Review This Branch
no-human-ai/no_human
Run the nohuman review gate (fresh-session adversarial reviewer + tamper guard) over the current branch or a GitHub pull request, with no server, no database, and no onboarding, and relay the…
Configure human-in-the-loop gating for AI agent review actions in Claude Code.
$ npx skills add wshobson/agents --skill review-agent-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents review-agent-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .claude/skills/review-agent-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .claude/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill review-agent-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents review-agent-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .agents/skills/review-agent-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .agents/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill review-agent-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents review-agent-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .cursor/skills/review-agent-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .cursor/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/review-agent-governance/skills/review-agent-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill review-agent-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents review-agent-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .gemini/skills/review-agent-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .gemini/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents review-agent-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill review-agent-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .github/skills/review-agent-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .github/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill review-agent-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents review-agent-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/review-agent-governance/skills/review-agent-setup .opencode/skills/review-agent-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-agent-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/review-agent-governance/skills/review-agent-setup into .opencode/skills/review-agent-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-agent-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-agent-setupConfigure human-in-the-loop gating for AI agent review actions in Claude Code.
Review Agent Setup is an agent skill from wshobson/agents. Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Pull requests and Human-in-the-loop approvals. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghnpxclaudenodeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
datatracker.ietf.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Agent Setup loads about 1.5k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 576 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 576 words, ~1,514 tokens.
.claude/skills/review-agent-setup/SKILL.md (or your agent's skills folder).Gate AI agent review actions (PR reviews, comments, merges, CI edits) behind explicit human approval. Every attempt, approved or denied, produces an Ed25519-signed receipt.
Install it in projects where a Claude Code agent:
gh pr review, gh pr merge)gh issue comment, gh issue close)gh release create).github/workflows/, .gitlab-ci.yml)main, master, release, production)If the agent is only doing local file edits and running tests, this plugin is
overkill. Use protect-mcp for general tool-call policy enforcement and skip
this one.
claude plugin install wshobson/agents/review-agent-governancecp .claude/plugins/review-agent-governance/policies/review-agent-governance.cedar \
./review-governance.cedarYou can edit this file to match your project's specific rules. See
../agents/review-policy-author.md for guidance on authoring review
policies.
mkdir -p ./review-receipts
echo "/review-receipts/" >> .gitignore
echo "/review-governance.key" >> .gitignore
echo "/.review-approved" >> .gitignore
if [ ! -e ./review-governance.key ]; then
d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./review-governance.key
fiprotect-mcp 0.7.4 sign does not create the key, so the last command creates
it, and it never replaces an existing key. Without a key, the receipts are
unsigned. To rotate the key, archive ./review-governance.key and
./review-receipts/receipts.jsonl first, then run the command again. Give auditors the publicKey
value from ./review-governance.key. Do not commit the file, because it also
holds the private key.
The Cedar policy denies review-surface actions unconditionally. To approve a specific action, open an approval window before it and close it after.
# Before the action you want to approve
touch ./.review-approved
# Let Claude Code run the review / comment / merge
# Immediately after
rm ./.review-approved/approve-review "Reviewing PR #123 authored by contributor X"This creates ./.review-approved with the given reason embedded as a note,
and records the reason in an unsigned approval log under
./review-receipts/approvals/. A follow-up rm is still needed to close the
window.
If you want every tool call to go through Cedar with no approval bypass:
export REVIEW_APPROVAL_FLAG=./.never-approveAny tool call matching a forbid rule will be denied; approved windows have no effect. Useful for CI or for a locked-down audit run.
List all receipts:
ls -la ./review-receipts/Verify every receipt offline with the public key:
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./review-governance.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./review-receipts/receipts.jsonl --key "$PUB"Exit 0 means every receipt verified. Exit 1 means a receipt failed verification, because it was tampered with, the key is wrong, or a line is malformed. Exit 2 means the receipts file could not be read.
A denied call never runs, so it has no receipt. To see what the policy blocked, run this inside Claude Code:
/list-pendingIt lists the tool calls that the PreToolUse hook blocked in the current session, with the tool name and the command or path.
