Agent skill

PR Review

by Mindrally in Mindrally/skills

Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture.

Apache-2.0Auto-check: notesDevelopment

Install PR Review

skills CLI
$ npx skills add Mindrally/skills --skill pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mindrally/skills pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mindrally/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pr-review .claude/skills/pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-review
GitHub stars
269
Token cost
~1.8k tokens
SKILL.md length
926 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
Apache-2.0

At a glance

Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture.

  • Works in 7 steps: Pick the angle — Determine emphasis from… → Get full file context — A diff alone… → Review against the angle's checklist —… → …
  • Asked to review a pull request
  • SKILL.md covers Workflow for Reviewing a PR, Output Discipline, Angle 1: Security and Angle 2: Performance, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

PR Review is an agent skill from Mindrally/skills. Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture. Use when asked to review a pull request, review a diff or set of changes, review "this PR," or provide a code review before merge.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests and Code review. The repository describes itself as: 265+ Claude Code skills for every major framework and language. Install with: npx skills add Mindrally/skills. The licence is Apache-2.0.

When your agent uses it

  • Asked to review a pull request
  • Provide a code review before merge

Example prompts

  • “this PR,”
  • “/pr-review”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Pick the angle — Determine emphasis from the user's request ("security", "perf", "tests", "arch"). If unspecified, ask which angle to use…
  2. Get full file context — A diff alone routinely misses bugs that live just outside the changed lines. If only a diff is available, request…
  3. Review against the angle's checklist — Work through the relevant checklist below in priority order; do not mix angles unless the user…
  4. Write specific, cited findings — Every finding names a file and line number and states the concrete defect, not a vague impression.
  5. Rank by severity — Group findings as blocker, important, or nit.
  6. State uncertainty explicitly — If the diff doesn't give enough context to be sure, say so and ask for more code rather than guessing.
  7. End with a verdict on its own line — Safe to merge | needs changes | reject (or the architecture-specific verdict below).

What it can do on your machine

Read from SKILL.md and the folder at commit 7682ca7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Review loads about 1.8k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 926 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:40
    n logs, secrets in client-bundled code, `.env` committed to the repo.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mindrally/skills at commit 7682ca7, republished under its Apache-2.0 licence (© Mindrally). 926 words, ~1,787 tokens.

Download SKILL.mdSave it as .claude/skills/pr-review/SKILL.md (or your agent's skills folder).
name
pr-review
description
Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture. Use when asked to review a pull request, review a diff or set of changes, review "this PR," or provide a code review before merge.
metadata.maintainer
Mindrally
metadata.source
https://github.com/Mindrally/skills

PR Review

This skill covers focused, angle-specific pull request review: picking the right lens (security, performance, tests, or architecture), producing specific and severity-ranked findings, and closing with a clear merge verdict.

Workflow for Reviewing a PR

  1. Pick the angle — Determine emphasis from the user's request ("security", "perf", "tests", "arch"). If unspecified, ask which angle to use, or default to security as the highest-risk default.
  2. Get full file context — A diff alone routinely misses bugs that live just outside the changed lines. If only a diff is available, request the surrounding file(s) before making confident claims.
  3. Review against the angle's checklist — Work through the relevant checklist below in priority order; do not mix angles unless the user asked for a full review.
  4. Write specific, cited findings — Every finding names a file and line number and states the concrete defect, not a vague impression.
  5. Rank by severity — Group findings as blocker, important, or nit.
  6. State uncertainty explicitly — If the diff doesn't give enough context to be sure, say so and ask for more code rather than guessing.
  7. End with a verdict on its own line — Safe to merge | needs changes | reject (or the architecture-specific verdict below).

Output Discipline

Applies to every review angle:

  • Cite file path and line number for each finding.
  • Rank findings by severity: blocker, important, nit.
  • Be specific. "This looks risky" is not a finding; "src/auth.ts:42 — JWT secret read from request body, see line 41" is a finding.
  • If the diff doesn't give enough context to be sure, say so explicitly and ask for the surrounding file.
  • End with a verdict on its own line: Safe to merge | needs changes | reject.

Angle 1: Security

Review the PR for security defects, in order of priority:

  1. Auth/authz — new endpoints or branches missing auth checks, role assumptions, IDOR (insecure direct object reference).
  2. Input validation — untrusted input flowing into queries, shell commands, file paths, deserialization, or eval.
  3. Injection — SQL, NoSQL, command, prompt injection, template injection.
  4. Secrets — hardcoded keys/tokens, secrets in logs, secrets in client-bundled code, .env committed to the repo.
  5. Output encoding — XSS via unescaped templating, raw HTML in user content, JSONP-style leaks.
  6. Crypto/randomness — Math.random() used for tokens, MD5/SHA1 for password or integrity purposes, missing IVs, custom-rolled crypto.
  7. Data exposure — PII in logs, overshared API responses, missing redaction.

Skip nice-to-haves; stick to defects.

Angle 2: Performance

Review for performance regressions:

  1. N+1 patterns — loops doing a DB or network call per item instead of batching.
  2. Hot-path allocations — new objects/arrays/maps created inside loops, regexes recompiled per call.
  3. Unbounded work — missing pagination, unconstrained result sets, recursion without a depth cap.
  4. Bad async — sequential awaits where Promise.all is correct, missing concurrency limits.
  5. Cache misuse — cache keys that omit a relevant variable, absent or pathological TTLs.
  6. Algorithm complexity — hidden O(n²) (e.g. .some() inside .map()), sorting inside a loop.

