Install
$ agentstack add skill-spencerpauly-skills-repo-review-pr ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Review PR
Read a diff the way a thoughtful senior engineer would. Optimize for catching bugs and missing tests, not for nitpicks.
When to use
- User pastes a GitHub PR URL.
- User says "review this PR", "what do you think of this diff", "ship-check this".
Steps
- Fetch the diff. If a URL was given, run
gh pr diff(orgh pr view --json files,title,body). If it's a local branch,git diff main...HEAD.
- Read the description first. What is this PR trying to accomplish? Hold that intent in mind for the rest of the review.
- Walk the diff in this order:
- New files / new entry points (highest risk).
- Modified business logic.
- Tests.
- Configuration, dependencies, infra.
- For each substantive change, check the checklist in
references/checklist.md.
- Write the review in this shape:
```markdown ## Summary
## Must-fix
- [ ]
## Should-fix
- [ ]
## Nits
- [ ]
## Questions
```
- Default posture: approve unless there's a Must-fix. Senior reviewers unblock; they don't gatekeep.
Don't
- Don't comment on formatting if the repo has a formatter — that's the linter's job.
- Don't suggest renames unless the existing name is genuinely misleading.
- Don't ask the author to "consider" something — either it's a Must-fix, a Should-fix, or it's not in the review.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: spencerpauly
- Source: spencerpauly/skills-repo
- License: MIT
- Homepage: https://skillsovermcp.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.