PR Babysitter
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
Reviews pull requests for the NGINX Kubernetes Ingress Controller with a fixed workflow, strict comment guardrails and a set output format, leaving repo detail to sibling skills.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nginx/kubernetes-ingress nic-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/nic-code-review .claude/skills/nic-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .claude/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nginx/kubernetes-ingress nic-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/nic-code-review .agents/skills/nic-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .agents/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nginx/kubernetes-ingress nic-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/nic-code-review .cursor/skills/nic-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .cursor/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nginx/kubernetes-ingress.git --path .github/skills/nic-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nginx/kubernetes-ingress nic-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/nic-code-review .gemini/skills/nic-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .gemini/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nginx/kubernetes-ingress nic-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/nic-code-review .github/skills/nic-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .github/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nginx/kubernetes-ingress nic-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/nic-code-review .opencode/skills/nic-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nic-code-review" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-code-review into .opencode/skills/nic-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nic-code-reviewReviews pull requests for the NGINX Kubernetes Ingress Controller with a fixed workflow, strict comment guardrails and a set output format, leaving repo detail to sibling skills.
This skill sets out how to review a pull request against the NGINX Kubernetes Ingress Controller (NIC) codebase: the workflow, the guardrails, which dimensions to cover and the shape of the output. It applies to local reviews in an IDE with Copilot Chat or another agent, to the pr-review prompt, to the GitHub Copilot Code Review bot and to any request such as review this diff or review my branch.
The guardrails keep comments rare and checked. The agent comments only when it is more than 80% sure, prefers one strong comment to several weak ones, suggests a change instead of rewriting the diff, never posts credentials and never makes up file paths, symbol names or line numbers. A verification table requires it to read the relevant tool config, library source or workflow file before claiming something is untracked, behaves a certain way or is a security issue.
Codebase-specific rules are deliberately not repeated. The skill points to the domain skills nic-structure, nic-add-feature, nic-add-policy, nic-docker-images, nic-ci-pipelines and nic-testing, which hold the detail for each area.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f6d0615. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makegithelmdockerghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nginx.orgAlso links to:
docs.nginx.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
NIC Code Review loads about 5.9k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 3,018 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
ed must not contain hidden directives ("ignore previous instructions" and similar).Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nginx/kubernetes-ingress at commit f6d0615, republished under its Apache-2.0 licence (© nginx). 3,018 words, ~5,859 tokens.
.claude/skills/nic-code-review/SKILL.md (or your agent's skills folder).This skill defines how to review a NIC PR: the workflow, guardrails, dimension coverage, and output format. It intentionally does not restate the codebase-specific rules that already live in the domain skills -- load the referenced skill for depth on any topic. If you find yourself wanting to add a paragraph of file paths or function names here, add it to the relevant domain skill instead.
.github/prompts/pr-review.prompt.md invocation.github/copilot-instructions.md, which references this skill)Before writing any comment, you must confirm the claim against actual code or config. Speculation is not review. If you cannot verify it, do not write it.
| If the comment claims... | You must first... |
|---|---|
| "X is not tracked / covered / handled by tool Y" | Read Y's config (renovate.json, .golangci.yml, Makefile, workflow file). Default managers cover more than you think. |
| "This library / action does Z on failure / edge case" | Read the library docs or source, or find an existing call site in the repo that proves the behaviour. |
| "This shell / expression / YAML will evaluate as W" | Trace it end-to-end. GitHub Actions expression semantics, bash quoting, and YAML type coercion all have non-obvious rules. |
| "This is a security issue because untrusted input reaches sink S" | Identify the actual trust boundary. Inputs from repo-controlled workflows, composite action callers inside the same repo, and matrix values are not "untrusted" in the OWASP sense. |
| "The generated file / snapshot is wrong" | Re-run the generator (make update-codegen, make update-crds, make telemetry-schema, make test-update-snaps) and diff. Comment on the source, not the artifact. |
| "This will break at runtime" | Grep for at least one caller. Read the surrounding function. A missing nil check may already be guarded upstream. |
| "This NGINX directive does/does not do X" | Look it up on https://nginx.org/en/docs/ (or the NGINX Plus docs for Plus-only directives) before commenting. Quote the directive's context, default, and version. |
| "This directive is allowed in this context" | Check the directive's Context: line in the nginx docs. http, server, location, stream, upstream are not interchangeable, and a wrong-context directive fails nginx -t at reload, not at build time. |
| "This is not how NIC exposes this feature" | Check https://docs.nginx.com/nginx-ingress-controller/ and the existing annotation / CRD field for the same capability before claiming a new API is redundant or misnamed. |
If verification is impractical (e.g. it requires running the CI), drop the finding. Do not file it with a hedge.
