pr-review
Address feedback left on a GitHub pull request: fetch unresolved review threads, make agreed Elixir/Phoenix code fixes, reply, and resolve. Use for …
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
PR Review Response
Close the review loop: fetch unresolved threads → fix → reply → resolve.
GitHub's isResolved is the state — re-runs are idempotent, handled
threads drop out automatically.
Usage
/phx:pr-review 42 # Triage unresolved threads on PR #42
/phx:pr-review 42 --fix # Triage + apply approved code fixes
/phx:pr-review https://... # Full URL also works (repo parsed from URL)
/phx:pr-review 42 --bots-only # Triage only CI bot threads (Copilot, Codex...)
/phx:pr-review 42 --no-resolve # Reply but leave threads open
Step 1: Resolve PR + Fetch Threads
gh pr view "$PR" --json number,title,state,baseRefName,headRefName,url,author
(accepts number or URL; URL also yields owner/repo). Then fetch ALL review
threads with thread IDs + resolved status — REST alone cannot do this:
cat > /tmp/review_threads.graphql <<'GQL'
query($owner:String!, $repo:String!, $pr:Int!, $cursor:String) {
repository(owner:$owner, name:$repo) {
pullRequest(number:$pr) {
reviewThreads(first:50, after:$cursor) {
pageInfo { hasNextPage endCursor }
nodes {
id isResolved isOutdated path line originalLine
comments(first:20) { nodes {
databaseId body createdAt
author { login __typename } } }
}
}
}
}
}
GQL
gh api graphql --paginate -F owner="$OWNER" -F repo="$REPO" -F pr="$PR" \
-F query=@/tmp/review_threads.graphql \
--jq '.data.repository.pullRequest.reviewThreads.nodes[]
| select(.isResolved == false)
| {threadId: .id, isOutdated, path, line: (.line // .originalLine),
firstCommentId: .comments.nodes[0].databaseId,
author: .comments.nodes[0].author.login,
isBot: (.comments.nodes[0].author.__typename == "Bot"),
body: .comments.nodes[0].body}'
Also fetch review summaries (gh api "repos/$OWNER/$REPO/pulls/$PR/reviews")
— they are NOT threads and cannot be resolved; surface CHANGES_REQUESTED
bodies separately. Bot detection: __typename == "Bot" / user.type == "Bot"
(the [bot] login suffix is NOT reliable across endpoints).
Step 2: Triage Table
Group by file, one row per thread. With --bots-only, keep only isBot rows.
| # | file:line | author | category | proposed action |
|---|-----------|--------|----------|-----------------|
Categories: code-change ("should be", "use X instead") · question
("why", "how does") · nitpick ("nit:", style) · praise (no action) ·
discussion (architecture) · bot-finding (CI bot inline comment —
verify before accepting, many are false positives) · outdated
(isOutdated: true — line moved; default: reply "addressed in {commit}" +
resolve). Present the table and let the user greenlight threads.
Step 3: Per-Thread Loop
For each greenlit thread:
- Read code at
path:line; check the suggestion against Iron Laws - Apply fix with a user-visible diff (only with
--fixor explicit ok) - Draft reply (templates:
${CLAUDE_SKILL_DIR}/references/response-patterns.md) - STOP — show diff + reply, get confirmation
- Post reply — REST, targeting the thread's root comment:
gh api --method POST \
"repos/$OWNER/$REPO/pulls/$PR/comments/$FIRST_COMMENT_ID/replies" \
-f body="$REPLY_TEXT"
- Resolve the thread (skip with
--no-resolve):
gh api graphql -f query='mutation($threadId:ID!){
resolveReviewThread(input:{threadId:$threadId}){
thread { id isResolved } }}' -F threadId="$THREAD_ID"
Mistake recovery: unresolveReviewThread takes the same input shape.
Step 4: Verify
mix compile --warnings-as-errors && mix test scoped to changed files.
Do NOT commit or push — leave that to the user.
Step 5: Final Summary
Print rollup: # | thread | action | status (replied/resolved/skipped).
List changed files. Optionally post a top-level conversation comment
(gh api --method POST "repos/$OWNER/$REPO/issues/$PR/comments" -f body=...)
with the rollup — only on user approval.
Iron Laws
- NEVER auto-post responses — Always show drafts and get explicit approval
- NEVER dismiss a review — Only the reviewer should dismiss
- Iron Laws override reviewer suggestions — If a suggestion violates an Iron Law, explain why in the reply
- Keep responses constructive — Acknowledge the feedback, explain reasoning
- Separate fixes from responses — Apply code changes in a distinct step
- NEVER resolve a thread without first posting a reply — every resolve is preceded by a reply on that thread explaining what was done
- NEVER claim a fix without a shown diff — no "should be fixed" replies without a user-visible change
- Bot findings get the same scrutiny as humans — decline Iron-Law-violating bot suggestions with explanation; never bulk-resolve "bot noise" without replies
Integration
PR receives review → /phx:pr-review {number} ← YOU ARE HERE
↓ fetch unresolved threads (GraphQL, paginated)
↓ triage table → user greenlights
↓ per thread: fix (diff) → reply → resolve
↓ verify (mix compile + test) → summary
Push changes → user handles git push
Next Steps
/phx:plan— if findings reveal scope gaps/phx:verify— full verification before pushing- Re-run
/phx:pr-reviewafter the next review round (idempotent)
References
${CLAUDE_SKILL_DIR}/references/response-patterns.md— Response templates and tone${CLAUDE_SKILL_DIR}/references/gh-commands.md— Full gh command reference (3 comment surfaces, pagination, bot detection)${CLAUDE_SKILL_DIR}/references/bot-triage.md— Batch-triaging CI bot review passes
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/elixir-phoenix/skills/pr-review/SKILL.md