GitHub Review Iteration
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
Multi-perspective code review for a branch before merging. An agent skill from microsoft/bocpy.
$ npx skills add microsoft/bocpy --skill branch-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/bocpy branch-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/branch-review .claude/skills/branch-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .claude/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/bocpy --skill branch-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/bocpy branch-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/branch-review .agents/skills/branch-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .agents/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/bocpy --skill branch-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/bocpy branch-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/branch-review .cursor/skills/branch-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .cursor/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/bocpy.git --path .github/skills/branch-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/bocpy --skill branch-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/bocpy branch-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/branch-review .gemini/skills/branch-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .gemini/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/bocpy branch-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/bocpy --skill branch-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/branch-review .github/skills/branch-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .github/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/bocpy --skill branch-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/bocpy branch-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/branch-review .opencode/skills/branch-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "branch-review" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/branch-review into .opencode/skills/branch-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "branch-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
branch-reviewMulti-perspective code review for a branch before merging. An agent skill from microsoft/bocpy.
Branch Review is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Multi-perspective code review for a branch before merging. Use when: reviewing a branch, preparing a PR, pre-merge review, auditing a feature branch, or when /branch-review is invoked. Spawns three constructive reviewer subagents (correctness, security, usability), then runs an adversarial gap analysis to find what they missed, and synthesizes all findings into a unified review report. All intermediate artifacts are persisted to .copilot/ so the process can be restarted from any step.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering UX design and Subagents. The repository describes itself as: Behavior-Oriented Concurrency in Python. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8f3ceb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Branch Review loads about 3.2k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,552 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/bocpy at commit c8f3ceb, republished under its MIT licence (© microsoft). 1,552 words, ~3,191 tokens.
.claude/skills/branch-review/SKILL.md (or your agent's skills folder).Perform a thorough multi-perspective code review of a branch before it is merged. Four independent reviewers examine the diff from competing viewpoints, and their findings are synthesized into one actionable report.
Findings use the same severity scale as the review-loop skill:
| Severity | Meaning |
|---|---|
| critical | Correctness bug, security vulnerability, or data loss risk. Must fix. |
| high | Likely bug, race condition, or significant design flaw. Should fix. |
| medium | Code smell, unclear logic, missing edge case, or maintainability concern. Recommended fix. |
| low | Style nit, naming suggestion, minor improvement. Fix at discretion. |
Every intermediate artifact produced by this skill is written to disk under
.copilot/reviews/<slug>/, where <slug> is a short kebab-case name derived
from the branch under review (e.g. work-stealing-scheduler for a branch
named feature/work-stealing-scheduler). This makes the process fully
resumable: if any step fails, is interrupted, or produces an unsatisfactory
result, you can re-run only the affected step using the on-disk artifacts
from prior steps as input.
.copilot/reviews/<slug>/
├── 00-context.md # Step 2 output (shared context block)
├── 00-diff.patch # Step 1 raw diff
├── 00-changed-files.txt # Step 1 file list
├── 10-review-correctness-lens.md # Step 3 outputs (one per lens)
├── 10-review-security-lens.md
├── 10-review-usability-lens.md
├── 20-adversarial.md # Step 4 output
├── 30-synthesis.md # Step 5 output (deduped findings)
├── 40-report.md # Step 6 output (final unified report)
├── 50-fixes-iter1.md # Step 7 notes (per fix pass, optional)
├── 50-fixes-iter2.md
└── ...Numeric prefixes preserve chronological order. The <slug> directory is
created at step 1 and reused for the whole run. If the same branch is
re-reviewed after fixes (step 8 loop-back), append a generation suffix
(e.g. <slug>-r2/) rather than overwriting the prior review.
At the start of every step, check whether the corresponding output file already exists. If it does:
Ask the user which to do if the choice is non-obvious. Never silently discard an existing artifact.
When the user asks to "restart from step N", load all artifacts numbered below N into context and re-run from step N onward.
Determine the branch and its merge target (default: main) and derive the
slug. Create .copilot/reviews/<slug>/ if it does not already exist.