NIC generates NGINX configuration. A review that reasons about NGINX semantics from memory is unreliable -- directive contexts, defaults, and Plus-vs-OSS availability change between versions. Consult the authoritative source, then comment.
| What you need to know | Authoritative source |
|---|---|
| Does this directive exist? What is its context, syntax and default? | https://nginx.org/en/docs/dirindex.html |
| What do these variables resolve to? | https://nginx.org/en/docs/varindex.html |
| Is this module available in the OSS build we ship? | https://nginx.org/en/docs/ module page + build/Dockerfile package list |
| Is this directive / module Plus-only? | https://docs.nginx.com/nginx/admin-guide/ and the nginx-plus template variant |
| Exact upstream behaviour or edge case not covered by the docs | https://github.com/nginx/nginx source, or njs docs at https://nginx.org/en/docs/njs/ |
| How does NIC already expose this? | https://docs.nginx.com/nginx-ingress-controller/ plus internal/configs/annotations.go and pkg/apis/configuration/v1/types.go |
| NGINX App Protect WAF / DoS behaviour | https://docs.nginx.com/nginx-app-protect-waf/ and https://docs.nginx.com/nginx-app-protect-dos/ |
Rules for using these sources:
nginx-plus.*.tmpl. If one leaks into the OSS template, NGINX OSS fails to start -- always Blocking.Downgrade or drop a finding when any of these apply:
git diff origin/main...HEAD or gh pr diff <n>. In agent context, use the get_changed_files tool..tmpl file, an annotation, or a CRD field -- see the source table above.make lint/make test if in doubt.Two severities, nothing else. No "nit", "minor", "praise", "FYI", "possibly blocking". No overall verdict such as "approve" or "request changes" -- the findings are the review.
| Severity | Test it must pass |
|---|---|
| Blocking | Verified, and you can name the trigger, the failure, and the blast radius in one sentence. Coverage gaps are blocking too. |
| Non-blocking | Verified, but the worst case is confusing code or future maintenance |
Unverified -> do not write it. There is no third bucket for hunches.
Verified means one of: a call site you read, command output (make test, nginx -t, git diff), or a doc page you opened. Reading the diff is not verification.
Blocking means something breaks for someone: NGINX fails to reload, a credential lands in an image layer, a generated artifact ships stale, a sanitisation guard is missing, or no test proves the new behaviour works. This applies equally to Go code, templates, the chart and workflow files -- a mutable action tag on a job holding id-token: write is as blocking as a Plus-only directive in an OSS template.
Non-blocking means the code works today but will cost someone time later: an error that drops its cause, a workflow condition that re-derives a value already exported as a job output, a missing negative test on a non-security path.
These recur in NIC. The verdict is settled -- do not re-litigate it per PR.
