Agent skill

GitHub Deep Review

by steipete in steipete/agent-scripts

GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first.

MITAuto-check passed

Install GitHub Deep Review

skills CLI
$ npx skills add steipete/agent-scripts --skill github-deep-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts github-deep-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github-deep-review .claude/skills/github-deep-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-deep-review
GitHub stars
7.3k
Token cost
~1.7k tokens
SKILL.md length
854 words
Files
2
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first.

  • Works in 5 steps: Reconstruct the reporter's scenario and… → Check whether current main already fixes… → Reproduce or create a minimal local/live… → …
  • SKILL.md covers Start, Review Contract, Code Reading Depth and Provenance, plus 4 more sections
  • Calls git, gh and rg

What it does

GitHub Deep Review is an agent skill from steipete/agent-scripts. GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It works with GitHub. The repository describes itself as: Scripts for agents, shared between my repositories. The licence is MIT.

Example prompts

  • “/github-deep-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Reconstruct the reporter's scenario and affected version/surface.
  2. Check whether current main already fixes it.
  3. Reproduce or create a minimal local/live proof when feasible.
  4. If clear, identify root cause and proposed fix.
  5. If solved on main, only comment/close when the user asks; include proof and the canonical commit/PR if known.

What it can do on your machine

Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Deep Review loads about 1.7k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 854 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 854 words, ~1,726 tokens.

Download SKILL.mdSave it as .claude/skills/github-deep-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-deep-review
description
GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first.

GitHub Deep Review

Review like Peter: high-confidence, evidence-first, code-aware, and willing to say "not proven" when the trail is weak. The goal is not a generic summary. The goal is to understand the bug class, find the real cause if possible, decide the best fix after reading enough code, and call out whether a larger refactor would improve the design.

Start

Use gh, not web browsing, for GitHub refs:

bash
gh issue view <n> --json number,title,state,author,body,comments,labels,updatedAt,url
gh pr view <n> --json number,title,state,author,body,comments,reviews,files,commits,statusCheckRollup,mergeStateStatus,headRefName,headRepositoryOwner,url
gh pr diff <n> --patch

For PRs, collect author context by default unless the author is Peter (steipete or an obvious Peter-owned account). Use the local workflow in ~/Projects/agent-scripts/skills/github-author-context/SKILL.md and include a short Author context: block near the top of the review when the author is not Peter. After merge/rejection/close/review, use that same author-context workflow to append a contributor note only when the interaction creates durable future-review signal.

For repo-local review, also inspect:

bash
git status --short --branch
git fetch origin
git log --oneline --decorate -20
rg "<key symbol/error/config/endpoint>"

If the repo has local instructions, issue/PR skills, docs lists, test guidance, or maintainer runbooks, read those before deciding.

Review Contract

Always answer these, explicitly:

  • URL/ref: issue or PR number and affected surface.
  • What is the bug or behavior being fixed?
  • Can we identify the root cause? If yes, where in code and why. If no, what evidence is missing.
  • For regressions, who/what introduced it and when? Include commit/PR provenance when traceable by bounded history; say unknown instead of guessing.
  • Is the current/proposed fix the best possible fix after reading adjacent code?
  • Would a bigger refactor improve correctness, clarity, or future maintainability?
  • What proof exists: tests, live repro, CI checks, docs, dependency docs/source, shipped/current behavior.
  • What remains risky or unverified.

Code Reading Depth

Read past the first touched file. Follow the real call path:

  • entrypoint -> validation/parsing -> routing/dispatch -> owner module -> shared helper -> persistence/network/runtime boundary
  • config/schema/docs -> runtime usage -> doctor/migration/fix path
  • provider/channel/plugin owner code -> generic core seam, only if multiple owners need it
  • tests around the touched surface plus adjacent regression tests

When behavior depends on a dependency, read the upstream docs/source/types or current package contract before assuming.

Prefer current source and executable proof over issue comments. Treat stale comments, old CI, and old release behavior as hints until rechecked.

