mcpbeat Sign in

Github Review Iteration Skill for Cursor

Orchestrates a GitHub PR review loop by delegating triage and implementation to dedicated sub-agents, then repeating until actionable review items are cleared. Use when the user says “address PR review”, “triage review comments”, or “iterate until review is clean”.

4k tokens
context cost
the whole folder, loaded on every use
4
files
ships runnable scripts
0
copies elsewhere
how many repositories repackaged it
418
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/prisma/prisma --skill github-review-iteration

What comes with it

7 249 bytes besides the instruction
agents/review-orchestrator.md
package.json
scripts/review-iterate.mjs

What it tells the agent to use

found in the instruction text
Task spawns other agents

The instruction itself

14 sections, as written by the author

GitHub Review Iteration

Run an iterative PR review loop: fetch state → render/summarize → triage actions → implement (code + Done + resolve) → re-fetch until the PR has no remaining actionable items.

This skill is an orchestrator. It delegates:

  • triage to ../review-triage-phase/agents/review-triager.md
  • implementation to ../review-implement-phase/agents/review-implementer.md

The orchestrator owns sequencing, handoff, and loop control. It does not perform triage or implementation directly when delegation is available.

Locating sibling skills and scripts

This skill depends on three sibling skills that live in the same parent directory:

  • ../review-fetch-phase/ — fetches and renders PR review state
  • ../review-triage-phase/ — triages review threads into an action plan
  • ../review-implement-phase/ — implements triaged actions and resolves threads

All script paths in this document are relative to this skill's directory. Use ../ to reach sibling skills. Do not search the workspace/repo for these files — they are part of the skills installation, not the project being reviewed.

Usage

This skill supports subcommands:

  • triage: fetch + triage into structured actions
  • implement: execute the triaged actions and update status
  • iterate: loop triageimplement until clear (default)
/github-review-iteration iterate <PR_URL> [output-dir]

When output-dir is omitted, use the standard layout: wip/reviews/<owner>_<repo>_pr-<number>/ (derived from PR URL).

Example:

/github-review-iteration iterate https://github.com/OWNER/REPO/pull/123

Files written (deterministic layout)

Store artifacts under:

wip/reviews/<owner>_<repo>_pr-<number>/

Canonical artifacts:

  • review-state.json (canonical v2)
  • review-actions.json (canonical v2)

Derived artifacts:

  • review-state.md
  • summary.txt (or JSON summary)
  • review-actions.md
  • apply-log.json (optional)

When you need a thin wrapper for path setup + standard script calls, run:

node ./scripts/review-iterate.mjs --pr <PR_URL>

For phase-specific execution without full orchestration, use:

  • /review-fetch-phase <PR_URL> [output-dir]
  • /review-triage-phase <PR_URL> [output-dir]
  • /review-implement-phase <PR_URL> [output-dir]

Behavioral rules

  • WILL ADDRESS items:
  • reply + 👍
  • leave unresolved until fixed
  • Not addressed in this PR items:
  • reply with rationale + 👎
  • resolve the thread
  • Implementation:
  • granular, intent-driven commits
  • explicit staging only (never git add -A / git add .)
  • reply “Done” and resolve when complete

Operational reliability notes (Cursor)

gh api TLS / cert failures in sandboxed shells

If GitHub administration fails with an error like:

  • x509: OSStatus -26276 (or similar TLS/certificate verification failures)

Treat it as an environment/sandbox cert-store mismatch, not a script bug.

Recovery:

  • Re-run the affected gh calls outside the sandbox (use a shell mode that uses the system cert store).
  • Do not disable TLS verification (no GH_NO_VERIFY_SSL, no custom curl flags).
  • After re-running, continue the loop normally (fetch → triage → implement → resolve → repeat).

JSON-first deterministic commands

All script paths below are relative to this skill's directory.

  • Fetch canonical JSON:
node ../review-fetch-phase/scripts/fetch-review-state.mjs --pr <PR_URL> --out-json <review-dir>/review-state.json
  • Render and summarize from JSON (pure scripts):
node ../review-fetch-phase/scripts/render-review-state.mjs --in <review-dir>/review-state.json --out <review-dir>/review-state.md
node ../review-fetch-phase/scripts/summarize-review-state.mjs --in <review-dir>/review-state.json --format text --out <review-dir>/summary.txt
  • Render triage plan from canonical actions JSON:
node ../review-triage-phase/scripts/render-review-actions.mjs --in <review-dir>/review-actions.json --out <review-dir>/review-actions.md

Data exchange format (triager → implementer)

review-actions.json is the contract between the triager and implementer.