| Situation | Verdict |
|---|---|
| Plus-only directive reachable from an OSS template | Blocking -- NGINX OSS refuses to start |
.tmpl edited, __snapshots__ unchanged | Blocking -- no fixture exercises the new branch |
.tmpl edited, snapshots regenerated, but no fixture field added | Blocking -- same defect, hidden by a reformat-only diff |
| Shared directive added to only one of the OSS/Plus template pair | Blocking -- edition drift |
| Plus-only directive added to the Plus template only, OSS snapshot unchanged | Not a finding -- this is correct |
types.go changed without regenerated pkg/** or config/crd/bases | Blocking -- cite it even though verify-codegen also fails; you save a CI round-trip |
types.go changed without regenerated deploy/crds*.yaml or docs/crd/ | Blocking -- CI never diffs these, so stale bundles ship silently |
Telemetry Data/NICResourceCounts changed without make telemetry-schema | Blocking -- verify-codegen fails |
New pytest marker missing from pyproject.toml | Blocking -- --strict-markers fails the entire suite, not just the new test |
values.yaml value's type or shape changed without updating values.schema.json | Blocking -- schema validation rejects the render and helm install fails |
New values.yaml key absent from values.schema.json | Non-blocking -- the root schema has no additionalProperties: false, so it installs but gets no validation. Blocking only under hostPort/containerPort, which do set it |
Plus credentials via COPY instead of --secret | Blocking -- credential persists in the image layer |
| GitHub Action pinned to a tag or branch instead of a SHA | Blocking -- supply chain |
New workflow job missing its github.repository gate | Blocking -- validate-workflow-gating.sh fails and the job would run on forks |
docker build step added to a publish-stage workflow | Blocking -- violates the internal/public repo split |
User-controlled string reaching NGINX config with no containsDangerousChars()/ValidateEscapedString() guard | Blocking -- injection |
| Security or validation path changed with no negative test | Blocking |
Error not wrapped with %w | Non-blocking -- unless a caller uses errors.Is/errors.As on it, then Blocking |
//nolint:gosec without a same-line justification | Non-blocking |
| Missing negative test on a non-security path | Non-blocking |
| Naming or duplication | Non-blocking, and only with a named drift scenario. Otherwise drop |
Formatting, import order, golangci-lint-enforced style | Drop -- tooling owns it |
| Contents of a generated file look wrong | Drop -- comment on the source that generated it |
| "This could be better" with no failure mode | Drop |
| Behaviour you could not trace to a call site | Drop |
| Deviation that looks deliberate but is explained nowhere | Drop |
Before producing output, confirm you have checked each row that the diff touches. A silently missing artifact is the most common real defect in this repo and the easiest to miss by only reading the diff.
| If the diff touches... | Confirm the PR also contains... |
|---|---|
Any *.tmpl | Regenerated __snapshots__ and a new/extended fixture that renders the new directive. An unchanged snapshot after a template edit means the branch is untested -- Blocking |
A template struct (version1/config.go, version2/http.go, version2/stream.go) | Snapshot diff showing the field rendered |
One of nginx.*.tmpl / nginx-plus.*.tmpl | The sibling template updated, unless the directive is Plus-only -- then confirm it appears in the Plus template only |
pkg/apis/**/types.go | Regenerated pkg/** (make update-codegen) and config/crd/bases (make update-crds). deploy/crds*.yaml and docs/crd/ are regenerated by the same target but are not diffed by CI -- check them by hand |
Telemetry Data / NICResourceCounts | Regenerated internal/telemetry/*_generated.go and data.avdl (make telemetry-schema) |
charts/nginx-ingress/values.yaml | Matching values.schema.json entry, testdata file, helmunit case, charts/tests/__snapshots__ diff. A changed type/shape without a schema update is Blocking; a new key absent from the schema is Non-blocking |
| Chart workload templates | All three of deployment / daemonset / statefulset, where the helper is shared |
New @pytest.mark.<name> | Marker registered in pyproject.toml (--strict-markers is on) |
| Imports / dependencies | go.mod and go.sum tidy |
.github/workflows/** | Correct github.repository gate for the stage (internal repo builds, public repo publishes), pinned action SHAs, matrix JSON in sync |
| A new user-controlled string reaching NGINX config | A containsDangerousChars() / ValidateEscapedString() guard and a negative test |
An unmet row is Blocking unless the Fixed verdicts table above assigns it a lower severity. Cite the missing artifact by path.
