when-reviewing-github-pr-use-github-code-review
Agent TeamsでGitHubプルリクエストをレビュー
セキュリティ、パフォーマンス、テスト、ドキュメントのすべてに注意が必要な場合、手作業のPRレビューは時間がかかります。このスキルは、専門化されたClaude、Codex、またはClaude Codeエージェントを調整し、構造化されたマージ判断の指針を作成します。
この Skill を自動インストールしないでください。
基準ポリシーにより、インストール操作の前にオペレーターのレビューが必要です。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "when-reviewing-github-pr-use-github-code-review" from https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review.md and its manifest at https://skillstore.io/api/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「when-reviewing-github-pr-use-github-code-review」を使用しています。 小規模なバックエンド認証PRをレビューする。
期待される結果:
レポートには、ブロッキングとなる認可の問題が1件、テストギャップが2件、変更要求の推奨が記載されます。
「when-reviewing-github-pr-use-github-code-review」を使用しています。 パフォーマンスリファクタリングのマージ準備状況を評価する。
期待される結果:
レビューはコメント付き承認の判断を示し、クエリ動作の改善に言及し、ベンチマーク更新を1件要求します。
「when-reviewing-github-pr-use-github-code-review」を使用しています。 公開API変更に関するドキュメントとテストカバレッジをレビューする。
期待される結果:
要約では、移行メモの不足、弱いエッジケーステスト、メンテナー向けの明確なアクション項目が指摘されます。
セキュリティ監査
重大All 46 static findings are false positives caused by Markdown backticks and fenced code blocks, not Ruby shell execution. Manual review found separate security risks in the workflow: untrusted relative script execution, unpinned npx package execution, and GitHub state mutation without a confirmation gate. No prompt injection text was found in the reviewed files.
確認済みのセキュリティ上の懸念 (3)
リスク要因
⚙️ 外部コマンド (46)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
DNYoussef. (2026). when-reviewing-github-pr-use-github-code-review security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/audits/10BibTeX形式の引用
@techreport{dnyoussef-dnyoussef-when-reviewing-github-pr-use-github-code-review-2026,
author = {DNYoussef},
title = {when-reviewing-github-pr-use-github-code-review security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "when-reviewing-github-pr-use-github-code-review security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "DNYoussef"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/dnyoussef-when-reviewing-github-pr-use-github-code-review/audits/10"
identifiers:
- type: other
value: "skillstore:dnyoussef-when-reviewing-github-pr-use-github-code-review:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
マージ前レビュー
機能ブランチのマージを承認する前に、構造化されたレビューを実行します。
セキュリティ重視のPR監査
機密性の高い変更に対して、セキュリティ、依存関係、認可のチェックを調整します。
大規模変更のトリアージ
大きなプルリクエストを重点レビュー領域に分割し、ブロッカーを要約します。
これらのプロンプトを試す
Review PR <url> with this skill. Produce a local report covering security, performance, quality, tests, and documentation. Do not post comments.
Use this skill on these changed files: <files>. Identify merge blockers, test gaps, and documentation needs. Return prioritized action items.
Review PR <url> and calculate merge readiness. Explain the score by category. Separate blocking issues from recommended improvements.
Run the full multi-agent review for PR <url>. Ask before running shell commands or writing to GitHub. Produce the final review draft locally.
ベストプラクティス
- シェルコマンドや外部ツールを有効にする前に、リポジトリの信頼性を確認します。
- まずローカルレポートを生成し、人間によるレビュー後にGitHubコメントを投稿します。
- マージ準備状況スコアを使用する前に、プロジェクト固有のレビュー基準を提供します。
回避
- 信頼できないプルリクエストワークスペースから参照スクリプトを実行すること。
- 人間による確認なしに自動承認やラベル変更を許可すること。
- エージェントの所見を、必須の人間によるコードオーナーレビューの代替として扱うこと。
よくある質問
このスキルは何をしますか?
GitHub認証情報は必要ですか?
レビューコメントを自動投稿できますか?
参照されているスクリプトは含まれていますか?
どのツールをサポートしていますか?
信頼できないプルリクエストに対して安全ですか?
開発者情報
作成者
DNYoussefライセンス
MIT
Skillstore リビジョン
r1
バージョンに関する注意
作者はバージョンを宣言していません。
参照
0519034dad657fb1f7706e0550e962beeda73fdf
メンテナンスの新しさ
2026/7/26
利用状況
4 ダウンロード · 174 閲覧
ファイル構成