Official agent skill

GitHub Review Iteration

by prisma in prisma/orm

Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

OfficialApache-2.0Auto-check passedDevelopment

Install GitHub Review Iteration

skills CLI
$ npx skills add prisma/orm --skill github-review-iteration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install prisma/orm github-review-iteration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/prisma/orm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-contrib/github-review-iteration .claude/skills/github-review-iteration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-review-iteration
GitHub stars
48k
Token cost
~2.2k tokens
SKILL.md length
815 words
Files
4 (incl. scripts)
Skills in repo
20
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

  • Works in 3 steps: Fetch canonical JSON → Render and summarize from JSON (pure… → Render triage plan from canonical…
  • Addressing all review comments on an open pull request
  • SKILL.md covers Locating sibling skills and…, Usage, Files written (deterministic… and Behavioral rules, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls node, git and gh; reaches github.com

What it does

The skill is an orchestrator that owns sequencing, handoff and loop control while delegating the real work to subagents: a review triager turns comment threads into a structured action plan, and a review implementer makes the changes, marks them done and resolves the threads. Fetching the PR review state, triage and implementation each live in sibling skills (`review-fetch-phase`, `review-triage-phase` and `review-implement-phase`) that must sit in the same parent directory.

Three subcommands are supported: `triage`, `implement` and `iterate`, which loops the first two until clear and is the default. It takes a PR URL and an optional output directory; without one, artifacts go under `wip/reviews/` in a folder named from the lowercased owner, repo and PR number. Scripts should run from the repository root, since the reviews root is resolved against the working directory, and script paths are relative to the skill's own installed location rather than the project being reviewed. A `scripts/review-iterate.mjs` script is bundled.

When your agent uses it

  • Addressing all review comments on an open pull request
  • Triaging review threads into a list of actions before coding
  • Iterating until a PR has no actionable review items left

Example prompts

  • “Address the review comments on https://github.com/acme/webapp/pull/123 and keep going until it is clean.”
  • “Triage the review comments on PR 123 into an action plan without changing any code.”
  • “Run the review iteration loop on my PR and resolve the threads you fix.”

Requirements

  • Node.js, for the bundled `review-iterate.mjs` script
  • The sibling review-fetch-phase, review-triage-phase and review-implement-phase skills
  • Access to the pull request on GitHub

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Fetch canonical JSON
  2. Render and summarize from JSON (pure scripts)
  3. Render triage plan from canonical actions JSON

What it can do on your machine

Read from SKILL.md and the folder at commit 095af7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Review Iteration loads about 2.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 815 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from prisma/orm at commit 095af7a, republished under its Apache-2.0 licence (© prisma). 815 words, ~2,226 tokens.

Download SKILL.mdSave it as .claude/skills/github-review-iteration/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
github-review-iteration
description
Orchestrates a GitHub PR review loop by delegating triage and implementation to dedicated sub-agents, then repeating until actionable review items are cleared. Use when the user says “address PR review”, “triage review comments”, or “iterate until review is clean”.
argument-hint
[triage|implement|iterate] [pr-url] [output-dir]

GitHub Review Iteration

Run an iterative PR review loop: fetch state → render/summarize → triage actions → implement (code + Done + resolve) → re-fetch until the PR has no remaining actionable items.

This skill is an orchestrator. It delegates:

  • triage to ../review-triage-phase/agents/review-triager.md
  • implementation to ../review-implement-phase/agents/review-implementer.md

The orchestrator owns sequencing, handoff, and loop control. It does not perform triage or implementation directly when delegation is available.

Locating sibling skills and scripts

This skill depends on three sibling skills that live in the same parent directory:

  • ../review-fetch-phase/ — fetches and renders PR review state
  • ../review-triage-phase/ — triages review threads into an action plan
  • ../review-implement-phase/ — implements triaged actions and resolves threads

All script paths in this document are relative to this skill's directory. Use ../ to reach sibling skills. Do not search the workspace/repo for these files — they are part of the skills installation, not the project being reviewed.

Run the scripts from the repository root, addressing them by their full path under the skills installation. The reviews root defaults to wip/reviews resolved against the working directory, so a run started elsewhere writes artifacts outside the repo-root wip/ tree that .gitignore covers. Pass --reviews-root <repo-root>/wip/reviews if you must run from another directory.

To run a path from the repository root, prefix it with this skill's installed location — .agents/skills/github-review-iteration/. So ../review-fetch-phase/scripts/fetch-review-state.mjs becomes .agents/skills/review-fetch-phase/scripts/fetch-review-state.mjs.

Usage

This skill supports subcommands:

  • triage: fetch + triage into structured actions
  • implement: execute the triaged actions and update status
  • iterate: loop triage → implement until clear (default)
text
/github-review-iteration iterate <PR_URL> [output-dir]

When output-dir is omitted, use the standard layout: wip/reviews/<owner>_<repo>_pr-<number>/ (derived from the PR URL, with owner and repo lowercased — derive a directory name by hand the same way, or the artifacts split across two directories).