# 1. Human reviews the agent's proposed comment
$ /list-pending
Blocked in this session:
- Bash "gh pr review 42 --approve --body 'LGTM'"
- Bash "gh pr comment 42 --body 'Looking good'"
# 2. Human decides the first one is appropriate, approves it
$ /approve-review "Approving LGTM on PR 42 after visual inspection"
./.review-approved created
# 3. Agent retries the action; this time it succeeds
$ agent: gh pr review 42 --approve --body "LGTM"
[receipt appended to ./review-receipts/receipts.jsonl, decision=allow]
# 4. Human closes the window
$ rm ./.review-approvedThe allowed call has a signed receipt that anyone with the public key can verify offline. The denied attempt has no receipt, and the approval log is not signed, so keep both in mind when you show the trail to an auditor.
If both plugins are installed, each plugin's hooks/hooks.json registers its
own PreToolUse hook, and Claude Code runs both on every tool call:
{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }Each evaluate.sh reads tool_name and tool_input from the hook payload on
stdin (Claude Code sets no TOOL_NAME variable) and evaluates its own policy:
./protect.cedar for protect-mcp and ./review-governance.cedar here.
Both hooks must pass for the tool call to proceed. Cedar deny in either policy blocks it.
© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/review-agent-governance/skills/review-agent-setup of wshobson/agents.
Open the folder on GitHubat commit 46891e7
Review Agent Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Agent Setup this skillwshobson/agents | 40k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Review This Branchno-human-ai/no_human | 332 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Open PRArcadeAI/arcade-mcp | 1k | — | ~2.9k | Automated safety check: Pass | MIT | |
| PR PlotsRussellSB/pytrendy | 106 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Load PR CommentsNeoLabHQ/context-engineering-kit | 1.7k | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Review Gateinkline/inkline | 1.5k | — | ~1.2k | Automated safety check: Pass | None |
no-human-ai/no_human
Run the nohuman review gate (fresh-session adversarial reviewer + tamper guard) over the current branch or a GitHub pull request, with no server, no database, and no onboarding, and relay the…
ArcadeAI/arcade-mcp
Prepare arcade-mcp changes for review by verifying intended behavior, filling the repository PR template, and creating or updating the PR.
RussellSB/pytrendy
A skill your agent uses when preparing a fix or feature PR for review and adding before/after plot evidence to the PR body.
NeoLabHQ/context-engineering-kit
A skill your agent uses to load open/unresolved PR review comments then aggregate them as tasks in .specs/comments/.md for parallel agents to fix.
inkline/inkline
The Inkline Guild's PR review checklist — correctness, simplicity, surgical diffs, changesets, doc freshness, semver, and Inkline-specific contract risks.
MemTensor/MemOS
Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
wshobson/agents
Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.
wshobson/agents
Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.
Works with
Categories
Configure human-in-the-loop gating for AI agent review actions in Claude Code. Review Agent Setup is an agent skill from wshobson/agents. Configure human-in-the-loop gating for AI agent review actions in Claude Code.
Review Agent Setup fits situations like: setting up a project where an agent may post PR reviews; edit CI configuration; you want a cryptographically auditable approval trail with Cedar-enforced gates.
Run `npx skills add wshobson/agents --skill review-agent-setup -a claude-code`. Or copy the skill folder (plugins/review-agent-governance/skills/review-agent-setup in wshobson/agents) into .claude/skills/review-agent-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill review-agent-setup -a codex`. Or copy the skill folder (plugins/review-agent-governance/skills/review-agent-setup in wshobson/agents) into .agents/skills/review-agent-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill review-agent-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-agent-setup, .gemini/skills/review-agent-setup, .github/skills/review-agent-setup and .opencode/skills/review-agent-setup in your project.
Going by SKILL.md and its folder, Review Agent Setup needs the command-line tools its instructions call (gh, npx, claude and node). Our summary lists: Node.js.
SKILL.md names 1 domain. As links in the text: datatracker.ietf.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Agent Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Agent Setup: Review This Branch (no-human-ai/no_human, 332 stars), Open PR (ArcadeAI/arcade-mcp, 1k stars), PR Plots (RussellSB/pytrendy, 106 stars) and Load PR Comments (NeoLabHQ/context-engineering-kit, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,305 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.