Collect the diff using one of these methods, in order of preference:
git diff <merge-target>...<branch> -- . ':!*.lock' — full diff against
the merge base. Save to 00-diff.patch.get_changed_files — if the working tree has uncommitted changes that are
part of the review.Also collect the list of changed files and save to 00-changed-files.txt:
git diff --name-only <merge-target>...<branch>Read the full current content of every changed file so reviewers have both the diff and the surrounding context.
Assemble a context block that every reviewer will receive and write it to
.copilot/reviews/<slug>/00-context.md. This file must be self-contained:
any subagent reading it should have everything it needs without further file
lookups (beyond the diff/changed-files artifacts referenced by path). Include:
00-diff.patch if
large, with key hunks inlined).00-changed-files.txt plus full current
content of each modified file (or excerpts with line ranges if very large).copilot-instructions.md (style, commenting, error handling, etc.).Keep the context block identical across all four reviewers to ensure a fair comparison.
Launch three subagents in parallel, each using a named lens agent operating in review mode. Each receives the context block (by path) and must return findings in the severity-tagged format defined above.
| # | Agent | Focus |
|---|---|---|
| 1 | correctness-lens | Logic errors, broken invariants, test gaps |
| 2 | security-lens | Injection, overflows, trust boundary violations |
| 3 | usability-lens | Naming, complexity, conventions, maintainability |
Each subagent prompt must include:
A directive to read .copilot/reviews/<slug>/00-context.md as its context
An instruction to operate in review mode
A directive to write the resulting findings to
.copilot/reviews/<slug>/10-review-<lens>.md and return a brief
confirmation plus the file path
These instructions:
Review the diff and changed files from the perspective described above. For each issue found, report it in this exact format:
[SEVERITY] Short title
- Location: file path and line number(s)
- Problem: what is wrong and why it matters
- Suggestion: concrete fix or remediation
where SEVERITY is one of: critical, high, medium, low.
If you find no issues from your perspective, state that explicitly. Do NOT fabricate issues. Only report genuine problems. Order findings by severity (critical first).
After the subagents return, verify all three 10-review-*.md files exist
before continuing.
After the three constructive reviewers return, spawn a fresh adversarial-lens
subagent operating in review mode. This step runs sequentially — the
adversarial reviewer receives the existing findings so it can focus on what the
others missed.
The adversarial subagent prompt must include:
A directive to read .copilot/reviews/<slug>/00-context.md and all three
.copilot/reviews/<slug>/10-review-*.md files
A directive to write its findings to
.copilot/reviews/<slug>/20-adversarial.md
These instructions:
You are the adversarial reviewer. The findings in the
10-review-*.mdfiles were produced by three constructive reviewers (correctness, security, usability). Your job is to find what they missed.Focus on:
- Code sections covered by NO existing finding (overlooked areas)
- Issue categories not represented in the existing findings
- Cross-component interactions no single lens would catch
- Unchecked assumptions and untested preconditions
- Silent divergences with no test coverage
- Fragile coupling where changing one thing silently breaks another
For each issue found, report it in this exact format:
[SEVERITY] Short title
- Location: file path and line number(s)
- Problem: what is wrong and why it matters
- Suggestion: concrete fix or remediation
where SEVERITY is one of: critical, high, medium, low.
If the existing findings are comprehensive and you find no gaps, the file must contain exactly: "No additional issues found." Do NOT duplicate issues already reported. Only report NEW problems. Order findings by severity (critical first).
Read all four reviewer outputs (10-review-*.md and 20-adversarial.md)
and write a synthesized findings list to
.copilot/reviews/<slug>/30-synthesis.md:
Each synthesized finding should retain its severity tag and a "Flagged by" attribution listing the contributing lenses.
Assemble the final report at .copilot/reviews/<slug>/40-report.md and
present it to the user. The report must contain these sections, in order:
Summary — one-paragraph overview: number of findings by severity, overall assessment (e.g., "ready to merge with minor fixes" or "has blocking issues").
Positive observations — bullet list of things the reviewers agreed were done well (design choices, test quality, documentation, etc.). Keep it brief but genuine — this provides signal about what to preserve during remediation.
