Skip to content
Back to skills

Pr Code Reviewer

ASecurity

Review a unified diff for bugs, security issues, and risks. Output to review.md with severity and recommended fix. Triggered by 'review this PR', 'review this diff', or running on diff.patch in the working directory.

  • 13 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentssqlcode-reviewsecurity

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add nano-step/eval-harness --skill pr-code-reviewer --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pr Code Reviewer?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Pr Code Reviewer
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nano-step-pr-code-reviewer/badge)](https://www.skillsdirectory.com/skills/nano-step-pr-code-reviewer)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: pr-code-reviewer
description: Review a unified diff for bugs, security issues, and risks. Output to review.md with severity and recommended fix. Triggered by 'review this PR', 'review this diff', or running on diff.patch in the working directory.
version: 0.1.0
---

# pr-code-reviewer (eval-harness demo skill)

Reads `diff.patch` from the working directory. Produces `review.md`.

## Method

1. Parse the diff into hunks
2. For each changed function/block, identify:
   - Security regressions (SQL injection, XSS, command injection, auth bypass)
   - Correctness regressions (race conditions, partial-failure, data loss)
   - Behavior regressions vs. the pre-change version
3. Tag each finding with severity: CRITICAL / HIGH / MEDIUM / LOW
4. For each non-LOW finding, recommend a concrete fix
5. If no findings of severity ≥ MEDIUM, write "Approve" / "LGTM" with brief rationale

## Output format (review.md)

```md
# Code Review: <PR description>

## Severity: <CRITICAL|HIGH|MEDIUM|LOW|APPROVE>

## Findings

### 1. <Finding title> (<severity>)
- File: <path>:<line>
- Issue: ...
- Recommended fix: ...
```

## Anti-patterns

- Demanding tests/docs on a trivial rename
- Stylistic preferences masquerading as blockers
- Vague "consider X" without explanation
- Missing CRITICAL issues to spend tokens on cosmetics

Files in this skill

  • SKILL.md1.3 KB
  • evals/cases/missing-error-handling-must-flag.yaml1.1 KB
  • evals/cases/rename-trivial-must-approve.yaml939 B
  • evals/cases/sql-injection-must-flag.yaml976 B
  • evals/fixtures/pr-missing-error-handling.diff424 B
  • evals/fixtures/pr-rename-trivial.diff271 B
  • evals/fixtures/pr-sql-injection.diff446 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…