Example:

text
/github-review-iteration iterate https://github.com/OWNER/REPO/pull/123

Files written (deterministic layout)

Store artifacts under:

wip/reviews/<owner>_<repo>_pr-<number>/

Canonical artifacts:

  • review-state.json (canonical v2)
  • review-actions.json (canonical v2)

Derived artifacts:

  • review-state.md
  • summary.txt (or JSON summary)
  • review-actions.md
  • apply-log.json (optional)

When you need a thin wrapper for path setup + standard script calls, run:

bash
node .agents/skills/github-review-iteration/scripts/review-iterate.mjs --pr <PR_URL>

For phase-specific execution without full orchestration, use:

  • /review-fetch-phase <PR_URL> [output-dir]
  • /review-triage-phase <PR_URL> [output-dir]
  • /review-implement-phase <PR_URL> [output-dir]

Behavioral rules

  • WILL ADDRESS items:
    • reply + 👍
    • leave unresolved until fixed
  • Not addressed in this PR items:
    • reply with rationale + 👎
    • resolve the thread
  • Implementation:
    • granular, intent-driven commits
    • explicit staging only (never git add -A / git add .)
    • reply “Done” and resolve when complete

Operational reliability notes (Cursor)

gh api TLS / cert failures in sandboxed shells

If GitHub administration fails with an error like:

  • x509: OSStatus -26276 (or similar TLS/certificate verification failures)

Treat it as an environment/sandbox cert-store mismatch, not a script bug.

Recovery:

  • Re-run the affected gh calls outside the sandbox (use a shell mode that uses the system cert store).
  • Do not disable TLS verification (no GH_NO_VERIFY_SSL, no custom curl flags).
  • After re-running, continue the loop normally (fetch → triage → implement → resolve → repeat).
JSON-first deterministic commands

All script paths below are relative to this skill's directory.

  1. Fetch canonical JSON:
bash
node ../review-fetch-phase/scripts/fetch-review-state.mjs --pr <PR_URL> --out-json <review-dir>/review-state.json
  1. Render and summarize from JSON (pure scripts):
bash
node ../review-fetch-phase/scripts/render-review-state.mjs --in <review-dir>/review-state.json --out <review-dir>/review-state.md
node ../review-fetch-phase/scripts/summarize-review-state.mjs --in <review-dir>/review-state.json --format text --out <review-dir>/summary.txt
  1. Render triage plan from canonical actions JSON:
bash
node ../review-triage-phase/scripts/render-review-actions.mjs --in <review-dir>/review-actions.json --out <review-dir>/review-actions.md
Show full SKILL.md (333 more words)Show less

Data exchange format (triager → implementer)

review-actions.json is the contract between the triager and implementer.

Minimum v2 shape:

json
{
  "version": 2,
  "pr": { "url": "https://github.com/OWNER/REPO/pull/123", "nodeId": "PR_kw..." },
  "reviewState": { "path": "review-state.json", "fetchedAt": "...", "version": 2 },
  "actions": [
    {
      "actionId": "A-001",
      "target": { "kind": "review_thread", "nodeId": "PRRT_xxx", "url": "..." },
      "decision": "will_address",
      "summary": "One-line description of what will be done",
      "rationale": null,
      "targetFiles": ["path/to/file.ts"],
      "acceptance": "How to tell it's done",
      "status": "pending",
      "done": null
    }
  ]
}

Rules:

  • Use node ids only for targets (target.nodeId).
  • Preserve actions[] order intentionally (do not reorder).
  • Implementer updates status (pending|in_progress|done) and done records in place.
  • Compound targets: A single pull_request_review body may contain multiple findings (especially from automated reviewers like CodeRabbit which bundle "outside diff range" comments into the review body). The triager must decompose these into sub-actions (e.g., A02a, A02b). Never blanket-dismiss review bodies without reading their content.

Procedure

triage
  1. Delegate to triage sub-agent

Invoke the review triager agent at ../review-triage-phase/agents/review-triager.md and pass:

  • PR URL
  • output paths:
    • <output-dir>/review-state.md
    • <output-dir>/review-state.json
    • <output-dir>/review-actions.md
    • <output-dir>/review-actions.json
  • optional scope constraints
  1. Require triage outputs

The triager must:

  • fetch review state (via ../review-fetch-phase/scripts/fetch-review-state.mjs)
  • triage review threads into review-actions.json decisions/status
  • write/update review-actions.md and review-actions.json
  1. Validate handoff contract

Before returning from triage, verify that <output-dir>/review-actions.json exists and is valid for implementer consumption (version, PR metadata, and actions[] with target.kind + target.nodeId).

implement
  1. Delegate to implementation sub-agent

Invoke the review implementer agent at ../review-implement-phase/agents/review-implementer.md and pass:

  • PR URL
  • <output-dir>/review-actions.md
  • <output-dir>/review-actions.json
  • optional scope constraints
  1. Require implementation outputs

The implementer must:

  • work through pending will_address actions
  • make focused, explicit-staging commits
  • run smallest relevant checks per action
  • reply "On it" when starting, then "Done" and resolve the thread when complete
  • update review-actions.json in-place (status, done)
  • re-fetch review state at the end to verify remaining actionable items

Responsibility note:

  • Posting "Done" and resolving completed threads belongs to the implementer phase and is part of marking actions done.
iterate

Repeat delegated triage → delegated implement until there are no remaining actionable review items.

