Install
$ agentstack add skill-pekral-cursor-rules-merge-github-pr ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Merge GitHub PR
Purpose
Merge pull requests that meet all required conditions.
Constraints
- Apply @rules/git/general.mdc
- Never merge a PR without a converged code review. A code review must have been run on the PR's final diff and report no errors — 0 Critical + 0 Moderate findings (Minor does not block). This is the hard merge gate from
@rules/git/general.mdcMerging; it is mandatory on every merge and is verified in step 2 below. - Never merge PRs with conflicts
- Never merge PRs with failing CI (unless explicitly instructed)
- Never bypass required approvals or protections
- The only tolerated CI failure is a GitHub Actions billing / account-limit error when the merge is explicitly requested (see GitHub Actions billing exception below). Any other failure — real test failure, lint, static analysis — still blocks.
Execution
1. Load PRs
- Identify candidate PRs ready for merge
- For each candidate, load PR context by running
skills/code-review-github/scripts/load-issue.sh— the single deterministic entry point. Never callgh pr view,gh pr checks, orgh api /repos/.../pulls/...directly. ReadisDraft,mergeable,mergeStateStatus,reviewDecision, andstatusCheckRollup[]off the resulting JSON document. - If the script is unavailable (missing tool, exit code 2/3) fall back to the GitHub MCP server.
2. Pre-checks (must all pass)
For each PR, derive the verdict from the JSON document loaded in step 1:
- Converged code review on the final diff (hard gate, no exception) — a code review must have run on the exact commits being merged and report no errors: 0 Critical + 0 Moderate findings (Minor does not block). Verify it from the PR's review comments in the loaded JSON: locate the latest code-review status comment (the technical CR comment / convergence status posted by
@skills/code-review-github/SKILL.md/@skills/process-code-review/SKILL.md), confirm it reportscriticalCount + moderateCount == 0, and confirm it reflects the head commit. Because the CR comment is upserted in place (@skills/code-review/SKILL.mdCross-run history — follow-up runs edit the same comment), use itsupdatedAt(notcreatedAt) for the staleness check: it is current only whenupdatedAtis at or after the newestcommits[].authoredDate(the head commit). A comment whoseupdatedAtpredates the head commit is stale and does not count. If no code-review comment exists, the latest one still carries Critical / Moderate findings, or itsupdatedAtpredates the head commit, do not merge — report that the code-review gate is unmet and that the review must be run (or re-run) to convergence via@skills/code-review-github/SKILL.md+@skills/process-code-review/SKILL.mdfirst. This gate is never waived — not by an explicit merge request, not by the billing exception below, and not by a GitHubreviewDecision == "APPROVED"on its own. - Not a Draft —
isDraft == false. A Draft PR signals the review/fix loop has not converged (@rules/git/general.mdcDraft pull requests): the Draft state mirrors the unmet code-review gate, so do not merge a Draft and report it as skipped. If the PR's code review has in fact converged (0 Critical + 0 Moderate), it must first be promoted out of Draft by@skills/process-code-review/SKILL.md(gh pr ready) before this skill will merge it — never flip a Draft to ready here just to merge it. The billing exception below never relaxes this. - No merge conflicts —
mergeable == "MERGEABLE"andmergeStateStatusis notDIRTYorBEHIND - CI is passing — every entry in
statusCheckRollup[]has a passingstate(SUCCESS/NEUTRAL/SKIPPED), with the single billing exception below when the merge was explicitly requested - Required approvals are present —
reviewDecision == "APPROVED" - Branch is up to date with base branch —
mergeStateStatus != "BEHIND"
If any check fails:
- do not merge
- report reason
GitHub Actions billing exception (explicit merge only)
A single, narrow exception relaxes the CI-passing check — only when the caller explicitly requested the merge (an automatic / opportunistic merge never qualifies):
- When it applies: the only blocking entries in
statusCheckRollup[]are GitHub Actions runs that did not execute because of a billing / account-limit problem — typically astateofERROR(or a workflow that never started) whose detail message is an unambiguous billing notice such as "The job was not started because recent account payments have failed or your spending limit needs to be increased", "billing", or "spending limit". In that case the gate ignores those specific entries and allows the merge. - Detection must stay conservative. Treat an entry as a billing failure only when its message clearly names a billing / payment / spending-limit cause. A bare
ERROR/FAILUREwith no billing wording is a real failure — never assume billing. When in doubt, do not merge: report the ambiguous entry and stop. - The exception is billing-only. It never relaxes any other gate: a missing or non-converged code review (the hard CR gate above), a Draft PR (
isDraft == true), a real CI failure (tests, lint, static analysis) on any non-billing entry,mergeStateStatus == "DIRTY"/"BEHIND", an unmergeable state, orreviewDecision != "APPROVED"still blocks the merge regardless of the explicit request. - Report what was waived. When the merge proceeds under this exception, list each ignored billing entry (check name + the billing message) in the output so the waiver is auditable.
When the merge was not explicitly requested, this exception does not apply — a billing failure blocks like any other failing check.
3. Merge
- Merge PR using CLI
- Use project default merge strategy
4. Post-merge
- Delete branch (if configured)
- Remove worktree (opt-in only) — if an isolated git worktree was explicitly created for this work unit (per
@rules/git/general.mdcWorktrees / Workspaces), remove it now that the merge is complete:
- Verify the worktree is not the currently active working tree and has no uncommitted changes. If it is active or dirty, report the issue and skip removal — never pass
--force. git worktree remove— removes the worktree directory and its metadata.git worktree prune— cleans up any remaining stale worktree metadata.
If no worktree was explicitly created for this work unit (the default: agent worked in the shared tree), skip this step entirely.
- Confirm merge success
Output
- List merged PRs
- List skipped PRs with reasons
Principles
- Safety over speed
- Never bypass CI or review gates — a converged code review (0 Critical + 0 Moderate) on the final diff is a mandatory precondition for every merge
- Merge only fully ready PRs
- Be explicit about skipped PRs
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: pekral
- Source: pekral/cursor-rules
- License: MIT
- Homepage: https://pekral.cz
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.