dev-pr

A workflow for publishing an already-reviewed code branch for review on GitHub, GitLab, or another code-hosting service.

In plain words
What is it for?
Use it to verify repository status, rebase a feature branch, resolve and validate conflicts, push the branch safely, and open or update a pull request or merge request.
Why use it?
It checks that the branch is suitable to publish, brings it up to date with the base branch, and prevents publishing when uncommitted changes still need to be committed.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/codeaholicguy/ai-devkit/dev-pr
Any agent
npx skills add codeaholicguy/ai-devkit --skill dev-pr
Clone the repo
git clone --depth 1 https://github.com/codeaholicguy/ai-devkit

Made for: Claude Code, Codex.

Per session 45 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 578 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00045 $0.00578
Opus 5 $0.00023 $0.00289
Sonnet 5 $0.00009 $0.00116
Haiku 4.5 $0.00005 $0.00058

Measured 2d ago against content hash 9bc593922afd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dev-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/dev-pr/SKILL.md · 47 lines

How it starts

The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Dev PR

Publish an already-reviewed branch for code review. Keep this separate from commit creation: if the branch has uncommitted changes, stop and ask the user to run the commit workflow first.

Contract

  1. Verify repository context with git status -sb, git branch --show-current, and git remote -v.
  2. Confirm the branch is not the base branch and has committed changes to publish.
  3. Fetch the remote before comparing or rebasing.
  4. Rebase the feature branch onto the latest remote base branch before push/review.
  5. Resolve conflicts carefully, preserving intended behavior, then rerun relevant validation.
  6. Push safely. Use --force-with-lease only when a rebase rewrote an already-pushed branch.
  7. Open or update the host's review request: PR, merge request, or equivalent.
  8. Report review URL, branch, HEAD SHA, validation results, push mode, and risks.

Publish Workflow

  1. Inspect local context:
    • git status -sb
    • git branch --show-current
    • git remote -v
  2. If uncommitted changes exist, stop. Do not stage, amend, squash, or commit in this skill.
  3. Identify the remote and base branch from repo conventions, upstream config, or user instruction; default to origin/main only when that matches the repo.
  4. Fetch the remote, inspect the delta, and rebase onto the remote base branch.
  5. If conflicts occur, inspect conflicted files and git diff, resolve minimally, validate when useful, git add, then continue the rebase. Stop if the correct resolution is unclear.
  6. Run relevant validation for the changed surface.
  7. Push:
    • First push: set upstream.
    • Normal update: plain push.
    • Rebased already-pushed branch: --force-with-lease.
  8. Open or update the review request using the host's tool/API/UI (gh, glab, forge CLI, web UI, or project-specific workflow).
  9. Write a concise review description. Include enough for reviewers to understand:
    • Summary: what changed, why, and how.
    • Validation: how it was verified.
    • Risks: notable risks or "none known".
  10. Report:
  • Review URL and state
  • Branch and HEAD SHA
  • Validation commands and exit codes
  • Push mode, including whether --force-with-lease was used
  • Risks, follow-ups, or blockers

Read the full file on GitHub · 47 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 47 lines · 45 tokens per session scan A 9bc593922afd

Subscribe to this mod's changes

dev-pr is a skill published in the GitHub repository codeaholicguy/ai-devkit (1,601 stars, last pushed 2d ago), licensed MIT. It adds 45 tokens to every session and 578 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

tmux

Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.

HKUDS/nanobot · 22 tokens

summarize

Summarize or extract text/transcripts from URLs, podcasts, and local files (great fallback for “transcribe this YouTube/video”).

HKUDS/nanobot · 32 tokens

foundry-config-setup

Resolve missing setup caused by a hardcoded Foundry project endpoint or model in a sample. Use when a sample fails because it uses a placeholder/hardcoded projectendpoint (for example "https://your-project.services.ai.azure.com") or a hardcoded model instead of reading them from the environment.

microsoft/agent-framework · 65 tokens

complete-partial-pr

Evaluate and complete an issue or PR where the submitted patch fixes only a narrow symptom of the reported pain point. Use when a contribution may miss adjacent integration surfaces, provider/spec semantics, roundtrip behavior, tests, docs, or historical maintainer decisions.

pydantic/pydantic-ai · 55 tokens

hive.chart-creation-foundations

Required reading whenever any chart tool is available. Teaches the one-tool embedding contract (call chartrender → live chart appears in chat AND a downloadable PNG lands in the queen session dir), the ECharts (data viz) vs Mermaid (structural diagrams) decision, the BI/financial-grade aesthetic baseline (no…

aden-hive/hive · 133 tokens

peon-ping-log

Log exercise reps for the Peon Trainer. Use when user says they did pushups, squats, or wants to log reps. Examples - "/peon-ping-log 25 pushups", "/peon-ping-log 30 squats", "log 50 pushups".

PeonPing/peon-ping · 64 tokens