Agent skill

PR Sweep

by TanStack in TanStack/ai

Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when…

MITAuto-check passedAgent Workflows

Install PR Sweep

skills CLI
$ npx skills add TanStack/ai --skill pr-sweep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TanStack/ai pr-sweep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TanStack/ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.grok/skills/pr-sweep .claude/skills/pr-sweep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-sweep
GitHub stars
3.2k
Token cost
~4.6k tokens
SKILL.md length
1,319 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when…

  • Works in 6 steps: Resolve repo + "us" set → List target PRs → Fan-out (read phase) → …
  • The user runs /pr-sweep (or /pr-inbound-sweep)
  • SKILL.md covers Args, Modes, Daily routine (recommended) and Prerequisites, plus 4 more sections
  • Calls gh and git; reaches github.com

What it does

PR Sweep is an agent skill from TanStack/ai. Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when relevant, optionally rebase in-house PRs, and report who should review. Supports full, changed-only, behind-only, and conflict-only scopes for cheap daily runs. Use when the user runs /pr-sweep (or /pr-inbound-sweep), or asks to "sweep PRs", "sweep inbound PRs", "security-check outside PRs", "rebase outsider PRs"…

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/security-checklist.md`).

It sits in Agent Workflows, covering Subagents and Security review. The repository describes itself as: 🤖 Type-safe, provider-agnostic TypeScript AI SDK for streaming chat, tool calling, agents, and multimodal apps across OpenAI, Anthropic, Gemini, React, Vue, Svelte, and Solid. The licence is MIT.

When your agent uses it

  • The user runs /pr-sweep (or /pr-inbound-sweep)
  • Asks to sweep PRs
  • Sweep inbound PRs
  • Security-check outside PRs

Example prompts

  • “sweep PRs”
  • “sweep inbound PRs”
  • “security-check outside PRs”
  • “/pr-sweep”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Resolve repo + "us" set
  2. List target PRs
  3. Fan-out (read phase)
  4. Aggregate dry-run report
  5. Apply mode
  6. Final report + assignment recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit 68aeada. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Sweep loads about 4.6k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 156 tokens; SKILL.md has 1,319 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TanStack/ai at commit 68aeada, republished under its MIT licence (© TanStack). 1,319 words, ~4,591 tokens.

Download SKILL.mdSave it as .claude/skills/pr-sweep/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
pr-sweep
description
Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when relevant, optionally rebase in-house PRs, and report who should review. Supports full, changed-only, behind-only, and conflict-only scopes for cheap daily runs. Use when the user runs /pr-sweep (or /pr-inbound-sweep), or asks to "sweep PRs", "sweep inbound PRs", "security-check outside PRs", "rebase outsider PRs", "rebase our PRs", "approve waiting CI on PRs", "daily PR sweep", or "prep external PRs for review".

PR Sweep

Prep PRs for review. Fan out one subagent per PR (cap 100). Default is dry-run (report only). Mutating steps require --apply (or the user saying "apply" / "go ahead").

Args

InvocationBehavior
/pr-sweepAll open non-draft PRs (full audit)
/pr-sweep 12 34 56Only those PR numbers
/pr-sweep --applyFull set, then rebase and push (--force-with-lease)
/pr-sweep --apply 12 34Rebase and push listed PRs only
/pr-sweep --outside-onlyAction target = outside authors only (default for mutations)
/pr-sweep --include-in-houseAlso rebase/update in-house branches (still never merge)
/pr-sweep --behindOnly PRs behind base / BEHIND / not up to date
/pr-sweep --conflictsOnly CONFLICTING / DIRTY / dirty merge state
/pr-sweep --changedOnly PRs changed since last snapshot (or updatedAt within 24h if no snapshot)
/pr-sweep --dailyRecommended daily recipe: --changed ∪ --behind ∪ --conflicts ∪ new outside PRs; security-scan new outside; lighter pass on the rest
/pr-sweep --apply --daily --include-in-houseDaily apply: prep outside + rebase ours when behind/conflicting

Combine freely: --apply --daily --include-in-house. Explicit PR numbers always win over filters.

