GitHub Review Iteration
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
Iterative review loop with subagent reviewer. An agent skill from microsoft/bocpy.
$ npx skills add microsoft/bocpy --skill review-loop -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/bocpy review-loop --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/review-loop .claude/skills/review-loop && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .claude/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loopType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/bocpy --skill review-loop -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/bocpy review-loop --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/review-loop .agents/skills/review-loop && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .agents/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/bocpy --skill review-loop -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/bocpy review-loop --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/review-loop .cursor/skills/review-loop && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .cursor/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/bocpy.git --path .github/skills/review-loop--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/bocpy --skill review-loop -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/bocpy review-loop --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/review-loop .gemini/skills/review-loop && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .gemini/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/bocpy review-loopInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/bocpy --skill review-loop -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/review-loop .github/skills/review-loop && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .github/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/bocpy --skill review-loop -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/bocpy review-loop --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/bocpy.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/review-loop .opencode/skills/review-loop && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-loop" agent skill from https://github.com/microsoft/bocpy/tree/main/.github/skills/review-loop into .opencode/skills/review-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-loop", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-loopIterative review loop with subagent reviewer. An agent skill from microsoft/bocpy.
Review Loop is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Iterative review loop with subagent reviewer. Use when: reviewing code changes, reviewing plans, auditing implementations, validating fixes, running code review, performing quality checks, or when /review is invoked. Spawns a fresh subagent to review a user-specified target, reports severity-tagged findings, applies approved fixes, and repeats until the user is satisfied.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Subagents and Code review. The repository describes itself as: Behavior-Oriented Concurrency in Python. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8f3ceb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Loop loads about 1.2k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 639 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/bocpy at commit c8f3ceb, republished under its MIT licence (© microsoft). 639 words, ~1,211 tokens.
.claude/skills/review-loop/SKILL.md (or your agent's skills folder).Iteratively review a target (code or plan) using a fresh subagent reviewer, present findings, apply fixes, and repeat until the user approves.
Findings are tagged with one of four severities:
| Severity | Meaning |
|---|---|
| critical | Correctness bug, security vulnerability, or data loss risk. Must fix. |
| high | Likely bug, race condition, or significant design flaw. Should fix. |
| medium | Code smell, unclear logic, missing edge case, or maintainability concern. Recommended fix. |
| low | Style nit, naming suggestion, minor improvement. Fix at discretion. |
Ask the user what to review if not already specified. The target can be:
Gather the full content of the target so it can be passed to the reviewer.
If a specific lens is requested (e.g., correctness-lens, security-lens,
adversarial-lens, etc.), use that named lens agent operating in review
mode. Otherwise, use a generic reviewer.
Launch a subagent with the following prompt structure:
You are a code reviewer performing a thorough review of the following target. Your job is to find bugs, design flaws, security issues, and quality problems.
Review target: {include the full content of the target here}
Additional context: {include relevant surrounding code, tests, or specifications the reviewer needs to understand the target}
Instructions:
Review the target for correctness, security, performance, readability, and adherence to project conventions.
For each issue found, report it in this exact format:
[SEVERITY] Short title
- Location: file path and line number (or plan step)
- Problem: what is wrong and why it matters
- Suggestion: concrete fix or remediation
where SEVERITY is one of: critical, high, medium, low.
If you find no issues, state explicitly that the target looks correct.
Do NOT fabricate issues. Only report genuine problems.
Order findings by severity (critical first).
Use the Explore subagent for read-only review of code. If the reviewer needs
to run tests or execute code to verify a finding, note that as an unverified
finding and let the main agent handle verification.
After the reviewer returns:
For each approved finding:
If a fix is non-trivial or ambiguous, ask the user for guidance rather than guessing.
After fixes are applied, ask the user:
All approved fixes have been applied. Should I run another review pass, or are we done?
© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/review-loop of microsoft/bocpy.
Open the folder on GitHubat commit c8f3ceb
Review Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Loop this skillmicrosoft/bocpy | 201 | — | ~1.2k | Automated safety check: Pass | MIT | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio PR ReviewCherryHQ/cherry-studio | 52k | — | ~3.9k | Automated safety check: Pass | AGPL-3.0 | |
| PR Reviewjaemk/self_update | 961 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Cursor Composer Task DelegateChachamaru127/claude-code-harness | 3.2k | — | ~4.4k | Automated safety check: Notes | MIT | |
| Local PR Reviewwindmill-labs/windmill | 18k | — | ~995 | Automated safety check: Pass | Custom licence |
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
CherryHQ/cherry-studio
Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.
jaemk/self_update
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
windmill-labs/windmill
Runs the same code review locally that GitHub's auto-review actions run on a PR, delegating to a fresh-context subagent so the review isn't biased by the main session's own reasoning.
HuangPuStar/FenixAgent
A skill your agent uses when starting an issue, bugfix, feature, or refactor that should be driven by multiple coordinated subagents: explore → plan → code → review, with the main agent acting as…
microsoft/bocpy
Multi-perspective code review for a branch before merging. An agent skill from microsoft/bocpy.
microsoft/bocpy
Write a C extension whose custom types can live inside a bocpy Cown and travel between worker sub-interpreters.
microsoft/bocpy
Follow bocpy commenting and documentation conventions. An agent skill from microsoft/bocpy.
microsoft/bocpy
Finalize a feature branch for merge. An agent skill from microsoft/bocpy.
microsoft/bocpy
Multi-perspective planning with rebuttal rounds and adversarial review loop.
microsoft/bocpy
Write tests for the bocpy message queue — the lock-free tag-based MPSC ring buffer.
Categories
Iterative review loop with subagent reviewer. An agent skill from microsoft/bocpy. Review Loop is an agent skill from microsoft/bocpy, published by the product's own GitHub organization. Iterative review loop with subagent reviewer.
Review Loop fits situations like: : reviewing code changes; reviewing plans; auditing implementations; validating fixes.
Run `npx skills add microsoft/bocpy --skill review-loop -a claude-code`. Or copy the skill folder (.github/skills/review-loop in microsoft/bocpy) into .claude/skills/review-loop in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/bocpy --skill review-loop -a codex`. Or copy the skill folder (.github/skills/review-loop in microsoft/bocpy) into .agents/skills/review-loop in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/bocpy --skill review-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-loop, .gemini/skills/review-loop, .github/skills/review-loop and .opencode/skills/review-loop in your project.
SKILL.md names no scripts, command-line tools or credentials: Review Loop is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Loop: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/bocpy, which has 201 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.
Source: microsoft/bocpy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.