Agent skill

Qv Devops PR Review

by tetherto in tetherto/qvac

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

Apache-2.0Auto-check passedDevelopment

Install Qv Devops PR Review

skills CLI
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tetherto/qvac qv-devops-pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .claude/skills/qv-devops-pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qv-devops-pr-review
GitHub stars
681
Token cost
~2.5k tokens
SKILL.md length
963 words
Files
2
Skills in repo
50
Repo updated
First seen
Licence
Apache-2.0

At a glance

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

  • Works in 5 steps: Run the generic /qv-pr-review flow up to… → Run the DevOps GitHub Actions security… → Re-print the consolidated chat overview → …
  • Reviewing a PR that touches DevOps paths
  • SKILL.md covers When to use this skill, Inputs, Safety rules and Efficiency rules, plus 2 more sections
  • Calls git, gh and bash

What it does

Qv Devops PR Review is an agent skill from tetherto/qvac. PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Use when reviewing a PR that touches DevOps paths or invoking /qv-devops-pr-review.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Pull requests, Security review and CI/CD. It works with GitHub Actions, Git and GitHub. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.

When your agent uses it

  • Reviewing a PR that touches DevOps paths
  • Invoking /qv-devops-pr-review

Example prompts

  • “/qv-devops-pr-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Run the generic /qv-pr-review flow up to step 7a (overview)
  2. Run the DevOps GitHub Actions security audit
  3. Re-print the consolidated chat overview
  4. Run /qv-pr-review steps 7b → 12
  5. Audit summary in chat (after posting)

What it can do on your machine

Read from SKILL.md and the folder at commit c3a6030. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Qv Devops PR Review loads about 2.5k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 963 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tetherto/qvac at commit c3a6030, republished under its Apache-2.0 licence (© tetherto). 963 words, ~2,511 tokens.

Download SKILL.mdSave it as .claude/skills/qv-devops-pr-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
qv-devops-pr-review
description
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Use when reviewing a PR that touches DevOps paths or invoking /qv-devops-pr-review.
disable-model-invocation
true

DevOps PR Review

A DevOps-flavored PR review on top of the generic /qv-pr-review flow. Adds a deterministic GitHub Actions security audit pass grounded in the repository's GitHub and CI guidance and the checklist below, so DevOps reviewers always see the same high-risk patterns regardless of the prose style of the diff.

The skill is a wrapper, not a fork — the bulk of the review (gitflow, CI, title/body, generic correctness, security) is done by /qv-pr-review. This skill layers DevOps-specific findings into the same pending review payload.

When to use this skill

Use when:

  • User asks to review a PR whose changes are dominated by DevOps-owned paths (.github/workflows/, .github/actions/, .github/scripts/, scripts/, IaC under terraform/, ansible/, k8s/, Dockerfile*, .github/CODEOWNERS, .github/dependabot.yml)
  • User invokes /qv-devops-pr-review with a PR URL
  • Triggered as a follow-up from /qv-devops-pr-status after the user picks a PR

If the PR's touched paths are dominated by a different pod, fall back to /qv-pr-review. The generic flow already auto-loads the relevant pod's rules.

Inputs

  • Required: PR URL (https://github.com/tetherto/qvac/pull/<num>)
  • Optional: user-provided focus notes

If the URL is missing, ask for it. Nothing else to ask up-front.

Safety rules

Inherits all safety rules from /qv-pr-review verbatim:

  • Read-only with respect to the user's local working tree. No git switch, git checkout, git reset, git restore, git stash, git pull, git merge, git rebase, git cherry-pick, git clean, gh pr checkout, or any write inside the user's working tree.
  • All file inspection happens in the worktree cache at ~/.cache/qvac-pr-review/pr-<num>/ (managed by worktree-prepare.mjs) or via gh api .../contents/<path>?ref=<sha> to /tmp/.

Efficiency rules

Inherits the ~5–8 shell-call budget from /qv-pr-review. The DevOps audit pass adds at most 3 additional reads (Read/Grep/Glob, not shell) per touched workflow/action file. Cache: reuse /tmp/pr-<num>.json, /tmp/pr-<num>.patch, and the worktree path from the underlying /qv-pr-review run.

Workflow

1. Run the generic /qv-pr-review flow up to step 7a (overview)

Read .agents/skills/qv-pr-review/SKILL.md and follow steps 0a → 7a inclusive:

  • 0a. Prepare worktree (worktree-prepare.mjs)
    1. Parse PR URL
    1. Fetch PR metadata
    1. Gitflow validation
    1. Read the applicable scoped instructions. DevOps paths use .github/AGENTS.md and its linked source documents. The PR-format spec lives in the devops-pr-create skill and is invoked explicitly.
    1. Validate PR title + body against the format spec inlined below (DevOps allowed prefixes: infra/feat/fix/chore/doc/test; tags: [bc]/[notask]/[skiplog]; title regex: ^([A-Z]+-\d+ )?(infra|feat|fix|chore|doc|test)(\[(bc|notask|skiplog)\])?: \S.+$)
    1. Review dimensions
  • 7a. Print risk overview in chat — but do not yet run step 7b (the inline-comment selection prompt). The DevOps audit pass in step 2 below contributes additional findings.
2. Run the DevOps GitHub Actions security audit

For every .github/workflows/*.yml and .github/actions/**/action.yml in the patch, perform the checks below using Read/Grep/Glob against the worktree path. Each check that fires becomes a finding with a tier per the table.

