Agent skill

Pre PR Audit

by sd0xdev in sd0xdev/sd0x-harness

Pre-PR confidence audit with 5-dimension scoring. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Pre PR Audit

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill pre-pr-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness pre-pr-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pre-pr-audit .claude/skills/pre-pr-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pre-pr-audit
GitHub stars
192
Token cost
~2.1k tokens
SKILL.md length
674 words
Files
3 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Pre-PR confidence audit with 5-dimension scoring. An agent skill from sd0xdev/sd0x-harness.

  • Works in 5 steps: Source: /risk-assess JSON top_affected… → Sort: dependent_count descending,… → Select: N=3 (fast) or N=10 (deep) → …
  • : final check before commit/push/PR
  • SKILL.md covers When NOT to Use, Positioning, Prohibited and Arguments, plus 7 more sections
  • Calls git and node

What it does

Pre PR Audit is an agent skill from sd0xdev/sd0x-harness. Pre-PR confidence audit with 5-dimension scoring. Use when: final check before commit/push/PR, evaluating PR readiness, assessing test quality + risk + coverage holistically. Triggers: pre-pr, readiness check, confidence audit, final verification, ready to PR, how confident. Not for: code review (use codex-review-fast), post-deploy verification (use feature-verify), periodic health (use project-audit).

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/output-template.md` and `references/scoring-model.md`).

It sits in Development. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : final check before commit/push/PR
  • Evaluating PR readiness
  • Assessing test quality + risk + coverage holistically

Example prompts

  • “/pre-pr-audit”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(bash:*), Skill, AskUserQuestion, Agent

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Source: /risk-assess JSON top_affected array (each: file + dependent_count)
  2. Sort: dependent_count descending, tie-break file ascending (stable sort)
  3. Select: N=3 (fast) or N=10 (deep)
  4. Deep supplement: git diff --name-only for files beyond top_affected cap
  5. Fallback: if /risk-assess unavailable, git diff --stat sorted by lines-changed descending

What it can do on your machine

Read from SKILL.md and the folder at commit a4d4bc1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(bash:*)
    • Skill
    • AskUserQuestion
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pre PR Audit loads about 2.1k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 674 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit a4d4bc1, republished under its MIT licence (© sd0xdev). 674 words, ~2,145 tokens.

Download SKILL.mdSave it as .claude/skills/pre-pr-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
pre-pr-audit
description
Pre-PR confidence audit with 5-dimension scoring. Use when: final check before commit/push/PR, evaluating PR readiness, assessing test quality + risk + coverage holistically. Triggers: pre-pr, readiness check, confidence audit, final verification, ready to PR, how confident. Not for: code review (use codex-review-fast), post-deploy verification (use feature-verify), periodic health (use project-audit).
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(bash:*), Skill, AskUserQuestion, Agent

Pre-PR Audit

Pre-deploy ultimate verification. Aggregates test quality, coverage, risk, and AC traceability into a single confidence index (0-100).

When NOT to Use

NeedUse Instead
Code review/codex-review-fast
Post-deploy runtime verification/feature-verify
Periodic project health/project-audit
Just run tests/verify
Just check risk/risk-assess

Positioning

auto-loop done → [user invokes] /pre-pr-audit → /smart-commit → /push-ci → /create-pr
                                     ↑
                        Pre-deploy ultimate verification

Prohibited

❌ git add | git commit | git push — per @rules/git-workflow.md

This skill audits and reports. It does not modify code or commit.

