Agent skill

Review Agent Setup

by wshobson in wshobson/agents

Configure human-in-the-loop gating for AI agent review actions in Claude Code.

MITAuto-check passedAgent Workflows

Install Review Agent Setup

skills CLI
$ npx skills add wshobson/agents --skill review-agent-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents review-agent-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .claude/skills/review-agent-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-agent-setup
GitHub stars
40k
Token cost
~1.5k tokens
SKILL.md length
576 words
Files
1
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Configure human-in-the-loop gating for AI agent review actions in Claude Code.

  • Works in 3 steps: Install the plugin → Copy the default policy to your project → Create a receipts directory and sign key
  • Setting up a project where an agent may post PR reviews
  • SKILL.md covers When to use this plugin, One-time setup, Per-session workflow and Verifying the receipts, plus 3 more sections
  • Calls gh, npx and claude

What it does

Review Agent Setup is an agent skill from wshobson/agents. Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Pull requests and Human-in-the-loop approvals. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.

When your agent uses it

  • Setting up a project where an agent may post PR reviews
  • Edit CI configuration
  • You want a cryptographically auditable approval trail with Cedar-enforced gates

Example prompts

  • “/review-agent-setup”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Install the plugin
  2. Copy the default policy to your project
  3. Create a receipts directory and sign key

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npx
    • claude
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • datatracker.ietf.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Agent Setup loads about 1.5k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 576 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 576 words, ~1,514 tokens.

Download SKILL.mdSave it as .claude/skills/review-agent-setup/SKILL.md (or your agent's skills folder).
name
review-agent-setup
description
Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.

review-agent-governance — Setup

Gate AI agent review actions (PR reviews, comments, merges, CI edits) behind explicit human approval. Every attempt, approved or denied, produces an Ed25519-signed receipt.

When to use this plugin

Install it in projects where a Claude Code agent:

  • Reviews, comments on, or merges pull requests (gh pr review, gh pr merge)
  • Triages issues (gh issue comment, gh issue close)
  • Publishes releases (gh release create)
  • Modifies CI configuration (.github/workflows/, .gitlab-ci.yml)
  • Pushes to protected branches (main, master, release, production)
  • Posts to external notification surfaces (Slack webhooks, Discord), once you add a rule for the command that posts (the default policy does not gate them)

If the agent is only doing local file edits and running tests, this plugin is overkill. Use protect-mcp for general tool-call policy enforcement and skip this one.

One-time setup

1. Install the plugin
bash
claude plugin install wshobson/agents/review-agent-governance
2. Copy the default policy to your project
bash
cp .claude/plugins/review-agent-governance/policies/review-agent-governance.cedar \
   ./review-governance.cedar

You can edit this file to match your project's specific rules. See ../agents/review-policy-author.md for guidance on authoring review policies.

3. Create a receipts directory and sign key
bash
mkdir -p ./review-receipts
echo "/review-receipts/" >> .gitignore
echo "/review-governance.key" >> .gitignore
echo "/.review-approved" >> .gitignore
if [ ! -e ./review-governance.key ]; then
  d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./review-governance.key
fi

protect-mcp 0.7.4 sign does not create the key, so the last command creates it, and it never replaces an existing key. Without a key, the receipts are unsigned. To rotate the key, archive ./review-governance.key and ./review-receipts/receipts.jsonl first, then run the command again. Give auditors the publicKey value from ./review-governance.key. Do not commit the file, because it also holds the private key.

Per-session workflow

The Cedar policy denies review-surface actions unconditionally. To approve a specific action, open an approval window before it and close it after.

Flag file (simplest)
bash
# Before the action you want to approve
touch ./.review-approved

# Let Claude Code run the review / comment / merge

# Immediately after
rm ./.review-approved
Slash command (from within Claude Code)
/approve-review "Reviewing PR #123 authored by contributor X"

This creates ./.review-approved with the given reason embedded as a note, and records the reason in an unsigned approval log under ./review-receipts/approvals/. A follow-up rm is still needed to close the window.

Dry-run everything (force full policy evaluation)

If you want every tool call to go through Cedar with no approval bypass:

bash
export REVIEW_APPROVAL_FLAG=./.never-approve

Any tool call matching a forbid rule will be denied; approved windows have no effect. Useful for CI or for a locked-down audit run.

Show full SKILL.md (234 more words)Show less

Verifying the receipts

List all receipts:

bash
ls -la ./review-receipts/

Verify every receipt offline with the public key:

bash
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./review-governance.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./review-receipts/receipts.jsonl --key "$PUB"

Exit 0 means every receipt verified. Exit 1 means a receipt failed verification, because it was tampered with, the key is wrong, or a line is malformed. Exit 2 means the receipts file could not be read.

A denied call never runs, so it has no receipt. To see what the policy blocked, run this inside Claude Code:

/list-pending

It lists the tool calls that the PreToolUse hook blocked in the current session, with the tool name and the command or path.