Quote the specific line, name the complexity class or bad pattern, and suggest the fix.

Angle 3: Tests

Review the test coverage on the PR:

  1. Tests for new code paths — every new branch should have at least one test.
  2. Edge cases — empty input, null/undefined, boundary values, errors thrown by dependencies.
  3. Assertion strength — assertions that would pass with the wrong value, snapshot-only tests, tests that only check the happy path.
  4. Mocking discipline — mocks that don't fail when the real interface changes, over-mocking that hides real behavior.
  5. Determinism — date/time/random/network not stubbed, leading to flaky tests.
  6. Test names — names that don't describe the behavior under test.

A test that exists is not the same as a test that catches regressions — read the assertions, not the test name.

Show full SKILL.md (316 more words)Show less

Angle 4: Architecture

Pull back from line-level concerns to review the shape of the change:

  1. Boundary drift — where did the seam between layers move? Did UI start reaching into the DB? Did domain types start importing transport types?
  2. Premature abstraction — interfaces, factories, or config layers with only one implementation; flag these as debt.
  3. Coupling — utilities now importing from feature modules, shared mutable state being introduced.
  4. Scalability — if this code path goes 10x, what breaks first?
  5. Reversibility — if this turns out wrong in a month, how hard is the rollback? Call out one-way doors explicitly.
  6. Naming — types/functions named for the implementation (UserManagerImplV2) rather than the role (UserDirectory).

End with: Architecturally sound | needs trim | re-think before merging.

Example Finding Format

src/api/orders.ts:118 (blocker, security)
  Order lookup uses `req.params.orderId` directly in a WHERE clause
  built via string concatenation — SQL injection. Use a parameterized
  query or the existing `db.orders.findById()` helper instead.

src/api/orders.ts:142 (nit, tests)
  `createOrder` has no test for the case where `items` is an empty
  array; current tests only cover the happy path with 1-3 items.

Verdict: needs changes

Reviewing Multiple Angles at Once

  • When the user asks for a "full review" rather than one specific angle, run all four checklists in sequence rather than blending them into one undifferentiated pass — each angle catches different classes of defect, and keeping them separate keeps findings traceable to a specific concern.
  • Present each angle under its own heading with its own verdict line; do not merge four verdicts into one summary sentence.
  • If time or context is limited, prioritize security first, then tests, then performance, then architecture — a security defect that ships is categorically worse than an architectural wart.

Common Pitfalls in Review

  • Approving based on the diff's intent ("looks like it adds validation") rather than reading what the code actually does.
  • Treating a passing test suite as proof of correctness — a test suite only proves the tests that exist pass, not that the right tests exist.
  • Letting scope creep into the review: flagging pre-existing issues untouched by the diff is fine to mention separately, but shouldn't block the PR under review.
  • Giving a verdict without having seen enough of the surrounding file to justify it — ask for more context instead of guessing.

© Mindrally, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in pr-review of Mindrally/skills.

Open the folder on GitHubat commit 7682ca7

Compare with similar skills

PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Review this skillMindrally/skills269—~1.8kAutomated safety check: NotesApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Open Code Review CLIalibaba/open-code-review45k—~3.1kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything86k—~1.4kAutomated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    45k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from Mindrally/skills

All 34 skills in this repo
  • Analytics Data Analysis

    Mindrally/skills

    Best practices for analytics, data analysis, and visualization using Python, pandas, matplotlib, seaborn, and Jupyter notebooks.

    269 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Best practices for AutoML and hyperparameter search with Optuna, Ray Tune, and PyCaret, covering search-space design, validation splits, and leakage prevention.

    269 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Blender Python Addon

    Mindrally/skills

    Best practices for writing Blender Python add-ons using the bpy API, covering operators, panels, properties, registration, and API-safe scripting.

    269 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices.

    269 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Clean Code

    Mindrally/skills

    Clean, maintainable, human-readable code principles combined with anti-over-engineering discipline: naming, single responsibility, DRY, and scoping changes to exactly what was requested.

    269 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Design Systems

    Mindrally/skills

    Comprehensive design system guidelines for building consistent, accessible, and scalable component libraries.

    269 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about PR Review

What does PR Review do?

Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture. PR Review is an agent skill from Mindrally/skills. Focused pull request review practices with severity-ranked, file-and-line-cited findings across four angles: security, performance, tests, and architecture.

When should I use PR Review?

PR Review fits situations like: asked to review a pull request; provide a code review before merge.

How do I install PR Review in Claude Code?

Run `npx skills add Mindrally/skills --skill pr-review -a claude-code`. Or copy the skill folder (pr-review in Mindrally/skills) into .claude/skills/pr-review in your project. Claude Code loads it when a task matches its description.

How do I install PR Review in Codex?

Run `npx skills add Mindrally/skills --skill pr-review -a codex`. Or copy the skill folder (pr-review in Mindrally/skills) into .agents/skills/pr-review in your project. Codex loads it when a task matches its description.

Can I use PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mindrally/skills --skill pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review, .gemini/skills/pr-review, .github/skills/pr-review and .opencode/skills/pr-review in your project.

What does PR Review need to run?

SKILL.md names no scripts, command-line tools or credentials: PR Review is instructions for the agent only.

Does PR Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is PR Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does PR Review use?

PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Review use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Review?

Skills that share tags, products or a category with PR Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Open Code Review CLI (alibaba/open-code-review, 45k stars) and GitHub Review Iteration (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Review?

Mindrally (a GitHub organization) maintains it in Mindrally/skills, which has 269 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 8, 2026.

Source: Mindrally/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.