Official agent skill

Reviewing Pull Requests

by Shopify in Shopify/shopify-app-js

Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…

OfficialMITAuto-check passedDevelopment

Install Reviewing Pull Requests

skills CLI
$ npx skills add Shopify/shopify-app-js --skill reviewing-pull-requests -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Shopify/shopify-app-js reviewing-pull-requests --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Shopify/shopify-app-js.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/reviewing-pull-requests .claude/skills/reviewing-pull-requests && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reviewing-pull-requests
GitHub stars
543
Token cost
~1.9k tokens
SKILL.md length
910 words
Files
3 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…

  • Works in 5 steps: Check CI status (gh pr checks ) → Review the dependency changelog for… → Verify compatibility with supported… → …
  • Asked to review a PR
  • SKILL.md covers Monorepo Structure, Early Exit Criteria, Triage: Detect Automated PRs and Initial Analysis, plus 8 more sections
  • Calls gh

What it does

Reviewing Pull Requests is an agent skill from Shopify/shopify-app-js, published by the product's own GitHub organization. Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency checks against established TypeScript/Node.js library patterns, and root cause analysis. Produces a structured review with breaking changes assessment, improvement suggestions, and community contribution guidance. Use when asked to review a PR, check for breaking changes, or validate code quality.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/review-output-template.md` and `references/semver-classification.md`).

It sits in Development, covering Pull requests and Root cause analysis. It works with Shopify, Node.js, TypeScript and GitHub. The licence is MIT.

When your agent uses it

  • Asked to review a PR
  • Check for breaking changes
  • Validate code quality

Example prompts

  • “Use the reviewing-pull-requests skill to review pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance…”
  • “/reviewing-pull-requests”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check CI status (gh pr checks )
  2. Review the dependency changelog for breaking changes
  3. Verify compatibility with supported Node.js versions
  4. Check for security advisories related to the update
  5. Skip single-responsibility analysis, root cause analysis, and pattern consistency checks

What it can do on your machine

Read from SKILL.md and the folder at commit 9e452e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reviewing Pull Requests loads about 1.9k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 910 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Shopify/shopify-app-js at commit 9e452e5, republished under its MIT licence (© Shopify). 910 words, ~1,908 tokens.

Download SKILL.mdSave it as .claude/skills/reviewing-pull-requests/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
reviewing-pull-requests
description
Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency checks against established TypeScript/Node.js library patterns, and root cause analysis. Produces a structured review with breaking changes assessment, improvement suggestions, and community contribution guidance. Use when asked to review a PR, check for breaking changes, or validate code quality.

Reviewing Pull Requests

Use the GitHub CLI (gh) for all GitHub interactions — fetching PRs, diffs, checks, etc. Direct URL fetching may not work reliably.

Monorepo Structure

shopify-app-js is a monorepo. Key package locations:

  • packages/api-clients/* — API client libraries
  • packages/apps/* — App framework packages

Keep this structure in mind when checking pattern consistency across packages.

Early Exit Criteria

Before running the full process, check if you can stop early:

  • CI failing: If gh pr checks shows failures on non-flaky tests, note the failures and defer detailed review until CI is green.
  • Draft PR: If the PR is in draft state, provide directional feedback on the approach rather than detailed line-by-line review. Focus on architecture, solution direction, and potential blockers.

Triage: Detect Automated PRs

After fetching PR metadata, check if this is from Dependabot, Renovate, or another bot:

bash
gh pr view <PR_NUMBER> --json author,labels

For automated dependency PRs, apply a simplified review:

  1. Check CI status (gh pr checks <PR_NUMBER>)
  2. Review the dependency changelog for breaking changes
  3. Verify compatibility with supported Node.js versions
  4. Check for security advisories related to the update
  5. Skip single-responsibility analysis, root cause analysis, and pattern consistency checks

For all other PRs, continue with the full review below.

Initial Analysis

Emit brief progress markers as you work (e.g., "Fetching PR metadata...", "Analyzing diff...", "Checking pattern consistency..."). Present the final review as a single structured block.

