PR Babysitter
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
Inspect selected PR comments or perform complete PR review triage; address verified findings when authorized.
$ npx skills add netdata/netdata --skill repo-pr-reviews -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install netdata/netdata repo-pr-reviews --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .claude/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .claude/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviewsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add netdata/netdata --skill repo-pr-reviews -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install netdata/netdata repo-pr-reviews --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .agents/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .agents/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add netdata/netdata --skill repo-pr-reviews -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install netdata/netdata repo-pr-reviews --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .cursor/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .cursor/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/netdata/netdata.git --path .agents/skills/repo-pr-reviews--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add netdata/netdata --skill repo-pr-reviews -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install netdata/netdata repo-pr-reviews --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .gemini/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .gemini/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install netdata/netdata repo-pr-reviewsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add netdata/netdata --skill repo-pr-reviews -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .github/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .github/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add netdata/netdata --skill repo-pr-reviews -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install netdata/netdata repo-pr-reviews --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/repo-pr-reviews .opencode/skills/repo-pr-reviews && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "repo-pr-reviews" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/repo-pr-reviews into .opencode/skills/repo-pr-reviews/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repo-pr-reviews", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
repo-pr-reviewsInspect selected PR comments or perform complete PR review triage; address verified findings when authorized.
Repo PR Reviews is an agent skill from netdata/netdata. Inspect selected PR comments or perform complete PR review triage; address verified findings when authorized. Covers GitHub review threads, bot feedback, SonarCloud findings and CI. Ordinary code review without PR-comment handling uses the relevant domain skills.
Its SKILL.md is about 8.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts (for example `scripts/_lib.sh`, `scripts/ci-status.sh` and `scripts/fetch-all.sh`).
It sits in Development, covering Pull requests. It works with GitHub. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 567162f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 11 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
bashghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONAR_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Repo PR Reviews loads about 8.1k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 4,263 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Requires the same `.env` config the `triage-sonarqube` skill uses`SONAR_HOST_URL`, `SONAR_PROJECT`). If `.env` is missing,Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from netdata/netdata at commit 567162f, republished under its GPL-3.0 licence (© netdata). 4,263 words, ~8,106 tokens.
.claude/skills/repo-pr-reviews/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.This skill gathers and verifies PR findings, then applies the authorized handling path below.
Authorization and read-only scope are owned by AGENTS.md#when-a-sow-is-required; Git operations by
AGENTS.md#git-and-pr-workflow; finding classification, review repetition and stopping by AGENTS.md#review.
Sources of findings, in priority order:
github-advanced-security.
Fetch the SonarCloud API explicitly for the complete finding set;
GitHub comments and the QualityGate summary are not a complete inventory.A finding is "relevant to this PR" if its existence (or its line location) is plausibly caused by the PR's diff. CI failures unrelated to this PR (a flaky test on an unrelated module, an infra outage) are NOT in scope -- note them, surface to the user at the end, do not fix them here.
The bar is the project's performance, stability, and long-term maintainability. Don't dismiss findings because they look minor.
These are non-negotiable. Skipping any of them will cost the user time.