Provenance

For bug/regression reviews, include a compact Provenance: answer when feasible:

  • Use git log -S/-G, git blame, and linked PRs/issues to locate candidates, not prove introduction. Before saying introduced by, inspect raw parents with git --no-replace-objects cat-file -p <sha> and verify that git --no-replace-objects diff --no-ext-diff --no-textconv <raw-parent> <sha> -- <path> changed the implicated behavior, using tests/repro when feasible. A genuine root needs raw-header proof that it has no parents.
  • Blame ^sha, porcelain boundary, and shallow/grafted history alone are not introduction proof. --root can hide boundary markers; git show and rev-list --parents can disguise a shallow boundary as a root. An available raw parent permits explicit comparison even at a shallow boundary; missing parents or an unverifiable patch require unknown with the gap, not inference from a subject, date, or author.
  • Separate code author, introducing PR author, merger, committer, automation trigger, and current PR author. Verify identities and triggers from explicit metadata/events; a role is not proof of causation, and an unverified identity stays unknown.
  • Use made visible by only for a verified trigger and carried forward by only for verified preexisting behavior. Apply the same evidence bar to summaries and owner hints, not just a Provenance: field. Include confidence: clear, likely, or unknown.
  • For features, docs, and refactors, write N/A; for untraceable bugs, report unknown with the missing evidence. Missing provenance does not invalidate an independently proven bug.
Show full SKILL.md (282 more words)Show less

Fix Quality Bar

Good fixes usually:

  • live at the ownership boundary where the bug belongs
  • preserve public/backward-compatible behavior unless the issue is about retiring it
  • add a regression test at the smallest meaningful seam
  • avoid broad special cases, hidden migrations, semantic sentinels, and provider/channel IDs in generic core
  • update docs/changelog when user-visible behavior changes
  • fail clearly in runtime paths and repair through doctor/migration paths when that is the established contract

Call out when a fix is only symptom-level. If a slightly larger refactor makes the invariant obvious and reduces future bugs, recommend it. If the refactor widens risk without improving the bug class, say so.

PR Review Shape

Lead with findings when reviewing a PR. Findings need file/line/symbol references and a concrete failure mode. Avoid vague "consider" comments.

If no blocking issues:

  • say no blocking correctness issues found
  • list the strongest proof checked
  • name residual risk/test gaps
  • answer whether the design is the best available shape

Do not approve, comment, close, merge, push, or land unless the user asked for that action.

Issue Review Shape

For bugs/issues:

  1. Reconstruct the reporter's scenario and affected version/surface.
  2. Check whether current main already fixes it.
  3. Reproduce or create a minimal local/live proof when feasible.
  4. If clear, identify root cause and proposed fix.
  5. If solved on main, only comment/close when the user asks; include proof and the canonical commit/PR if known.

If reproduction is not feasible, say exactly what blocks it and what evidence would make the decision reliable.

Output Template

Use this shape when the user asks "what is this about", "is this the best fix", or "what did we fix":

text
Ref: #123 / PR #456
Surface: <runtime/CLI/provider/channel/docs>

Bug: <one or two sentences>
Cause: <code path + confidence>
Provenance: <introduced/made visible/carried forward by commit/PR/date, or N/A/unknown>
Best fix: <what should change and why>
Refactor: <yes/no, specific shape>
Proof: <tests/live/CI/source/dependency docs>
Risk: <remaining uncertainty>

Keep it concise, but do not skip the cause/fix/refactor/proof decision.

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/github-deep-review of steipete/agent-scripts.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 79150cf

Compare with similar skills

GitHub Deep Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Deep Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Deep Review this skillsteipete/agent-scripts7.3k—~1.7kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed

More from steipete/agent-scripts

All 45 skills in this repo
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated 2 days ago
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about GitHub Deep Review

What does GitHub Deep Review do?

GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first. GitHub Deep Review is an agent skill from steipete/agent-scripts. GitHub deep review: bugs, PRs, best fix, stale-or-real, read code first.

How do I install GitHub Deep Review in Claude Code?

Run `npx skills add steipete/agent-scripts --skill github-deep-review -a claude-code`. Or copy the skill folder (skills/github-deep-review in steipete/agent-scripts) into .claude/skills/github-deep-review in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Deep Review in Codex?

Run `npx skills add steipete/agent-scripts --skill github-deep-review -a codex`. Or copy the skill folder (skills/github-deep-review in steipete/agent-scripts) into .agents/skills/github-deep-review in your project. Codex loads it when a task matches its description.

Can I use GitHub Deep Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill github-deep-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-deep-review, .gemini/skills/github-deep-review, .github/skills/github-deep-review and .opencode/skills/github-deep-review in your project.

What does GitHub Deep Review need to run?

Going by SKILL.md and its folder, GitHub Deep Review needs the command-line tools its instructions call (git, gh and rg).

Does GitHub Deep Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Deep Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Deep Review use?

GitHub Deep Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Deep Review use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Deep Review?

Skills that share tags, products or a category with GitHub Deep Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Deep Review?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,259 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.