Loop contract:

  1. Run triage delegation and read resulting review-actions.json.
  2. Inspect review-actions.json; if no will_address actions remain with pending or in_progress status, stop and report completion.
  3. Run implement delegation.
  4. Re-run triage delegation to refresh state and determine next iteration.
  5. Continue until clear.

Optional shortcuts (repo-specific)

If this repo provides dedicated slash commands or subagents for triage/implementation, prefer them to reduce manual steps.

© prisma, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts) in skills-contrib/github-review-iteration of prisma/orm.

  • SKILL.md
  • agents/review-orchestrator.md
  • package.json
  • scripts/review-iterate.mjs

Open the folder on GitHubat commit 095af7a

Compare with similar skills

GitHub Review Iteration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Review Iteration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Review Iteration this skillprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Pull Request Code Review Orchestratoropeninterpreter/openinterpreter69k2 repos~163Automated safety check: PassApache-2.0
.NET MAUI Code Reviewdotnet/efcore15k—~2kAutomated safety check: PassMIT

Similar skills

  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Official

    Deep code-only review of a pull request or candidate patch for correctness, safety and .NET MAUI conventions, judging the code before reading the PR description.

    15k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Has a separate agent review a code change without editing it, checking behavior, security, regressions, complexity, tests and docs before merge.

    412 GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from prisma/orm

All 20 skills in this repo
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    Auto-check passed
  • Official

    Implements triaged pull request review actions, commits focused fixes, posts status replies on GitHub and resolves the threads.

    48k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated today
    Auto-check passed
  • Official

    Replaces a plain TypeScript union plus switch statements with frozen subclasses and a visitor interface when several places dispatch on the same variants.

    48k GitHub stars~830 tokensUpdated today
    Auto-check passed
  • Official

    Guides an outside contributor through opening a prisma/orm pull request from a fork that follows CONTRIBUTING.md and passes review on the first round.

    48k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Official

    Creates a GitHub pull request for the Prisma repo with a Linear-ticket-prefixed title and a decision-led narrative description, inferring the ticket from context.

    48k GitHub stars~4.6k tokensUpdated today
    Auto-check passed

Works with

Questions about GitHub Review Iteration

What does GitHub Review Iteration do?

Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left. The skill is an orchestrator that owns sequencing, handoff and loop control while delegating the real work to subagents: a review triager turns comment threads into a structured action plan, and a review implementer makes the changes, marks them done and resolves the threads. Fetching the PR review state, triage and implementation each live in sibling skills (`review-fetch-phase`, `review-triage-phase` and `review-implement-phase`) that must sit in the same parent directory.

When should I use GitHub Review Iteration?

GitHub Review Iteration fits situations like: addressing all review comments on an open pull request; triaging review threads into a list of actions before coding; iterating until a PR has no actionable review items left.

How do I install GitHub Review Iteration in Claude Code?

Run `npx skills add prisma/orm --skill github-review-iteration -a claude-code`. Or copy the skill folder (skills-contrib/github-review-iteration in prisma/orm) into .claude/skills/github-review-iteration in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Review Iteration in Codex?

Run `npx skills add prisma/orm --skill github-review-iteration -a codex`. Or copy the skill folder (skills-contrib/github-review-iteration in prisma/orm) into .agents/skills/github-review-iteration in your project. Codex loads it when a task matches its description.

Can I use GitHub Review Iteration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add prisma/orm --skill github-review-iteration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-review-iteration, .gemini/skills/github-review-iteration, .github/skills/github-review-iteration and .opencode/skills/github-review-iteration in your project.

What does GitHub Review Iteration need to run?

Going by SKILL.md and its folder, GitHub Review Iteration needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node, git and gh). Our summary lists: Node.js, for the bundled `review-iterate.mjs` script; The sibling review-fetch-phase, review-triage-phase and review-implement-phase skills; Access to the pull request on GitHub.

Does GitHub Review Iteration access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is GitHub Review Iteration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does GitHub Review Iteration use?

GitHub Review Iteration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Review Iteration use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Review Iteration?

Skills that share tags, products or a category with GitHub Review Iteration: Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars), PR Review (jaemk/cached, 2.1k stars) and Pull Request Code Review Orchestrator (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Review Iteration?

prisma (a GitHub organization, an official publisher) maintains it in prisma/orm, which has 47,701 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 6, 2026.

Source: prisma/orm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.