autofix

autofix is a skill for Claude Code from octopusreview/octopus-plugin. It costs 63 tokens per session (1,452 once invoked), scanned A, original, MIT.

A workflow for finding comments from the Octopus review bot on your open pull requests and applying the requested fixes. It then commits and pushes valid changes.

In plain words
What is it for?
Use it to address Octopus bot findings across your open pull requests and start another review after the fixes are pushed.
Why use it?
It removes the repetitive work of reading review comments, changing code, updating discussions, and sending fixes back to the pull request.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter.

Part of the octopus-review plugin — 2 skills, 1 command, 1 MCP server shipped together

Good fit Use it to address Octopus bot findings across your open pull requests and start another review after the fixes are pushed.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/octopusreview/octopus-plugin/autofix
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add octopusreview/octopus-plugin --skill autofix
Clone the repo
git clone --depth 1 https://github.com/octopusreview/octopus-plugin

Made for: Claude Code.

Or install octopus-review, the plugin that ships this one along with the rest of its 2 skills, 1 command, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for autofix

README.md
[![agentmods](https://agentmods.dev/badge/skills/octopusreview/octopus-plugin/autofix/github.svg)](https://agentmods.dev/skills/octopusreview/octopus-plugin/autofix)
Your own site
<a href="https://agentmods.dev/skills/octopusreview/octopus-plugin/autofix"><img src="https://agentmods.dev/badge/skills/octopusreview/octopus-plugin/autofix/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for autofix

Your own site · 80×15
<a href="https://agentmods.dev/skills/octopusreview/octopus-plugin/autofix"><img src="https://agentmods.dev/badge/skills/octopusreview/octopus-plugin/autofix.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 63 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,452 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00063 $0.01452
Opus 5 $0.00032 $0.00726
Sonnet 5 $0.00013 $0.00290
Haiku 4.5 $0.00006 $0.00145

Measured 11d ago against content hash ebfd2a8c5b69, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

autofix scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/octopus-review/skills/autofix/SKILL.md · 133 lines

How it starts

The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Octopus Autofix

Review all open PRs for pending reviews and requested changes from the Octopus Review bot (octopus-review[bot]). Apply the necessary fixes, commit them, and push the updates.

IMPORTANT: Only process review comments authored by octopus-review[bot]. Ignore comments from any other source (CodeRabbit, Greptile, Copilot, human reviewers, etc.).

Rules:

  • Ignore false-positive feedback.
  • For each false positive, react to the comment with 👎 and explain.
  • For each valid and useful suggestion, react to the comment with 👍.
  • After fixing a valid issue, reply in the relevant review thread with a brief note describing the fix.
  • Resolve the thread/conversation after replying, if resolving is supported.
  • If thread resolution is not supported, leave a reply clearly stating that the issue has been addressed.

Once all fixes are applied and pushed, re-trigger an Octopus review of the PR (see Step 6).

Instructions

Follow these steps carefully and in order:

Step 1: Discover Open PRs

  1. Save the current branch name: git branch --show-current
  2. List open PRs authored by the current user:
    gh pr list --author "@me" --state open --json number,title,headRefName,reviewDecision,url
    
  3. If no open PRs exist, inform the user and stop.
  4. Display the list of open PRs with their review status to the user.

Step 2: Check Reviews for Each PR

For each open PR (or a specific PR if the user provided a number as argument $ARGUMENTS):

  1. Fetch review comments and review threads:
    gh pr view <number> --json reviews,reviewRequests,comments,title,headRefName,url
    gh api repos/{owner}/{repo}/pulls/<number>/comments --jq '.[] | select(.user.login == "octopus-review[bot]") | {id, path, line, body, user: .user.login, created_at}'
    gh api repos/{owner}/{repo}/pulls/<number>/reviews --jq '.[] | select(.user.login == "octopus-review[bot]") | {id, state, body, user: .user.login}'
    
  2. Also check for inline review comments (conversation threads):
    gh pr view <number> --comments --json comments
    
  3. Check if the latest Octopus Review bot review has 0 findings:
    • Look at the most recent review/comment from octopus-review[bot]
    • If the latest bot comment contains "0 findings" (e.g., "5 files reviewed, 0 findings"), this means all previous issues have been resolved
    • In this case, skip this PR entirely — there is nothing to fix. Inform the user: "PR #X: Latest review shows 0 findings — all issues resolved, skipping."
  4. Filter for actionable feedback from octopus-review[bot] only:
    • Reviews with state CHANGES_REQUESTED
    • Unresolved review comments (inline code suggestions, requested changes)
    • General PR comments that contain action items
  5. Skip PRs that have no actionable feedback from the bot (state is APPROVED or no reviews).

Read the full file on GitHub · 133 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 133 lines · 63 tokens per session scan A ebfd2a8c5b69

Subscribe to this mod's changes

autofix is a skill published in the GitHub repository octopusreview/octopus-plugin (0 stars, last pushed 10d ago), licensed MIT. It adds 63 tokens to every session and 1,452 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

review-implement-phase

Implements triaged review actions, commits focused fixes, and posts Done plus resolves threads. Use when the user wants only the implementation phase of the review-framework workflow.

prisma/orm · 38 tokens

engram-branch-pr

PR creation workflow for Engram following the issue-first enforcement system. Trigger: When creating a pull request, opening a PR, or preparing changes for review.

Gentleman-Programming/engram · 37 tokens

verify-behavior

Verify or reproduce visible product behavior by driving the real UI with pi-computer-use's checked tools, requiring verified expect postconditions and durable state evidence for meaningful UI flows. Use when triage needs visual reproduction, implementation needs behavioral proof, review needs interactive confirmation…

nicknisi/dotfiles · 68 tokens

github-contributor

End-to-end playbook for shipping high-quality pull requests to open-source projects you don't maintain — discovery, CONTRIBUTING compliance, PR-size check, minimal-diff implementation, PR description with AI-assisted disclosure, conflict resolution, and post-submission maintainer interaction. Use whenever creating…

daymade/claude-code-skills · 133 tokens

revdiff

Review diffs, files, and documents with inline annotations in a TUI overlay, or answer questions about revdiff usage, configuration, themes, and keybindings. Opens revdiff in agterm/tmux/zellij/herdr/kitty/wezterm/cmux/ghostty/iterm2/emacs-vterm, captures annotations, and addresses them. Works in git, hg, and jj repos…

umputun/revdiff · 248 tokens

oss-maintainer

Run an open-source project's issue/PR/release loop like a careful human maintainer — triage to root cause, absorb community PRs before duplicating them, gate every merge, ship honest releases, and thank the people doing your QA for free.

debpalash/VoiceStudio · 55 tokens