Skip to content

v0.4.0 — pr-review skill

Choose a tag to compare

@PeterGuy326 PeterGuy326 released this 10 May 08:34
· 18 commits to main since this release

pr-review skill shipped — a generic 8-stage PR review SOP that guards exactly the gates release-sop Step 2 later replays. Same hard-gate philosophy as release-sop: every step has a written gate, failure stops execution at that step, no skip path, no "fix it in a follow-up". Agent-agnostic markdown contract; Git-host-agnostic (GitHub / GitLab / Gitea).

Added

  • skills/pr-review/SKILL.md — generic 8-stage PR review SOP (#1) — encodes Step 0 PR context load (GitHub gh / GitLab glab / Gitea tea / manual), Step 1 DoR meta check (title convention, What/Why, linked issue, target branch, PR size, clean history), Step 2 change classification + interface/behavior/data impact (breaking → must be flagged + CHANGELOG Breaking + migration note), Step 3 line-level code review (correctness, edge/failure, error handling, resource & concurrency, consistency, unintended side effects) producing [blocking] / [nit] comments, Step 4 test-coverage gate (tests same-PR, regression test for fixes, no skipped tests, CI green — zero-test feature PR or red CI ⇒ hard BLOCK), Step 5 CHANGELOG-entry gate (presence + Keep-a-Changelog format + granularity; content generation deferred to changelog-bot), Step 6 security-review trigger checklist (auth / crypto / parsers & deserialization / permission model / dependency bumps / CI secrets & pull_request_target / new endpoints — must write an explicit hit-or-no-hit line), Step 7 verdict report (✅ APPROVE / 🔁 REQUEST_CHANGES / ⛔ BLOCK with per-gate results, unmet-item list with "how to fix", security verdict, line-level comments, one-line conclusion). Includes edge-case runbook (CI in-flight, sole-maintainer author, hotfix PR, oversized diff, bot/dependency PR, vendored/generated code, reviewer out of depth), seven red lines (no approve on red CI, no zero-test feature PR, no unflagged breaking change, security trigger ⇒ must route, no "fix in a follow-up", no self-approve, don't promote nits to blockers or demote blockers to nits), and explicit composition with release-sop (this skill guards exactly the gates release-sop Step 2 later replays), changelog-bot, hotfix-flow, issue-triage. Agent-agnostic: same contract loads into Claude Code / Qoder / Cursor / Custom GPT / generic LLM.
  • README.md — pr-review promoted from 🚧 planned to ✅ shipped — Skills table row rewritten with the 8-stage summary; quickstart now has a pr-review curl one-liner alongside release-sop; Usage section gains a pr-review trigger table; repo-layout tree updated to show skills/pr-review/SKILL.md and the new examples/ directory. install.sh needs no change — it already auto-discovers any skills/<name>/SKILL.md.
  • examples/pr-review-demo.md — worked pr-review transcript — the 8 steps run end-to-end against a hypothetical PR (feat(http): add --retry N flag): Step 0 context load, DoR pass, change classification flagging stale docs, a line-level review surfacing two [blocking] (unreset POST body on retry, unbounded un-jittered backoff) plus two [nit], a test-coverage gate noting a missing regression test, a missing-CHANGELOG-entry gate, an explicit no-hit security-trigger judgement, a 🔁 REQUEST_CHANGES verdict report with a numbered how-to-fix list, then a second pass after the author's follow-up commit flipping it to ✅ APPROVE. Closes with notes on when the verdict would instead be ⛔ BLOCK / 🔒 SECURITY REVIEW REQUIRED, and on why this repo's own PR #1 is a near-trivial APPROVE (docs-only).