Example: approving a PR review

bash
# 1. Human reviews the agent's proposed comment
$ /list-pending
  Blocked in this session:
  - Bash "gh pr review 42 --approve --body 'LGTM'"
  - Bash "gh pr comment 42 --body 'Looking good'"

# 2. Human decides the first one is appropriate, approves it
$ /approve-review "Approving LGTM on PR 42 after visual inspection"
  ./.review-approved created

# 3. Agent retries the action; this time it succeeds
$ agent: gh pr review 42 --approve --body "LGTM"
  [receipt appended to ./review-receipts/receipts.jsonl, decision=allow]

# 4. Human closes the window
$ rm ./.review-approved

The allowed call has a signed receipt that anyone with the public key can verify offline. The denied attempt has no receipt, and the approval log is not signed, so keep both in mind when you show the trail to an auditor.

Composing with protect-mcp

If both plugins are installed, each plugin's hooks/hooks.json registers its own PreToolUse hook, and Claude Code runs both on every tool call:

json
{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }

Each evaluate.sh reads tool_name and tool_input from the hook payload on stdin (Claude Code sets no TOOL_NAME variable) and evaluates its own policy: ./protect.cedar for protect-mcp and ./review-governance.cedar here.

Both hooks must pass for the tool call to proceed. Cedar deny in either policy blocks it.

Standards

  • Ed25519 — RFC 8032 (digital signatures)
  • JCS — RFC 8785 (deterministic JSON canonicalization)
  • Cedar — AWS's open authorization policy language
  • IETF draft — draft-farley-acta-signed-receipts

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/review-agent-governance/skills/review-agent-setup of wshobson/agents.

Open the folder on GitHubat commit 46891e7

Compare with similar skills

Review Agent Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Agent Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Agent Setup this skillwshobson/agents40k—~1.5kAutomated safety check: PassMIT
Review This Branchno-human-ai/no_human332—~1.4kAutomated safety check: PassMIT
Open PRArcadeAI/arcade-mcp1k—~2.9kAutomated safety check: PassMIT
PR PlotsRussellSB/pytrendy106—~1.2kAutomated safety check: PassMIT
Load PR CommentsNeoLabHQ/context-engineering-kit1.7k—~2.1kAutomated safety check: PassGPL-3.0
Review Gateinkline/inkline1.5k—~1.2kAutomated safety check: PassNone

Similar skills

  • Review This Branch

    no-human-ai/no_human

    Run the nohuman review gate (fresh-session adversarial reviewer + tamper guard) over the current branch or a GitHub pull request, with no server, no database, and no onboarding, and relay the…

    332 GitHub stars~1.4k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Open PR

    ArcadeAI/arcade-mcp

    Prepare arcade-mcp changes for review by verifying intended behavior, filling the repository PR template, and creating or updating the PR.

    1k GitHub stars~2.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • PR Plots

    RussellSB/pytrendy

    A skill your agent uses when preparing a fix or feature PR for review and adding before/after plot evidence to the PR body.

    106 GitHub stars~1.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Load PR Comments

    NeoLabHQ/context-engineering-kit

    A skill your agent uses to load open/unresolved PR review comments then aggregate them as tasks in .specs/comments/.md for parallel agents to fix.

    1.7k GitHub stars~2.1k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Review Gate

    inkline/inkline

    The Inkline Guild's PR review checklist — correctness, simplicity, surgical diffs, changesets, doc freshness, semver, and Inkline-specific contract risks.

    1.5k GitHub stars~1.2k tokensUpdated 28 days ago
    Agent WorkflowsAuto-check passed
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed

Questions about Review Agent Setup

What does Review Agent Setup do?

Configure human-in-the-loop gating for AI agent review actions in Claude Code. Review Agent Setup is an agent skill from wshobson/agents. Configure human-in-the-loop gating for AI agent review actions in Claude Code.

When should I use Review Agent Setup?

Review Agent Setup fits situations like: setting up a project where an agent may post PR reviews; edit CI configuration; you want a cryptographically auditable approval trail with Cedar-enforced gates.

How do I install Review Agent Setup in Claude Code?

Run `npx skills add wshobson/agents --skill review-agent-setup -a claude-code`. Or copy the skill folder (plugins/review-agent-governance/skills/review-agent-setup in wshobson/agents) into .claude/skills/review-agent-setup in your project. Claude Code loads it when a task matches its description.

How do I install Review Agent Setup in Codex?

Run `npx skills add wshobson/agents --skill review-agent-setup -a codex`. Or copy the skill folder (plugins/review-agent-governance/skills/review-agent-setup in wshobson/agents) into .agents/skills/review-agent-setup in your project. Codex loads it when a task matches its description.

Can I use Review Agent Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill review-agent-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-agent-setup, .gemini/skills/review-agent-setup, .github/skills/review-agent-setup and .opencode/skills/review-agent-setup in your project.

What does Review Agent Setup need to run?

Going by SKILL.md and its folder, Review Agent Setup needs the command-line tools its instructions call (gh, npx, claude and node). Our summary lists: Node.js.

Does Review Agent Setup access the network?

SKILL.md names 1 domain. As links in the text: datatracker.ietf.org. This is read from the text; nothing was executed.

Is Review Agent Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Agent Setup use?

Review Agent Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Agent Setup use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Agent Setup?

Skills that share tags, products or a category with Review Agent Setup: Review This Branch (no-human-ai/no_human, 332 stars), Open PR (ArcadeAI/arcade-mcp, 1k stars), PR Plots (RussellSB/pytrendy, 106 stars) and Load PR Comments (NeoLabHQ/context-engineering-kit, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Agent Setup?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,305 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.