Contributor-First PR Merge
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
Deep-dive review of any GitHub PR in tetherto/qvac. An agent skill from tetherto/qvac.
$ npx skills add tetherto/qvac --skill qv-pr-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tetherto/qvac qv-pr-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qv-pr-review .claude/skills/qv-pr-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .claude/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tetherto/qvac --skill qv-pr-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tetherto/qvac qv-pr-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/qv-pr-review .agents/skills/qv-pr-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .agents/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-pr-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tetherto/qvac qv-pr-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/qv-pr-review .cursor/skills/qv-pr-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .cursor/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tetherto/qvac.git --path .agents/skills/qv-pr-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tetherto/qvac --skill qv-pr-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tetherto/qvac qv-pr-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/qv-pr-review .gemini/skills/qv-pr-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .gemini/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tetherto/qvac qv-pr-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tetherto/qvac --skill qv-pr-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/qv-pr-review .github/skills/qv-pr-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .github/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-pr-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tetherto/qvac qv-pr-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/qv-pr-review .opencode/skills/qv-pr-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "qv-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-pr-review into .opencode/skills/qv-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-pr-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
qv-pr-reviewDeep-dive review of any GitHub PR in tetherto/qvac. An agent skill from tetherto/qvac.
Qv PR Review is an agent skill from tetherto/qvac. Deep-dive review of any GitHub PR in tetherto/qvac. Validates gitflow, CI, title/body format, code quality, security, and applicable repo rules. Posts a PENDING review with inline comments. Use when reviewing a PR, given a PR link, or invoking /qv-pr-review.
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/sdk-plugin-checklist.md`).
It sits in Development, covering Pull requests, Git workflow and Technical documentation. It works with GitHub. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 673ea94. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Qv PR Review loads about 6.3k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 2,972 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tetherto/qvac at commit 673ea94, republished under its Apache-2.0 licence (© tetherto). 2,972 words, ~6,302 tokens.
.claude/skills/qv-pr-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Manual-trigger PR review for any GitHub PR in the configured repository. Produces:
The user submits the pending review manually from the GitHub UI.
Use when:
/qv-pr-review/qv-sdk-pr-status, /qv-pr-mine, or another pod's status/my skillThe skill applies to any PR; scoped repository instructions and PR-template formats applicable to the touched paths are discovered dynamically (see step 4 / step 5).
https://github.com/tetherto/qvac/pull/1234)If PR URL is missing, ask for it. Nothing else to ask unless the user's seed notes are ambiguous.
Carefully check the changes, focusing on:
Style nits, doc polish, and unverified hunches are NOT the focus. Don't pad the review with them.
Use these tiers when assembling findings. Tiers drive what surfaces in the chat overview and what is proposed for inline comments. The user always has final say over what gets posted.
Selection rule: never silently include a Low finding in the inline payload. The user picks (see step 7b).
This skill is read-only with respect to the user's local working tree. The user may have uncommitted changes, be on a feature branch, or have pending work — never disturb it.
Forbidden commands (no matter the circumstance):
git switch, git checkout (any ref/file)git reset (any mode), git restoregit stash (push, pop, drop, anything)git pull, git merge, git rebase, git cherry-pickgit cleangh pr checkout/qv-pr-review runs by default in worktree mode (see step 0a). The dedicated cache directory at ~/.cache/qvac-pr-review/ is fully isolated from the user's working tree — it lives outside the repo entirely. Inside that cache directory only, the shared script (worktree-prepare.mjs) is allowed to:
git fetch <remote> "pull/<n>/head:refs/pr/<n>/head"git worktree add --detach <cache-path> refs/pr/<n>/headgit -C <cache-path> reset --hard refs/pr/<n>/head (when SHA drifted)git -C <cache-path> reset --hard HEAD (when the cached worktree is dirty at the same SHA)git -C <cache-path> clean -fdx (only after SHA drift, to evict stale untracked build/test artifacts)git worktree remove --force <cache-path> and git worktree prunegit -C <cache-path> rev-parse|log|show|diff|statusThese run from the script, not from the agent. The agent itself MUST NOT run any of the forbidden commands above — including inside the cache path. The agent only Reads/Greps/Globs source files in the cache path and never writes to them during /qv-pr-review.