page=N+1 request. fetch-all.sh does this automatically.AGENTS.md#review. Handle non-blocking findings under
AGENTS.md#scope-discipline-at-every-step and AGENTS.md#followup-discipline; do not silently discard them or
promote them to shipping blockers merely because a reviewer requested them.AGENTS.md#review).ci-status.sh. If there are PR-caused failures, fix
them and bundle into the same push. If checks are still running,
that's fine -- ignore them and push anyway. The next push triggers
fresh CI on the new code, which is what we actually care about.AGENTS.md#review and trigger comments are authorized,
re-trigger the selected bots, then use wait-for-activity.sh for their feedback.wait-for-activity.sh times out (30 min, no new comments):
re-check ci-status.sh. If checks are still running, that's normal,
surface to the user. Treat PR-caused failures as blockers; report unrelated failures without fixing them.AGENTS.md#review to decide whether to
repeat a round; do not re-trigger solely to obtain an approval phrase. Trigger comments require authorization.trigger-cubic.sh).trigger-coderabbit.sh; @coderabbitai review is incremental,
full review re-reads the whole PR).trigger-copilot.sh is kept for the case where credits exist,
but it is not part of the loop and Copilot never blocks the exit
condition. Address any comments it does post like any other AI bot.wait-for-activity.sh with the 30-min timeout and
move on if nothing changes.AGENTS.md#review.AGENTS.md#review; a push alone does not
require another review when the current change already has adequate coverage.cubic-dev-ai[bot], coderabbitai[bot], copilot[bot] and
variants): handle
within the authorized path above. Verify every finding; fix, reply and resolve only when those actions are
authorized. Inspection alone ends with a report.github-advanced-security): verify findings against the originating analyzer and
current source. Use the same authorized thread workflow; mirrored Sonar issues also need their Sonar disposition
under step 3b.sonarqubecloud[bot], github-actions[bot],
netdata-bot[bot]): read for signal (e.g. quality
gate status). They don't usually require a reply.For live GitHub fetching, use gh authenticated for the repo. Sonar fetching additionally needs its configured
authentication below. Reading supplied comments or reviewing this skill needs neither setup.
The skill reads upstream (or origin) from git remotes to derive the
repo slug. Override with PR_REPO_SLUG=owner/repo if working cross-repo.
State for each PR is cached under <repo-root>/.local/audits/pr-reviews/pr-<N>/:
pr.json -- top-level PR metadataissue-comments.json -- top-level PR comments (REST)review-comments.json -- inline review comments (REST)reviews.json -- review submissions with body (REST)review-threads.json -- per-thread, with isResolved (GraphQL)summary.txt -- human-readable triage summaryFETCH-INCOMPLETE -- present only while a fetch is running or after one aborted; the snapshot is partial, re-run
fetch-all.sh before reading anything else hereFor supplied-comment-only inspection, skip the commands in steps 1-2, verify the supplied findings directly, then
report under step 8. For other inspections, use the selected sources in steps 1-2, verify the findings, then report
under step 8. For complete triage, all sources apply. For authorized addressing, apply
steps 3-4, perform only authorized remote actions, and use AGENTS.md#review to decide whether steps 5-7 are needed.
Run when the selected scope requires fetching GitHub comments. For supplied-comment-only inspection, use the supplied evidence directly and skip this step.
bash .agents/skills/repo-pr-reviews/scripts/fetch-all.sh <PR_NUMBER>Tail-prints a summary.txt that shows the per-author count and the list of
open review threads. Use this as the input to the rest of the cycle.
Run only when Sonar findings belong to the selected scope and need fetching. Supplied Sonar evidence can be inspected without this fetch or credential setup; a comment-only scope skips this step.
bash .agents/skills/repo-pr-reviews/scripts/fetch-sonar-findings.sh <PR_NUMBER>This script fetches the full SonarCloud finding set, including findings absent from GitHub inline comments:
.local/audits/pr-reviews/pr-<N>/sonar-issues.json.local/audits/pr-reviews/pr-<N>/sonar-hotspots.jsonRequires the same .env config the triage-sonarqube skill uses
(SONAR_TOKEN, SONAR_HOST_URL, SONAR_PROJECT). If .env is missing,
the script prints what's needed and exits.
An empty issue/hotspot list does not prove the quality gate passed. Inspect
/api/qualitygates/project_status?projectKey=<project>&pullRequest=<PR> for
failed metric conditions. For duplication, use
/api/duplications/show?key=<file-component-key>&pullRequest=<PR>: each
duplications[].blocks[] identifies from, size, and _ref; files
resolves those references. Preserve test cases when sharing duplicated setup.
