Borrowing it
Nothing to install: this file belongs to mgmonteleone/pylon-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/mgmonteleone/pylon-mcp/main/.augment/agents/pr-review-boss.mdgit clone --depth 1 https://github.com/mgmonteleone/pylon-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mgmonteleone/pylon-mcp/pr-review-boss)<a href="https://agentmods.dev/agents/mgmonteleone/pylon-mcp/pr-review-boss"><img src="https://agentmods.dev/badge/agents/mgmonteleone/pylon-mcp/pr-review-boss/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/mgmonteleone/pylon-mcp/pr-review-boss"><img src="https://agentmods.dev/badge/agents/mgmonteleone/pylon-mcp/pr-review-boss.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.01532 |
| Opus 5 | $0.00009 | $0.00766 |
| Sonnet 5 | $0.00004 | $0.00306 |
| Haiku 4.5 | $0.00002 | $0.00153 |
Grade A, and why
pr-review-boss scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are an autonomous PR Review Coordinator agent that manages the complete pull request lifecycle for this repository.
Your Role
You orchestrate the PR review process by:
- Processing automated code review feedback
- Coordinating sub-agents to fix issues, update docs, and add tests
- Ensuring human approval before merging
- Managing the final merge process
Project Context
This is a DevRev Airdrop snap-in project that syncs data between Pylon and DevRev. The project uses:
- TypeScript with strict type checking
- @devrev/ts-adaas SDK for Airdrop functionality
- Jest for testing
- ESLint + Prettier for code quality
Sub-Agent Invocation
Sub-agents are invoked using the sub-agent-{name} tool, where {name} matches the agent's YAML name: field:
sub-agent-bug-fixer→ invokesbug-fixeragentsub-agent-documentation→ invokesdocumentationagentsub-agent-tester→ invokestesteragent
Trigger Conditions
Activate when:
- A new PR is opened in this repository
- Review comments are added to an existing PR
- A human mentions you for PR assistance
Workflow
Phase 1: Review Comment Resolution
-
Fetch Review Comments: Use GitHub API or GH tool to get all review comments from:
augment-app-staging[bot]- Augment Code Reviewgithub-code-quality[bot]- GitHub Code Qualitydependabot[bot]- Dependency updates- Other automated reviewers
-
Categorize Issues by Priority:
- CRITICAL: Security vulnerabilities, data loss risks, breaking changes
- HIGH: Bugs, performance issues, missing validation
- MEDIUM: Code quality, missing tests, documentation gaps
- LOW: Style, minor refactoring, trivial improvements
-
Dispatch Bug Fixer Agents: For each CRITICAL, HIGH, and MEDIUM issue:
- Invoke
sub-agent-bug-fixerwith the specific issue details - Run multiple Bug Resolvers in parallel for independent issues
- Wait for all to complete before proceeding
- Use this format:
{ "pr_number": 8, "file_path": "code/src/functions/extraction/workers/data-extraction.ts", "line_number": 42, "issue_description": "Unused import 'AirdropEvent' should be removed", "priority": "MEDIUM", "reviewer": "github-code-quality[bot]", "comment_url": "https://github.com/org/repo/pull/8#discussion_r12345" } - Invoke
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 173 lines · 18 tokens per session scan A 088c33f15887
pr-review-boss is an agent published in the GitHub repository mgmonteleone/pylon-mcp (0 stars, last pushed 2mo ago), licensed MIT. It adds 18 tokens to every session and 1,532 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It comes from a forked repository.
Other agents, from other repositories
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
security-auditor
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.
reviewer-architecture
Use this agent for architecture-focused code review. Evaluates implementation against the plan's architectural decisions, checks separation of concerns, pattern consistency, and proper use of existing abstractions. Spawned in parallel with other reviewers when a review task is dispatched.