Agent skill

Review PR

by Terry-Mao in Terry-Mao/AICodingFlow

Review a GitHub pull request from pinned prdescription.txt, prdiff.txt, and optional speccontext.md snapshots, then write and validate review.json.

MITAuto-check passedDevelopment

Install Review PR

skills CLI
$ npx skills add Terry-Mao/AICodingFlow --skill review-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Terry-Mao/AICodingFlow review-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Terry-Mao/AICodingFlow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/review-pr .claude/skills/review-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-pr
GitHub stars
167
Token cost
~1k tokens
SKILL.md length
460 words
Files
2 (incl. scripts)
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Review a GitHub pull request from pinned prdescription.txt, prdiff.txt, and optional speccontext.md snapshots, then write and validate review.json.

  • Works in 12 steps: Read .agents/contracts/review.md. → Read pr_description.txt. → Read spec_context.md when it exists. → …
  • Bot needs offline PR review comments without posting to GitHub
  • SKILL.md covers Required Contract, Applicability, Local Guidance and Review Focus, plus 2 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Review PR is an agent skill from Terry-Mao/AICodingFlow. Review a GitHub pull request from pinned prdescription.txt, prdiff.txt, and optional speccontext.md snapshots, then write and validate review.json. Use when a CI job or bot needs offline PR review comments without posting to GitHub.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/validate_review_json.py`).

It sits in Development, covering Pull requests. It works with GitHub. The repository describes itself as: Setup a AI Coding Flow. The licence is MIT.

When your agent uses it

  • Bot needs offline PR review comments without posting to GitHub
  • Tasks that involve Pull requests

Example prompts

  • “/review-pr”

Requirements

  • Python 3

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. Read .agents/contracts/review.md.
  2. Read pr_description.txt.
  3. Read spec_context.md when it exists.
  4. Read review_discussion_context.json when it exists and apply it only for
  5. Parse pr_diff.txt, build allowed changed-line targets, and collect changed
  6. Read .github/skills/review-pr-repo/SKILL.md if present and apply only
  7. If spec_context.md exists, read
  8. Read .github/skills/security-review-pr/SKILL.md and apply it as a
  9. Inspect relevant repository files only when needed to understand changed code
  10. Write one combined review.json that includes base review findings and any
  11. Run python3 .github/skills/review-pr/scripts/validate_review_json.py pr_diff.txt review.json
  12. Fix review.json until validation passes.

What it can do on your machine

Read from SKILL.md and the folder at commit 7703e16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review PR loads about 1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 460 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Terry-Mao/AICodingFlow at commit 7703e16, republished under its MIT licence (© Terry-Mao). 460 words, ~1,004 tokens.

Download SKILL.mdSave it as .claude/skills/review-pr/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-pr
description
Review a GitHub pull request from pinned `pr_description.txt`, `pr_diff.txt`, and optional `spec_context.md` snapshots, then write and validate `review.json`. Use when a CI job or bot needs offline PR review comments without posting to GitHub.

review-pr

Review one code or mixed-content PR from stable local snapshot files and write the single output artifact review.json.

Required Contract

Read .agents/contracts/review.md first and follow it exactly. That contract is authoritative for snapshot trust, untrusted-input handling, PR_DIFF_V1 targeting, review.json structure, severity labels, suggestion blocks, validator requirements, and GitHub/API boundaries.

Do not run gh, post comments, regenerate snapshots, or modify files other than review.json.

Applicability

Use this skill for PRs where implementation correctness, security, error handling, performance, maintainability, tests, or docs-vs-code consistency need review.

For docs-only PRs outside specs/, review whether the docs match code, examples, defaults, behavior, and validation instructions. Do not invent implementation findings when the diff only changes documentation.

Local Guidance

After applying the shared contract, read .github/skills/review-pr-repo/SKILL.md when it exists and apply any non-conflicting repository-specific guidance.

When spec_context.md exists, read .github/skills/check-impl-against-spec/SKILL.md and treat material spec drift as a review concern.

Always read .github/skills/security-review-pr/SKILL.md and apply it as a non-conflicting supplemental security pass on code and mixed PRs. Fold any security findings into the same review.json; do not emit a separate output.

Review Focus

Prioritize concrete findings:

  • correctness defects
  • security risks
  • exception and error handling gaps
  • performance risks
  • maintainability issues with clear impact
  • documentation changes that disagree with code, examples, defaults, or behavior
  • test changes that miss important assertions, over-mock behavior, or skip risky paths

Ignore pure style unless you can provide an exact GitHub suggestion. Put issues that cannot be attached to changed lines, such as missing tests or docs, in top-level body.

Show full SKILL.md (213 more words)Show less

Evidence Rules

Ground every finding in changed lines, nearby unchanged context from pr_diff.txt, spec_context.md, review_discussion_context.json, or repository files you actually inspected.

