scope | "skipped" |
| The query fails (source unreachable, connection error, etc.) | "error" |
This step only collects evidence, the emit decision and fix template live in reference/rubric-correctness.md § C-12. When any source is "skipped" or "error", note the coverage gap in the output's Scope section.
Score the in-scope files against each applicable rubric. You don't need to read all seven: pick by content:
| Rubric | Read when |
|---|---|
rubric-correctness.md | Always |
rubric-documentation.md | Always (every source/measure/dimension should be documented) |
rubric-style.md | Always |
rubric-structure.md | Always |
rubric-queries.md | Any in-scope file has view: or run: |
rubric-rendering.md | Any in-scope file has a # rendering tag |
rubric-governance.md | Any in-scope file has ##! experimental.access_modifiers or include {} blocks |
Findings use the canonical shape from reference/severity-taxonomy.md:
{
"id": "C1",
"severity": "critical",
"category": "correctness-join",
"file": "packages/x/customers.malloy",
"line_range": [12, 12],
"rule": "C-12 declared primary_key is not unique in the data",
"current": "primary_key: customer_id (customer_id has duplicates per execute_query check)",
"expected": "customer_id is unique per row, or the source carries a where: that scopes to a uniquely-keyed subset",
"suggested_fix": "...",
"confidence": 95,
"source": "rule"
}Drop findings with confidence < 80. The output should feel curated, not exhaustive.
After per-file findings, scan for systemic patterns. This is the highest-value output. Examples that emerged from real reviews:
include {} curationconn.sql() where Malloy-native patterns existtotal_revenue vs net_revenue, etc.)Promote these to a Cross-Cutting Themes section in the output. They are usually more actionable than per-line findings, collapse 3+ findings of the same rule into one theme with the file list, and emit individual findings only for the top 2–3 worst offenders.
Apply reference/output-template.md. Section order is fixed (skip if empty):
<details> per file)Default ./malloy-review-<YYYYMMDD-HHMMSS>.md. Tell the user the path and the top 1–3 issues inline. End with an offer to start fixing, most reviews are the start of iterative work, not a static report.
| Scope | Behavior |
|---|---|
| ≤5 files / ≤500 LOC | Trim Coverage Map and Cross-Cutting sections, likely nothing to surface. Skip the Suggested Split section. |
| 6–20 files / 500–2000 LOC | The canonical workflow above. Include all sections that have content. |
| >20 files / >2000 LOC | Add a mandatory Suggested Split section. Risk-tier files into DEEP / SAMPLE / SKIM (DEEP = top ~25% by content signals: joins, access modifiers, source-level where:, public surface). Cap per-file finding count at ~12 per dimension; promote overflow into Cross-Cutting Themes. Blocker, critical, and diagnostic findings never count against the cap. |
Single-file mode (user passes one .malloy file): trim the template hard. Drop the Coverage Map, Cross-Cutting Themes, and Suggested Split sections. Lean conversational; write the file AND print the Summary + Findings inline so the user doesn't need to open the file for a small review. End with a fix offer ("Want me to fix B1?").
Audit mode (user passes a directory or invokes inside a publisher.json package): every file is in play. Coverage Map matters more, the user needs to know what was deep-reviewed vs. skimmed. For unfamiliar packages, consider running just the source-level summary first, presenting it, and asking whether to proceed with full review.
PR mode (--pr <n>):
gh pr view <n> --json state,isDraft,title,baseRefName,headRefName,url,author and gh pr diff <n> --name-only. Stop if the PR is closed or has no .malloy changes..malloy and intersect with any path argument, that's the scope.gh pr checkout <n> if the working tree is clean, otherwise via gh api repos/<owner>/<repo>/contents/<path>?ref=<headRef>). Don't clobber working state without asking.# Malloy Model Review, PR #<n>: <title> with branch/package/LOC/url metadata.--comment, post via gh pr comment <n> -F <file> (cap at GitHub's 65,536-char limit; if larger, post the exec summary + top issues and reference the local file). Lead the comment body with <!-- malloy-review: <timestamp> --> so re-runs can detect prior reviews. Never post without --comment..malloy files. Output is the Markdown review only.--comment.where: clauses and deliberate private: choices are part of how Malloy models work. If something looks unusual, surface it as a "Question for the Author," not a finding.© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files in skills/malloy-review of malloydata/publisher.
Open the folder on GitHubat commit c43a052
Malloy Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malloy Review this skillmalloydata/publisher | 116 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Copilot PR Autopilotgithub/awesome-copilot | 40k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Comment Judgefmflurry/settings-opencode | 171 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Codebase to Coursezarazhangrui/codebase-to-course | 5.7k | — | ~4.4k | Automated safety check: Pass | None | |
| TendrillableIvy-Interactive/Ivy-Tendril | 202 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
github/awesome-copilot
Copilot left 14 review comments on your PR — half are nits. An agent skill from github/awesome-copilot.
fmflurry/settings-opencode
LLM-as-a-judge rubric for code comments (forbidden, false, stale, narration, noise, keep).
zarazhangrui/codebase-to-course
Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.
Ivy-Interactive/Ivy-Tendril
Find "Tendrillable" GitHub issues - open, recent, code-requiring issues that an agent can plan and one-shot WITHOUT asking clarifying questions, with high probability of success.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
CherryHQ/cherry-studio
Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.
malloydata/publisher
Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
malloydata/publisher
Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.
malloydata/publisher
Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.
malloydata/publisher
Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.
malloydata/publisher
Decide whether ONE answer matches its golden, and say whether you believe the golden.
Works with
Categories
Malloy semantic-model code review. An agent skill from malloydata/publisher. Malloy Review is an agent skill from malloydata/publisher. Malloy semantic-model code review.
Malloy Review fits situations like: critique a .malloy file; A folder of Malloy models; A GitHub PR that touches Malloy.
Run `npx skills add malloydata/publisher --skill malloy-review -a claude-code`. Or copy the skill folder (skills/malloy-review in malloydata/publisher) into .claude/skills/malloy-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add malloydata/publisher --skill malloy-review -a codex`. Or copy the skill folder (skills/malloy-review in malloydata/publisher) into .agents/skills/malloy-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-review, .gemini/skills/malloy-review, .github/skills/malloy-review and .opencode/skills/malloy-review in your project.
Going by SKILL.md and its folder, Malloy Review needs the command-line tools its instructions call (gh).
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Malloy Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Malloy Review: Copilot PR Autopilot (github/awesome-copilot, 40k stars), Comment Judge (fmflurry/settings-opencode, 171 stars), Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars) and Tendrillable (Ivy-Interactive/Ivy-Tendril, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 10, 2026.
Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.