Install
$ agentstack add skill-fvadicamo-dev-agent-skills-github-pr-merge ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
GitHub PR merge
Merges Pull Requests after validating pre-merge checklist and handling post-merge cleanup.
Current PR
!gh pr view --json number,title,state -q '"PR #\(.number): \(.title) (\(.state))"' 2>/dev/null
Core workflow
1. Check comments status
Verify all review comments have at least one reply:
REPO=$(gh repo view --json nameWithOwner -q '.nameWithOwner')
PR=$(gh pr view --json number -q '.number')
# Find unreplied comment IDs
gh api repos/$REPO/pulls/$PR/comments --jq '
[.[] | select(.in_reply_to_id) | .in_reply_to_id] as $replied |
[.[] | select(.in_reply_to_id == null) | select(.id | IN($replied[]) | not) | .id]
'
If unreplied comments exist:
- STOP the merge process
- Inform user: "Found unreplied comments: [IDs]. Run github-pr-review first."
- NEVER reply to comments from this skill
2. Check milestone
gh pr view $PR --json milestone -q '.milestone.title // "none"'
- If milestone is assigned: include it in the checklist summary (step 5)
- If no milestone: check for open milestones and warn the user
gh api repos/$REPO/milestones --jq '[.[] | select(.state=="open")] | length'
If open milestones exist but the PR has none, surface a warning in the checklist: - Milestone: ⚠ not assigned (open milestones exist)
Do NOT block the merge for a missing milestone. It is a warning only.
3. Run validation
Run tests, linting, and verify CI checks. All MUST pass before proceeding.
gh pr checks $PR
4. Verify changelog completeness
Skip if the repo has no CHANGELOG.md. Otherwise make sure every commit this merge will publish is reflected in the changelog, so a release-promotion merge (develop → main) never leaves commits unlogged.
List the commits this PR brings into the base, and the changelog lines it adds:
BASE=$(gh pr view $PR --json baseRefName -q .baseRefName)
HEAD=$(gh pr view $PR --json headRefName -q .headRefName)
git log --oneline origin/$BASE..origin/$HEAD
git diff origin/$BASE...origin/$HEAD -- CHANGELOG.md
- Every commit that changes shipped behavior (
feat/fix/perf, behavior-affectingrefactor) MUST have a matching changelog line; purechore/docs/testcommits that do not change shipped behavior may be omitted. - For a release-promotion merge, also confirm the version was bumped (the top
## [x.y.z]entry is new) and matches the manifest version(s). - If any behavior-changing commit is missing from the changelog: STOP. Report the unlogged commits and ask the user to update the changelog and version before merging. NEVER edit the changelog from this skill.
5. Confirm with user
ALWAYS show checklist summary and ask before merging:
Pre-merge checklist:
- Comments: all replied
- Tests: passing
- Lint: passing
- CI: green
- Milestone: v0.1.0 (or ⚠ not assigned)
- Changelog: complete (or n/a)
Ready to merge PR #X. Proceed?
6. Execute merge
First determine the merge direction. It decides whether the head branch may be deleted:
gh pr view $PR --json baseRefName,headRefName -q '"\(.headRefName) -> \(.baseRefName)"'
Branch deletion rule:
- Topic branch →
develop(head is afeature/fix/etc. branch): the branch is spent. Propose deleting it and merge with--delete-branch. develop→main(or any long-lived branch as head): NEVER delete the head branch.developandmainare permanent. Omit--delete-branchand do not propose deletion.
# Add --delete-branch ONLY for a topic branch merging into develop.
gh pr merge $PR --merge --delete-branch --body "$(cat 0`: report remaining open items count. No action needed.
- **NEVER** close a milestone automatically without explicit user confirmation.
## Merge message format
Concise format for a clean git log:
- Key change 1 (what was added/fixed)
- Key change 2
- Key change 3
Reviews: 7/7 addressed (Gemini 5, Codex 2) Tests: 628 passed (88% cov) Refs: Task 8, Req 14-15
- 3-5 bullet points max for changes
- One line each for reviews summary, test results, and task references
- No headers (##), no verbose sections
- Total: ~10 lines max
## Important rules
- **ALWAYS** run tests, lint, and CI checks before merging
- **ALWAYS** verify all review comments have replies
- **ALWAYS** check milestone assignment before merging (warn if missing, do not block)
- **ALWAYS** (repos with a CHANGELOG) verify it accounts for every behavior-changing commit this merge publishes; STOP and report any that are missing
- **ALWAYS** confirm with user before executing merge
- **ALWAYS** use merge commit (`--merge`), never squash/rebase
- **ALWAYS** delete the head branch only when merging a topic branch (`feature`/`fix`/etc.) into `develop`
- **NEVER** delete `develop` or `main`. On a `develop` → `main` merge, omit `--delete-branch` and never propose deletion
- **ALWAYS** check milestone completion after merge and report open items count
- **NEVER** merge with failing tests, lint, or CI checks
- **NEVER** skip user confirmation
- **NEVER** close a milestone without explicit user confirmation
- **NEVER** reply to PR comments from this skill - use github-pr-review instead
- **STOP** merge if unreplied comments exist and direct user to review skill
## Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- **Author:** [fvadicamo](https://github.com/fvadicamo)
- **Source:** [fvadicamo/dev-agent-skills](https://github.com/fvadicamo/dev-agent-skills)
- **License:** MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.