Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
A skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.
$ npx skills add pproenca/dot-skills --skill bug-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pproenca/dot-skills bug-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/bug-review .claude/skills/bug-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .claude/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pproenca/dot-skills --skill bug-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pproenca/dot-skills bug-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/bug-review .agents/skills/bug-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .agents/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pproenca/dot-skills --skill bug-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pproenca/dot-skills bug-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/bug-review .cursor/skills/bug-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .cursor/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pproenca/dot-skills.git --path .agents/skills/bug-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pproenca/dot-skills --skill bug-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pproenca/dot-skills bug-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/bug-review .gemini/skills/bug-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .gemini/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pproenca/dot-skills bug-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pproenca/dot-skills --skill bug-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/bug-review .github/skills/bug-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .github/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pproenca/dot-skills --skill bug-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pproenca/dot-skills bug-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/bug-review .opencode/skills/bug-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bug-review" agent skill from https://github.com/pproenca/dot-skills/tree/master/.agents/skills/bug-review into .opencode/skills/bug-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bug-reviewA skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.
Bug Review is an agent skill from pproenca/dot-skills. Use this skill when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review. Trigger on PR review, bug finding, code review, "review this PR", "check for bugs", "find issues in this PR". This is a multi-pass review workflow with 5 parallel passes, majority voting, independent Opus validation, and resolution rate tracking. Also trigger on /bug-review:resolve to classify whether findings were fixed at merge time, and /bug-review:report for resolution…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `config.json`, `gotchas.md` and `hooks/hooks.json`).
It sits in Development, covering Pull requests. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 10 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitghnpmgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, gh and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bug Review loads about 2.2k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 928 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 928 words, ~2,186 tokens.
.claude/skills/bug-review/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.Multi-pass PR review agent with 5 parallel review passes, majority voting, independent Opus validation, and resolution rate learning. Posts inline PR comments and optionally generates autofix commits. Tracks whether findings get resolved at merge time and uses that signal to improve future reviews.
/bug-review <PR-number-or-URL>/bug-review:resolve <PR> to classify resolutions after merge/bug-review:report for resolution rate statisticsOn first run, verify:
gh CLI is installed and authenticated (gh auth status)jq is installed (for JSON processing)bc is installed (for resolution rate calculations; pre-installed on most systems)Read config.json for configuration (passes, vote threshold, models, category weights).
/bug-review <PR>
|
v
Fetch PR context + gather-context.sh
|
v
5 parallel passes (shuffled diffs, Sonnet) --> Aggregate & vote (3/5 majority)
|
v
Independent Opus validator --> Dedup --> Present findings --> Post + store
|
(later, after merge)
v
/bug-review:resolve <PR> --> Classify resolutions --> Update category weights<PR>${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/ — if cache exists for the same head commit, offer to resume from the last checkpointscripts/fetch-pr.sh <pr-identifier> to get PR diff + metadata as JSONscripts/gather-context.sh <changed-files-json> to get prioritized context (callers, types, tests, repo rules).bug-review.md from repo root if it exists${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/context.jsonFor each pass (1-5), prepare a shuffled diff:
scripts/shuffle-diff.sh <pass-number> < pr.diff > pass-<N>.diffLaunch 5 Agent subprocesses in parallel. Read review-passes.md for the exact prompt for each pass.
Use model from config.json agent_model (default: "sonnet").
Each agent returns a JSON array of findings.
Save checkpoint: Write all pass results to ${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/pass-results.json
vote_threshold)final_score = votes × severity_weight × category_weightIf only 1-2 passes found bugs and the others found none, present findings but note they lack consensus.
Save checkpoint: Write voted findings to cache.
Launch a separate Agent using validator_model from config.json (default: "opus").
This agent has NOT seen the review passes. It receives only the voted findings and the original code. Read the Validator section in review-passes.md for the prompt.
For each finding, the validator outputs: {id, verdict: "KEEP"|"DISCARD", confidence, reasoning}
Remove DISCARDed findings. Multiply each finding's score by the validator's confidence.