Modes

  • dry-run (default): fetch, classify, security-scan, decide relevance / rebase need / CI need / assign recommendation. No push, no CI approve, no comments.
  • apply: after dry-run logic, rebase + git push --force-with-lease + CI approve for PRs that pass security and are marked actionable, in the same turn. --apply on the invocation is consent — do not wait for a second yes. Still never merge a PR and never comment on a PR. A local rebase with no push is a failed apply. Record results in SWEEP-*.md only.
Option A — Grok /loop (same machine, session-scoped, expires ~7d)
text
/loop 1d /pr-sweep --apply --daily --include-in-house

Or dry-run every morning and apply only when you say go:

text
/loop 1d /pr-sweep --daily --include-in-house

/loop intervals: Nm / Nh / Nd (min 60s). Cancel with scheduler_list → scheduler_delete <id>.

Option B — Manual weekday
text
/pr-sweep --daily --include-in-house          # dry-run first
/pr-sweep --apply --daily --include-in-house  # after skimming plan
What --daily processes

Build the action set as the union of:

  1. New outside PRs — open outside non-draft not present in the previous snapshot (full security scan).
  2. Changed — updatedAt newer than last snapshot sweptAt, or head SHA changed vs snapshot.
  3. Behind — mergeStateStatus is BEHIND or not up to date with default branch.
  4. Conflicts — mergeable == CONFLICTING or mergeStateStatus in DIRTY, BLOCKED with dirty indicators.
  5. CI waiting approval — outside PRs with first-time-contributor gate (cheap; no full diff if already in snapshot as security: clean).

Skip from action set (still note counts in report):

  • Drafts (unless listed explicitly)
  • security: alert from prior snapshot until human clears
  • PRs marked blocked-conflicts in the last 24h with no updatedAt change (avoid thrashing)
  • Bot version/release PRs (changeset-release/*, pure Renovate) unless --include-bots

Cost target: daily should touch tens, not all open history. Full /pr-sweep remains the weekly deep scan.

Snapshot (enables --changed / --daily)

Path: .agent/pr-sweep/snapshot.json

json
{
  "repo": "TanStack/ai",
  "sweptAt": "2026-08-10T18:00:00Z",
  "defaultBranch": "main",
  "defaultBranchSha": "abc…",
  "prs": {
    "1069": {
      "author": "mikemikimike",
      "outside": true,
      "headSha": "def…",
      "updatedAt": "2026-08-10T04:01:40Z",
      "security": "clean",
      "mergeable": "MERGEABLE",
      "mergeStateStatus": "UNSTABLE",
      "lastAction": "approve-ci",
      "lastActionAt": "2026-08-10T17:30:00Z"
    }
  }
}

Write/update after every run (dry-run or apply). Diff against this file for --changed. If missing, treat all open PRs as new for one full pass, then write the snapshot.

Prerequisites

bash
gh auth status
gh repo view --json nameWithOwner,defaultBranchRef,owner

Stop if not authenticated. Confirm you are in the target repo (or pass owner/repo if the user named one).

Safety (hard rules)

