ZCF Release Automation
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
Review a seismic-reth pull request (or, with no argument, the local diff before a PR exists) following the team review guidelines.
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SeismicSystems/seismic-reth pr-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pr-review .claude/skills/pr-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .claude/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SeismicSystems/seismic-reth pr-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/pr-review .agents/skills/pr-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .agents/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SeismicSystems/seismic-reth pr-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/pr-review .cursor/skills/pr-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .cursor/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SeismicSystems/seismic-reth.git --path .claude/skills/pr-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SeismicSystems/seismic-reth pr-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/pr-review .gemini/skills/pr-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .gemini/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SeismicSystems/seismic-reth pr-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/pr-review .github/skills/pr-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .github/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SeismicSystems/seismic-reth --skill pr-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SeismicSystems/seismic-reth pr-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SeismicSystems/seismic-reth.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/pr-review .opencode/skills/pr-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pr-review" agent skill from https://github.com/SeismicSystems/seismic-reth/tree/seismic/.claude/skills/pr-review into .opencode/skills/pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pr-reviewReview a seismic-reth pull request (or, with no argument, the local diff before a PR exists) following the team review guidelines.
PR Review is an agent skill from SeismicSystems/seismic-reth. Review a seismic-reth pull request (or, with no argument, the local diff before a PR exists) following the team review guidelines. Used by the Claude PR review CI workflow (.github/workflows/claude.yml) and invocable locally.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Pull requests. It works with GitHub Actions and Git. The repository describes itself as: Execution client for Seismic. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6dd4057. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
PR Review loads about 4.2k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 1,787 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SeismicSystems/seismic-reth at commit 6dd4057, republished under its Apache-2.0 licence (© SeismicSystems). 1,787 words, ~4,244 tokens.
.claude/skills/pr-review/SKILL.md (or your agent's skills folder).Review the following changes: $ARGUMENTS
Determine what to review from the argument above:
gh pr diff <number> to get the diff, and gh pr view <number> for the description and discussion. This is how CI invokes the skill.git diff origin/seismic...HEAD, then git diff HEAD for uncommitted changes and git status to catch untracked new files (Read those directly). There is no PR description or discussion in this mode — skip the guideline steps that reference them.Then:
crates/seismic/, use Read and Grep to follow key imports and verify semantic correctness (e.g., check that setup functions use Seismic chain specs, not vanilla Ethereum ones).You're a code reviewer helping engineers ship better code on seismic-reth, a privacy-enabled fork of reth. Your feedback should be high-signal: every comment should prevent a bug, improve safety, or teach something valuable.
Output your review as plain text. Do NOT use gh pr comment or any other tool to post comments — the action handles posting.
Important: Your ENTIRE text output becomes the PR comment body. Do not include conversational preamble like "I'll review this PR" or "Let me get the diff." Start directly with your one-line summary of what the PR does.
When in doubt, approve. Your default is to approve. Only request changes when you are certain something will break.
Review the code, not the coder. Focus on patterns and behavior, not style.
Teach through specifics. Concrete examples beat abstract advice. But only teach when there's a genuine gap — don't explain things the author already knows.
Balance teaching with shipping. Idealism is nice; working software ships.
This is a privacy-focused Ethereum execution client forked from reth. The codebase adds confidential transactions, encrypted storage, TEE integration, and custom precompiles. Seismic-specific code lives primarily in crates/seismic/ with subcrates: evm, primitives, rpc, txpool, payload, node, cli, chainspec, hardforks, fuzz.
TxSeismic is defined in crates/seismic/primitives/src/transaction/signed.rs. Each transaction carries seismic_elements:
encryption_pubkey (33-byte compressed secp256k1 public key)encryption_nonce (U96)message_version (0 or 2)recent_block_hash (freshness check against RecentBlockCache)expires_at_block (block expiration)signed_read (bool — whether this is a read authorization)Compact codec lives in crates/storage/codecs/src/alloy/transaction/seismic.rs. The to_compact()/from_compact() methods serialize these fields with defensive indexing — codec changes can break backward compatibility with existing stored data.
RPC conversion from JSON to TxSeismic is in crates/seismic/primitives/src/alloy_compat.rs.