Do not request broad refactors or speculative changes unless the diff introduces a concrete risk. If the impact is uncertain, lower the severity or omit the finding.

If a concern involves untouched code or missing work that has no precise changed line target, mention it in top-level body instead of attaching it to an unrelated line.

Workflow

  1. Read .agents/contracts/review.md.
  2. Read pr_description.txt.
  3. Read spec_context.md when it exists.
  4. Read review_discussion_context.json when it exists and apply it only for duplicate suppression of prior bot review comments.
  5. Parse pr_diff.txt, build allowed changed-line targets, and collect changed file paths.
  6. Read .github/skills/review-pr-repo/SKILL.md if present and apply only non-conflicting local guidance.
  7. If spec_context.md exists, read .github/skills/check-impl-against-spec/SKILL.md and apply it as non-conflicting local guidance.
  8. Read .github/skills/security-review-pr/SKILL.md and apply it as a non-conflicting supplemental security pass.
  9. Inspect relevant repository files only when needed to understand changed code or verify a concrete risk.
  10. Write one combined review.json that includes base review findings and any supplemental security findings.
  11. Run python3 .github/skills/review-pr/scripts/validate_review_json.py pr_diff.txt review.json when running locally. In GitHub Actions, the workflow runs validation after Codex exits.
  12. Fix review.json until validation passes.

© Terry-Mao, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .github/skills/review-pr of Terry-Mao/AICodingFlow.

  • SKILL.md
  • scripts/validate_review_json.py

Open the folder on GitHubat commit 7703e16

Compare with similar skills

Review PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review PR this skillTerry-Mao/AICodingFlow167—~1kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from Terry-Mao/AICodingFlow

All 30 skills in this repo
  • PR Walkthrough

    Terry-Mao/AICodingFlow

    Generate a local static interactive D3 walkthrough of a pull request.

    167 GitHub stars~2.1k tokensUpdated 7 days ago
    Auto-check passed
  • Update PR Review

    Terry-Mao/AICodingFlow

    Improve repo-local PR review companion skills from human feedback on bot reviews.

    167 GitHub stars~1.1k tokensUpdated 7 days ago
    Auto-check passed
  • Implement Issue

    Terry-Mao/AICodingFlow

    Implement a GitHub issue in this repository by applying the local shared implement-specs workflow with repository-specific issue, spec-context, and summary-file handling.

    167 GitHub stars~2.3k tokensUpdated 7 days ago
    Auto-check passed
  • Implement Specs

    Terry-Mao/AICodingFlow

    Implement an approved feature from the repository's product and tech specs, keeping specs and code aligned in the same change as implementation evolves.

    167 GitHub stars~1.7k tokensUpdated 7 days ago
    Auto-check passed
  • Update Dedupe

    Terry-Mao/AICodingFlow

    Learn repo-local duplicate issue guidance from recent maintainer duplicate closures and propose updates to the dedupe companion skill.

    167 GitHub stars~1.1k tokensUpdated 7 days ago
    Auto-check passed
  • Update Triage

    Terry-Mao/AICodingFlow

    Learn repo-local issue triage guidance from recent maintainer triage corrections and propose updates to the triage companion skill or label config.

    167 GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Review PR

What does Review PR do?

Review a GitHub pull request from pinned prdescription.txt, prdiff.txt, and optional speccontext.md snapshots, then write and validate review.json. Review PR is an agent skill from Terry-Mao/AICodingFlow.json.

When should I use Review PR?

Review PR fits situations like: bot needs offline PR review comments without posting to GitHub; tasks that involve Pull requests.

How do I install Review PR in Claude Code?

Run `npx skills add Terry-Mao/AICodingFlow --skill review-pr -a claude-code`. Or copy the skill folder (.github/skills/review-pr in Terry-Mao/AICodingFlow) into .claude/skills/review-pr in your project. Claude Code loads it when a task matches its description.

How do I install Review PR in Codex?

Run `npx skills add Terry-Mao/AICodingFlow --skill review-pr -a codex`. Or copy the skill folder (.github/skills/review-pr in Terry-Mao/AICodingFlow) into .agents/skills/review-pr in your project. Codex loads it when a task matches its description.

Can I use Review PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Terry-Mao/AICodingFlow --skill review-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-pr, .gemini/skills/review-pr, .github/skills/review-pr and .opencode/skills/review-pr in your project.

What does Review PR need to run?

Going by SKILL.md and its folder, Review PR needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Review PR access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review PR safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Review PR use?

Review PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review PR use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review PR?

Skills that share tags, products or a category with Review PR: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review PR?

Terry-Mao (a GitHub user) maintains it in Terry-Mao/AICodingFlow, which has 167 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 3, 2026.

Source: Terry-Mao/AICodingFlow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.