Agent skill

Review Skia Update

by mono in mono/SkiaSharp

Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp.

MITAuto-check passedDevelopment

Install Review Skia Update

skills CLI
$ npx skills add mono/SkiaSharp --skill review-skia-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mono/SkiaSharp review-skia-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-skia-update .claude/skills/review-skia-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-skia-update
GitHub stars
5.6k
Token cost
~1.6k tokens
SKILL.md length
704 words
Files
19 (incl. scripts, references)
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp.

  • Works in 4 steps: Run the Orchestrator → Write Summaries & Build Report → Review Companion C# PR → …
  • Tasks that involve Pull requests
  • SKILL.md covers ⛔ MANDATORY FIRST STEPS (do…, Overview, Phase 1 — Run the Orchestrator and Phase 2 — Write Summaries &…, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Review Skia Update is an agent skill from mono/SkiaSharp. Review a Skia upstream merge PR in mono/skia. Produces a security-auditable report by diffing against the upstream branch, verifying generated P/Invoke bindings, checking source integrity, and auditing DEPS changes. Triggers: "review skia update PR NNN", "review skia PR", "review skia bump", "check skia update integrity".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `references/csharp-review.md`, `references/schema-cheatsheet.md` and `references/skia-review-schema.json`).

It sits in Development, covering Pull requests. The repository describes itself as: SkiaSharp is a cross-platform 2D graphics API for .NET platforms based on Google's Skia Graphics Library. It provides a comprehensive 2D API that can be used across mobile… The licence is MIT.

When your agent uses it

  • Tasks that involve Pull requests

Example prompts

  • “review skia update PR NNN”
  • “review skia PR”
  • “review skia bump”
  • “/review-skia-update”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Run the Orchestrator
  2. Write Summaries & Build Report
  3. Review Companion C# PR
  4. Validate & Persist

What it can do on your machine

Read from SKILL.md and the folder at commit 6e0e83e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 14 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Skia Update loads about 1.6k tokens when it runs, and up to ~9.1k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 704 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mono/SkiaSharp at commit 6e0e83e, republished under its MIT licence (© mono). 704 words, ~1,629 tokens.

Download SKILL.mdSave it as .claude/skills/review-skia-update/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
review-skia-update
description
Review a Skia upstream merge PR in mono/skia. Produces a security-auditable report by diffing against the upstream branch, verifying generated P/Invoke bindings, checking source integrity, and auditing DEPS changes. Triggers: "review skia update PR #NNN", "review skia PR", "review skia bump", "check skia update integrity".

Review Skia Update

Analyze a Skia upstream merge PR in mono/skia and produce a structured, schema-validated review report. Reduces 100K–500K line diffs to focused, human-reviewable artifacts.

⛔ MANDATORY FIRST STEPS (do not skip)

  1. Read THIS entire SKILL.md before any investigation
  2. Read references/schema-cheatsheet.md for required JSON fields

Overview

A Skia update always involves two PRs that must be reviewed together:

  • mono/skia PR — the Skia submodule bump (C headers, DEPS, upstream merge)
  • SkiaSharp PR — the companion C# changes (generated bindings, hand-written wrappers)
Phase 1: Run orchestrator  →  Phase 2: Write summaries & build report
Phase 3: Review C# PR      →  Phase 4: Validate & persist

Phase 1 — Run the Orchestrator

A single script handles all mechanical work: fetching PR metadata, checking out both PRs, running the generator, checking source integrity, auditing DEPS, and analyzing companion PR files.

bash
python3 .agents/skills/review-skia-update/scripts/run_review.py \
    --skia-pr {skia_pr_number} \
    --skiasharp-pr {skiasharp_pr_number} \
    --milestone {milestone_number}

All three parameters are required. A Skia update always has a companion SkiaSharp PR. Extract the milestone number from the PR title, body, or branch name (e.g. 147 from "Bump skia to milestone 147" or "Dev/update skia 147"). The orchestrator validates this against cgmanifest.json and the PR title for consistency.