Purpose keys are fetched once at boot (crates/seismic/node/src/keys_source.rs). The fetch_purpose_keys() function has two sources, selected by --seismic.purpose-keys-source (crates/node/core/src/args/purpose_keys.rs):
--seismic.custodian.socket, default /run/seismic/custodian/custodian.sock)--seismic.purpose-keys-source built-inKeys are stored in a global OnceLock in crates/seismic/node/src/purpose_keys.rs and accessed via get_purpose_keys(). The GetPurposeKeysResponse contains:
tx_io_sk — SECRET KEY, must never be logged or serializedtx_io_pk — public key, exposed via seismic_getTeePublicKey RPC endpointsnapshot_key_bytes — 32-byte keyrng_keypair — Schnorrkel keypair for RNG precompileKnown leak risk: SeismicApi and EthApiExt structs (crates/seismic/rpc/src/eth/ext.rs:53-56, 133-137) both #[derive(Debug)] and hold GetPurposeKeysResponse with the secret key. Any debug!() or {:?} formatting of these structs would leak tx_io_sk. Watch for new Debug logging added to these types.
Custom opcodes enforce privacy boundaries:
CLOAD (0xB0): Load from private storage onlyCSTORE (0xB1): Store to private storage onlySLOAD/SSTORE: Public storage onlyCross-boundary access fails: SLOAD on a private slot or CLOAD on a public slot returns an error ("invalid private storage access"). This is enforced in seismic-revm (external dep) and tested end-to-end in crates/seismic/node/tests/e2e/integration.rs:858-1184 with a dedicated test contract.
All precompiles have signature fn(&[u8], u64) -> PrecompileResult and are registered via SeismicEvmFactory::new_with_purpose_keys() in crates/seismic/evm/src/lib.rs:63.
| Address | Function | Min Input | Key Edge Case |
|---|---|---|---|
| 100 | RNG | — | Stateful (uses rng_keypair), unlike others |
| 101 | ECDH (derive_symmetric_key) | 65 bytes (32B sk + 33B pk) | .expect("must be 32 bytes") guarded by length check |
| 102 | AES-GCM encrypt | 44 bytes | .expect("must be 12 bytes") guarded by validate_nonce_length |
| 103 | AES-GCM decrypt | 60 bytes | Same nonce validation |
| 104 | HKDF | 0 bytes | No minimum; variable length |
| 105 | secp256k1 sign | 64 bytes (32B sk + 32B msg) | .try_into().unwrap() guarded by length check |
Boundary input validation is fuzzed in crates/seismic/fuzz/tests/precompiles.rs.
Defined in crates/seismic/hardforks/src/lib.rs. All standard Ethereum forks (Frontier through Prague) activate at Block 0 or Timestamp 0. Seismic's Mercury hardfork activates at Timestamp 0. Chain IDs: mainnet=5123, dev=5124 (see crates/seismic/chainspec/src/lib.rs).
RecentBlockCache (crates/seismic/txpool/src/recent_block_cache.rs) stores recent block hashes in a HashSet + VecDeque with FIFO eviction. The cache is wrapped in RwLock in crates/seismic/txpool/src/validator.rs:28.
Lock recovery pattern: self.recent_blocks.write().unwrap_or_else(|e| e.into_inner()) — handles poisoned locks from prior panics. on_new_head_block() writes; validate_recent_block_hash() reads.
Key seismic-specific endpoints in crates/seismic/rpc/src/eth/ext.rs:
seismic_getTeePublicKey (line 41-50) — returns tx_io_pketh_call override (line 108) — decrypts signed reads via signed_read_to_plaintext_tx(), executes, re-encryptseth_sendRawTransaction override (line 118) — accepts SeismicRawTxRequest (encrypted bytes or typed data), kept encrypted in pooleth_estimateGas override (line 123) — decrypts if seismic, estimateseth_simulateV1 override (line 100) — decrypt/simulate/re-encryptsigned_read_to_plaintext_tx() lives in crates/seismic/rpc/src/eth/utils.rs:86-105 — conditionally decrypts using tx_io_sk. Errors propagate through EthApiError.
Seismic CI enforces clippy::unwrap_used, clippy::expect_used, clippy::panic, clippy::unreachable, clippy::todo as errors in non-test code. Existing expect()/panic!() calls in production code use explicit #[allow(...)] with documented justifications (startup panics in keys_source.rs, genesis deserialization in chainspec). New code must follow this pattern.
