GitHub Workflow Automation
FNOSP/FlyNarwhal
Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.
Code review of a pull request, branch, or diff. An agent skill from werf/werf.
$ npx skills add werf/werf --skill review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install werf/werf review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review .claude/skills/review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .claude/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/werf/werf/tree/main/.agents/skills/reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add werf/werf --skill review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install werf/werf review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/review .agents/skills/review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .agents/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add werf/werf --skill review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install werf/werf review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/review .cursor/skills/review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .cursor/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/werf/werf.git --path .agents/skills/review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add werf/werf --skill review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install werf/werf review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/review .gemini/skills/review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .gemini/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install werf/werf reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add werf/werf --skill review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/review .github/skills/review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .github/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add werf/werf --skill review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install werf/werf review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/werf/werf.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/review .opencode/skills/review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review" agent skill from https://github.com/werf/werf/tree/main/.agents/skills/review into .opencode/skills/review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewCode review of a pull request, branch, or diff. An agent skill from werf/werf.
Review is an agent skill from werf/werf. Code review of a pull request, branch, or diff. Covers technical, product, and risk perspectives in one pass and produces a consolidated report. Use when asked to review a PR, branch, or code changes.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Pull requests, CI/CD and Code review. It works with Docker and Git. The repository describes itself as: A solution for implementing efficient and consistent software delivery to Kubernetes facilitating best practices. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fa73c7a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review loads about 2k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,052 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from werf/werf at commit fa73c7a, republished under its Apache-2.0 licence (© werf). 1,052 words, ~2,045 tokens.
.claude/skills/review/SKILL.md (or your agent's skills folder).Evidence-based and blunt. Every finding references a specific file:line, function, or component. NEVER sugarcoat, NEVER pad with praise, NEVER report a concern that is not grounded in the diff or the codebase. Style preferences are not defects — but a violation of AGENTS.md or CODESTYLE.md is a convention finding, not a preference.
If you wrote the diff you are reviewing now, say so explicitly in the report's Verdict and treat this pass as necessary but insufficient. challenge-review/SKILL.md covers why self-review inherits your own design assumptions and what to recommend instead — read it, don't re-derive it here.
(inferred), and proceed — do not stall, and do not invent criteria silently.git fetch, then diff against the branch the PR actually targets. werf maintains release branches (1.2, 2.63, 3, …), so main is the wrong base for a backport. State the resolved base in the report. For uncommitted work, review git diff / git diff --cached instead.file:line from that commit's blob (git show <head>:<path>), never from the worktree. The worktree sits on the base, so any file the PR itself changed has different line numbers there, and a comment anchored on a worktree line number lands on the wrong line — or is rejected outright.task works, run task build and task test:unit — a review that never compiled the change is an opinion. NEVER run task format: it would rewrite the diff under review.Code structure and correctness only — user impact belongs to the product perspective.
AGENTS.md and CODESTYLE.md are the standard. This project prefers a bit of duplication over abstraction and minimizes interfaces and generics — flag deviations in either direction, and NEVER report duplication as a DRY defect on its own.Cover the ones the diff actually touches; stay silent about the rest.
Passing tests, high coverage, and the author's confidence are not evidence of correctness, whoever wrote the diff. Read test-the-tests/SKILL.md and run its mutation loop against every load-bearing test: mutate the implementation and confirm the test fails, rather than reading the assertions and trusting they'd catch a regression. This is not optional — skipping it because the tests "look thorough" is exactly the failure mode it exists to catch.
For a non-trivial or high-risk diff, or a diff that touches tests or verification infrastructure, also read challenge-review/SKILL.md as an independent challenge pass. It covers check-gaming detection (weakened assertions, quietly skipped tests, mocked-out critical behavior, and more) in one place, so this list doesn't drift from it again.
What the change does for the user — not how the code is written.
WERF_* env counterpart, a renamed or removed flag needs a deprecation path, and exit codes plus machine-readable output (--build-report-path, --save-deploy-report) are parsed by users' CI — changing that schema is a breaking change.task doc:gen, never a hand edit, and a hand-edited CHANGELOG.md is itself a defect (release-please owns it). Feature docs under pages_en need their pages_ru counterpart.Derive risks from the technical and product findings plus the diff — including compound ones, where a technical flaw produces a product gap or an operational hazard. Likelihood is Likely/Possible/Unlikely, severity is Critical/High/Medium/Low; be realistic, do not inflate. Every risk needs a concrete location.
Classify each risk as Technical, Security, UX/Product, or Operational, and report risks only when they exist — an empty matrix is noise. A go.mod bump of nelm, kubedog, or common-go carries the widest blast radius here: it silently changes deploy behavior for everyone.
