Skip to content
Back to skills

Review Pr

ASecurity

Reviews the current branch's changes against its base branch as a pull request: correctness of new and modified code, test coverage for it, and documentation accuracy. Use when asked to review a branch, a diff, or a pull request.

  • 7,287 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
code-qualitybashgitdocumentation

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add trailofbits/skills --skill review-pr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review Pr?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Review Pr
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/trailofbits-review-pr/badge)](https://www.skillsdirectory.com/skills/trailofbits-review-pr)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: review-pr
description: "Reviews the current branch's changes against its base branch as a pull request: correctness of new and modified code, test coverage for it, and documentation accuracy. Use when asked to review a branch, a diff, or a pull request."
allowed-tools: Read Grep Glob Bash
---

# PR Review

Review the branch's change surface, not the whole repository.

1. Establish the diff: `git diff <base>...HEAD` (and `git diff <base>` when the working
   tree carries uncommitted changes that belong to the branch). The base branch is named
   by the caller; fall back to `main`.
2. Review every changed hunk for correctness: wrong results on edge inputs, unhandled
   error paths, and behavior that contradicts the function's name or callers.
3. Check test coverage for the changed behavior: new logic without a test exercising its
   edge cases is a finding.
4. Check documentation the diff made stale: statements in README or docs that were true
   on the base branch and are false after the change.
5. Report every defect found, each with a severity; include minor and informational
   findings. Do not report defects in files the branch did not touch — they are outside
   the pull request.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…