  1. Never merge a PR.
  2. Never git push --force. Only git push --force-with-lease.
  3. Never mutate on a security finding (security: "alert"). Report and stop that PR.
  4. Default action target = outside only. In-house rebases require --include-in-house (or explicit PR numbers that happen to be in-house).
  5. In-house security: skip malware fan-out unless the PR touches scripts/, .github/workflows/, lockfiles, or install lifecycle — then light scan only.
  6. Worktrees only for apply-mode git ops (spawn_subagent with isolation: "worktree"). Do not checkout foreign branches in the main workspace.
  7. Cap concurrent apply subagents at 8 (worktrees + API). Read-only fan-out may go up to 100.
  8. If rebase conflicts cannot be resolved cleanly in under ~10 minutes of agent work, abort, leave a note in the report, do not push partial state.
  9. --apply / "apply" / "go ahead" / "yes" after a dry-run is consent. Write the apply plan into the report and mutate immediately. Do not stop for a second yes, including when more than 5 PRs would be mutated. Daily /loop … --apply likewise fires without re-prompting.
  10. Prefer rebase for both outside and in-house. Use merge-from-base only when the agent JSON says so (many merge commits, prior merge strategy).
  11. Push is part of rebase. After a clean rebase (or merge-from-base), run git push --force-with-lease onto the PR head remote, then verify gh pr view N --json headRefOid changed. Do not mark the PR done until the remote moved or you recorded push-403.
  12. Never comment on a PR. GitHub already notifies the author on push. A comment from the maintainer reads as a review ping / waiting-on-author. Record rebase/CI results in .agent/pr-sweep/SWEEP-*.md only. No gh pr comment, no review comments, no issue comments.

Procedure

Show full SKILL.md (569 more words)Show less
1. Resolve repo + "us" set
bash
OWNER_REPO=$(gh repo view --json nameWithOwner --jq '.nameWithOwner')
OWNER=$(echo "$OWNER_REPO" | cut -d/ -f1)
REPO=$(echo "$OWNER_REPO" | cut -d/ -f2)
DEFAULT_BRANCH=$(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')
DEFAULT_SHA=$(git rev-parse origin/$DEFAULT_BRANCH 2>/dev/null || gh api repos/$OWNER/$REPO/commits/$DEFAULT_BRANCH --jq .sha)

Build in-house logins (US):

  1. Org members (if owner is an org):
    bash
    gh api orgs/$OWNER/members --paginate --jq '.[].login' 2>/dev/null
  2. Repo collaborators with admin or maintain or push:
    bash
    gh api repos/$OWNER/$REPO/collaborators --paginate --jq '.[] | select(.permissions.admin or .permissions.maintain or .permissions.push) | .login'
  3. Logins in CODEOWNERS (and resolve teams when cheap).
  4. Bots: dependabot[bot], renovate[bot], github-actions[bot], copilot-swe-agent[bot], etc. → in-house.

Author is outside if login ∉ US.

2. List target PRs
bash
gh pr list --state open --limit 200 \
  --json number,title,url,author,isDraft,baseRefName,headRefName,headRepository,headRepositoryOwner,isCrossRepository,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,additions,deletions,changedFiles,createdAt,updatedAt,assignees,headRefOid

(REST fallback if GraphQL 502s.)

Apply filters in order:

  1. Explicit numbers → use only those.
  2. Drop drafts from action set (mention under skipped).
  3. If --conflicts → keep only conflicting/dirty.
  4. If --behind → keep only behind/not up to date.
  5. If --changed → keep only snapshot-diffed changes (or 24h updatedAt if no snapshot).
  6. If --daily → union of new-outside ∪ changed ∪ behind ∪ conflicts ∪ waiting-approval (see Daily).
  7. Else → all open non-draft.

If count > 100, process 100 most-recently-updated; list the rest under "Skipped (over budget)".

3. Fan-out (read phase)

Spawn up to 100 parallel general-purpose subagents. One PR per agent.

Cheap path (daily / already-clean outside): if snapshot has security: clean and head SHA unchanged and only behind/conflicts flag flipped, skip full gh pr diff malware scan — re-fetch mergeability + checks only.

Each agent returns one JSON object only:

json
{
  "number": 123,
  "title": "...",
  "url": "https://github.com/...",
  "author": "login",
  "outside": true,
  "draft": false,
  "security": "clean|alert|review",
  "securityReasons": ["..."],
  "relevant": true,
  "relevanceReason": "<=120 chars",
  "behindBase": true,
  "mergeable": "MERGEABLE|CONFLICTING|UNKNOWN",
  "rebasePlan": "none|rebase|merge-from-base|blocked-conflicts|blocked-security|n/a-skip",
  "ci": {
    "overall": "passing|failing|pending|waiting-approval|none",
    "needsWorkflowApproval": false,
    "failedChecks": [],
    "pendingChecks": []
  },
  "assignForReview": true,
  "assignTo": ["login-or-team"],
  "priority": "P0|P1|P2|P3",
  "actionsPlanned": [
    "security-alert",
    "rebase",
    "push-force-with-lease",
    "approve-ci",
    "none"
  ],
  "blockers": "<=120 chars or empty",
  "summary": "<=160 chars"
}
Per-PR agent instructions (embed fully)
You are auditing GitHub PR <URL> in <OWNER/REPO> for pr-sweep.
Mode: read-only. Do not push, comment, approve, or merge.

1) Fetch:
   gh pr view <N> --json title,body,author,isDraft,baseRefName,headRefName,headRepositoryOwner,isCrossRepository,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,files,additions,deletions,commits,url,assignees,headRefOid
   gh pr checks <N> 2>/dev/null || true
   # Full diff only if: outside AND (new OR security not yet clean in snapshot OR headSha changed)
   gh pr diff <N>   # when required

2) outside: true if author.login not in: <US_LOGINS_CSV>

3) Security:
   - Outside: always for new/changed head; use checklist references/security-checklist.md (next to this SKILL.md)
   - In-house: clean by default unless scripts/CI/lockfile/install lifecycle touched
   security: alert | review | clean

4) relevant + relevanceReason

5) behindBase + rebasePlan:
   - none | rebase | merge-from-base | blocked-conflicts | blocked-security | n/a-skip
   - In-house with --include-in-house: rebasePlan is rebase/merge-from-base/blocked-conflicts (not n/a-skip)
   - In-house without include: rebasePlan n/a-skip

6) CI: overall + needsWorkflowApproval + failed/pending checks

7) assignForReview, assignTo, priority, actionsPlanned

Return ONLY the JSON object on one line.
4. Aggregate dry-run report

Write .agent/pr-sweep/SWEEP-YYYY-MM-DD.md (create dirs). Structure:

markdown
# PR Sweep — <OWNER/REPO> — <date> — mode: dry-run|apply — scope: full|daily|behind|conflicts|changed

## Security alerts

## Needs human eyes

## Outside PRs — recommended actions

## In-house PRs — recommended actions # when --include-in-house

## Skipped

## Apply plan

Also update snapshot.json (even on dry-run) with current head SHAs and merge state.

Print a short chat summary: alert count, would-rebase count (outside / in-house), CI approvals, top assign list (max 5), report path.

If mode is dry-run, stop here (unless user then says apply).

5. Apply mode

--apply is consent. Write the Apply plan into the report and mutate in this turn. Do not wait for another yes.

Done for a rebase target = default-branch is an ancestor of the remote head SHA (push landed) or result: push-403 is recorded. Local-only rebase = failed apply.

Process PRs that are actionable:

AuthorSecurityFlagMutate?
outsidecleandefaultyes (rebase, approve-ci)
outsidealert/reviewanyno (report only)
in-houseclean--include-in-houseyes (rebase only; CI approve usually N/A)
in-house—no flagno
5a. Security gate

If security != "clean" → skip mutations.

5b. Rebase / update base (worktree subagent)

spawn_subagent with isolation: "worktree", max 8 concurrent. Embed the push + verify steps in the child prompt (completion criterion: remote SHA changed).

bash
BEFORE=$(gh pr view <N> --json headRefOid --jq .headRefOid)
gh pr checkout <N>
git fetch origin <DEFAULT_BRANCH>
git rebase origin/<DEFAULT_BRANCH>
# only if agent said merge-from-base:
# git merge origin/<DEFAULT_BRANCH>
# conflicts: resolve only clear non-overlapping/import/lockfile/generated cases.
# else: git rebase --abort; result=blocked-conflicts; do not push.

git push --force-with-lease
# Forks: push to the upstream `gh pr checkout` set (often not origin).
# If no upstream: git push --force-with-lease <fork-remote> HEAD:<headRefName>

AFTER=$(gh pr view <N> --json headRefOid --jq .headRefOid)
# MUST: AFTER != BEFORE. If equal, the push did not land — not done.