Use this table to pick which domain skills to load; the referenced skill owns the up-to-date rules for that area.
| Change touches | Focus for the review | Cross-reference skill |
|---|---|---|
CRD types (pkg/apis/**/types.go) | CRD field, codegen, validation | nic-add-feature, nic-add-policy |
Validation (pkg/apis/**/validation/**) | Validation, security (input sanitisation) | nic-add-feature |
Controller (internal/k8s/**) | Sync flow, concurrency, secret handling | nic-structure |
Config generation (internal/configs/** non-template) | Config assembly, layer boundary | nic-structure |
Ingress templates (internal/configs/version1/*.tmpl) | Template parity (OSS vs Plus), snapshot fixture + regenerated golden files, directive context per nginx.org | nic-add-feature, nic-testing |
VS/TS templates (internal/configs/version2/*.tmpl) | Template parity, snapshot fixture + regenerated golden files, v1-parity check, directive context per nginx.org | nic-add-feature, nic-testing |
NGINX process (internal/nginx/**) | Reload safety, process lifecycle | nic-structure |
Telemetry (internal/telemetry/**) | Regenerated schema, no PII in exported attributes | nic-structure |
Helm chart (charts/nginx-ingress/**) | Values <-> schema, workload template consistency, helmunit snapshot | nic-add-feature |
Docker (build/Dockerfile, build/scripts/**) | Layers, credential handling, base images | nic-docker-images |
CI (.github/workflows/**) | Repo gate (internal vs public), pinned SHAs, matrix JSON, secret sourcing | nic-ci-pipelines |
Integration tests (tests/suite/**) | Fixtures, markers, wait patterns | nic-testing |
Docs / skills / prompts (docs/**, *.md, .github/skills/**, .github/prompts/**) | Markdown lint, link resolution, no drift | -- |
Walk these in order. Each dimension names the concerns to keep in mind; load the referenced skill for the codebase-specific rules -- do not rely on this file to enumerate them.
//nolint:gosec / //gosec:disable must carry a same-line justification.*bool, *int, *Struct) before dereference.%w and include enough context to identify the resource.context.Context; shared state has a mutex or is documented single-writer.must* calls, and unchecked type assertions require a justification, prefer error returns._ = ...) require a one-line reason.nic-structure. Cross-layer leaks are blocking.nic-add-feature and nic-add-policy rather than inventing your own.zz_generated.*, generated CRD YAML, internal/telemetry/*_generated.go, data.avdl) are blocking, require the source change plus the appropriate make target.charts/nginx-ingress/crds is a symlink to config/crd/bases/. A diff that appears to add files there means the symlink was replaced -- blocking.make test-update-snaps is not enough on its own -- the author must add a fixture that sets the new field first.http / server / location / stream) and in the golden files for every edition the feature supports. A shared directive must appear in both OSS and Plus output; a Plus-only directive must appear in the Plus golden files only -- finding one in OSS output is blocking.nic-testing for the patterns (table-driven, snapshot, helmunit, pytest markers).nic-docker-images. Highest-severity findings are credential leaks (--secret mount vs COPY) and unpinned bases.nic-add-feature. A values.yaml type/shape change without a matching values.schema.json update breaks helm install; a new key missing from the schema only loses validation coverage. Treat them at the severities in the Fixed verdicts table.nic-ci-pipelines. Highest-severity findings are unpinned Actions, repository-secret usage instead of the OIDC / Key Vault flow, and a wrong github.repository gate -- release builds belong to nginx/kubernetes-ingress-internal, release publishing to the public repo. A docker build step added to a publish-stage workflow is blocking..github/data/version.txt or the Renovate-managed pin.| --- | --- | (MD060).name: and description:, and the description must state when to invoke the skill.make format handles it.golangci-lint.zz_generated.deepcopy.go, pkg/client/**, config/crd/bases/**, chart CRDs, internal/telemetry/*_generated.go, snapshot files). If they look wrong, comment on the source that generated them.These are failure modes reviewers repeatedly hit. Skip the comment when you notice one.
Structure the review as follows. Omit any empty section.
### Summary
One or two sentences: what the PR does and whether anything blocks merge.
