Install
$ agentstack add skill-wednesday-solutions-ai-agent-skills-pr-review ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
PR Review — Gemini Fix Queue
Trigger
Load this skill when a dev wants to act on PR review comments:
- "Fix the review comments"
- "Triage the PR feedback"
- "Apply fixes from the review"
- "@agent fix #1 #3"
- "@agent fix all"
- "What do I need to fix in this PR?"
Also triggered automatically by GitHub Actions when Gemini bot posts a PR review.
Do NOT use this skill for: creating a new PR (use pr-create), or committing code (use git-os). This skill only runs on an already-open PR that has review comments on it.
Priority Order
Fix in this order — lower number = fix first.
| Rank | Category | Examples | |------|----------|---------| | 1 | security | auth issues, injection risks, data exposure | | 2 | breaking | API contract changes, interface changes | | 3 | logic | wrong conditions, missing edge cases | | 4 | performance | N+1 queries, unnecessary re-renders | | 5 | naming | variable/function/class names, casing | | 6 | style | formatting, whitespace, import order |
Rule: never fix a style item while a security or breaking issue is pending.
Review Report Format
# Gemini Review — PR #
| # | Category | File | Issue | Status |
|---|----------|------|-------|--------|
| 1 | security | src/db.js | SQL query not parameterized | ⬜ pending |
| 2 | logic | src/user.js | Missing null check on user.profile | ⬜ pending |
| 3 | naming | src/auth.js | Variable `x` is unclear | ⬜ pending |
To fix: `@agent fix #1 #2` Fix all: `@agent fix all`
Tools
| Action | Tool | |--------|------| | Read a file before applying a fix | Read | | Apply a fix to a file | Edit | | Run git commands (commit, push) | Bash | | Search for a pattern across files | Grep | | Find files by name | Glob |
Agent Fix Rules
- Never auto-fix without explicit dev approval (
@agent fix #N) - Read
git-osSKILL.md before making any commit - One commit per fix item
- Commit format:
fix(scope): description\n\nResolves review item #N - Push to the same PR branch
- Update the report — mark fixed items as
✅ fixed
Failure Handling
If a fix cannot be applied cleanly, post a comment explaining the conflict. Never force-push or silently skip a fix.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: wednesday-solutions
- Source: wednesday-solutions/ai-agent-skills
- License: MIT
- Homepage: https://www.npmjs.com/package/@wednesday-solutions-eng/ai-agent-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.