Repository navigation
v0.4.0 — pr-review skill
pr-review skill shipped — a generic 8-stage PR review SOP that guards exactly the gates release-sop Step 2 later replays. Same hard-gate philosophy as release-sop: every step has a written gate, failure stops execution at that step, no skip path, no "fix it in a follow-up". Agent-agnostic markdown contract; Git-host-agnostic (GitHub / GitLab / Gitea).
Added
skills/pr-review/SKILL.md— generic 8-stage PR review SOP (#1) — encodes Step 0 PR context load (GitHubgh/ GitLabglab/ Giteatea/ manual), Step 1 DoR meta check (title convention, What/Why, linked issue, target branch, PR size, clean history), Step 2 change classification + interface/behavior/data impact (breaking → must be flagged + CHANGELOGBreaking+ migration note), Step 3 line-level code review (correctness, edge/failure, error handling, resource & concurrency, consistency, unintended side effects) producing[blocking]/[nit]comments, Step 4 test-coverage gate (tests same-PR, regression test for fixes, no skipped tests, CI green — zero-test feature PR or red CI ⇒ hardBLOCK), Step 5 CHANGELOG-entry gate (presence + Keep-a-Changelog format + granularity; content generation deferred tochangelog-bot), Step 6 security-review trigger checklist (auth / crypto / parsers & deserialization / permission model / dependency bumps / CI secrets &pull_request_target/ new endpoints — must write an explicit hit-or-no-hit line), Step 7 verdict report (✅ APPROVE/🔁 REQUEST_CHANGES/⛔ BLOCKwith per-gate results, unmet-item list with "how to fix", security verdict, line-level comments, one-line conclusion). Includes edge-case runbook (CI in-flight, sole-maintainer author, hotfix PR, oversized diff, bot/dependency PR, vendored/generated code, reviewer out of depth), seven red lines (no approve on red CI, no zero-test feature PR, no unflagged breaking change, security trigger ⇒ must route, no "fix in a follow-up", no self-approve, don't promote nits to blockers or demote blockers to nits), and explicit composition withrelease-sop(this skill guards exactly the gatesrelease-sopStep 2 later replays),changelog-bot,hotfix-flow,issue-triage. Agent-agnostic: same contract loads into Claude Code / Qoder / Cursor / Custom GPT / generic LLM.README.md—pr-reviewpromoted from 🚧 planned to ✅ shipped — Skills table row rewritten with the 8-stage summary; quickstart now has apr-reviewcurl one-liner alongsiderelease-sop; Usage section gains apr-reviewtrigger table; repo-layout tree updated to showskills/pr-review/SKILL.mdand the newexamples/directory.install.shneeds no change — it already auto-discovers anyskills/<name>/SKILL.md.examples/pr-review-demo.md— workedpr-reviewtranscript — the 8 steps run end-to-end against a hypothetical PR (feat(http): add --retry N flag): Step 0 context load, DoR pass, change classification flagging stale docs, a line-level review surfacing two[blocking](unreset POST body on retry, unbounded un-jittered backoff) plus two[nit], a test-coverage gate noting a missing regression test, a missing-CHANGELOG-entry gate, an explicit no-hit security-trigger judgement, a🔁 REQUEST_CHANGESverdict report with a numbered how-to-fix list, then a second pass after the author's follow-up commit flipping it to✅ APPROVE. Closes with notes on when the verdict would instead be⛔ BLOCK/🔒 SECURITY REVIEW REQUIRED, and on why this repo's own PR #1 is a near-trivialAPPROVE(docs-only).