Org-fork 403 (maintainerCanModify false): record push-403, do not retry loops. Still never git push --force.

Apply child prompt (embed fully)
You are applying pr-sweep to GitHub PR https://github.com/OWNER/REPO/pull/N.
Mode: APPLY in a worktree. Never merge. Never git push --force (lease only). Never comment on the PR.

DONE only when the PR's remote head SHA changed, or you return result=push-403 or blocked-conflicts.
A local rebase with no push is a FAILED apply. Do not stop after rebase.

1. BEFORE=$(gh pr view N --json headRefOid --jq .headRefOid)
2. gh pr checkout N
3. git fetch origin DEFAULT_BRANCH
4. git rebase origin/DEFAULT_BRANCH
   Conflicts: resolve only trivial non-overlapping import/lockfile/generated cases.
   Else git rebase --abort and return blocked-conflicts (no push).
5. git push --force-with-lease
   Forks: push the upstream gh pr checkout configured (often not origin).
   No upstream: git push --force-with-lease <fork-remote> HEAD:<headRefName>
6. AFTER=$(gh pr view N --json headRefOid --jq .headRefOid)
   If AFTER == BEFORE and rebase was not already-current: push did not land — not done.

Return ONLY JSON:
{"number":N,"pushed":true|false,"newHeadSha":"...","result":"rebased-pushed|already-current|blocked-conflicts|push-403|error","blockers":"","summary":""}
5c. Approve waiting workflows (outside, relevant, clean)
bash
gh api -X POST repos/$OWNER/$REPO/actions/runs/<RUN_ID>/approve

If 403/404 → note manual approval needed. Do not re-run failing CI unless asked.

6. Final report + assignment recommendations

Update the markdown report with Results: mutated, still blocked, assign-for-review table.

Do not gh pr edit --add-assignee unless the user said "assign them".

Offer once (opt-in): publish report as secret gist:

bash
gh gist create .agent/pr-sweep/SWEEP-YYYY-MM-DD.md --desc "PR sweep — <OWNER/REPO> — <date>"

Secret is the default — never --public unless asked.

Chat closer: ≤5 lines — alerts, actions taken, top PRs to review, report path, gist URL if created.

Orchestrator tips

  • Prefer one read fan-out, then a smaller apply fan-out only for real mutations.
  • Daily first: load snapshot → filter → only then fan out. Avoid 60-agent full scans every day.
  • In-house rebases share the same force-with-lease rules; branches on the origin repo push to origin.
  • Org-fork push 403s (maintainerCanModify false / org policy): report partial; do not retry loops.
  • Cost: <20 PRs → main thread fine; no need for 100 agents.
  • Does not replace triage-github (backlog ranking) or pr-babysit (ongoing CI/comment fixing).

Reference

© TanStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .grok/skills/pr-sweep of TanStack/ai.

  • SKILL.md
  • references/security-checklist.md

Open the folder on GitHubat commit 68aeada

Compare with similar skills

PR Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Sweep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Sweep this skillTanStack/ai3.2k—~4.6kAutomated safety check: PassMIT
Skillkitrfxlamia/skillkit102—~3.7kAutomated safety check: PassApache-2.0
Review SwarmDimillian/Skills4k1 repos~1.6kAutomated safety check: PassMIT
Team Composition Patternswshobson/agents40k—~2kAutomated safety check: PassMIT
Claude Code Agent Developmentanthropics/claude-plugins-official38k8 repos~2.8kAutomated safety check: PassApache-2.0
Subagent Driven DevelopmentAsvarox/allkaraoke26138 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Skillkit

    rfxlamia/skillkit

    Toolkit for creating and validating skills and subagents. An agent skill from rfxlamia/skillkit.

