What problem does it solve?
Pull request reviews often miss critical security issues, lack consistency, and provide unstructured feedback that is hard to act on. This Skill automates comprehensive analysis with mandatory security checklists, risk-based mode escalation, and structured findings that ship as inline comments.
Core Features & Use Cases
- Smart-Default Mode: Runs full security pass, risk scoring, and content-type detection automatically without requiring flags.
- Security Checklist (S1-S15): Mandatory scan for recurring security pitfalls including auth bypass, secret leakage, injection, and supply chain risks.
- Risk-Based Escalation: Auto-promotes to three-role adversarial council or cross-model copilot verification based on blast radius and diff content.
- Content-Type Awareness: Detects doc, skill, rule, template, spec, infra, and code changes to calibrate severity and trigger oracle completeness checks.
- Cross-Check Consistency: Validates same-type files against each other and cross-references prescriptive content against reference repositories.
Quick Start
Use the pr-review skill to analyze pull request 123 and post the findings inline after you confirm the authorization.