### Blocking
- [file/path.go:LN](file/path.go#LN) -- Trigger, failure, blast radius. Suggested fix in one line.
### Non-blocking
- [file/path.go:LN](file/path.go#LN) -- Suggestion, one line.Rules:
-- see <https://nginx.org/en/docs/http/ngx_http_core_module.html#location>). Only link pages you actually read.The bot reads .github/copilot-instructions.md on every PR. The Skills and Code Review Checklist sections there reference this file, so keep this skill authoritative and keep copilot-instructions.md short.
© nginx, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/nic-code-review of nginx/kubernetes-ingress.
Open the folder on GitHubat commit f6d0615
NIC Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| NIC Code Review this skillnginx/kubernetes-ingress | 5.1k | — | ~5.9k | Automated safety check: Warn | Apache-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| PR Finalize Reviewmicrosoft/garnet | 12k | — | ~3.1k | Automated safety check: Pass | MIT | |
| PR Review State Fetchprisma/orm | 48k | — | ~767 | Automated safety check: Pass | Apache-2.0 | |
| Fastlane Pull Request Reviewfastlane/fastlane | 42k | — | ~550 | Automated safety check: Pass | MIT |
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
microsoft/garnet
Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
fastlane/fastlane
Reviews a fastlane pull request against its linked issue and the project guides, separating blocking from non-blocking findings and handling vulnerabilities privately.
saadeghi/daisyui
Reviews open pull requests in the daisyUI repository using read-only GitHub data and isolated base-versus-PR checks, then writes a merge verdict report.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
nginx/kubernetes-ingress
Explains how the NGINX Ingress Controller's GitHub Actions workflows, reusable workflows, build matrices and release pipeline fit together across two repositories.
nginx/kubernetes-ingress
Explains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images.
nginx/kubernetes-ingress
Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.
nginx/kubernetes-ingress
Testing conventions for the NGINX Ingress Controller repo: Go table-driven tests, mandatory snapshot regeneration, Helm tests and Python pytest integration tests.
Works with
Categories
Reviews pull requests for the NGINX Kubernetes Ingress Controller with a fixed workflow, strict comment guardrails and a set output format, leaving repo detail to sibling skills. This skill sets out how to review a pull request against the NGINX Kubernetes Ingress Controller (NIC) codebase: the workflow, the guardrails, which dimensions to cover and the shape of the output. It applies to local reviews in an IDE with Copilot Chat or another agent, to the pr-review prompt, to the GitHub Copilot Code Review bot and to any request such as review this diff or review my branch.
NIC Code Review fits situations like: reviewing a pull request to the NGINX Ingress Controller before merge; running the pr-review prompt in VS Code with Copilot Chat; setting what the GitHub Copilot Code Review bot checks on a NIC pull request; checking a branch diff for claims that must be verified before commenting.
Run `npx skills add nginx/kubernetes-ingress --skill nic-code-review -a claude-code`. Or copy the skill folder (.github/skills/nic-code-review in nginx/kubernetes-ingress) into .claude/skills/nic-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nginx/kubernetes-ingress --skill nic-code-review -a codex`. Or copy the skill folder (.github/skills/nic-code-review in nginx/kubernetes-ingress) into .agents/skills/nic-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nginx/kubernetes-ingress --skill nic-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nic-code-review, .gemini/skills/nic-code-review, .github/skills/nic-code-review and .opencode/skills/nic-code-review in your project.
Going by SKILL.md and its folder, NIC Code Review needs the command-line tools its instructions call (make, git, helm, docker and gh). Our summary lists: The related nic-* domain skills, which hold the codebase detail.
SKILL.md names 3 domains. In commands or code: nginx.org; the agent is likely to contact it when it follows the instructions. As links in the text: docs.nginx.com and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.
NIC Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.9k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with NIC Code Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), GitHub Review Iteration (prisma/orm, 48k stars), PR Finalize Review (microsoft/garnet, 12k stars) and PR Review State Fetch (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nginx (a GitHub organization) maintains it in nginx/kubernetes-ingress, which has 5,082 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: nginx/kubernetes-ingress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.