alan-review-pr
Review GitHub Pull Requests with Alan
Pull request reviews often miss context or produce vague feedback. This skill gathers GitHub evidence and posts focused, line-specific findings through Alan MCP tools.
インストール前に停止して確認を求めてください。
計画を確認し、ファイルを変更する前にユーザーの明示的な同意を得てください。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "alan-review-pr" from https://skillstore.io/skills/supatest-ai-alan-review-pr.md and its manifest at https://skillstore.io/api/skills/supatest-ai-alan-review-pr/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「alan-review-pr」を使用しています。 Review owner/payments#42 and focus on security regressions.
期待される結果:
Blocking: Missing authorization check in the updated refund handler. The review identifies the affected line, explains the unauthorized refund scenario, and proposes a focused repair.
「alan-review-pr」を使用しています。 Review the current repository pull request number 87.
期待される結果:
- Important: Retry handling can submit the same operation twice after a timeout.
- Nit: The new error branch lacks a meaningful assertion in its test.
- Summary: Two findings, with CI status and links to each inline comment.
セキュリティ監査
高リスクMost static findings are false positives caused by Markdown backticks or examples that explicitly prohibit credential access. Three Alan URLs are real low-risk network references, while session URL publication, untrusted PR content, and automatic review posting create meaningful semantic risks.
確認済みのセキュリティ上の懸念 (3)
機能レビュー項目 (3)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (4)
📁 ファイルシステムへのアクセス (2)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/supatest-ai-alan-review-pr/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/supatest-ai-alan-review-pr?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/supatest-ai-alan-review-pr?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/supatest-ai-alan-review-pr/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/supatest-ai-alan-review-pr.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
supatest-ai. (2026). alan-review-pr security audit report (audit version 1) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/supatest-ai-alan-review-pr/audits/1BibTeX形式の引用
@techreport{supatest-ai-supatest-ai-alan-review-pr-2026,
author = {supatest-ai},
title = {alan-review-pr security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/supatest-ai-alan-review-pr/audits/1},
note = {Author version 1.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "alan-review-pr security audit report (audit version 1)"
version: "1.0.0"
type: report
authors:
- name: "supatest-ai"
date-released: "2026-08-20"
url: "https://skillstore.io/skills/supatest-ai-alan-review-pr/audits/1"
identifiers:
- type: other
value: "skillstore:supatest-ai-alan-review-pr:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
Review a Maintainer Pull Request
Inspect a pending change and publish focused feedback before merge.
Screen Security-Sensitive Changes
Check authentication, input handling, and secret management changes for concrete vulnerabilities.
Standardize Team Review Quality
Apply consistent severity, confidence, and comment formats across pull requests.
これらのプロンプトを試す
Review owner/repository#42. Analyze the changed code and prepare evidence-based inline findings.
Review https://github.com/owner/repository/pull/42. Include CI status, existing discussion, and only issues introduced by this pull request.
Review owner/repository#42. Prioritize authentication, injection, validation, race conditions, and missing tests. Exclude style-only feedback.
Review owner/repository#42 for release readiness. Correlate the diff, full files, prior comments, and CI results. Report only findings above 90 percent confidence.
ベストプラクティス
- Provide a complete PR URL or repository reference to avoid remote resolution errors.
- Review the proposed comments and session links before authorizing GitHub writes.
- Use focused review priorities when the pull request affects sensitive or critical systems.
回避
- Do not use the skill when Alan GitHub MCP tools are unavailable.
- Do not treat generated findings as a substitute for tests or human approval.
- Do not publish private session URLs or sensitive repository details in review comments.
よくある質問
Which pull request formats are supported?
Does this skill require GitHub credentials?
Does the skill post comments automatically?
What issues does the review prioritize?
Can it read failed CI logs?
Will it report existing repository problems?
開発者情報
作成者
supatest-aiライセンス
MIT
作者バージョン
v1.0.0
Skillstore リビジョン
r1
参照
bdb71a4bc34515f37772ae85fd5501f9c2ff33b0
メンテナンスの新しさ
2026/8/20
利用状況
0 ダウンロード · 0 閲覧
ファイル構成
📄 SKILL.md