review-pr
Review a pull request for issues and feedback.
What this skill does
Review a pull request and provide detailed feedback on the changes.
## Modes
The skill has three modes, selected by an optional argument:
- `findings` — display review findings only; never modify code or post to GitHub
- `fix` — display findings, then walk through each issue and apply local fixes as commits
- `post` — display findings, then post review comments to GitHub via `gh api`
If no argument is provided, run the findings phase first, then use `AskUserQuestion` to ask whether to `fix`, `post`, or `stop`.
## Review Steps (all modes)
1. Fetch PR details and full diff using `gh pr view` and `gh pr diff`. If the diff is empty, stop and tell the user.
2. Skip generated/vendored files: lock files (`*.lock`, `package-lock.json`, `yarn.lock`), `*.designer.cs`, auto-generated code, vendored dependencies
3. For large PRs, prioritize the most-changed files first
4. Focus on actionable issues, not positive feedback
## Findings Phase (always run first)
- Display all review findings in the CLI output only
- Label each comment with a severity emoji: 🔴 CRITICAL, 🟠 HIGH, 🟡 MEDIUM, 🟢 LOW
- Sort comments by severity (most critical first), then by file path and line number:
1. 🔴 **CRITICAL**: Security vulnerabilities, data loss, crashes
2. 🟠 **HIGH**: Logic errors, bugs, incorrect behavior
3. 🟡 **MEDIUM**: Performance issues, missing error handling
4. 🟢 **LOW**: Code style, minor improvements, suggestions
- Keep the summary concise: one line per issue with severity, `file_path:line_number`, and a brief description
If no issues were found, say so and stop regardless of mode.
## After Findings
Behavior after the findings phase depends on the mode:
- **`findings` mode**: stop here.
- **`fix` mode**: continue to "Fix Flow" below.
- **`post` mode**: continue to "Post Flow" below.
- **No mode argument**: use `AskUserQuestion` with options `fix`, `post`, `stop`. Then run the corresponding flow (or stop).
## Fix Flow
DO NOT post any comments to GitHub in this flow.
### Step 1 — Ask About Each Issue
For each issue in order, use `AskUserQuestion` to ask what to do. Offer options:
- **"Fix it"** — investigate and implement a fix
- **"Skip"** — do nothing for this issue
Collect answers for **all** issues before applying any fixes. Track each answer as `{issue index, severity, file:line, action}`.
### Step 2 — Apply Fixes
After all answers are collected, work through each "Fix it" issue in order (most critical first):
1. Make the code change
2. Stage and commit the change following the `git-commit` skill conventions (imperative mood, concise subject ≤ 50 chars)
3. Move to the next "Fix it" issue
Skipped issues are not touched.
### Step 3 — Final Summary
If any changes were committed, show a summary listing:
- Issues fixed, with the commit subject for each
- Issues skipped
If no changes were made, no summary is needed.
## Post Flow
- Use `gh api` to create a review with specific line comments
- Endpoint: `repos/OWNER/REPO/pulls/PR_NUMBER/reviews`
- Each comment must specify: `path`, `line` (or `start_line`/`end_line`), `body`
- Include footer in review body: `"\n\n---\n*Review by Claude Code*"`
- ALWAYS use event type: `COMMENT`
- NEVER use `REQUEST_CHANGES` or `APPROVE` — human review required
- Group related comments under a single review
### Comment body guidelines
- Reference code directly with `file_path:line_number`
- Explain why something is an issue, not just what
- Suggest a concrete fix when possible
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.