#CheckBasisFinding tier
A1Every uses: <vendor>/<action>@<ref> is pinned to a 40-char SHA (regex @[0-9a-f]{40}\b) with a trailing # v<ver> comment. Tag pins (@v3, @main, branch refs) fail. First-party ./.github/actions/<name> references are exempt..github/AGENTS.mdHigh
A2Permissions are declared explicitly — either a top-level permissions: block, OR every job has its own permissions: block. Relying on repo-default permissions fails..github/AGENTS.mdHigh
A3No occurrence of permissions: write-all anywhere in the workflow..github/AGENTS.mdHigh
A4If the workflow uses pull_request_target, none of its jobs check out PR HEAD via actions/checkout@... ref: ${{ github.event.pull_request.head.sha }} or ${{ github.head_ref }}..github/AGENTS.mdHigh
A5No direct interpolation of ${{ github.event.pull_request.title }}, body, head_ref, commits[*].message, or any github.event.* user-controlled field inside run: blocks. They MUST be piped via env:..github/AGENTS.mdHigh
A6If the workflow has id-token: write, OIDC is consumed by an auth action (google-github-actions/auth, aws-actions/configure-aws-credentials, azure/login) — not used for token forging that reaches a long-lived credential..github/AGENTS.mdMedium
A7No ${{ secrets.X }} interpolated directly inside a run: block. Pass via env: or action with: instead..github/AGENTS.mdHigh
A8No set -x / bash -x in steps that touch secrets; no printenv, env, cat, or echo of a secret value, even for "debugging"..github/AGENTS.mdHigh
A9Concurrency block is declared. Release/state-mutating workflows have cancel-in-progress: false.Current workflow conventionsMedium
A10Every job has timeout-minutes. Default budget 30; >30 needs a justifying comment.Current workflow conventionsLow
A11continue-on-error: true is NOT set on Tier-1 checks (lint, format, type-check, security scans, tests).docs/devops/TIER-1-SCOPE.mdMedium
A12Outputs use $GITHUB_OUTPUT, never the deprecated ::set-output::.Current workflow conventionsLow
A13When actions/cache is used, cache writes are gated on non-fork triggers (push / workflow_dispatch / merge_group) — not blanket on pull_request..github/AGENTS.mdMedium
A14Workflow filename matches the existing repo conventions (on-pr-*.yml, on-merge-*.yml, on-pr-close-*.yml, release-*.yml, create-github-release-*.yml, prebuilds-*.yml, pr-test-*.yml, pr-validation-*.yml, pr-checks-*.yml, integration-*-*.yml, reusable-*.yml, trigger-reusable-*.yml). New file with a divergent name → finding. Pre-existing files keep their name unless the PR renames them.Active workflow namesLow
Show full SKILL.md (204 more words)Show less

For each finding, capture: file, line, the offending excerpt (3-8 lines), the tier, and a one-line "why" pulled from the rule. Write findings into the same chat overview structure that /qv-pr-review step 7a uses, under a new sub-heading ### GHA security audit.

3. Re-print the consolidated chat overview

After both passes, re-print the full overview (gitflow / CI / generic-high / generic-medium / GHA-audit / lows / verified) so the user sees one ranked list. Findings retain the deep-link + excerpt rules from /qv-pr-review step 7a.

4. Run /qv-pr-review steps 7b → 12

Continue with the generic flow:

  • 7b. Selection prompt — the multi-select includes BOTH generic findings and GHA-audit findings. Defaults: every High pre-selected (including all GHA-audit Highs); Medium pre-selected; Low opt-in.
    1. Assemble inline comments from the user-confirmed set
    1. Pre-flight check
    1. Show the gh api ... pulls/<num>/reviews command, wait for confirmation
    1. Post on confirmation
    1. Output the link to the pending review
5. Audit summary in chat (after posting)

After the pending review URL is printed, append a single-line audit summary:

GHA audit: <H high> / <M medium> / <L low> findings on N workflow files. <K> filed inline; <skipped> skipped per user.

This makes audit coverage observable without reading the inline payload.