Minimum v2 shape:

{
  "version": 2,
  "pr": { "url": "https://github.com/OWNER/REPO/pull/123", "nodeId": "PR_kw..." },
  "reviewState": { "path": "review-state.json", "fetchedAt": "...", "version": 2 },
  "actions": [
    {
      "actionId": "A-001",
      "target": { "kind": "review_thread", "nodeId": "PRRT_xxx", "url": "..." },
      "decision": "will_address",
      "summary": "One-line description of what will be done",
      "rationale": null,
      "targetFiles": ["path/to/file.ts"],
      "acceptance": "How to tell it's done",
      "status": "pending",
      "done": null
    }
  ]
}

Rules:

  • Use node ids only for targets (target.nodeId).
  • Preserve actions[] order intentionally (do not reorder).
  • Implementer updates status (pending|in_progress|done) and done records in place.
  • Compound targets: A single pull_request_review body may contain multiple findings (especially from automated reviewers like CodeRabbit which bundle "outside diff range" comments into the review body). The triager must decompose these into sub-actions (e.g., A02a, A02b). Never blanket-dismiss review bodies without reading their content.

Procedure

triage

  • Delegate to triage sub-agent

Invoke the review triager agent at ../review-triage-phase/agents/review-triager.md and pass:

  • PR URL
  • output paths:
  • <output-dir>/review-state.md
  • <output-dir>/review-state.json
  • <output-dir>/review-actions.md
  • <output-dir>/review-actions.json
  • optional scope constraints
  • Require triage outputs

The triager must:

  • fetch review state (via ../review-fetch-phase/scripts/fetch-review-state.mjs)
  • triage review threads into review-actions.json decisions/status
  • write/update review-actions.md and review-actions.json
  • Validate handoff contract

Before returning from triage, verify that <output-dir>/review-actions.json exists and is valid for implementer consumption (version, PR metadata, and actions[] with target.kind + target.nodeId).

implement

  • Delegate to implementation sub-agent

Invoke the review implementer agent at ../review-implement-phase/agents/review-implementer.md and pass:

  • PR URL
  • <output-dir>/review-actions.md
  • <output-dir>/review-actions.json
  • optional scope constraints
  • Require implementation outputs

The implementer must:

  • work through pending will_address actions
  • make focused, explicit-staging commits
  • run smallest relevant checks per action
  • reply "On it" when starting, then "Done" and resolve the thread when complete
  • update review-actions.json in-place (status, done)
  • re-fetch review state at the end to verify remaining actionable items

Responsibility note:

  • Posting "Done" and resolving completed threads belongs to the implementer phase and is part of marking actions done.

iterate

Repeat delegated triage → delegated implement until there are no remaining actionable review items.

Loop contract:

  • Run triage delegation and read resulting review-actions.json.
  • Inspect review-actions.json; if no will_address actions remain with pending or in_progress status, stop and report completion.
  • Run implement delegation.
  • Re-run triage delegation to refresh state and determine next iteration.
  • Continue until clear.

Optional shortcuts (repo-specific)

If this repo provides dedicated slash commands or subagents for triage/implementation, prefer them to reduce manual steps.

Other skills for the same job

different authors, same section of the catalogue
Gemini
by softaworks
×2

Use when the user asks to run Gemini CLI for code review, plan review, or big context (>200k) processing. Ideal for comprehensive analysis requiring large context windows. Uses Gemini 3 Pro by default for state-of-the-art reasoning and coding.

5k tokens
Claude Skills
by ComeOnOliver
×2

Claude Skills meta-skill: extract domain material (docs/APIs/code/specs) into a reusable Skill (SKILL.md + references/scripts/assets), and refactor existing Skills for clarity, activation reliability, and quality gates.

13k tokens scripts
Backend Atomic Commit
by ComeOnOliver
×1

> Pedantic backend pre-commit and atomic commit Skill for Django/Optimo-style repos. Enforces local AGENTS.md / CLAUDE.md, pre-commit hooks, .security/* helpers, and Monty’s backend engineering taste – with no AI signatures in commit messages.

14k tokens
Safe Edit
by ComeOnOliver
×1

Automatically backs up files, saves diffs, uses agents/skills, and ensures modular code (<200 lines) before any implementation. Use this skill for ALL code changes to ensure safe, reversible, and clean implementations.

11k tokens
Sharing Skills
by ComeOnOliver
×1

Use when you've developed a broadly useful skill and want to contribute it upstream via pull request - guides process of branching, committing, pushing, and creating PR to contribute skills back to upstream repository

4k tokens
Od Code Migration
by nexu-io

Default reference pipeline for the code-migration taskKind — code-import → design-extract → token-map → rewrite-plan → patch-edit ↔ build-test devloop → diff-review → handoff.

4k tokens
Review Agent Setup
by wshobson

Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.

1k tokens
Auto Updater
by anthropics
vendor

> Check installed community skills for updates. Shows a diff and requires explicit approval before applying. Use when the user says "check for updates", "update my skills", "anything new for my installed skills", or when invoked from the registry-sync agent.

2k tokens

How to use it

Copy the folder

Take prisma/github-review-iteration from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.