Install
$ agentstack add skill-fcakyon-claude-codex-settings-review-pr ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Review PR
Review a pull request for bugs, regressions, missing tests, and risky changes.
When explicitly invoked with extra text, treat that text as the PR number or URL. If no PR reference is provided, infer it from the current branch.
Process
- Preferred execution
- If subagents are available, use
github-dev:pr-reviewerand pass the PR reference. - Otherwise follow the manual steps below.
- Parse PR reference
- If a PR number or URL is provided, extract owner, repo, and PR number.
- If not, auto-detect the PR from the current branch with
gh pr view --json number,headRefName.
- Fetch PR data
- Use
gh pr difffor the full diff. - Use
gh pr view --json filesfor the changed file list. - Skip generated or vendored files such as
.lock,.min.js,.min.css,dist/,build/,vendor/,node_modules/,_pb2.py, and images.
- Review focus
- Only report issues that require fixes.
- Only review PR changes, never pre-existing issues in unchanged code.
- Prioritize bugs, security issues, breaking changes, performance issues, edge cases, and missing tests.
- Combine related issues that share the same root cause.
- Keep the list short and high signal.
- Review comment rules
- Only create pending PR comments, never submit or confirm the review automatically.
- Use
ghfor GitHub operations. - Start comments in lowercase, keep them short, avoid end punctuation when possible.
- Use simple language for both bot-facing and human-facing comments.
Output Format
If issues are found, report them in descending severity with file references and a final recommendation of NEEDS_CHANGES.
If no issues are found, return APPROVE - No fixes required.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: fcakyon
- Source: fcakyon/claude-codex-settings
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.