Systematically gather information before reviewing:

  1. Fetch PR metadata:
    bash
    gh pr view <PR_NUMBER> --json number,title,body,state,isDraft,author,createdAt,updatedAt,files,additions,deletions,baseRefName,headRefName,mergeable,commits,labels | cat
  2. Check CI status:
    bash
    gh pr checks <PR_NUMBER>
  3. Get the diff:
    bash
    gh pr diff <PR_NUMBER>
  4. For any issue references in the PR body (e.g., #123, fixes #456), fetch each:
    bash
    gh issue view <number> --json number,title,body,state,author,createdAt,updatedAt | cat
    If deeper issue context is needed, use the investigating-github-issues skill.
  5. Search for existing patterns in the codebase — find similar code, check if similar functionality already exists, look for existing test patterns for similar features.
  6. Verify the problem being solved — check if the issue actually exists, whether the solution addresses the root cause, and if there are existing solutions in the codebase.

Monorepo Scope Assessment

Determine the blast radius of the PR:

  • Which packages does this PR touch? List them.
  • Does it cross package boundaries? Cross-package PRs deserve extra scrutiny for coordination issues.
  • For changes to shared types or utilities that other packages depend on, trace the dependency chain to identify all affected consumers.
  • Are changes to re-exported APIs consistent across the source and re-exporting packages?

Version Maintenance Check

Apply the version maintenance policy (see ../shared/references/version-maintenance-policy.md):

  • Is this PR targeting a maintained version/branch?
  • If the PR fixes a bug in an unmaintained major version, flag it — the fix should target the latest major version instead.

Solution Validation

Before diving into code review, critically evaluate:

  • Right solution? Could the same goal be achieved by modifying existing code instead of adding new code?
  • Right location? Should this functionality be in an existing module rather than a new one?
  • All areas covered? What other parts of the codebase might need similar changes?
  • Problem verified? Set up a reproduction to verify the issue exists and that the PR fixes it.

Critical Thinking Requirements

  1. Question PR descriptions — don't assume the description accurately describes what the code does
  2. Verify claims — if a PR claims certain files need changes, verify each one actually needs them
  3. Look for existing solutions — before accepting new code, check if existing code could be extended
  4. Test edge cases — consider behavior in different scenarios (development/production, embedded/non-embedded)
  5. Challenge scope — if changes seem too broad, investigate if fewer changes would suffice
Show full SKILL.md (344 more words)Show less

Pattern Discovery Protocol

When reviewing structural changes:

  1. Map the inheritance chain of affected classes
  2. Identify all included modules and their effects
  3. Trace through the actual code execution path
  4. Identify which methods are actually called and when
  5. Check for test coverage that would catch issues

Core Review Checks

Changeset Verification

Check if the PR includes a changeset file (typically in .changeset/ directory):

  • Does a changeset exist for this PR? If the PR modifies package behavior, one should be present.
  • Does the changeset's bump level (major/minor/patch) match your semver classification?
  • Does the changeset description accurately summarize the change for end users?
  • If no changeset exists and one is needed, flag it.
Single Responsibility Validation

Evaluate whether the PR changes only one logical unit of work:

  • Are all changes related to the stated purpose?
  • Do the changes address a single issue or feature?
  • Are there opportunistic fixes unrelated to the main change?

Multiple unrelated changes → recommend splitting the PR.

Semver Compliance Analysis

Classify the change as MAJOR, MINOR, or PATCH. See references/semver-classification.md for detailed rules.

Pattern Consistency Enforcement

Verify alignment with established library patterns. When checking a pattern, find a canonical example in the same package to compare against:

  • Code Organization: file structure follows existing module patterns
  • Naming Conventions: functions, variables, and files match existing style
  • Error Handling: consistent error types and handling strategies
  • Testing Patterns: test structure and coverage match existing tests
  • Documentation Style: JSDoc comments and inline documentation consistency
  • TypeScript Patterns: type definitions, interfaces, and generic usage
  • Module Exports: consistent export patterns (named vs default)
  • Async Patterns: promise handling and async/await usage

Special Analysis Checklist

  • TypeScript changes: verify all type exports are properly maintained, no type information is lost
  • API changes: check if README.md or API docs need updating
  • Dependency changes: assess security implications and compatibility with supported Node.js versions
  • Test changes: ensure coverage is maintained or improved, never decreased
  • Configuration changes: verify backward compatibility and migration paths
  • Cross-package changes: verify consistency across all affected packages and their consumers

Produce the Review

Write the review following the template in references/review-output-template.md.

© Shopify, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/reviewing-pull-requests of Shopify/shopify-app-js.