The same cache path is also used by /qv-pr-test, so it may contain untracked build/test artifacts such as node_modules, dist, native build/ directories, or logs. Those artifacts are ignored by /qv-pr-review; the patch is computed from committed refs (<BASE_REF>...HEAD), not from the worktree's unstaged or untracked state.
If you need PR file contents:
<cache-path>/...). The path is at the PR head SHA.--no-worktree): gh api repos/{owner}/{repo}/contents/{path}?ref={sha} and write to /tmp/.Read repository instructions and conventions from the user's current workspace as-is — do not switch branches to "get the latest" version.
Every shell call costs a user approval. Keep the total small (~5-8 calls).
cat/head/tail, Grep instead of grep/rg, Glob instead of find, Write instead of echo > / heredoc.gh pr checkout. Use worktree mode (default, see step 0a) for full local context at the PR head SHA. The cache lives under ~/.cache/qvac-pr-review/ and never touches the user's working tree./tmp/pr-<num>.json and /tmp/pr-<num>.patch, reuse via Read/Grep. The worktree path is reused across step calls; don't re-prepare it.gh pr checks — statusCheckRollup in gh pr view --json already has every check.gh run view --log-failed --job <id> per failing job.file, od, wc -c, cat -A) unless a CI log explicitly names an encoding issue.Copy this checklist and track progress:
- [ ] 0a. Prepare worktree (default-on; skip if user passed --no-worktree)
- [ ] 1. Parse PR URL
- [ ] 2. Fetch PR data (2 shell calls)
- [ ] 3. Validate gitflow
- [ ] 4. Read applicable repository instructions for the touched paths
- [ ] 5. Validate PR title + body against the discovered format rules
- [ ] 6. Review: CI + general + security + rules — classify findings by severity
- [ ] 6b. Apply SDK plugin checklist (only if PR touches plugin paths)
- [ ] 7a. Print risk overview in chat (high + medium + material lows)
- [ ] 7b. Ask user which findings to include as inline comments (high+medium pre-selected, lows opt-in)
- [ ] 8. Assemble inline comments + write payload (only the user-confirmed set)
- [ ] 9. Pre-flight check (count, files, line numbers)
- [ ] 10. Show gh api command, wait for user confirmation
- [ ] 11. POST the PENDING review
- [ ] 12. Output link to pending reviewWorktree mode is the default — full local Read/Grep/Glob context at the PR head SHA, isolated under ~/.cache/qvac-pr-review/, never touches the user's working tree. The same script also fetches the PR's base ref and writes the canonical PR diff to /tmp/. Skip this step only if the user invoked /qv-pr-review URL --no-worktree.
node .agents/skills/_lib/pr-skills/worktree-prepare.mjs <PR-URL>Parse the script's output:
stdout on success has four lines:
WORKTREE_PATH=<absolute path>
HEAD_SHA=<sha>
PATCH_PATH=/tmp/pr-<num>.patch
BASE_REF=<remote>/<baseRefName>WORKTREE_PATH: the working root for files at the PR head SHA. Use this for all Read/Grep/Glob in steps 6 and 7a.PATCH_PATH: a unified diff computed locally with git diff <BASE_REF>...HEAD (3-dot). 3-dot semantics match GitHub's PR view exactly — only what the PR introduces, regardless of how far behind the base the PR is. Use this anywhere the workflow refers to the patch; do NOT use 2-dot.BASE_REF: the local tracking ref the diff was computed against (e.g. upstream/main). Useful if you need to re-run a custom diff inside the worktree.stderr on failure has a single line:
WORKTREE_FALLBACK=<one-line reason>The script's exit code is 0 even on failure. If you observe WORKTREE_FALLBACK, fall back to the API-only flow: fetch file contents via gh api repos/{owner}/{repo}/contents/{path}?ref={headRefOid} and the patch via gh pr diff <num> --patch > /tmp/pr-<num>.patch. Surface the fallback reason once in the chat overview's ### Verified (no action) section so the user knows local context is missing — e.g. "Worktree prep failed (<reason>); excerpts come from gh api."
When the user passes --no-worktree, skip this step entirely and use the API-only flow without surfacing any fallback note.
