Install any skill in seconds. Free to start, no credit card required.
Get Started Free →First-pass GitHub PR review: OWASP Top 10, style violations, scope creep, breaking changes. Comments before the maintainer looks.
.claude/skills/mergisi-pr-first-review/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-10 | ✗→✓ | ▲ Improved | -26% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 38% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 16% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 36% | 0% |
| case-22 | ✗→✓ | ▲ Improved | -1% | 0% |
A first-pass code review for incoming pull requests. Catches the obvious things — failing tests, security anti-patterns, scope creep, breaking changes — and leaves comments before the maintainer opens the PR. The maintainer's review starts from "is this AI right?" instead of "what does this PR do?".
For every new PR (or new commit on an existing PR):
.eslintrc / .prettierrc / framework convention being violated?*.min.js, dist/), and snapshot tests.Default trigger is the GitHub pull_request.opened and pull_request.synchronize webhooks. Configure via hermes webhook list. For manual run:
/pr-first-review owner/repo#312yamlgithub: default_repo: "owner/repo" block_on_high_severity: false # set true to actually request changes skip_paths: - "package-lock.json" - "yarn.lock" - "pnpm-lock.yaml" - "**/*.min.js" - "dist/**" - "__snapshots__/**" severity_thresholds: high: ["sql_injection", "xss", "ssrf", "exposed_secret", "broken_auth"] medium: ["scope_creep", "missing_test", "style_violation"] low: ["typo", "unused_import"] comment_style: "constructive" # alternative: "terse"
PR review needs nuance — a Haiku-class model will miss security-relevant context.
Out of the box this skill produces ~10-15% false positives. Calibrate over the first 30 days:
.eslintrc or remove style from severity_thresholds.medium.metadata block.Pairs naturally with github-issue-triage — issues come in, get triaged; PRs go out, get reviewed. Both should run as the same agent under the triager personality.
The 4-agent GitHub Maintainer Team ships with this skill plus changelog automation, docs sync, and shared coordination via AGENTS.md. See crewclaw.com/use-cases/github-maintainer-team.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 8,531 | 13,458 | +58% | 1 | 1 | 0% | 709 | 2,601 | +267% | 0 | 0 | — |
case-02 | fail→fail | 10,051 | 13,396 | +33% | 1 | 1 | 0% | 846 | 2,579 | +205% | 0 | 0 | — |
case-03 | pass→pass | 5,458 | 3,384 | -38% | 1 | 1 | 0% | 1,169 | 1,782 | +52% | 0 | 0 | — |
case-04 | pass→pass | 14,391 | 5,685 | -60% | 1 | 1 | 0% | 2,501 | 2,237 | -11% | 0 | 0 | — |
case-05 | pass→pass | 9,353 | 5,294 | -43% | 1 | 1 | 0% | 1,754 | 2,101 | +20% | 0 | 0 | — |
case-06 | pass→pass | 10,699 | 10,313 | -4% | 1 | 1 | 0% | 1,920 | 3,008 | +57% | 0 | 0 | — |
case-07 | pass→pass | 9,465 | 7,444 | -21% | 1 | 1 | 0% | 1,610 | 2,445 | +52% | 0 | 0 | — |
case-08 | pass→pass | 5,806 | 3,785 | -35% | 1 | 1 | 0% | 985 | 1,850 | +88% | 0 | 0 | — |
case-09 | pass→pass | 7,277 | 4,969 | -32% | 1 | 1 | 0% | 1,060 | 2,057 | +94% | 0 | 0 | — |
case-10 | fail→pass | 14,120 | 2,658 | -81% | 1 | 1 | 0% | 2,335 | 1,720 | -26% | 0 | 0 | — |
case-11 | pass→pass | 5,217 | 2,241 | -57% | 1 | 1 | 0% | 814 | 1,574 | +93% | 0 | 0 | — |
case-12 | fail→pass | 30,874 | 5,949 | -81% | 1 | 1 | 0% | 1,585 | 2,188 | +38% | 0 | 0 | — |
case-13 | pass→pass | 18,229 | 10,331 | -43% | 1 | 1 | 0% | 3,023 | 3,012 | -0% | 0 | 0 | — |
case-14 | pass→pass | 6,143 | 4,211 | -31% | 1 | 1 | 0% | 1,034 | 1,904 | +84% | 0 | 0 | — |
case-15 | pass→pass | 5,412 | 3,697 | -32% | 1 | 1 | 0% | 1,021 | 1,840 | +80% | 0 | 0 | — |
case-16 | pass→pass | 4,817 | 3,243 | -33% | 1 | 1 | 0% | 859 | 1,706 | +99% | 0 | 0 | — |
case-17 | fail→pass | 11,344 | 15,328 | +35% | 1 | 1 | 0% | 1,883 | 2,183 | +16% | 0 | 0 | — |
case-18 | pass→pass | 16,091 | 14,750 | -8% | 1 | 1 | 0% | 2,682 | 3,530 | +32% | 0 | 0 | — |
case-19 | pass→pass | 12,331 | 1,691 | -86% | 1 | 1 | 0% | 1,910 | 1,436 | -25% | 0 | 0 | — |
case-20 | pass→pass | 18,244 | 10,430 | -43% | 1 | 1 | 0% | 3,164 | 2,992 | -5% | 0 | 0 | — |
case-21 | fail→pass | 9,729 | 18,528 | +90% | 1 | 1 | 0% | 1,746 | 2,375 | +36% | 0 | 0 | — |
case-22 | fail→pass | 13,456 | 5,663 | -58% | 1 | 1 | 0% | 2,116 | 2,090 | -1% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 21 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +23 percentage points is the difference between those two pass rates over the 21 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 8/3/2026 | +27% |
Other measured skills in the registry, with their headline benchmark lift.