Agent skill

Review

by webern in webern/cargo-readme

Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

Apache-2.0Auto-check: notesTesting & QA

Install Review

skills CLI
$ npx skills add webern/cargo-readme --skill review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install webern/cargo-readme review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/webern/cargo-readme.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review .claude/skills/review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review
GitHub stars
385
Token cost
~2k tokens
SKILL.md length
947 words
Files
5
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

  • Works in 6 steps: Clone into a Temp Directory → Gather PR Context → Check Out the PR and Rebase → …
  • Tasks that involve Failing and flaky tests
  • SKILL.md covers Your Role as the Filter, Step 1: Clone into a Temp…, Step 2: Gather PR Context and Step 3: Check Out the PR and…, plus 4 more sections
  • Calls gh and git

What it does

Review is an agent skill from webern/cargo-readme. Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage. Fetches PR data, checks out the branch, diagnoses CI failures, and walks the maintainer through the review interactively.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `architect-agent.md`, `conservative-agent.md` and `security-agent.md`).

It sits in Testing & QA, covering Failing and flaky tests, Test coverage and Technical documentation. It works with GitHub and Rust. The repository describes itself as: Generate README.md from docstrings. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Failing and flaky tests
  • Tasks that involve Test coverage
  • Tasks that involve Technical documentation

Example prompts

  • “Use the review skill to review a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage”
  • “/review”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Agent, Edit, Write, LSP, WebFetch, WebSearch, TaskCreate, TaskUpdate, TaskList, NotebookEdit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Clone into a Temp Directory
  2. Gather PR Context
  3. Check Out the PR and Rebase
  4. Run Sub-agent Reviews
  5. Present the Review
  6. Interactive Loop

What it can do on your machine

Read from SKILL.md and the folder at commit d76a96d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Agent
    • Edit
    • Write
    • LSP
    • WebFetch
    • WebSearch

    …and 4 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review loads about 2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 947 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Agent, Edit, Write, LSP, WebFetch, WebSearch, TaskCreate, TaskUpdate, TaskLi

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from webern/cargo-readme at commit d76a96d, republished under its Apache-2.0 licence (© webern). 947 words, ~1,962 tokens.

Download SKILL.mdSave it as .claude/skills/review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
review
description
Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage. Fetches PR data, checks out the branch, diagnoses CI failures, and walks the maintainer through the review interactively.
allowed-tools
Bash, Read, Grep, Glob, Agent, Edit, Write, LSP, WebFetch, WebSearch, TaskCreate, TaskUpdate, TaskList, NotebookEdit
argument-hint
<pr-number>
disable-model-invocation
true
effort
high

Review PR #$0

You are a code review assistant for a maintainer who inherited this codebase and does not know it deeply. Your job is to help them make fast, confident merge/reject decisions. Be direct and blunt with the maintainer. Do not sugarcoat findings.

Read AGENTS.md at the repo root before starting — it contains the architectural rules and policies for this project.

Your Role as the Filter

You will run four specialized sub-agents that are deliberately picky — designed to over-flag. Your job is to be the experienced, level-headed reviewer who filters their output:

  • If a finding is technically correct but practically irrelevant for a project of this size, drop it or downgrade it to a note.
  • If multiple agents flagged the same thing from different angles, consolidate into one finding.
  • If a finding is speculative ("this could be a problem if..."), either drop it or clearly label it as speculative.
  • Think about whether a real senior maintainer would actually care. If probably not, leave it out.
  • Pedantic nits that don't affect correctness, safety, or users should be dropped entirely.

The goal is a tight, useful review — not a laundry list. Fewer high-quality findings are far more valuable than many marginal ones.

Step 1: Clone into a Temp Directory

Clone the repo into a temporary directory so the review is fully isolated from the user's working tree. This allows reviews to run in parallel with other work.

bash
REVIEW_DIR=$(mktemp -d)
gh repo clone . "$REVIEW_DIR" -- --quiet
cd "$REVIEW_DIR"

All subsequent steps run inside $REVIEW_DIR. The user's working tree is never touched.