Extract owner, repo, pr_number from the URL. If ~/.config/qvac-pr-skills/config.json exists, verify the PR repo matches github.repo; otherwise use the repo in the provided PR URL.
gh pr view <num> --repo tetherto/qvac \
--json number,title,state,mergeable,baseRefName,headRefName,headRefOid,isCrossRepository,headRepositoryOwner,files,author,body,statusCheckRollup \
> /tmp/pr-<num>.jsonIn worktree mode (default), the patch is already at /tmp/pr-<num>.patch from step 0a — do NOT re-fetch it via gh pr diff.
In --no-worktree mode (or after a WORKTREE_FALLBACK), additionally:
gh pr diff <num> --repo tetherto/qvac --patch > /tmp/pr-<num>.patchEverything else comes from these files via Read/Grep. No additional shell calls for PR data.
Read baseRefName, headRefName, isCrossRepository, headRepositoryOwner from /tmp/pr-<num>.json. Full gitflow rules are in docs/gitflow.md.
Allowed directions (fork to upstream):
| Head (fork branch) | Base (upstream) | OK? |
|---|---|---|
| anything | main | yes |
| anything | release-<pkg>-<x.y.z> | yes (must bump version + changelog) |
| anything | feature-<pkg>-* / tmp-<pkg>-* | yes |
Blocker patterns:
release-* to main — WRONGmain to release-* — WRONGrelease-* to release-* — WRONGfeature-* / tmp-* to main — WRONGmain to feature-* / tmp-* — WRONGRelease-PR extra checks (base is release-<pkg>-<x.y.z>):
packages/<pkg>/package.json version must increase vs basepackages/<pkg>/CHANGELOG.md must be updatedUse file-reading tools, not shell commands, for instruction discovery:
AGENTS.md./tmp/pr-<num>.json (files[].path), read each nested AGENTS.md between the repository root and that path. The nearest file has the most specific guidance..github/teams/<pod>.json has ownedPaths matching the touched files, use that file for current pod scope and ownership rather than a copied package list.If scoped instructions or the applicable PR template define a format, validate the PR title and body against it. Common shape (used by the SDK pod and likely others):
Title (format: TICKET prefix[tag]: subject or prefix[notask]: subject):
feat fix doc test chore infra[api] [bc] [mod] [notask] [skiplog][api] required when diff adds new exports/public API surface[bc] required when diff removes/changes existing public API signatures[mod] required when model constants changeBody — use the matching .github/PULL_REQUEST_TEMPLATE/<template>.md if one is referenced by the loaded rule:
[bc] requires BEFORE/AFTER code blocks[api] requires usage example[mod] requires Added/Removed models listIf no format rule applies, skip this step. Title/body violations go in the chat overview only, not as inline PR comments.
Apply the review philosophy. Classify every finding as High, Medium, or Low. Skip any dimension with no findings.
package.json whose dependency specifiers changed, with no pnpm-lock.yaml in the same PR. CI installs frozen, so the stale lockfile aborts the install before the project matrix is built and blocks every open PR, not only this one. Check the package.json hunks for changed specifiers rather than assuming a manifest edit implies one; a scripts or files change needs no lockfile update (High)*Approval*/approval-worker). Name the failing job + actual error. For failing jobs only: gh run view --repo tetherto/qvac --log-failed --job <job_id> > /tmp/pr-<num>-<job_id>.log (High)packages/sdk / packages/cli / packages/sdk-python change with no docs/website/content/docs diff and no library-only note in the body — point at /qv-docs-update (Medium). Skip reference/**-only diffs: those are generated by the qv-sdk-changelog skill on releaseWhen verifying a suspected bug, attempt to construct a concrete reproduction (input → code path → observed behavior). If you cannot, classify it Medium at most and say so.
If the PR touches SDK plugin paths, also run the SDK plugin integration checklist. Trigger when any touched path (files[].path in /tmp/pr-<num>.json) matches:
packages/sdk/server/bare/plugins/**packages/sdk/client/api/**packages/sdk/schemas/plugin.ts or packages/sdk/schemas/load-model.tspackages/sdk/schemas/*-config.tspackages/sdk/schemas/completion-stream.ts or packages/sdk/schemas/batch-completion-stream.tspackages/sdk/server/worker.tspackages/sdk/commands/bundle/**If no path matches, skip this step entirely — no checklist output. When it triggers, read references/sdk-plugin-checklist.md and follow its "How to apply" and "Output integration" sections. Real blocking gaps are classified by severity here in step 6 and flow into the normal inline-comment selection (step 7b); the cross-cutting summary renders as the ### SDK plugin checklist block in the step 7a overview.
