Use this skill when posting the final summary comment after all inline comments are posted. Apply as the LAST step of code review after all findings are classified and inline comments are complete. Detects context (agent mode sticky comment, GitHub Actions MCP tool, or local file) and routes output accordingly.
npx skills add https://github.com/bitwarden/ai-plugins --skill posting-review-summary
Check contexts in this order — use the first match:
| Context | How to Detect | Action |
| ------------------------- | ------------------------------------------------------------------------------------------------ | ------------------------------------------------- |
| Agent Mode | Sticky comment context provided in prompt (comment ID + <!-- bitwarden-code-review --> marker) | Write summary to /tmp/review-summary.md |
| GitHub Actions (tag mode) | mcp__github_comment__update_claude_comment available AND no sticky comment context | Update sticky comment via MCP tool |
| Local review | Neither agent mode context nor MCP tool available | Write to review-summary.md in working directory |
FORBIDDEN: Do not use gh pr comment to create summary comments.
If PR title, description, or test plan is genuinely deficient, add as a finding in the Code Review Details collapsible section.
Genuinely deficient means:
Adequate (DO NOT flag):
- ❓ **QUESTION**: PR title could be more specific
- Suggested: "Fix null check in UserService.getProfile"
## 🤖 Bitwarden Claude Code Review
**Overall Assessment:** APPROVE / REQUEST CHANGES
[Up to 4 neutral sentences describing what was reviewed]
<details>
<summary>Code Review Details</summary>
[Findings grouped by severity - see ordering below]
[Optional PR Metadata Assessment - only for truly deficient metadata]
</details>
When the PR diff includes dependency manifest file changes, add a Dependency Changes subsection inside the <details> block, after the findings list and before the optional PR Metadata Assessment.
Only render this table when there are meaningful version changes — not for lock file-only churn with no manifest changes.
### Dependency Changes
| Package | Change | Ecosystem |
| ----------------- | --------------------- | --------- |
| `@foo/bar` | New (1.2.0) | npm |
| `lodash` | 3.x → 4.x (**major**) | npm |
| `Newtonsoft.Json` | 13.0.1 → 13.0.3 | NuGet |
| `old-package` | Removed | npm |
Bold the word "major" for major version bumps. Mark new additions as "New (version)" and removals as "Removed".
Ordering: Group findings by severity in this exact order:
Omit empty categories entirely.
Format per finding:
- [emoji]: [One-line description]
- `filename.ts:42`
Example:
<details>
<summary>Code Review Details</summary>
- ❌ : SQL injection in user query builder
- `src/auth/queries.ts:87`
- ⚠️ : Missing null check on optional config
- `src/config/loader.ts:23`
</details>
When sticky comment context is provided in the prompt (comment ID + marker):
/tmp/review-summary.md using the Write tool\n\n<!-- bitwarden-code-review --> at the end of the file contentmcp__github_comment__update_claude_commentgh pr comment or gh apiThe workflow post-step will read this file and update the placeholder comment automatically.
Use mcp__github_comment__update_claude_comment to update the sticky comment with the summary.
Write summary to review-summary.md in working directory.
Use when the user asks to run Gemini CLI for code review, plan review, or big context (>200k) processing. Ideal for comprehensive analysis requiring large context windows. Uses Gemini 3 Pro by default for state-of-the-art reasoning and coding.
Claude Skills meta-skill: extract domain material (docs/APIs/code/specs) into a reusable Skill (SKILL.md + references/scripts/assets), and refactor existing Skills for clarity, activation reliability, and quality gates.
> Pedantic backend pre-commit and atomic commit Skill for Django/Optimo-style repos. Enforces local AGENTS.md / CLAUDE.md, pre-commit hooks, .security/* helpers, and Monty’s backend engineering taste – with no AI signatures in commit messages.
Automatically backs up files, saves diffs, uses agents/skills, and ensures modular code (<200 lines) before any implementation. Use this skill for ALL code changes to ensure safe, reversible, and clean implementations.
Use when you've developed a broadly useful skill and want to contribute it upstream via pull request - guides process of branching, committing, pushing, and creating PR to contribute skills back to upstream repository
Default reference pipeline for the code-migration taskKind — code-import → design-extract → token-map → rewrite-plan → patch-edit ↔ build-test devloop → diff-review → handoff.
Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.
> Check installed community skills for updates. Shows a diff and requires explicit approval before applying. Use when the user says "check for updates", "update my skills", "anything new for my installed skills", or when invoked from the registry-sync agent.
Take bitwarden/posting-review-summary from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.