Inline comment style for GHA-audit findings

Inherit the comment style from /qv-pr-review. Add one DevOps-specific convention: every GHA-audit finding's body MUST cite the rule it traces back to, e.g.:

markdown
Untrusted input piped directly into shell. Per `.github/AGENTS.md`,
this MUST go through an `env:` block — `${{ github.event.pull_request.title }}` lands in the rendered shell verbatim and is exploitable.

```yaml
env:
  PR_TITLE: ${{ github.event.pull_request.title }}
run: |
  echo "$PR_TITLE"

The cite makes the audit finding auditable: the reviewer can verify the rule still says what the comment claims.

## Quality Checklist

Before posting the pending review, verify:

- [ ] Underlying `/qv-pr-review` workflow ran through step 7a successfully (worktree prepared, gitflow checked, CI checked, scoped instructions loaded, title/body validated)
- [ ] GHA-audit pass ran on every changed `.github/workflows/*.yml` and `.github/actions/**/action.yml`
- [ ] Each GHA-audit finding has: file path, post-change line, 3-8 line excerpt at PR head SHA, deep link, tier, and source citation
- [ ] User-confirmed selection from step 7b matches the assembled payload exactly (count + IDs)
- [ ] Audit summary line is printed after step 12

## References

- Generic PR review skill (parent flow): [.agents/skills/qv-pr-review/SKILL.md](../qv-pr-review/SKILL.md)
- GitHub Actions and secrets guidance: [.github/AGENTS.md](../../../.github/AGENTS.md)
- DevOps PR-create skill (canonical home for commit / PR-title format): [`devops-pr-create`](../qv-devops-pr-create/SKILL.md)
- Pod metadata: [.github/teams/devops.json](../../../.github/teams/devops.json)
- Worktree manager: [.agents/skills/_lib/pr-skills/worktree-prepare.mjs](../_lib/pr-skills/worktree-prepare.mjs)

© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/qv-devops-pr-review of tetherto/qvac.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit c3a6030

Compare with similar skills

Qv Devops PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Qv Devops PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Qv Devops PR Review this skilltetherto/qvac681—~2.5kAutomated safety check: PassApache-2.0
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
PR Createposit-dev/skills531—~4.3kAutomated safety check: WarnMIT
ReviewdogAgentSecOps/SecOpsAgentKit2201 repos~3kAutomated safety check: PassCustom licence
Ghbubbuild/bub1.7k—~798Automated safety check: PassApache-2.0
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT

Similar skills

  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • PR Create

    posit-dev/skills

    Creates a pull request from current changes, monitors GitHub CI, and debugs any failures until CI passes.

    531 GitHub stars~4.3k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    220 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Gh

    bubbuild/bub

    GitHub CLI skill for interacting with GitHub via the gh command line tool.

    1.7k GitHub stars~798 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed

More from tetherto/qvac

All 50 skills in this repo
  • Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.

    681 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Qv Docs Update

    tetherto/qvac

    Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.

    681 GitHub stars~11k tokensUpdated yesterday
    Auto-check passed
  • Qv Agent Stack Sync

    tetherto/qvac

    Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.

    681 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…

    681 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).

    681 GitHub stars~702 tokensUpdated yesterday
    Auto-check passed
  • Qv Addon Changelog

    tetherto/qvac

    Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.

    681 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Questions about Qv Devops PR Review

What does Qv Devops PR Review do?

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Qv Devops PR Review is an agent skill from tetherto/qvac. PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

When should I use Qv Devops PR Review?

Qv Devops PR Review fits situations like: reviewing a PR that touches DevOps paths; invoking /qv-devops-pr-review.

How do I install Qv Devops PR Review in Claude Code?

Run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a claude-code`. Or copy the skill folder (.agents/skills/qv-devops-pr-review in tetherto/qvac) into .claude/skills/qv-devops-pr-review in your project. Claude Code loads it when a task matches its description.

How do I install Qv Devops PR Review in Codex?

Run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a codex`. Or copy the skill folder (.agents/skills/qv-devops-pr-review in tetherto/qvac) into .agents/skills/qv-devops-pr-review in your project. Codex loads it when a task matches its description.

Can I use Qv Devops PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qv-devops-pr-review, .gemini/skills/qv-devops-pr-review, .github/skills/qv-devops-pr-review and .opencode/skills/qv-devops-pr-review in your project.

What does Qv Devops PR Review need to run?

Going by SKILL.md and its folder, Qv Devops PR Review needs the command-line tools its instructions call (git, gh and bash).

Does Qv Devops PR Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Qv Devops PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Qv Devops PR Review use?

Qv Devops PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Qv Devops PR Review use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Qv Devops PR Review?

Skills that share tags, products or a category with Qv Devops PR Review: GitHub Actions Hardening (github/awesome-copilot, 40k stars), PR Create (posit-dev/skills, 531 stars), Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars) and Gh (bubbuild/bub, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Qv Devops PR Review?

tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 681 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 7, 2026.

Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.