Print the overview below directly in chat. This is for the user — nothing is posted yet. After printing, pause for the selection step (7b). If the user pushes back on a finding, drop it before continuing.
Important: the user's local checkout may be on a different branch / different commit than the PR head. They cannot trust line numbers from their working tree. Every High/Medium finding MUST therefore include:
A short code excerpt fetched from the PR head SHA (already in /tmp/pr-<num>-<file>.ts from step 6 verification, or via gh api repos/{owner}/{repo}/contents/{path}?ref={headRefOid}). 3-8 lines of context max — just enough to make the bug visible without the user opening the PR.
A deep link to the PR file diff so the user can click straight to the right place on GitHub. GitHub PR file anchors use SHA256 of the file path (GitHub switched from MD5/SHA1 in 2022):
https://github.com/tetherto/qvac/pull/<num>/files#diff-<sha256(path)>R<line>
Where <sha256(path)> is sha256(<path>) (lowercase hex, no trailing newline). The R<line> suffix anchors the right (post-change) side at that line; use L<line> for the left side.
Compute it in shell:
printf '%s' 'packages/sdk/foo.ts' | shasum -a 256 | awk '{print $1}'Fallback when SHA256 isn't convenient: link to the blob at the head SHA — https://github.com/tetherto/qvac/blob/<headRefOid>/<path>#L<line> — also clickable and lands on the right line, but doesn't show the diff context. Prefer the diff anchor when you have it.
Do NOT use SHA1 of the path — that produces a hash GitHub no longer recognises and the anchor will silently fail to scroll.
Format:
## PR #<num> — review overview
<1-line summary of what this PR does>
### Gitflow / Title / CI
<one-line status, omit subsections that are clean>
### High-risk
<numbered list — empty list is fine, write "none" explicitly>
1. **<short title>** — [`<path>:<line>`](<deep link>)
<one-sentence explanation, with repro hint if relevant>
```ts
<3-8 line excerpt from the PR head>
```
### Medium-risk
<numbered list — empty list is fine, write "none" explicitly>
1. **<short title>** — [`<path>:<line>`](<deep link>)
<one-sentence explanation>
```ts
<3-8 line excerpt from the PR head>
```
### Low-risk (informational)
<numbered list — omit the section entirely if there are no material lows>
1. **<short title>** — [`<path>:<line>`](<deep link>)
<one-sentence note>
### Verified (no action)
<optional: short bullets for things you specifically checked and cleared, only if the reviewer might otherwise wonder>
### SDK plugin checklist
<only when step 6b triggered AND has gaps — omit entirely otherwise. Format per references/sdk-plugin-checklist.md "Output integration".>
---
PR diff: <https://github.com/tetherto/qvac/pull/<num>/files>Rules for what goes in each section:
The excerpts MUST come from files at the PR head SHA, never from the user's working tree.
<WORKTREE_PATH>/<path> (the worktree is checked out at the PR head SHA). Glob/Grep with the worktree path as the search root.--no-worktree: fetch with gh api repos/{owner}/{repo}/contents/{path}?ref=<headRefOid> (decode .content from base64) and Read from /tmp/.The excerpt's line numbers must match the line you're calling out.
Immediately after the overview, present a confirmation prompt. The defaults follow the severity tier rules (high+medium pre-selected, lows opt-in). The user can override any selection.
Use a structured multi-select question (one per finding) so the user clicks instead of typing. Format the prompt as:
For each finding, confirm whether it should be posted as an inline comment.
Defaults: High + Medium = include; Low = skip.Each finding becomes one option in a single multi-select question (id inline_picks, allow_multiple: true). Pre-select High + Medium by listing them as the recommended choices in the prompt text (the tool itself doesn't surface defaults, so spell them out: e.g. "Recommended: 1, 2, 3"). Lows are listed as additional options.
If the user is text-driven instead of clicking, accept replies like:
Echo back the final selected list before moving to step 8 so the user can object once more. Do NOT proceed to step 8 until you have an explicit confirmation. If the user picks "none", skip steps 8-12 and end the session.
blocker:, nit:, etc.) inside the comment body — severity is conveyed by which findings make it into the chat overview.Build the payload from the user-confirmed selection in step 7b only. Never include a finding the user did not opt into (especially Lows). If the confirmed set is empty, stop here — don't post an empty review.
