Revue de PR

VérifiéSûr

Examine une pull request pour la correction, la sécurité, la qualité du code et les tests. Fournit des commentaires en ligne structurés avec des badges de sévérité.

Spar Skills Guide Bot
DeveloppementIntermédiaire
0029/08/2026
Claude Code
#pr-review#github#code-review#quality#security

Recommandé pour

Notre avis

Automatise la revue de pull requests GitHub en récupérant le diff, les commentaires existants et en publiant des retours inline avec des niveaux de sévérité.

Points forts

  • Fournit une checklist structurée couvrant l'exactitude, la sécurité, la qualité du code et les tests.
  • Publie des commentaires directement sur la PR avec des badges de gravité clairs.
  • Évite les doublons en récupérant d'abord les reviews existantes.
  • Vérifie que la description de la PR explique le pourquoi, le quoi et le comment.

Limites

  • Nécessite la CLI GitHub et une authentification avec accès au dépôt.
  • Inclut des conventions spécifiques au dépôt (ex. patterns AutoGPT) qui ne s'appliquent pas partout.
  • Ne peut pas détecter tous les problèmes automatiquement ; dépend de l'analyse de l'agent.
Quand l'utiliser

Utilisez-le pour une revue de PR approfondie avec des commentaires inline exploitables.

Quand l'éviter

Évitez en l'absence de PR GitHub (ex. revue de code local) ou si vous ne voulez qu'un résumé rapide.

Analyse de sécurité

Sûr
Score qualité92/100

The skill uses GitHub CLI commands to fetch PR data and post inline review comments. It does not involve destructive actions, exfiltration, obfuscation, or disabling safety. While it uses bash and network APIs, the operations are legitimate and user-invoked for PR review.

Aucun point d'attention détecté

Exemples

Review a specific PR
Review PR #1234 in the repository and post inline comments for any issues you find.
Review current branch PR
Find the PR for my current branch and give me a full review with severity-tagged feedback.
Check PR quality from URL
Check the quality of PR https://github.com/Significant-Gravitas/AutoGPT/pull/5678 and post comments if needed.

name: pr-review description: Review a PR for correctness, security, code quality, and testing issues. TRIGGER when user asks to review a PR, check PR quality, or give feedback on a PR. user-invocable: true args: "[PR number or URL] — if omitted, finds PR for current branch." metadata: author: autogpt-team version: "1.0.0"

PR Review

Find the PR

gh pr list --head $(git branch --show-current) --repo Significant-Gravitas/AutoGPT
gh pr view {N}

Read the PR description

Before reading code, understand the why, what, and how from the PR description:

gh pr view {N} --json body --jq '.body'

Every PR should have a Why / What / How structure. If any of these are missing, note it as feedback.

Read the diff

gh pr diff {N}

Fetch existing review comments

Before posting anything, fetch existing inline comments to avoid duplicates:

gh api repos/Significant-Gravitas/AutoGPT/pulls/{N}/comments --paginate
gh api repos/Significant-Gravitas/AutoGPT/pulls/{N}/reviews

What to check

Description quality: Does the PR description cover Why (motivation/problem), What (summary of changes), and How (approach/implementation details)? If any are missing, request them — you can't judge the approach without understanding the problem and intent.

Correctness: logic errors, off-by-one, missing edge cases, race conditions (TOCTOU in file access, credit charging), error handling gaps, async correctness (missing await, unclosed resources).

Security: input validation at boundaries, no injection (command, XSS, SQL), secrets not logged, file paths sanitized (os.path.basename() in error messages).

Code quality: apply rules from backend/frontend CLAUDE.md files.

Architecture: DRY, single responsibility, modular functions. Security() vs Depends() for FastAPI auth. data: for SSE events, : comment for heartbeats. transaction=True for Redis pipelines.

Testing: edge cases covered, colocated *_test.py (backend) / __tests__/ (frontend), mocks target where symbol is used not defined, AsyncMock for async.

Output format

Every comment must be prefixed with 🤖 and a criticality badge:

| Tier | Badge | Meaning | |---|---|---| | Blocker | 🔴 **Blocker** | Must fix before merge | | Should Fix | 🟠 **Should Fix** | Important improvement | | Nice to Have | 🟡 **Nice to Have** | Minor suggestion | | Nit | 🔵 **Nit** | Style / wording |

Example: 🤖 🔴 **Blocker**: Missing error handling for X — suggest wrapping in try/except.

Post inline comments

For each finding, post an inline comment on the PR (do not just write a local report):

# Get the latest commit SHA for the PR
COMMIT_SHA=$(gh api repos/Significant-Gravitas/AutoGPT/pulls/{N} --jq '.head.sha')

# Post an inline comment on a specific file/line
gh api repos/Significant-Gravitas/AutoGPT/pulls/{N}/comments \
  -f body="🤖 🔴 **Blocker**: <description>" \
  -f commit_id="$COMMIT_SHA" \
  -f path="<file path>" \
  -F line=<line number>
Skills similaires