Findings — Critical / High — a Markdown table with columns:
#, Severity, Title, Location, Flagged by, Status.
Below the table, expand each row with the full problem description and
suggested fix.
Findings — Medium — same table + expansion format.
Findings — Low — same table + expansion format.
Trade-offs — any unresolved disagreements between reviewers, with both sides stated.
Remediation plan — a numbered, ordered list of concrete steps to address the findings. Group related fixes into a single step where sensible. Each step should name the finding(s) it addresses and briefly describe what to do. Order by priority: blocking issues first, then medium, then low.
Action prompt — ask the user which findings to address. Options:
For each approved finding:
Record a short summary of the pass to
.copilot/reviews/<slug>/50-fixes-iter<i>.md (incrementing i for each
re-review pass) noting which findings were addressed, which were deferred,
and any test results. This makes it possible to resume mid-remediation if
the session is interrupted.
If a fix is ambiguous or touches architecture, ask the user for guidance and
record the decision in the same 50-fixes-iter<i>.md file.
After all approved fixes are applied:
All approved fixes have been applied and tests pass. Should I run another review pass on the updated diff, or is the branch ready to merge?
<slug>-r2/) and go to step 1 with the updated diff. The prior
review's artifacts remain on disk for reference.© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/branch-review of microsoft/bocpy.
Open the folder on GitHubat commit c8f3ceb
Branch Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Branch Review this skillmicrosoft/bocpy | 201 | — | ~3.2k | Automated safety check: Pass | MIT | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio PR ReviewCherryHQ/cherry-studio | 52k | — | ~3.9k | Automated safety check: Pass | AGPL-3.0 | |
| Jevgrepdzhng/jevgrep | 2.5k | — | ~741 | Automated safety check: Pass | MIT | |
| PR Cyclejaemk/cached | 2.1k | — | ~4.8k | Automated safety check: Notes | MIT | |
| Inference Format Optimizera2ui-project/a2ui | 17k | — | ~985 | Automated safety check: Pass | Apache-2.0 |
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
CherryHQ/cherry-studio
Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.
dzhng/jevgrep
A skill your agent uses for questions about how, why, or where behavior works in a repository, including questions that name a function or setting.
jaemk/cached
PR review-and-update cycle — the orchestrator that takes a PR from review to resolved.
a2ui-project/a2ui
Iterative benchmarking, evaluation, and algorithmic optimization of alternative A2UI inference formats (such as Express, Atom, and Elemental).
jaemk/self_update
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.
microsoft/bocpy
Write a C extension whose custom types can live inside a bocpy Cown and travel between worker sub-interpreters.
microsoft/bocpy
Follow bocpy commenting and documentation conventions. An agent skill from microsoft/bocpy.
microsoft/bocpy
Finalize a feature branch for merge. An agent skill from microsoft/bocpy.
microsoft/bocpy
Multi-perspective planning with rebuttal rounds and adversarial review loop.
microsoft/bocpy
Write tests for the bocpy message queue — the lock-free tag-based MPSC ring buffer.
microsoft/bocpy
Think in Behavior-Oriented Concurrency, not threads-and-locks.
Categories
Multi-perspective code review for a branch before merging. An agent skill from microsoft/bocpy. Branch Review is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Multi-perspective code review for a branch before merging.
Branch Review fits situations like: : reviewing a branch; pre-merge review; auditing a feature branch; /branch-review is invoked.
Run `npx skills add microsoft/bocpy --skill branch-review -a claude-code`. Or copy the skill folder (.github/skills/branch-review in microsoft/bocpy) into .claude/skills/branch-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/bocpy --skill branch-review -a codex`. Or copy the skill folder (.github/skills/branch-review in microsoft/bocpy) into .agents/skills/branch-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/bocpy --skill branch-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/branch-review, .gemini/skills/branch-review, .github/skills/branch-review and .opencode/skills/branch-review in your project.
Going by SKILL.md and its folder, Branch Review needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Branch Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Branch Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), Jevgrep (dzhng/jevgrep, 2.5k stars) and PR Cycle (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/bocpy, which has 201 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.
Source: microsoft/bocpy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.