Arguments

ArgDescriptionDefault
--mode fast|deepExecution depthfast
--strictNon-zero exit on ⛔ PR-Blockedoff
--jsonMachine-readable JSON outputoff
--base <ref>Compare against refHEAD

Workflow

mermaid
sequenceDiagram
    participant U as User
    participant PA as /pre-pr-audit
    participant RA as /risk-assess
    participant TR as /codex-test-review
    participant CC as /check-coverage
    participant ST as State / Artifacts

    U->>PA: /pre-pr-audit [--mode fast|deep]

    par Phase A: Collect
        PA->>ST: [Background Agent] Read precommit/verify state (freshness)
        PA->>RA: [Foreground — blocking] /risk-assess --mode fast
        PA->>PA: [Background Agent] Detect changed files + map to tests
    end

    Note over PA,RA: A2 (/risk-assess) must complete before Phase B — Module Selection depends on top_affected

    par Phase B: Targeted
        PA->>TR: [Foreground] /codex-test-review (top-N risky modules)
        PA->>CC: [Background Agent: coverage-analyst] /check-coverage (deep mode only)
        PA->>PA: [Background Agent] AC trace (if request doc exists)
    end

    PA->>PA: Phase C: Aggregate + hard-fail + gate
    PA->>U: Phase D: Report + confidence index
Phase A: Collect (parallel with dispatch annotations)
StepDispatchActionSource
A1Background AgentRead precommit gate statenode scripts/review-state.js check --format=json(installed copy first: .claude/scripts/review-state.js)— precommit.passed is content-addressed, so no separate freshness check; checker absent → report "no verdict source", never a pass
A2Foreground (blocking)Invoke /risk-assess --mode fastSkill tool — get risk_level, top_affected, overall_score
A3Background AgentDetect changed files + map to test filesgit diff --name-only HEAD → match against test/ patterns

A2 MUST stay foreground: Phase B Module Selection depends on top_affected from /risk-assess output. A1 and A3 dispatch as background Agents and run in parallel with A2.

Phase B: Targeted (parallel, mode-dependent, with dispatch annotations)
StepDispatchfastdeepAction
B1Foregroundtop-3top-10 + supplement/codex-test-review on selected modules (see Module Selection)
B2Background Agent (coverage-analyst)skip✅/check-coverage for pyramid balance
B3Background Agentskip✅ (if request doc)AC trace: parse ## Acceptance Criteria → map to test evidence

B2 uses coverage-analyst agent (agents/coverage-analyst.md) for background execution. B3 dispatches as a background Agent for AC parsing. B1 stays foreground as the primary assessment.

Module Selection (deterministic)
  1. Source: /risk-assess JSON top_affected array (each: file + dependent_count)
  2. Sort: dependent_count descending, tie-break file ascending (stable sort)
  3. Select: N=3 (fast) or N=10 (deep)
  4. Deep supplement: git diff --name-only for files beyond top_affected cap
  5. Fallback: if /risk-assess unavailable, git diff --stat sorted by lines-changed descending
Phase C: Aggregate
  1. Score each dimension per references/scoring-model.md
  2. Apply evidence confidence cap
  3. Check hard-fail overrides
  4. Compute final index
Phase D: Output

Output report per references/output-template.md. Include:

  • Confidence index (0-100) + gate sentinel
  • Per-dimension score table
  • Hard-fail check results
  • Findings (prioritized)
  • Next actions

5 Dimensions

#DimensionWeightChecks
1Execution Integrity25%All tests pass, precommit passed, HEAD freshness, no flaky indicators
2Coverage Adequacy25%Unit/Integration/E2E pyramid balance, per-module gap analysis
3Test Quality20%AAA compliance, naming, assertion depth, edge cases (per @rules/testing.md)
4Risk-to-Test Alignment20%High-risk files have tests, risk level ↔ test depth proportional
5Evidence Governance10%AC traceability, exception policy compliance, expiry check
Show full SKILL.md (252 more words)Show less

Gate

User-Facing (3-tier)
GateScoreSentinel
✅ Ready>=85✅ PR-Ready
⚠️ Needs attention60-84⚠️ PR-Caution
⛔ Not ready<60⛔ PR-Blocked
Hard-Fail Overrides (force ⛔ regardless of score)

Before the four exception checks sourced from the testing contract, Read @skills/test-review/references/testing-contract.md; if that Read fails, stop the audit before scoring and report that no readiness verdict can be given — never emit a PR-Ready, PR-Caution or PR-Blocked sentinel with the hard-fail checks unrun, and never judge an exception from memory.