For complete triage, or when CI belongs to the selected inspection scope, run
bash .agents/skills/repo-pr-reviews/scripts/ci-status.sh <PR> once early to capture which checks are failing
right now. You're looking for failures caused by the current PR
(typo in a YAML file you added, a script that doesn't pass shellcheck,
a build that breaks because of the diff). DO NOT fix CI yet -- just note
the failures as input alongside review comments and Sonar findings. They
all get addressed in the same iteration so a single push covers them.
These commands read a completed fetch-all.sh cache and apply only when fetched GitHub threads are selected evidence.
For supplied-comment-only inspection, assistants MUST skip both commands even if a cache exists and verify the
supplied evidence directly.
bash .agents/skills/repo-pr-reviews/scripts/list-open-threads.sh <PR_NUMBER> # full bodies
bash .agents/skills/repo-pr-reviews/scripts/list-open-threads.sh <PR_NUMBER> --short # one line per threadThe "short" output is a table: thread-id | path:line | author. The full
form prints every comment in each thread.
This is per-thread, not batched. Do not prepare a list of replies and fire them in a loop. Do not post all replies first and resolve all later. Walk one thread at a time:
For thread N:
AGENTS.md#review; fix blockers and approved improvements, including similar
in-scope instances. Record dispositions for non-blocking items under the root scope and follow-up rules.bash .agents/skills/repo-pr-reviews/scripts/reply-thread.sh <PR> <comment-id> "<reply>"<comment-id> is the databaseId of the FIRST comment in the thread
(from review-threads.json -> .[].comments.nodes[0].databaseId).posted reply id=.... Resolving a thread whose reply failed
hides it from the needs-attention view with nothing written in it, which
reads to a human as a silently dismissed review.bash .agents/skills/repo-pr-reviews/scripts/resolve-thread.sh <thread-id><thread-id> is the GraphQL node id (review-threads.json -> .[].id,
starts with PRRT_). Resolving immediately after replying takes the
thread out of the "needs attention" view; leaving threads open without
resolution accumulates noise.Then move to thread N+1. Reply-and-resolve, reply-and-resolve. Never queue them up.
The reason: the order makes intent visible to humans watching the PR -- they see "agent posted reply, agent resolved" as one motion per thread, not "agent dumped 14 replies, then dumped 14 resolves". Bulk operations look mechanical and erode trust in the address pass.
Skip this step when Sonar findings are outside the selected scope. Use supplied evidence or the selected fetch from step 1b; an unrelated cached Sonar file does not add it to scope.
For each issue in sonar-issues.json and each hotspot in
sonar-hotspots.json:
AGENTS.md#review; fix blockers and approved improvements, including similar
in-scope instances. Disposition other findings under the root scope and follow-up rules.triage-sonarqube provides
sonar-mark.sh fp <KEY> "<reason>" to mark it False Positive in SonarCloud. Comments are ASCII-only (Cloudflare).AGENTS.md#review and
report unmet required quality gates explicitly.When a Sonar finding is mirrored into a GitHub thread, handle that thread under step 3 as well as the Sonar classification above. Replying to or resolving the GitHub thread does not change the Sonar issue state; a Sonar transition does not replace an explanation in the GitHub thread. Both actions require their existing authorization.
Reviewers run in parallel. Multiple bots and humans can be appending findings WHILE you're addressing the current batch. If you push the moment your queue is empty, the findings that arrived during this iteration get attributed to your fresh commit instead of the previous one -- and on the next round you end up "fixing" findings that no longer apply because you addressed them implicitly with the next push. The result: chronic desync, where your commit and the reviewers' findings are always one round apart.
Before an authorized push for complete triage, re-fetch all sources (comments, Sonar, CI). For explicitly scoped handling, refresh the selected finding sources and check CI; report the scope limit. Triage new findings against HEAD. Resolve verified blockers before pushing; handle non-blocking items under the root scope/follow-up rules. This reduces stale work but is not an atomic barrier: new feedback can arrive after the fetch.