Output: raw-results.json in the output directory with all check results, including mechanically generated file lists and diffs for upstream integrity, interop integrity, DEPS, and companion PR files.

After this runs, the working tree is checked out to the PR state — you can browse files locally.

⚠️ If the orchestrator fails, report the failure and stop. Do not attempt to run individual scripts manually.

⚠️ NO-RETRY POLICY: Run the orchestrator exactly ONCE. If generation reports FAIL, that is the result. Do NOT re-run to get a different outcome.


Phase 2 — Write Summaries & Build Report

Read references/writing-summaries.md for detailed guidance.

  1. Load raw-results.json from the output directory printed by the orchestrator
  2. For every item in added/removed/changed across ALL sections (upstream, interop, companion PR): read the diff and write a factual summary
  3. Verify removed patches — For each removed upstream patch, check the new upstream code to determine WHY it was dropped. See writing-summaries.md "Verifying Removed Patches" for the required process. Never speculate about patch removal reasons.
  4. Assemble the final JSON report conforming to skia-review-schema.json
  5. Include actual diff content in the JSON (not file path references)
  6. Save the report to {output_dir}/{pr_number}.json — the same directory as raw-results.json

Phase 3 — Review Companion C# PR

Read references/csharp-review.md for detailed guidance.

The orchestrator already produced the companionPr section with file lists and diffs in raw-results.json. This phase adds human-oriented review context:

  1. Ignore generator-owned declaration and interop changes in *.generated.cs, but review direct /// documentation-comment changes reported by the orchestrator
  2. For each companion PR file, review the diff for: null handling, disposal patterns, ABI compatibility
  3. Check test coverage for new/changed APIs
  4. Add relatedFiles cross-links to interop files where applicable

The working tree is checked out to the companion PR, so you can read files directly.


Show full SKILL.md (249 more words)Show less

Phase 4 — Validate & Persist

1. Validate

🛑 PHASE GATE: You CANNOT proceed to persist without passing validation. Skipping validation = INVALID review. The task is incomplete.

bash
python3 .agents/skills/review-skia-update/scripts/validate-skia-review.py {output_dir}/{pr_number}.json
  • Exit 0 = ✅ valid → proceed to persist
  • Exit 1 = ❌ fix the errors listed in the output, then re-run. Repeat up to 3 times.
  • Exit 2 = fatal error, stop and report

⚠️ NEVER hand-roll your own validation. NEVER assume it passes. RUN THE SCRIPT.

2. Persist

🛑 PHASE GATE: The validator MUST have printed ✅ before you reach this step. If you have not run the validation script, GO BACK and run it now.

Copy the validated JSON to output/ai/ for collection.

bash
python3 .agents/skills/review-skia-update/scripts/persist-skia-review.py {output_dir}/{pr_number}.json

This copies the JSON to output/ai/repos/mono-skia/ai-review/ and generates an HTML report alongside it. The HTML is a self-contained file (Bootstrap 5 + diff2html) suitable for attaching to a PR/issue or uploading as a gist.

To push to the data-cache branch separately, use the persist-aw-data GitHub Actions workflow.

3. Present summary
✅ Review: ai-review/{pr_number}.json

Generated Files:    PASS/FAIL
Upstream Integrity: PASS/REVIEW_REQUIRED (Na/Nr/Nc)
Interop Integrity:  PASS/REVIEW_REQUIRED (Na/Nc)
DEPS Audit:         PASS/REVIEW_REQUIRED (Na/Nc)
Companion PR:       PASS/REVIEW_REQUIRED (Na/Nc)
Risk:               HIGH/MEDIUM/LOW

After presenting the summary, ask the user if they'd like to open the HTML report in their browser to review the full contents (diffs, recommendations, dependency table, etc.). If yes:

bash
open output/ai/repos/mono-skia/ai-review/{pr_number}.html  # macOS
# or: xdg-open ... (Linux) / start ... (Windows)

Rules

  1. Run orchestrator first — Do not run individual check scripts manually
  2. No retries — Run once, report what happened
  3. Never trust generated files — The orchestrator regenerates independently
  4. No per-file PASS/FAIL — AI provides factual summaries; all items need human review
  5. Include actual diffs in JSON — Dashboard renders them directly
  6. Validate before persist — Must see ✅ valid
  7. No absolute paths in report — Redact to relative paths

© mono, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references) in .agents/skills/review-skia-update of mono/SkiaSharp.

