with one click
review-pr
// Review a PR on action-artifacts (GitHub Action for Scality Artifacts service lifecycle management)
// Review a PR on action-artifacts (GitHub Action for Scality Artifacts service lifecycle management)
| name | review-pr |
| description | Review a PR on action-artifacts (GitHub Action for Scality Artifacts service lifecycle management) |
| argument-hint | <pr-number-or-url> |
| disable-model-invocation | true |
| allowed-tools | Read, Bash(gh repo view *), Bash(gh pr view *), Bash(gh pr diff *), Bash(gh pr comment *), Bash(gh api *), Bash(git diff *), Bash(git log *), Bash(git show *) |
You are an expert code reviewer. Review this PR: $ARGUMENTS
Parse $ARGUMENTS to extract the repo and PR number:
REPO: and PR_NUMBER: (CI mode), use those values directly.https://github.com/), extract owner/repo and the PR number from it.gh repo view --json nameWithOwner -q .nameWithOwner.REPO: and PR_NUMBER:): post inline comments and summary to GitHub.gh pr view <number> --repo <owner/repo> --json title,body,headRefOid,author,files
gh pr diff <number> --repo <owner/repo>
Read changed files to understand the full context around each change (not just the diff hunks).
Analyze the changes against these criteria:
| Area | What to check |
|---|---|
| dist/ sync | If src/ files changed, dist/index.js must also be updated. Missing dist rebuild is a common CI failure. |
| TypeScript strictness | No any casts that bypass type safety, no ! non-null assertions without justification, proper return type annotations on exported functions. |
| Async error handling | Uncaught promise rejections, missing await, .catch() omitted, errors swallowed silently in retry loops (utils.ts). |
| Axios HTTP calls | Check status codes are handled, timeouts are set, error messages surface the upstream response body. |
| Input validation | New action inputs in action.yaml must be reflected in inputs-artifacts.ts and constants.ts. Required inputs should be validated early; missing required inputs should fail fast with a clear message. |
| Retry logic | Retried operations should be idempotent; verify new upload/API calls are wrapped with retry where appropriate (utils.ts retry helper). |
| GitHub Actions output | New outputs declared in action.yaml must be set via core.setOutput(); missing outputs silently break downstream ${{ steps.X.outputs.Y }} references. |
| Secrets / credentials | No tokens, passwords, or API keys hardcoded or logged. Ensure artifact credentials (user, password) are not exposed in log output. |
| Breaking changes | Changes to action.yaml inputs/outputs (renames, removals, type changes) break all callers that pin to this action. Flag anything that changes the public interface. |
| Security | Command injection via @actions/exec if user-controlled input is passed to shell without sanitization. SSRF risk if URLs are constructed from untrusted inputs. |
For each specific issue, post a comment on the exact file and line:
gh api -X POST -H "Accept: application/vnd.github+json" "repos/<owner/repo>/pulls/<number>/comments" -f body="Your comment<br><br>ā Claude Code" -f path="path/to/file" -F line=<line_number> -f side="RIGHT" -f commit_id="<headRefOid>"
The command must stay on a single bash line. Never use newlines in bash commands ā use <br> for line breaks in comment bodies. Never put <br> inside code blocks or suggestion blocks.
Each inline comment must:
```suggestion
corrected-line-here
```
Only suggest when you can show the exact replacement. For architectural or design issues, just describe the problem.
Example with a suggestion block:
gh api ... -f body=$'Missing the shared-guidelines update command.<br><br>\n```suggestion\n/plugin update shared-guidelines@scality-agent-hub\n/plugin update scality-skills@scality-agent-hub\n```\n<br><br>ā Claude Code' ...
$'...' quoting with \n for code fence boundaries. Escape single quotes as \' (e.g., don\'t)ā Claude CodeUse the line number from the new version of the file (the line number you'd see after the PR is merged), which corresponds to the line parameter in the GitHub API.
gh pr comment <number> --repo <owner/repo> --body "LGTM<br><br>Review by Claude Code"
The command must stay on a single bash line. Never use newlines in bash commands ā use <br> for line breaks in comment bodies.
Do not describe or summarize the PR. For each issue, state the problem on one line, then list one or more suggestions below it:
- <issue>
- <suggestion>
- <suggestion>
If no issues: just say "LGTM". End with: Review by Claude Code
Do NOT post anything to GitHub. Instead, output the review directly as text.
For each issue found, output:
**<file_path>:<line_number>** ā <what's wrong and how to fix it>
When the fix is a concrete line change, include a fenced code block showing the suggested replacement.
At the end, output a summary section listing all issues. If no issues: just say "LGTM".
End with: Review by Claude Code