skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
mathews-tom/armory120 installs

pr-review

Diff-based PR review across code quality, test coverage, silent failures, type design, and comment quality with severity-ranked findings. Triggers on: "review my PR", "review this code", "check my changes", "audit this PR", "code review". NOT for pre-landing gate, use pre-landing-review.

How do I install this agent skill?

npx skills add https://github.com/mathews-tom/armory --skill pr-review
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill is safe to use for its intended purpose of reviewing code changes. It follows security best practices and does not exhibit malicious behavior. It is noted for an indirect prompt injection surface as it processes external code diffs which could potentially contain adversarial instructions.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

PR Review

Diff-based code review across five dimensions. Reads the changed files, selects applicable review methodologies, and produces an aggregated report with severity-ranked findings.

Native alternative: Claude Code's /ultrareview runs a lightweight native bug-focused review (three free per month on Pro/Max plans at Opus 4.7's launch). Use this skill for five-dimension severity-ranked analysis (code quality + tests + error handling + types + comments) with file:line references; use /ultrareview for a quick bug-hunting pass on a diff.

Reference Files

FileContentsLoad When
references/code-review.mdGuideline compliance, bug detection, confidence scoringAlways
references/test-analysis.mdBehavioral test coverage, criticality ratingTest files changed
references/error-handling.mdSilent failure patterns, catch block analysisError handling changed
references/type-design.mdInvariant analysis, 4-dimension rating rubricType definitions added/modified
references/comment-quality.mdComment accuracy, long-term value, rot detectionComments/docstrings added

Workflow

Phase 1: Scope

  1. Determine the review target:
    • Default: git diff (unstaged changes)
    • If user specifies a PR: git diff main...HEAD or gh pr diff <number>
    • If user specifies files: review those files directly
  2. List all changed files with git diff --name-only
  3. Read the project's CLAUDE.md (if present) for project-specific rules

Phase 2: Route

Classify changed files and select applicable dimensions:

ConditionDimensionReference to Load
AlwaysCode reviewreferences/code-review.md
Files matching *test*, *spec*, *_test.*, test_*Test analysisreferences/test-analysis.md
Files containing try/catch, except, .catch, Result, error callbacksError handlingreferences/error-handling.md
Files containing class, interface, type, struct, enum, dataclass definitionsType designreferences/type-design.md
Files with new/modified docstrings, JSDoc, or block commentsComment qualityreferences/comment-quality.md

Load only the reference files that apply. Skip dimensions with no matching files.

Phase 3: Review

For each applicable dimension, analyze the diff using the loaded methodology:

  1. Code review — scan every changed file for guideline violations and bugs. Apply confidence scoring (0-100). Only report issues >= 80.
  2. Test analysis — map test coverage to changed code paths. Rate gaps 1-10. Only report gaps >= 5.
  3. Error handling — examine every error handler in the diff for silent failures. Classify CRITICAL/HIGH/MEDIUM.
  4. Type design — evaluate new or modified types on 4 dimensions (encapsulation, invariant expression, usefulness, enforcement). Rate each 1-10.
  5. Comment quality — verify accuracy, assess long-term value, flag comment rot.

Phase 4: Aggregate

Merge all findings into a single report, deduplicated and severity-ranked.

Deduplication rules:

  • If two dimensions flag the same file:line, keep the higher-severity finding
  • If code-review and error-handling both flag an empty catch block, merge into one finding with the error-handling severity (it's the specialist)

Severity mapping across dimensions:

DimensionMaps to CriticalMaps to ImportantMaps to Suggestion
Code reviewConfidence 90-100Confidence 80-89—
Test analysisRating 9-10Rating 7-8Rating 5-6
Error handlingCRITICALHIGHMEDIUM
Type designAny rating <= 3/10Any rating 4-6/10Rating 7-8/10
Comment qualityFactually incorrectMisleading or incompleteRestates obvious code

Output Format

# PR Review Summary

**Scope:** [X files changed, Y dimensions applied]
**Dimensions:** [list of active dimensions]

## Critical Issues (must fix before merge)
- **[dimension]** `file:line` — Description. Fix suggestion.

## Important Issues (should fix)
- **[dimension]** `file:line` — Description. Fix suggestion.

## Suggestions (consider)
- **[dimension]** `file:line` — Description.

## Strengths
- What's well-done in this changeset.

## Recommended Action
1. Fix critical issues
2. Address important issues
3. Consider suggestions
4. Re-run review after fixes

If no issues are found at any severity level, confirm the code meets standards with a brief summary of what was reviewed and which dimensions were applied.


Aspect Selection

Users can request specific dimensions instead of running all:

User SaysDimensions Applied
"review my PR" / "check my changes"All applicable (default)
"review the code" / "check code quality"Code review only
"check the tests" / "is test coverage good"Test analysis only
"check error handling" / "find silent failures"Error handling only
"review the types" / "check type design"Type design only
"check the comments" / "review documentation"Comment quality only

When a specific aspect is requested, load only that reference file and skip routing.


Error Handling

ProblemResolution
No git diff availableAsk user to specify files or scope
CLAUDE.md not foundReview against general best practices; note the absence
No test files in diffSkip test analysis dimension; note in output
Diff is emptyReport "no changes to review" and stop
Diff exceeds context limitsFocus on files the user is most likely to care about; summarize skipped files

Calibration Rules

  1. Precision over recall. A false positive erodes trust in the review. Only report issues at >= 80 confidence (code review) or >= 5 criticality (tests). Silence is better than noise.
  2. File:line references are mandatory. Every finding must include a specific location. Vague findings ("consider improving error handling") are not actionable.
  3. Project rules override general rules. If CLAUDE.md says "use arrow functions", do not flag arrow functions even if conventional style prefers function declarations.
  4. Deduplication is mandatory. If two dimensions flag the same issue, merge them. Never report the same problem twice.
  5. Acknowledge strengths. A review that only lists problems is demoralizing. Note what's done well, even briefly.
  6. Code-refiner handles simplification. This skill reviews and reports. It does not refactor or simplify — that's the code-refiner skill's job. Keep the roles separate.

Rationalizations

RationalizationReality
"Tests pass, so the code is fine"Tests are necessary but insufficient — they miss architecture, security, readability, and maintainability concerns
"It's a small diff, no real review needed"Small changes cause most production incidents; a 3-line auth bypass is worse than a 300-line refactor
"We'll clean it up later"Later never comes — the review IS the quality gate before code becomes legacy
"The author is senior, I trust them"Seniority doesn't prevent mistakes; fresh eyes catch what familiarity blinds
"I already reviewed similar code recently"Each diff has unique context — assumptions from past reviews cause missed issues
"This is just a refactor, nothing can break"Refactors change behavior in subtle ways — verify with tests and trace call sites

Red Flags

  • Approving without reading every changed file in full (not just diff hunks)
  • No file:line references in findings — vague feedback is not actionable
  • Skipping a review dimension because "it looks fine"
  • Reporting only style issues while ignoring logic, security, or architecture
  • Reviewing generated code (migrations, protobuf stubs) with the same rigor as hand-written code
  • Merging findings from different dimensions without deduplication

Verification

  • Every changed file read in full, not just diff hunks
  • Each review dimension scored: correctness, security, performance, readability, architecture
  • Every finding includes a file:line reference
  • At least one actionable finding per 100 lines changed, or explicit "no issues found" with justification
  • Review summary includes risk level (LOW/MEDIUM/HIGH/CRITICAL) and blocking vs. non-blocking classification
  • Strengths acknowledged — review is not 100% negative

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/mathews-tom/armory/pr-review">View pr-review on skillZs</a>