Step 2: Gather PR Context

Fetch PR metadata, diff, comments, review threads, and CI status using gh. Derive {owner}/{repo} dynamically:

bash
gh repo view --json nameWithOwner --jq .nameWithOwner

Check if the user has a pending review:

bash
gh api repos/{owner}/{repo}/pulls/$0/reviews --jq '.[] | select(.state == "PENDING")'
CI failure diagnosis

If any CI checks have failed, dig into the logs:

bash
gh run list --commit <head-sha> --json databaseId,name,status,conclusion
gh run view <run-id> --log-failed

Read the failed logs and diagnose the root cause. Report this to the user as part of your review.

Step 3: Check Out the PR and Rebase

bash
gh pr checkout $0

After checkout, check if the branch is behind main or has merge conflicts:

bash
git merge-base --is-ancestor main HEAD || echo "Branch is behind main"
git merge --no-commit --no-ff main 2>&1 | head -5; git merge --abort 2>/dev/null

If the branch needs a rebase, tell the user and offer to rebase onto main. Explain that conflicts will be resolved favoring our more recent main edits (-X ours). Wait for the user to agree before proceeding.

If the user agrees:

bash
git rebase main -X ours

If the rebase produces results the user should see, show them. If the user declines, continue the review on the branch as-is.

Step 4: Run Sub-agent Reviews

Spin up four specialized review agents in parallel using the Agent tool. For each agent, read its instruction file from ${CLAUDE_SKILL_DIR} and include those instructions in the agent prompt along with the full PR diff, title/description, and changed file list.

  1. Architect agent — architect-agent.md
  2. Conservative agent — conservative-agent.md
  3. Security agent — security-agent.md
  4. Testing agent — testing-agent.md

Step 5: Present the Review

Synthesize all findings into a single, unified review. Do not present findings as separate agent sections — weave them together into a coherent narrative organized by severity and topic.

Structure
  1. One-line verdict: MERGE / NEEDS WORK / REJECT
  2. PR summary: What this PR does in 2-3 sentences.
  3. CI status: Pass/fail. If failed, what broke and why.
  4. Findings: Organized by severity (blocking → warnings → notes). Each finding includes:
    • What the issue is (specific file and line)
    • Why it matters
    • What should be done about it
  5. Missing tests: Specific test cases that should exist but don't.
  6. Final recommendation: Your honest, blunt assessment.
Show full SKILL.md (400 more words)Show less
Severity levels
  • Blocking — Must be fixed before merge. Bugs, security issues, architectural violations, breaking changes.
  • Warning — Should be fixed, but could be merged with a follow-up issue.
  • Note — FYI for the maintainer. No action required.
False positive filtering

Before including any finding, verify it by reading the actual code. Do not report issues based on assumptions. If you are not confident a finding is real, do not include it.

Do not comment on things that are fine. Do not pad the review with praise or filler.

Step 6: Interactive Loop

After presenting the review, enter an interactive loop. The user may:

Post comments to the PR

When the user asks you to post comments:

  • If no pending review exists, create one:
    bash
    gh api repos/{owner}/{repo}/pulls/$0/reviews -f event=PENDING -f body=""
  • Add comments to the pending review using the GitHub API. For inline comments, use the pull request review comment API.
  • Tone: Be friendly, grateful, and constructive to contributors. Frame change requests as suggestions. Example: "Thanks for this! One thing I noticed — would it make sense to..." not "This is wrong. Fix it."
  • Use GitHub's suggestion syntax for specific code changes:
    ```suggestion
    the exact replacement code here
    ```
Submit the review

When the user wants to submit:

bash
# Comment only
gh api repos/{owner}/{repo}/pulls/$0/reviews/<review-id> -X PUT -f event=COMMENT -f body="<summary>"

# Approve
gh api repos/{owner}/{repo}/pulls/$0/reviews/<review-id> -X PUT -f event=APPROVE -f body="<summary>"

# Request changes
gh api repos/{owner}/{repo}/pulls/$0/reviews/<review-id> -X PUT -f event=REQUEST_CHANGES -f body="<summary>"

Only submit when the user explicitly asks.

Push fix commits

When the user asks you to fix something directly:

  1. Confirm with the user exactly what you will change before making any edits.
  2. Make the fix on the checked-out PR branch.
  3. Commit and push only after explicit user approval.
Create follow-up issues

When the user wants to merge but track remaining work:

bash
gh issue create --title "<title>" --body "<body>"

Only create issues when the user explicitly asks. Link them to the PR in the issue body.