OverrideConditionSource
Precommit staleNot passed after latest editAuto-loop state
Prohibited domain exceptionSecurity/data-integrity/regression AC uses manual exceptionrules/testing.md § Evidence Model
Exception cap exceededException count > AC-count-based cap@skills/test-review/references/testing-contract.md § Evidence Model
Expired exceptionPast ISO 8601 expiry date@skills/test-review/references/testing-contract.md § Evidence Model
Invalid reason classNon-enum reason in exception@skills/test-review/references/testing-contract.md § Evidence Model
Unverified exceptionNo Codex VALID_EXCEPTION verdict@skills/test-review/references/testing-contract.md § Evidence Model
Evidence staleArtifacts HEAD SHA ≠ current HEADFreshness check
Critical untested/risk-assess HIGH+ on zero-coverage filesRisk alignment

Scoring

See references/scoring-model.md for formulas. Summary:

  • Check score: pass=1, partial=0.5, fail=0, N/A=excluded
  • Dimension score: applicable_sum / applicable_count × 100
  • Raw: weighted average (N/A dimensions excluded, weights renormalized)
  • Cap: evidence confidence (1.0 / 0.9 / 0.75 / 0.6)
  • Final: round(raw × cap)

Verification

  • All 5 dimensions scored (or N/A with reason)
  • Hard-fail checks evaluated
  • Gate sentinel output matches score
  • No git add/commit/push executed
  • Findings include file:line references

References

  • references/scoring-model.md — Scoring formulas, weights, confidence caps
  • references/output-template.md — Report format, JSON schema, sentinel strings
  • @skills/test-review/references/testing-contract.md — exception gates, caps and expiry (hard-fail source)
  • @rules/testing.md — evidence core and the domains that never take an exception (hard-fail source)
  • @rules/testing-project.md — Project-specific overrides

Examples

Input: /pre-pr-audit
Action: fast mode → collect state + risk → test-review top-3 → aggregate → 85/100 ✅ PR-Ready

Input: /pre-pr-audit --mode deep
Action: deep mode → collect + risk → test-review top-10 + coverage + AC trace → aggregate → 72/100 ⚠️ PR-Caution

Input: /pre-pr-audit --strict
Action: fast mode → score 55 → ⛔ PR-Blocked → exit code 1

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/pre-pr-audit of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/output-template.md
  • references/scoring-model.md

Open the folder on GitHubat commit a4d4bc1

Compare with similar skills

Pre PR Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pre PR Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pre PR Audit this skillsd0xdev/sd0x-harness192—~2.1kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 89 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Pre PR Audit

What does Pre PR Audit do?

Pre-PR confidence audit with 5-dimension scoring. An agent skill from sd0xdev/sd0x-harness. Pre PR Audit is an agent skill from sd0xdev/sd0x-harness. Pre-PR confidence audit with 5-dimension scoring.

When should I use Pre PR Audit?

Pre PR Audit fits situations like: : final check before commit/push/PR; evaluating PR readiness; assessing test quality + risk + coverage holistically.

How do I install Pre PR Audit in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill pre-pr-audit -a claude-code`. Or copy the skill folder (skills/pre-pr-audit in sd0xdev/sd0x-harness) into .claude/skills/pre-pr-audit in your project. Claude Code loads it when a task matches its description.

How do I install Pre PR Audit in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill pre-pr-audit -a codex`. Or copy the skill folder (skills/pre-pr-audit in sd0xdev/sd0x-harness) into .agents/skills/pre-pr-audit in your project. Codex loads it when a task matches its description.

Can I use Pre PR Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill pre-pr-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pre-pr-audit, .gemini/skills/pre-pr-audit, .github/skills/pre-pr-audit and .opencode/skills/pre-pr-audit in your project.

What does Pre PR Audit need to run?

Going by SKILL.md and its folder, Pre PR Audit needs the command-line tools its instructions call (git and node). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(bash:*), Skill, AskUserQuestion, Agent.

Does Pre PR Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pre PR Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pre PR Audit use?

Pre PR Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pre PR Audit use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Pre PR Audit?

Skills that share tags, products or a category with Pre PR Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pre PR Audit?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 8, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.