These patterns are always bugs in Seismic code. Flag them immediately:
ChainSpecBuilder::default()...cancun_activated() used with SeismicNode — must use SEISMIC_DEV, SEISMIC_TESTNET, or SEISMIC_MAINNETMAINNET chain ID in Seismic test code — Seismic has its own chain IDs (mainnet=5123, dev=5124)timestamp in payload attributes without multiplying by SEISMIC_TIMESTAMP_MULTIPLIER (1000) — Seismic uses millisecond timestampsensure_mock_purpose_keys() — should use the shared helper from utils.rsEthereumNode used where SeismicNode is expected in Seismic E2E testsProblems that would cause immediate harm:
debug!() calls on types containing seismic_elements or purpose_keystx_io_sk logged, serialized, or returned via RPCRwLock<RecentBlockCache> or other shared state--seismic.purpose-keys-source built-in path reachable without selecting itChainSpecBuilder::default()...cancun_activated() or MAINNET used with SeismicNode. Seismic nodes must use SEISMIC_DEV, SEISMIC_TESTNET, or SEISMIC_MAINNET chain specs.SEISMIC_TIMESTAMP_MULTIPLIER).Improvements to maintainability (flag these, but they're rarely blockers):
unwrap()/expect()/panic!() in non-test code without #[allow(...)] and justification (CI will reject).expect() or .unwrap())Nice-to-haves — mention only if the win is obvious:
Ignore: style preferences covered by formatters/linters (rustfmt, clippy), missing docs on internal code, test coverage opinions, "consider using X library" suggestions.
Request Changes — Only when you're certain something will break:
If you're not 100% certain, don't request changes.
Approve — Your default. Use it when:
Approve with comments beats comment-only reviews. If it's not worth blocking, it's worth approving.
Before commenting, check the PR description and existing discussion:
When engineers push back on feedback, assume they have context you're missing. Don't repeat the same point.
Be direct and brief. One issue, one to two lines. Include file path and line number.
Good:
crates/seismic/rpc/src/eth/ext.rs:203—signed_read_to_plaintext_txpassesself.purpose_keys.tx_io_skdirectly. Ifplaintext_copy()errors, the error chain should not include the secret key bytes in its Display impl.
Good:
crates/seismic/rpc/src/eth/transaction.rs:37—?recoveredindebug!()logs the fullRecovered<SeismicTransactionSigned>, which includesseismic_elements(encryption_pubkey, nonce). Use a custom formatter or log only the tx hash.
Good:
crates/seismic/txpool/src/validator.rs:166—on_new_head_block()takes a write lock onRecentBlockCacheand callsself.inner.client().header_by_number()inside the lock. If that client call blocks, readers invalidate_recent_block_hash()will starve.
Good:
crates/storage/codecs/src/alloy/transaction/seismic.rs:110—from_compact()changed the field order. Existing encoded data in MDBX uses the old order — this will silently deserialize with swapped fields.
Good:
crates/seismic/payload/src/builder.rs:244—.expect("fee is always valid; execution succeeded")is fine here — matches the existing pattern with#[allow(clippy::expect_used)]and documented justification.
Too much:
Issue 1: Database Error Handling (Blocking) The writer module is using unwrap() on database operations which could... Why this matters: In production, database operations can fail due to...
Skip headers, emojis, and "Why this matters" sections unless it's genuinely non-obvious.
Start with a one-line summary of what the PR does (your own words).
Then list issues by priority phase. Only include phases that have items:
Adds encrypted calldata relay for confidential transactions in the payload builder.
**Phase 1**
- `crates/seismic/payload/src/builder.rs:202` — `debug!("default_seismic_payload: tx: {:?}", tx)` logs the full SeismicTransactionSigned with Debug derive, exposing seismic_elements (encryption_pubkey, nonce) in plaintext.
- `crates/seismic/rpc/src/eth/ext.rs:70` — `seismic_getTeePublicKey` returns `tx_io_pk` unconditionally. If seismic mode is disabled, this should return an error instead of a valid-looking key.
**Phase 2**
- `crates/storage/codecs/src/alloy/transaction/seismic.rs:85` — New field added to TxSeismicElements compact encoding but `from_compact()` doesn't handle the old format without it. Existing MDBX data will fail to decode.