Use the Write tool to create /tmp/pr-<num>-review.json:
{
"commit_id": "<headRefOid>",
"comments": [
{
"path": "packages/<pkg>/src/foo.ts",
"line": 42,
"body": "comment text"
}
]
}Omit the event field. The GitHub REST API only accepts APPROVE, REQUEST_CHANGES, or COMMENT; omitting it leaves the review in PENDING state, which is what this skill targets.
Line numbers must reference the post-PR file line numbers (the + side line numbers in the patch, mapped to the file at the PR head SHA). When in doubt, fetch the file at the head SHA via gh api repos/{owner}/{repo}/contents/{path}?ref={sha} and verify line numbers there before composing the payload.
Show the user:
Count of inline comments and which files they touch. Cross-reference against the user-confirmed selection from step 7b — counts MUST match exactly. If they don't, something was added or dropped silently; stop and reconcile before proceeding.
A rendered Markdown preview of every inline comment, one per file:line anchor. Reproduce the comment body verbatim as Markdown — do NOT show the raw JSON payload, do NOT escape newlines. The user reads the preview to decide whether to approve posting; raw JSON is unreadable. Format:
### Preview — comment <n> of <total>
**File**: `<path>:<line>`
---
<verbatim comment body, rendered as Markdown>
---If the comment body contains fenced code blocks, render them as fenced code blocks in the preview (not as escaped strings).
Show the exact gh api command but do NOT run it until the user says to proceed:
gh api repos/tetherto/qvac/pulls/<num>/reviews \
--method POST \
--input /tmp/pr-<num>-review.jsonRun the command. If it fails, show the error and the JSON payload for debugging.
https://github.com/tetherto/qvac/pull/<num>#pullrequestreview-<review_id>references/sdk-plugin-checklist.mdpackages/sdk/AGENTS.md.github/teams/<pod>.jsonAGENTS.md files.github/PULL_REQUEST_TEMPLATE/docs/gitflow.md© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .agents/skills/qv-pr-review of tetherto/qvac.
Open the folder on GitHubat commit 673ea94
Qv PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Qv PR Review this skilltetherto/qvac | 685 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | |
| Contributor-First PR MergeHKUDS/OpenHarness | 16k | 1 repos | ~847 | Automated safety check: Pass | MIT | |
| Create Pull Requestcline/cline | 70k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Create Pull Request with Work Item IDmakeplane/plane | 61k | — | ~824 | Automated safety check: Pass | AGPL-3.0 | |
| Creating Description For Gh PRredis/jedis | 12k | — | ~838 | Automated safety check: Pass | MIT | |
| Pascal Editor PR Openerpascalorg/editor | 25k | — | ~619 | Automated safety check: Pass | MIT |
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
cline/cline
Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.
makeplane/plane
Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.
redis/jedis
Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.
pascalorg/editor
Opens or refreshes a pull request on pascalorg/editor from the current branch, describing only what the branch's commits and diff actually contain.
remix-run/react-router
Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.
tetherto/qvac
Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.
tetherto/qvac
Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.
tetherto/qvac
Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.
tetherto/qvac
Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…
tetherto/qvac
Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).
tetherto/qvac
Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.
Works with
Categories
Deep-dive review of any GitHub PR in tetherto/qvac. An agent skill from tetherto/qvac. Qv PR Review is an agent skill from tetherto/qvac. Deep-dive review of any GitHub PR in tetherto/qvac.
Qv PR Review fits situations like: given a PR link; invoking /qv-pr-review.
Run `npx skills add tetherto/qvac --skill qv-pr-review -a claude-code`. Or copy the skill folder (.agents/skills/qv-pr-review in tetherto/qvac) into .claude/skills/qv-pr-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tetherto/qvac --skill qv-pr-review -a codex`. Or copy the skill folder (.agents/skills/qv-pr-review in tetherto/qvac) into .agents/skills/qv-pr-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill qv-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qv-pr-review, .gemini/skills/qv-pr-review, .github/skills/qv-pr-review and .opencode/skills/qv-pr-review in your project.
Going by SKILL.md and its folder, Qv PR Review needs the command-line tools its instructions call (git, gh and node).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Qv PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Qv PR Review: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Create Pull Request with Work Item ID (makeplane/plane, 61k stars) and Creating Description For Gh PR (redis/jedis, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 685 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 10, 2026.
Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.