    102 GitHub stars~3.7k tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check passed
  • Review Swarm

    Dimillian/Skills

    Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test…

    4k GitHub starsUsed in 1 repo~1.6k tokens
    Agent WorkflowsAuto-check passed
  • Design optimal agent team compositions with sizing heuristics, preset configurations, and agent type selection.

    40k GitHub stars~2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 8 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Subagent Driven Development

    Asvarox/allkaraoke

    A skill your agent uses when executing implementation plans with independent tasks in the current session

    261 GitHub starsUsed in 38 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Dispatching Parallel Agents

    ultralisp/ultralisp

    A skill your agent uses when facing 2+ independent tasks that can be worked on without shared state or sequential dependencies

    258 GitHub starsUsed in 41 repos~1.5k tokens
    Agent WorkflowsAuto-check passed

More from TanStack/ai

All 24 skills in this repo
  • I Have Adhd

    TanStack/ai

    A skill your agent uses when the user invokes /i-have-adhd, says they have ADHD, or asks for ADHD-friendly output.

    3.2k GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • A skill your agent uses when wiring honcho() from @tanstack/ai-memory/honcho — a hosted memory adapter where recall is a dialectic answer over the user's representation (no discrete fragments).

    3.2k GitHub starsUsed in 1 repo~457 tokens
    Auto-check passed
  • A skill your agent uses when wiring inMemory() from @tanstack/ai-memory/in-memory — explains setup, options (embedder, extract, topK/minScore), when to pick it (dev/tests/single-process demos), and…

    3.2k GitHub starsUsed in 1 repo~448 tokens
    Auto-check passed
  • A skill your agent uses when wiring redis() from @tanstack/ai-memory/redis in production — covers client setup (ioredis or node-redis via fromNodeRedis), the storage model, client-side ranking…

    3.2k GitHub starsUsed in 1 repo~840 tokens
    Auto-check passed
  • A skill your agent uses when adding a public teaching example or a docs tutorial.

    3.2k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • AI Persistence

    TanStack/ai

    Durability and state persistence for TanStack AI chats with @tanstack/ai-persistence.

    3.2k GitHub stars~3.3k tokensUpdated today
    Auto-check passed

Categories

Questions about PR Sweep

What does PR Sweep do?

Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when…. PR Sweep is an agent skill from TanStack/ai. Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when relevant, optionally rebase in-house PRs, and report who should review.

When should I use PR Sweep?

PR Sweep fits situations like: the user runs /pr-sweep (or /pr-inbound-sweep); asks to sweep PRs; sweep inbound PRs; security-check outside PRs.

How do I install PR Sweep in Claude Code?

Run `npx skills add TanStack/ai --skill pr-sweep -a claude-code`. Or copy the skill folder (.grok/skills/pr-sweep in TanStack/ai) into .claude/skills/pr-sweep in your project. Claude Code loads it when a task matches its description.

How do I install PR Sweep in Codex?

Run `npx skills add TanStack/ai --skill pr-sweep -a codex`. Or copy the skill folder (.grok/skills/pr-sweep in TanStack/ai) into .agents/skills/pr-sweep in your project. Codex loads it when a task matches its description.

Can I use PR Sweep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TanStack/ai --skill pr-sweep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-sweep, .gemini/skills/pr-sweep, .github/skills/pr-sweep and .opencode/skills/pr-sweep in your project.

What does PR Sweep need to run?

Going by SKILL.md and its folder, PR Sweep needs the command-line tools its instructions call (gh and git).

Does PR Sweep access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is PR Sweep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Sweep use?

PR Sweep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PR Sweep use?

About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 780 tokens, read only when the agent opens those files.

What are the alternatives to PR Sweep?

Skills that share tags, products or a category with PR Sweep: Skillkit (rfxlamia/skillkit, 102 stars), Review Swarm (Dimillian/Skills, 4k stars), Team Composition Patterns (wshobson/agents, 40k stars) and Claude Code Agent Development (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Sweep?

TanStack (a GitHub organization) maintains it in TanStack/ai, which has 3,172 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 8, 2026.

Source: TanStack/ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.