--dry-run and the keep policies still hold.giterminism_manager.*_linux.go / *_others.go pairs must stay in sync, as must the Buildah and Docker backends — and a reviewer on macOS cannot compile the Buildah side at all.go.mod replaces cobra and oras with werf/3p-* forks — upstream documentation is not authoritative for them.task commands, never raw Go tools.Print the report. Do not write it into the repository unless the user asks for a file.
# Code Review Report
**Base:** `<resolved base branch>`
**Diff:** [X files, +Y/-Z lines]
## Verdict
- Technical: [up to 3 sentences, or `no findings`]
- Product: [up to 3 sentences, or `no findings`]
- Risk: [up to 3 sentences, or `no findings`]
## DoD Criteria
| Criteria | Inferred? | Met? | Evidence |
| :--- | :--- | :--- | :--- |
| [criterion] | yes/no | ✅/⚠️/❌ | file:line |
## Issues
- **Critical** — blocking, with file:line
- **Major** — significant concern
- **Minor** — suggestion
## Risks
Sorted by severity, then by likelihood.
| № | Risk | Type | Likelihood | Severity | Location | Circumstances | Consequences | Recommendation |
| :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- |
## Not verified
- What was not built, run, or reachable — and why (Buildah paths do not compile on macOS, e2e needs Linux with kind).Headers in English, everything else in the user's language.
© werf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/review of werf/werf.
Open the folder on GitHubat commit fa73c7a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in werf/werf, which our catalogue first saw on October 7, 2026.
Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review this skillwerf/werf | 4.7k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Workflow AutomationFNOSP/FlyNarwhal | 495 | 7 repos | ~5.4k | Automated safety check: Pass | AGPL-3.0 | |
| PR Reviewkimdre/doco-cd | 1.7k | — | ~311 | Automated safety check: Pass | Apache-2.0 | |
| Local Review Codexwindmill-labs/windmill | 18k | — | ~755 | Automated safety check: Pass | Custom licence | |
| CI Adhoc Testnubjs/nub | 4.4k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Renovate Actions PR Reviewbacknotprop/plannotator | 9.2k | — | ~640 | Automated safety check: Pass | Apache-2.0 |
FNOSP/FlyNarwhal
Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.
kimdre/doco-cd
Review pull request diffs for correctness and regressions, and provide actionable feedback when asked to review a PR.
windmill-labs/windmill
Run the CI Codex PR review locally against this branch's unpushed work (committed + uncommitted) before pushing.
nubjs/nub
Run ad-hoc / exploratory tests on a real OS or platform via CI when the behavior CANNOT be reproduced on the local host or in Docker — macOS Seatbelt / sandbox-exec / codesigning, Windows cmd.exe /…
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
pavel-molyanov/molyanov-ai-dev
Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations.
werf/werf
werf conventions for branch names and commit messages. An agent skill from werf/werf.
werf/werf
Generates Pull Request titles and descriptions according to werf conventions.
werf/werf
Independent challenge pass for a non-trivial or high-risk change.
werf/werf
How to treat conclusions inherited from an earlier session — handover notes, prepared comments, verdict files, plans.
werf/werf
Analyze the current session for harness-worthy lessons — repeated corrections, discovered conventions, skill bugs — and turn them into concrete repo changes: docs, skills, task targets, linter…
werf/werf
Verify a test actually falsifies the behavior it claims to cover, via real mutation.
Categories
Code review of a pull request, branch, or diff. An agent skill from werf/werf. Review is an agent skill from werf/werf. Code review of a pull request, branch, or diff.
Review fits situations like: asked to review a PR; tasks that involve Pull requests; tasks that involve CI/CD.
Run `npx skills add werf/werf --skill review -a claude-code`. Or copy the skill folder (.agents/skills/review in werf/werf) into .claude/skills/review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add werf/werf --skill review -a codex`. Or copy the skill folder (.agents/skills/review in werf/werf) into .agents/skills/review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add werf/werf --skill review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review, .gemini/skills/review, .github/skills/review and .opencode/skills/review in your project.
Going by SKILL.md and its folder, Review needs the command-line tools its instructions call (git). Our summary lists: Docker.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review: GitHub Workflow Automation (FNOSP/FlyNarwhal, 495 stars), PR Review (kimdre/doco-cd, 1.7k stars), Local Review Codex (windmill-labs/windmill, 18k stars) and CI Adhoc Test (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
werf (a GitHub organization) maintains it in werf/werf, which has 4,728 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.
Source: werf/werf on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.