# Complete-triage example. Scoped handling refreshes only its selected finding sources.
# Both paths check CI before an authorized push.
bash .agents/skills/repo-pr-reviews/scripts/fetch-all.sh <PR_NUMBER>
bash .agents/skills/repo-pr-reviews/scripts/fetch-sonar-findings.sh <PR_NUMBER>
bash .agents/skills/repo-pr-reviews/scripts/ci-status.sh <PR_NUMBER>The ci-status.sh line is the third source: a CI failure that is
CAUSED by this PR's changes (added a script that doesn't pass
shellcheck, broke a YAML parse, etc.) is in scope and must be folded
in. CI failures unrelated to this PR are noted, surfaced to the user
at the end, but not fixed here.
If the fresh snapshot contains an unassessed finding, verify and disposition it before pushing. Additional fixes
require relevant validation; repeat review only under AGENTS.md#review, not merely because another comment arrived.
Assess whether the current change has adequate review and validation under AGENTS.md#review. The main agent owns
that assessment; independent review of the entire PR is not a prerequisite for every push. Reuse earlier evidence
that still holds, assess new fixes and their interactions, and widen coverage when changes invalidate earlier
assumptions. Do not launch a reviewer merely because a push is next or claim readiness for unassessed work.
When independent review is useful, adapt the scope and lenses to the unresolved question:
Review <decision/change/fix and affected interactions> on branch
<X>, against<base or reviewed state>. Read AGENTS.md and the active SOW <filename, if any>. Assess <relevant risks/questions> using <owner/validation evidence>. Trace dependencies needed for this scope and report material gaps beyond it. Classify each finding under AGENTS.md Review, with file/line evidence, trigger, consequence and a suggested fix. This is read-only: do not edit files, mutate remote or Git state, stop processes, or launch other agents.
Verify reviewer findings before acting. Handle blockers and optional improvements under the root review, scope and follow-up rules. A reviewer returning no suggestions is not required before proceeding.
bash .agents/skills/repo-pr-reviews/scripts/ci-status.sh <PR_NUMBER>Exit codes:
0 -- no observed failed or running checks; this also covers an empty rollup and is not proof of required coverage2 -- runs in progress; this need not delay an already-authorized fix push. Waiting for CI
between iterations destroys throughput. The new push triggers fresh CI
on the new code, which is what matters.3 -- runs failing -- fix the failures and bundle them into the push.CI failures unrelated to this PR (a flaky test on a different module, an infra outage) are NOT in scope for this PR -- note them, surface to the user, move on. Do not make drive-by fixes here.
When a further review round is warranted under AGENTS.md#review, and posting trigger comments is authorized,
run the selected reviewers after the fix commits have been pushed:
bash .agents/skills/repo-pr-reviews/scripts/trigger-cubic.sh <PR_NUMBER>
bash .agents/skills/repo-pr-reviews/scripts/trigger-coderabbit.sh <PR_NUMBER>cubic and coderabbit re-review when mentioned in a new top-level PR comment. Copilot is deliberately absent: see rule 8. If a new reviewer is selected for repeated review, document its re-trigger mechanism here; recognizing its comments does not by itself require repeatedly invoking it.
bash .agents/skills/repo-pr-reviews/scripts/wait-for-activity.sh <PR_NUMBER>Default timeout 30 min, poll every 30 s. Returns 0 on new activity, 124 on timeout. Use it when awaiting a warranted review round; a bot's "no new findings" comment is evidence to assess, not a required exit phrase.
What counts as "new activity":
Iteration and completion follow AGENTS.md#review. Re-fetch and assess new findings when another round is warranted;
do not repeat merely to reach zero open threads, zero optional suggestions, or a particular bot verdict.
When the inspection or authorized handling ends, summarize for the user:
Commit messages on the address-the-comments cycle should describe the change, not the reviewer or the cycle:
Follow AGENTS.md#git-and-pr-workflow for attribution. Describe the technical change without reviewer credit;
a tool name needed to explain changed integration behavior is valid technical context.