Compute each finding's final confidence field:
confidence = (votes / total_passes) × validator_confidenceFindings with confidence < 0.5 are shown with a "low confidence" warning.
Save checkpoint: Write validated findings to cache.
Run scripts/dedup.sh <pr-number> to get existing [bug-review] comments.
Match by location proximity (file + line within +/-10) and category — not text similarity.
Display a table:
| # | Severity | Confidence | File | Line | Title | Votes |
|---|
For each finding, show full description, trigger scenario, suggested fix, and validator reasoning.
Ask the user (using AskUserQuestion with multiSelect):
If no findings survived voting + validation: "No bugs found across 5 review passes. The changes look clean."
Write approved findings to a temporary JSON file, then run:
scripts/post-review.sh <pr-number> <findings-json-file>Then persist findings for resolution tracking:
scripts/store-findings.sh <pr-number> <findings-json-file> <head-commit-sha>For each finding selected for autofix:
git diff --stat — verify only the finding's file was modified and diff is under 20 lines. If exceeded, revert and warn.npm test, go test ./..., pytest, etc.)fix: {title} [bug-review]git checkout -- <file>) and report to userSafety: one commit per fix, run tests between fixes, never force-push, scope-validate every fix.
<PR>Run after a PR is merged to classify whether findings were resolved.
scripts/classify-resolutions.sh <pr-number>${CLAUDE_PLUGIN_DATA}/bug-review/findings/pr-{N}.jsonscripts/update-weights.sh to adjust category weightsDisplay resolution rate statistics across all tracked PRs.
Run scripts/resolution-report.sh which outputs:
Teams can create .bug-review.md at their repo root:
## Focus Areas
- Pay special attention to authentication flows
- Check all database queries for SQL injection
## Ignore
- Don't flag issues in generated files (*.generated.ts)
- Ignore style-only concerns
## Invariants
- All API endpoints must check req.user before accessing user data
- Database migrations must be reversible
## Severity Overrides
- Treat any auth bypass as CRITICAL regardless of category defaultRead workflow.md for detailed step-by-step with error handling. Read review-passes.md for all 5 review pass prompts and the validator. Read categories.md for bug categories and learned weights.
© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references) in .agents/skills/bug-review of pproenca/dot-skills.
Open the folder on GitHubat commit cf93c57
Bug Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bug Review this skillpproenca/dot-skills | 214 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Check PRonyx-dot-app/onyx | 32k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 85k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| PR Design DocOpenHands/OpenHands | 90k | — | ~2.4k | Automated safety check: Pass | MIT |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
OpenHands/OpenHands
For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
pproenca/dot-skills
Audio forensics and voice recovery guidelines for CSI-level audio analysis.
pproenca/dot-skills
Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.
pproenca/dot-skills
Create well-structured RFCs and technical proposals for software projects.
pproenca/dot-skills
Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.
pproenca/dot-skills
Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…
pproenca/dot-skills
Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…
Categories
A skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review. Bug Review is an agent skill from pproenca/dot-skills. Use this skill when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.
Bug Review fits situations like: A user asks to review a pull request for bugs; wants AI code review focused on correctness issues; runs /bug-review; find issues in this PR.
Run `npx skills add pproenca/dot-skills --skill bug-review -a claude-code`. Or copy the skill folder (.agents/skills/bug-review in pproenca/dot-skills) into .claude/skills/bug-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pproenca/dot-skills --skill bug-review -a codex`. Or copy the skill folder (.agents/skills/bug-review in pproenca/dot-skills) into .agents/skills/bug-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill bug-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-review, .gemini/skills/bug-review, .github/skills/bug-review and .opencode/skills/bug-review in your project.
Going by SKILL.md and its folder, Bug Review needs a shell for the scripts in its folder and the command-line tools its instructions call (git, gh, npm and go). Our summary lists: A Bash shell.
SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Bug Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Bug Review: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 214 GitHub stars. The repository holds 182 skills in this directory. The repository was last updated on August 15, 2026.
Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.