Investigate further

The user may ask you to dig deeper into specific findings. Use sub-agents to fan out research: read more code, check git blame, run tests, etc.

Rules

  • NEVER post comments, submit reviews, push commits, or create issues without explicit user approval. The user must ask you to do each of these things.
  • NEVER approve or reject a PR on your own. Only the user decides.
  • Be blunt with the maintainer. Be kind to contributors. All external-facing communication is warm, grateful, and constructive.
  • No AI identifiers. Nothing in comments, commits, or issues should reveal AI involvement.
  • Verify before reporting. Read the actual code before flagging an issue.
  • Derive repo info dynamically. Never hardcode owner/repo.

© webern, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in .claude/skills/review of webern/cargo-readme.

  • SKILL.md
  • architect-agent.md
  • conservative-agent.md
  • security-agent.md
  • testing-agent.md

Open the folder on GitHubat commit d76a96d

Compare with similar skills

Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review this skillwebern/cargo-readme385—~2kAutomated safety check: NotesApache-2.0
GreptimeDB Fuzz CI Failure InvestigationGreptimeTeam/greptimedb6.7k—~4.4kAutomated safety check: PassApache-2.0
Reviewapollographql/apollo-mcp-server311—~2.9kAutomated safety check: PassMIT
Unblock PRdatadog-labs/agent-skills177—~2.7kAutomated safety check: PassMIT
Audit Prep Assistanttrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0
Apple Container Test RunnerRustPython/RustPython22k—~467Automated safety check: PassMIT

Similar skills

  • Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code.

    6.7k GitHub stars~4.4k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Review

    apollographql/apollo-mcp-server

    Review a GitHub pull request for a Rust codebase. An agent skill from apollographql/apollo-mcp-server.

    311 GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Unblock PR

    datadog-labs/agent-skills

    Load when investigating a failing PR CI pipeline or checking PR health.

    177 GitHub stars~2.7k tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Audit Prep Assistant

    trailofbits/skills

    Official

    Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Apple Container Test Runner

    RustPython/RustPython

    Runs RustPython tests inside a Linux container built with Apple's container CLI, so macOS users can compare Linux results with their local ones.

    22k GitHub stars~467 tokensUpdated today
    Testing & QAAuto-check passed
  • Plans the smallest check that could disprove a code change in the OpenLogi project, then escalates through reproduction, focused tests and a final gate before a push.

    23k GitHub stars~1.4k tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from webern/cargo-readme

  • Update Deps

    webern/cargo-readme

    Update cargo dependencies to their latest major versions one at a time, verifying each with check/build/test and committing individually.

    385 GitHub stars~661 tokensUpdated 11 days ago
    Auto-check passed

Works with

Questions about Review

What does Review do?

Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage. Review is an agent skill from webern/cargo-readme. Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

When should I use Review?

Review fits situations like: tasks that involve Failing and flaky tests; tasks that involve Test coverage; tasks that involve Technical documentation.

How do I install Review in Claude Code?

Run `npx skills add webern/cargo-readme --skill review -a claude-code`. Or copy the skill folder (.claude/skills/review in webern/cargo-readme) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.

How do I install Review in Codex?

Run `npx skills add webern/cargo-readme --skill review -a codex`. Or copy the skill folder (.claude/skills/review in webern/cargo-readme) into .agents/skills/review in your project. Codex loads it when a task matches its description.

Can I use Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add webern/cargo-readme --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.

What does Review need to run?

Going by SKILL.md and its folder, Review needs the command-line tools its instructions call (gh and git). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Agent, Edit, Write, LSP, WebFetch, WebSearch, TaskCreate, TaskUpdate, TaskList, NotebookEdit.

Does Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Review use?

Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review?

Skills that share tags, products or a category with Review: GreptimeDB Fuzz CI Failure Investigation (GreptimeTeam/greptimedb, 6.7k stars), Review (apollographql/apollo-mcp-server, 311 stars), Unblock PR (datadog-labs/agent-skills, 177 stars) and Audit Prep Assistant (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review?

webern (a GitHub user) maintains it in webern/cargo-readme, which has 385 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 26, 2026.

Source: webern/cargo-readme on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.