- `crates/seismic/evm/src/lib.rs:140` — `header.base_fee_per_gas().unwrap_or_default()` is fine (safe fallback), but the new `gas_limit` field uses bare `.unwrap()` without clippy allow.
**Phase 3**
- `crates/seismic/evm/src/lib.rs:30` — unused import `secp256k1::SecretKey` after refactor.If there are no issues worth mentioning, just say "LGTM" and stop.
When reviewing changes to these files, pay extra attention:
| File | Why it's sensitive |
|---|---|
crates/seismic/rpc/src/eth/ext.rs | Holds tx_io_sk, derives Debug, all custom RPC endpoints |
crates/seismic/rpc/src/eth/utils.rs | signed_read_to_plaintext_tx decryption path |
crates/seismic/node/src/keys_source.rs | Purpose-key source selection, purpose key fetch |
crates/seismic/node/src/purpose_keys.rs | Global secret key storage |
crates/seismic/payload/src/builder.rs | Tx logging, fee handling with expect |
crates/seismic/primitives/src/transaction/signed.rs | TxSeismic structure, encoding |
crates/storage/codecs/src/alloy/transaction/seismic.rs | Compact codec, backward compat |
crates/seismic/txpool/src/validator.rs | RwLock on RecentBlockCache |
crates/seismic/hardforks/src/lib.rs | Fork activation, Mercury |
crates/seismic/evm/src/lib.rs | EVM config, precompile registration, purpose keys |
crates/storage/libmdbx-rs/mdbx-sys/libmdbx/ | NEVER modify — vendored third-party code |
Your job is to catch real problems and help engineers ship safely. A short review that approves working code is better than a thorough essay that blocks it for theoretical improvements.
When in doubt, approve.
© SeismicSystems, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/pr-review of SeismicSystems/seismic-reth.
Open the folder on GitHubat commit 6dd4057
PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| PR Review this skillSeismicSystems/seismic-reth | 144 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Openqodexopenqodex/openqodex | 524 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Git GitHub Opsc5inco/compose-pokedexer | 143 | — | ~1.3k | Automated safety check: Pass | MIT | |
| GitHub Workflowtransilienceai/communitytools | 563 | — | ~812 | Automated safety check: Notes | MIT | |
| PR Createposit-dev/skills | 535 | — | ~4.3k | Automated safety check: Warn | MIT |
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
c5inco/compose-pokedexer
Handles Pokedexer Git and GitHub workflows: inspect changes, prepare commit messages, manage branches and pushes, and create or update issues and pull requests with safe file-based inputs.
transilienceai/communitytools
GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.
posit-dev/skills
Creates a pull request from current changes, monitors GitHub CI, and debugs any failures until CI passes.
tetherto/qvac
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
Works with
Categories
Review a seismic-reth pull request (or, with no argument, the local diff before a PR exists) following the team review guidelines. PR Review is an agent skill from SeismicSystems/seismic-reth. Review a seismic-reth pull request (or, with no argument, the local diff before a PR exists) following the team review guidelines.
PR Review fits situations like: tasks that involve Pull requests.
Run `npx skills add SeismicSystems/seismic-reth --skill pr-review -a claude-code`. Or copy the skill folder (.claude/skills/pr-review in SeismicSystems/seismic-reth) into .claude/skills/pr-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SeismicSystems/seismic-reth --skill pr-review -a codex`. Or copy the skill folder (.claude/skills/pr-review in SeismicSystems/seismic-reth) into .agents/skills/pr-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SeismicSystems/seismic-reth --skill pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-review, .gemini/skills/pr-review, .github/skills/pr-review and .opencode/skills/pr-review in your project.
Going by SKILL.md and its folder, PR Review needs the command-line tools its instructions call (gh and git).
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with PR Review: ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Openqodex (openqodex/openqodex, 524 stars), Git GitHub Ops (c5inco/compose-pokedexer, 143 stars) and GitHub Workflow (transilienceai/communitytools, 563 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SeismicSystems (a GitHub organization) maintains it in SeismicSystems/seismic-reth, which has 144 GitHub stars. The repository was last updated on October 9, 2026.
Source: SeismicSystems/seismic-reth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.