post

A command that posts an existing code-review report to the current GitLab merge request, including inline comments on changed lines and a summary comment.

In plain words
What is it for?
Use it after a code review has already produced a report to publish location-specific findings and the final review summary on the GitLab merge request.
Why use it?
It sends review findings to the right discussion without running the review again or inventing new findings.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/fprochazka/claude-code-plugins/post
Clone the repo
git clone --depth 1 https://github.com/fprochazka/claude-code-plugins
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,214 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.01214
Opus 5 $0.00010 $0.00607
Sonnet 5 $0.00004 $0.00243
Haiku 4.5 $0.00002 $0.00121

Measured 2d ago against content hash 00ab5c3ed358, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

post scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/code-review/commands/post.md · 123 lines

How it starts

The opening of the file, as written. The whole thing — 123 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Post Code Review to MR

Post the code-review report from this session to the current GitLab merge request as a combination of inline diff comments (for findings anchored to specific file/line locations) and one standalone summary comment (for everything else plus the final verdict).

This command only posts. It does not re-run the review and it does not re-analyze the diff. If no review report exists in this session, stop and tell the user to run /code-review:full first.

Phase 1 — Locate the report (in-session only)

The report must already exist in this session's conversation history, produced by an earlier /code-review:full run. Do NOT search the filesystem, do NOT re-derive findings from the diff, do NOT re-launch review agents.

  • If you can see the report in the current session context → proceed.
  • If you cannot → stop immediately and reply with:

    No code-review report found in this session. Run /code-review:full first, then re-run /code-review:post.

Do not invent findings. Use only what the existing report says.

Phase 2 — Load tooling

Before making any GitLab calls, invoke the glab-discussion skill to load its usage guidance for MR diff comments, replies, and standalone discussions.

If the skill is unavailable, stop and tell the user.

Phase 3 — Identify the target MR

You should already know the MR from the /code-review:full context loaded earlier in this session. Use that MR. If the MR is ambiguous or missing, ask the user for the MR URL before posting anything.

Phase 4 — Plan the comment placement

Group every finding from the report into exactly one of two buckets:

  • Inline diff comment — the finding clearly points at a specific file (and ideally a specific line / hunk) in the MR diff.
  • Summary comment — the finding is cross-cutting, architectural, about commit hygiene, about release/rollout, about something not visible in the diff, or otherwise has no good single anchor.

Every finding ends up exactly once — never both.

Read the full file on GitHub · 123 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 123 lines · 20 tokens per session scan A 00ab5c3ed358

Subscribe to this mod's changes

post is a command published in the GitHub repository fprochazka/claude-code-plugins (11 stars, last pushed 4d ago), licensed MIT. It adds 20 tokens to every session and 1,214 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.