Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Pr Ready

ASecurity

Run the pre-submit gauntlet (security-audit, code-review, simplify, review-polish) over a change before opening or merging a PR.

13,119 stars
0 votes
0 copies
1 views
Added 9/20/2026
researchrustgobashcode-reviewgitsecurity

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add rommapp/romm --skill pr-ready --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pr Ready?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Pr Ready
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rommapp-pr-ready/badge)](https://www.skillsdirectory.com/skills/rommapp-pr-ready)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: pr-ready
description: Run the pre-submit gauntlet (security-audit, code-review, simplify, review-polish) over a change before opening or merging a PR.
argument-hint: "[PR number | branch | nothing for the current branch]"
disable-model-invocation: true
---

# PR-ready gauntlet

Run the four review passes RomM applies to every non-trivial PR, in this order,
over one fixed range. Do not skip a step or reorder them.

## Target

`$ARGUMENTS` is a PR number, a branch, or nothing (the current branch). Resolve
it to a fetched target and derive `$RANGE` before step 1, then reuse `$RANGE`
for every step. `HEAD` is the right target only when `$ARGUMENTS` is empty, so
run the dispatch rather than assuming it: skip it and all four passes review the
current checkout instead of what was asked for.

```bash
set -eu

git fetch origin master

case "$ARGUMENTS" in
"") TARGET="$(git rev-parse HEAD)" ;;
# a pull ref needs its own refspec, the fetch above will not create it
*[!0-9]*) git fetch origin "$ARGUMENTS"; TARGET="$(git rev-parse FETCH_HEAD)" ;;
*) git fetch origin "pull/$ARGUMENTS/head"; TARGET="$(git rev-parse FETCH_HEAD)" ;;
esac

RANGE="$(git merge-base origin/master "$TARGET")..$TARGET"
```

An all-digit argument is a PR number, anything else is a branch.

`set -e` is load-bearing here, because each failure otherwise fails open. A base
fetch that dies on the network, an argument that resolves to nothing, a missing
merge base: each leaves a side of `$RANGE` empty, and git reads an empty side as
`HEAD`, so `..$TARGET` is a valid range over the wrong commits rather than an
error. Abort on the first failure instead of handing four passes a range built
without the thing you asked them to review.

## Before steps 2 to 4

Step 1 is read-only and runs against `$RANGE` from wherever you are. The rest
are not: they rewrite files and run the repository's own code from the target
ref, including test runners, builds, `trunk`, package lifecycle scripts, and git
hooks. A clean step 1 verdict is no substitute for that, since an audit can miss
what it is looking for. So run steps 2 to 4 only on a ref you trust. On anything
else, stop after step 1 and report, or run the rest in an isolated environment
with no credentials and no network.

They also need the target checked out. Checking out a fetched sha detaches
`HEAD`, where each step's commits belong to no branch and go away on the next
switch, so give the work a branch first:

```bash
git switch -c "pr-ready/$(git rev-parse --short "$TARGET")" "$TARGET"
```

Those commits are local either way. They reach the PR only if you can push to
its source branch, so on a fork you cannot write to, the summary is the
deliverable and the commits are not.

Skip the branch when the target is already the current one. There, uncommitted
work counts as part of the change under review: commit or stash anything
unrelated first, so each step's edits stay attributable.

## Steps

1. **`security-audit`** over `$RANGE`. Read-only. Stop on a `malicious`
   verdict; `needs attention` is a finding for step 2, not a stop.
2. **`code-review` at `xhigh` with `--fix`**, targeting the resolved target
   rather than "the current diff", so it sees the whole change.
3. **`simplify`**, after the correctness fixes so it can simplify those too.
4. **`review-polish`** last: its verification gate has to cover everything the
   earlier steps rewrote, and `trunk fmt` has to run after the final edit.

Commit after each step that changes files, naming the step in the message. A bad
automated fix is then one `git revert` away instead of tangled with three other
passes.

Finish with one consolidated summary rather than four transcripts: the security
verdict, what steps 2 and 3 changed by area, which checks ran and their results,
and anything still needing a human decision.

The summary also carries what the PR description needs and the transcripts hold: the
screenshots step 4 captured, which the PR body references and `gh ... --attach` uploads
under the `Screenshots` heading, and the `mermaid` block for a change that moved a
boundary.

Four passes in one session is a lot of context. For a very large diff, run the
steps in separate sessions against the same `$RANGE`.

Attribution

rommapprommapp
View sourceMore from rommapp →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Competitor Analysis

This skill provides comprehensive analysis of competitor SEO and GEO strategies, revealing what's working in your market and identifying opportunities to outperform the competition.

1823 votes

Deep Research

Universal deep research agent team. 13-agent pipeline for rigorous academic research on any topic. 8 modes: full research, quick brief, paper review, lit-review, fact-check, three-way literature scan, Socratic guided research dialogue, and systematic review with optional meta-analysis. Covers research question formulation, Socratic mentoring, methodology design, systematic literature search, source verification, cross-source synthesis, risk of bias assessment, meta-analysis, APA 7.0 report co...

494352 votes

Paperclip Distill

Use when an operation issue is a Paperclip cursor-window, distill, or backfill — `operationType: "distill"` or `"backfill"` and the body references a Paperclip source bundle for a project or root issue. Turn raw Paperclip activity into a wiki-insightful project page, decisions log, and history note. This skill exists specifically to replace the stiff, datestamp-heavy templated output that the deterministic distiller produces.

813271 votes

Academic Pipeline

Orchestrator for the full academic research pipeline: research -> write -> integrity check -> review -> revise -> re-review -> re-revise -> final integrity check -> finalize. Coordinates deep-research, academic-paper, and academic-paper-reviewer into a seamless 10-stage workflow with mandatory, coverage-bounded integrity checks, two-stage peer review, and auditable quality-assurance artifacts. Triggers on: academic pipeline, research to paper, full paper workflow, paper pipeline, end-to-end p...

494351 votes

Exa Search

Semantic search, similar content discovery, and structured research using Exa API

304951 votes
View all in research →