  • SKILL.md
  • references/csharp-review.md
  • references/schema-cheatsheet.md
  • references/skia-review-schema.json
  • references/writing-summaries.md
  • scripts/.gitignore
  • scripts/check_companion.py
  • scripts/check_companion_test.py
  • scripts/check_deps.py
  • scripts/check_generated_files.py
  • scripts/check_generated_files_test.py
  • scripts/check_source.py
  • scripts/persist-skia-review.py
  • scripts/regenerate_bindings.py
  • scripts/render-skia-review.py
  • scripts/run_review.py
  • scripts/run_review_test.py
  • scripts/validate-skia-review.py
  • scripts/viewer.html

Open the folder on GitHubat commit 6e0e83e

Compare with similar skills

Review Skia Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Skia Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Skia Update this skillmono/SkiaSharp5.6k—~1.6kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands91k—~2.4kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    91k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Record PR Demo

    payloadcms/payload

    A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.

    45k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from mono/SkiaSharp

All 21 skills in this repo
  • Issue Fix

    mono/SkiaSharp

    Fix bugs in SkiaSharp C bindings. An agent skill from mono/SkiaSharp.

    5.6k GitHub stars~5.1k tokensUpdated yesterday
    Auto-check passed
  • Issue Repro

    mono/SkiaSharp

    Reproduce a SkiaSharp issue systematically and capture structured reproduction results.

    5.6k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Issue Triage

    mono/SkiaSharp

    Triage a SkiaSharp GitHub issue or PR into structured JSON with classification (type, area, platform, severity), suggested response, automatable actions, and companion Markdown/HTML reports.

    5.6k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Sample Scout

    mono/SkiaSharp

    Scout Skia GM (golden master) samples in the externals/skia submodule to find demos worth porting to the SkiaSharp Gallery.

    5.6k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Skia Analyst

    mono/SkiaSharp

    Analyze Skia features for SkiaSharp - produces a unified analysis of what shipped (upstream engine benefits, PR links, migration guides) and what's missing (impact/priority/effort scoring, hidden…

    5.6k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Review Skia Update

What does Review Skia Update do?

Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp. Review Skia Update is an agent skill from mono/SkiaSharp. Review a Skia upstream merge PR in mono/skia.

When should I use Review Skia Update?

Review Skia Update fits situations like: tasks that involve Pull requests.

How do I install Review Skia Update in Claude Code?

Run `npx skills add mono/SkiaSharp --skill review-skia-update -a claude-code`. Or copy the skill folder (.agents/skills/review-skia-update in mono/SkiaSharp) into .claude/skills/review-skia-update in your project. Claude Code loads it when a task matches its description.

How do I install Review Skia Update in Codex?

Run `npx skills add mono/SkiaSharp --skill review-skia-update -a codex`. Or copy the skill folder (.agents/skills/review-skia-update in mono/SkiaSharp) into .agents/skills/review-skia-update in your project. Codex loads it when a task matches its description.

Can I use Review Skia Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mono/SkiaSharp --skill review-skia-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-skia-update, .gemini/skills/review-skia-update, .github/skills/review-skia-update and .opencode/skills/review-skia-update in your project.

What does Review Skia Update need to run?

Going by SKILL.md and its folder, Review Skia Update needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Review Skia Update access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Skia Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Review Skia Update use?

Review Skia Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Skia Update use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.5k tokens, read only when the agent opens those files.

What are the alternatives to Review Skia Update?

Skills that share tags, products or a category with Review Skia Update: Finishing a Development Branch (obra/superpowers, 297k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and PR Design Doc (OpenHands/OpenHands, 91k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Skia Update?

mono (a GitHub organization) maintains it in mono/SkiaSharp, which has 5,589 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 10, 2026.

Source: mono/SkiaSharp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.