  • SKILL.md
  • references/review-output-template.md
  • references/semver-classification.md

Open the folder on GitHubat commit 9e452e5

Compare with similar skills

Reviewing Pull Requests next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reviewing Pull Requests compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reviewing Pull Requests this skillShopify/shopify-app-js543—~1.9kAutomated safety check: PassMIT
Issue BriefVasiHemanth/tokentelemetry377—~1.5kAutomated safety check: PassMIT
CodeScope Codebase Graph AnalysisQwenLM/qwen-code28k1 repos~9.3kAutomated safety check: PassApache-2.0
Review Implement Phaseprisma/orm48k—~1.7kAutomated safety check: PassApache-2.0
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0
Issue TracerZaxbyHub/opencode-swarm493—~4.4kAutomated safety check: PassMIT

Similar skills

  • Issue Brief

    VasiHemanth/tokentelemetry

    Explain a GitHub issue, discussion, or feature request in plain language before deciding whether to build it.

    377 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Answers questions about code structure, history, bugs and PR risk using a CodeScope knowledge graph and semantic index built from the repository.

    28k GitHub starsUsed in 1 repo~9.3k tokens
    DevelopmentAuto-check passed
  • Official

    Implements triaged pull request review actions, commits focused fixes, posts status replies on GitHub and resolves the threads.

    48k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    493 GitHub stars~4.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Gh Bot Comment

    jetstreamapp/jetstream

    Post GitHub PR/issue comments, reviews, and review replies as the Jetstream bot account instead of the user's personal account.

    126 GitHub stars~616 tokensUpdated today
    DevelopmentAuto-check passed

More from Shopify/shopify-app-js

  • Adding API Versions

    Shopify/shopify-app-js

    Official

    A skill your agent uses when adding a new API version to the shopify-api package, creating REST resource files for a new version, updating API version constants, or handling breaking changes like…

    543 GitHub stars~923 tokensUpdated today
    Auto-check passed
  • Investigating GitHub Issues

    Shopify/shopify-app-js

    Official

    Read-only investigation and analysis of GitHub issues for Shopify/shopify-app-js.

    543 GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings

Categories

Questions about Reviewing Pull Requests

What does Reviewing Pull Requests do?

Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…. Reviewing Pull Requests is an agent skill from Shopify/shopify-app-js, published by the product's own GitHub organization.js library patterns, and root cause analysis.

When should I use Reviewing Pull Requests?

Reviewing Pull Requests fits situations like: asked to review a PR; check for breaking changes; validate code quality.

How do I install Reviewing Pull Requests in Claude Code?

Run `npx skills add Shopify/shopify-app-js --skill reviewing-pull-requests -a claude-code`. Or copy the skill folder (.claude/skills/reviewing-pull-requests in Shopify/shopify-app-js) into .claude/skills/reviewing-pull-requests in your project. Claude Code loads it when a task matches its description.

How do I install Reviewing Pull Requests in Codex?

Run `npx skills add Shopify/shopify-app-js --skill reviewing-pull-requests -a codex`. Or copy the skill folder (.claude/skills/reviewing-pull-requests in Shopify/shopify-app-js) into .agents/skills/reviewing-pull-requests in your project. Codex loads it when a task matches its description.

Can I use Reviewing Pull Requests in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Shopify/shopify-app-js --skill reviewing-pull-requests -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reviewing-pull-requests, .gemini/skills/reviewing-pull-requests, .github/skills/reviewing-pull-requests and .opencode/skills/reviewing-pull-requests in your project.

What does Reviewing Pull Requests need to run?

Going by SKILL.md and its folder, Reviewing Pull Requests needs the command-line tools its instructions call (gh). Our summary lists: Node.js.

Does Reviewing Pull Requests access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Reviewing Pull Requests safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Reviewing Pull Requests use?

Reviewing Pull Requests is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reviewing Pull Requests use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 957 tokens, read only when the agent opens those files.

What are the alternatives to Reviewing Pull Requests?

Skills that share tags, products or a category with Reviewing Pull Requests: Issue Brief (VasiHemanth/tokentelemetry, 377 stars), CodeScope Codebase Graph Analysis (QwenLM/qwen-code, 28k stars), Review Implement Phase (prisma/orm, 48k stars) and Code Review (nteract/semiotic, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reviewing Pull Requests?

Shopify (a GitHub organization, an official publisher) maintains it in Shopify/shopify-app-js, which has 543 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: Shopify/shopify-app-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.