(Comments on the PR are an exception when they're operational mentions
required by the bot itself: @cubic-dev-ai please review again is a
direct trigger for that bot, and the trigger script enforces it. Outside
operational triggers, the same rule applies to comments.)
Be substantive but brief. The bot's prompt-text is verbose; your reply doesn't have to be. Examples:
<sha-or-paragraph>: <one-sentence what changed>."<one-sentence why>: <evidence
citation>." Add a code comment if it'll help future reviewers.<line>, but the
related <other-line> is intentional because <reason>."Maintainer / dev / community comments go to the user FIRST. Your message should:
Then act per their direction. Do not respond to humans on the user's behalf without explicit direction. Existing explicit direction for the response remains valid; do not request it again. A request to review a human comment does not itself authorize a reply.
| Bot | Role | Re-trigger |
|---|---|---|
cubic-dev-ai[bot] | Line-level code review | New PR comment mentioning @cubic-dev-ai |
coderabbitai[bot] | Line-level code review | trigger-coderabbit.sh (@coderabbitai review) -- NEVER @coderabbit, that is a different, unrelated GitHub user |
copilot[bot] | Line-level code review | Not re-triggered -- no credits (see rule 8) |
sonarqubecloud[bot] | Quality-gate status | Auto, on each scan run -- read its issue comment |
github-advanced-security | Mirrored code-scanning findings | Auto, on each scan upload; inspect the originating analyzer |
github-actions[bot] | CI status / labels | Auto, on each workflow run |
netdata-bot[bot] | Repo automation (labels, etc.) | Auto |
If a new AI reviewer appears in the project, classify it by adding to
PR_AI_BOT_RE in _lib.sh so the skill recognizes it.
The mention is @coderabbitai, never @coderabbit. @coderabbit is a
real, unrelated GitHub user; mentioning it pings a stranger on every
iteration and never reaches the bot. trigger-coderabbit.sh hardcodes the
correct handle -- do not hand-write the mention. The same care applies to
@cubic-dev-ai. Before posting any comment containing an @, check the
handle against the bot directory above.
coderabbitai[bot] posts line-level findings, not just summaries. It was
originally classified here as informational; it is an AI reviewer and its
threads need the same verify-reply-resolve treatment as cubic's.
coderabbit cites external URLs (learn.netdata.cloud, upstream GitHub) as
evidence. Those citations are often directionally right but not
authoritative for the branch under review -- verify against the source in the
checkout before acting. Example: it correctly flagged that a Function needs a
signed-in identity, but the proof is the HTTP_ACCESS_* flags in the
producer, not the doc page it linked.
Both reviewers will flag a generated page's content when the real defect is in the generator or the shared template. Fix the producer, regenerate, and say so in the reply -- otherwise the same finding returns on the next vendor page.
| Symptom | Likely cause |
|---|---|
fetch-all.sh returns suspiciously round counts | Pagination missed pages. Re-run; fetch-all auto-probes when count is a multiple of 100. |
fetch-all.sh aborts with page N probe FAILED and leaves FETCH-INCOMPLETE in the state dir | gh auth or rate limit; the cache is incomplete. Fix gh auth status, re-run; do not read the partial dump. |
A GraphQL helper script fails with cursor_args[@]: unbound variable | macOS Bash 3.2 plus set -u treats empty array expansion as unbound. Keep gh api argument arrays non-empty before expansion or branch the first-page GraphQL call. This affected both fetch-all.sh and wait-for-activity.sh. |
reply-thread.sh -> 404 | Wrong comment id (use databaseId from review-threads.json, not the GraphQL node id). |
reply-thread.sh -> line N: 2: usage, yet the thread ends up resolved | The comment id expanded to empty AND the resolve ran anyway. Never chain reply and resolve so that resolve can run after reply fails: run reply-thread.sh, confirm it printed posted reply id=..., THEN resolve. See the bash-vs-zsh note below. |
An associative-array lookup (${MAP[key]}) is empty in a helper loop | The interactive shell here is zsh, not bash. declare -A plus ${MAP[key]} does not behave the same, so ids silently expand to nothing. Pass literal ids, or drive the loop from python3 output one line at a time, rather than building a shell map. |
resolve-thread.sh -> "thread not found" | Used REST id instead of GraphQL node id. |
trigger-copilot.sh succeeds but no new review | Expected. The org has no Copilot review credits, which is why it is not in the loop. Do not wait on it. |
trigger-cubic.sh succeeds but no new review | cubic ignores comments without an explicit @cubic-dev-ai mention. The script always prepends it. |
ci-status.sh exits 3 (failing) | Fix PR-caused failures before pushing; report unrelated failures. Exit 3 wins over 2 when checks are also running. |
ci-status.sh exits 2 (running) | CI hasn't finished. Push anyway -- waiting on CI between iterations destroys throughput. The next push triggers a fresh CI run on the new code, which is what matters. (See Step 4b.) |
| Bot keeps re-flagging the same line after a fix push | The bot didn't see the new commit because it wasn't re-triggered. |
wait-for-activity.sh 124 timeout | Check available feedback and CI; use AGENTS.md#review and report coverage gaps. Silence or resolved threads alone do not establish readiness. |
For capture timing and authorization, follow AGENTS.md#knowledge-capture.
Examples of things to capture:
PR_AI_BOT_RE)© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (scripts) in .agents/skills/repo-pr-reviews of netdata/netdata.
Open the folder on GitHubat commit 567162f
Repo PR Reviews next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Repo PR Reviews this skillnetdata/netdata | 81k | — | ~8.1k | Automated safety check: Notes | GPL-3.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Check PRonyx-dot-app/onyx | 32k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Contributor-First PR MergeHKUDS/OpenHarness | 16k | 1 repos | ~847 | Automated safety check: Pass | MIT | |
| Create Pull Requestcline/cline | 70k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Pull Request Title and Body Writeropeninterpreter/openinterpreter | 69k | 2 repos | ~1.1k | Automated safety check: Pass | Apache-2.0 |
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
cline/cline
Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.
openinterpreter/openinterpreter
Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
netdata/netdata
Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.
netdata/netdata
Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.
netdata/netdata
Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.
netdata/netdata
Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.
netdata/netdata
Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.
netdata/netdata
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
Works with
Categories
Inspect selected PR comments or perform complete PR review triage; address verified findings when authorized. Repo PR Reviews is an agent skill from netdata/netdata. Inspect selected PR comments or perform complete PR review triage; address verified findings when authorized.
Repo PR Reviews fits situations like: tasks that involve Pull requests.
Run `npx skills add netdata/netdata --skill repo-pr-reviews -a claude-code`. Or copy the skill folder (.agents/skills/repo-pr-reviews in netdata/netdata) into .claude/skills/repo-pr-reviews in your project. Claude Code loads it when a task matches its description.
Run `npx skills add netdata/netdata --skill repo-pr-reviews -a codex`. Or copy the skill folder (.agents/skills/repo-pr-reviews in netdata/netdata) into .agents/skills/repo-pr-reviews in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill repo-pr-reviews -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/repo-pr-reviews, .gemini/skills/repo-pr-reviews, .github/skills/repo-pr-reviews and .opencode/skills/repo-pr-reviews in your project.
Going by SKILL.md and its folder, Repo PR Reviews needs a shell for the scripts in its folder, the command-line tools its instructions call (bash and gh) and credentials named SONAR_TOKEN. Our summary lists: A Bash shell; A credential in SONAR_TOKEN.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Repo PR Reviews is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.1k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Repo PR Reviews: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,878 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 11, 2026.
Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.