Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add restarter/lets-workflow --skill loop-gh-prgit clone --depth 1 https://github.com/restarter/lets-workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/restarter/lets-workflow/loop-gh-pr)<a href="https://agentmods.dev/skills/restarter/lets-workflow/loop-gh-pr"><img src="https://agentmods.dev/badge/skills/restarter/lets-workflow/loop-gh-pr/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/restarter/lets-workflow/loop-gh-pr"><img src="https://agentmods.dev/badge/skills/restarter/lets-workflow/loop-gh-pr.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00118 | $0.02757 |
| Opus 5.5 | $0.00047 | $0.01103 |
| Sonnet 5.5 | $0.00024 | $0.00551 |
| Haiku 4.5 | $0.00012 | $0.00276 |
Grade A, and why
loop-gh-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 166 lines — stays where its author put it; the contents beside it link to each section on GitHub.
loop-gh-pr
Compose a /loop that periodically lists open GitHub PRs via gh, detects what is new since the last tick (new PR / new commits / new comments), auto-runs a READ-ONLY /lets:review <N> --json draft for each code change, fires a lets cmux notify, and reschedules - WITHOUT ever posting to a PR.
The skill never invokes /loop itself - Claude Code's /loop is a UI command. It composes the prompt and presents it for paste; once active, the autonomous run uses ScheduleWakeup per tick.
Autonomy boundary (the whole point): /lets:review --json is read-only - it computes findings and posts NOTHING. So the loop safely auto-runs review. Posting (inline / general / approve / merge) is ALWAYS the human's call, out-of-band. The loop stops at a ready draft in .lets/reviews/ + a notification and keeps watching. Never saw -> reviewed -> posted.
IMPORTANT: If the spec below invokes any deferred tool (e.g.
AskUserQuestion), you MUST load and call it as specified.
Step 1: Pre-flight (always run)
Confirm github flow + gh auth + that listing PRs works, before composing a long-lived loop.
LETS_PROJECT_ROOT=$(git rev-parse --show-toplevel)
# 1. github flow only (v1). LETS_PR_FLOW is substituted by the orchestrator from LETS Config.
# If LETS_PR_FLOW != github -> surface "loop-gh-pr is github-only in v1 (LETS_PR_FLOW={value});
# bitbucket waits on lets-6pxvm" and exit.
# 2. gh present + authed
gh auth status 2>&1 | head -5 || { echo "gh not authed - run: gh auth login"; exit 1; }
# 3. smoke: list open PRs (the watch set). If `comments` is rejected as a list field,
# drop it here and have the loop fall back to per-PR `gh pr view <N> --json comments`.
gh pr list --state open --json number,title,headRefOid,isDraft,url,updatedAt,comments --limit 30 2>&1 | head -40
Surface a short summary of the current open non-draft PRs (number, title, head SHA short, comment count) so the user sees exactly what the loop will watch. If gh auth status fails -> surface and exit. If gh pr list errors (e.g. not a GitHub remote) -> surface verbatim and exit. Never compose a loop the autonomous run cannot execute.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 166 lines · 118 tokens per session scan A 9a408058af1a
loop-gh-pr is a skill published in the GitHub repository restarter/lets-workflow (17 stars, last pushed today), licensed MIT. It adds 118 tokens to every session and 2,757 once invoked, about $0.0005 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-24.
Other skills, from other repositories
requesting-code-review
Use when implementation is done and you need a structured pre-PR review workflow. Triggers: 'ready for review', 'review my changes before PR', 'pre-merge check', 'is this ready', 'submit for review'. NOT for: post-merge review (use code-review) or deciding how to integrate (use finishing-a-development-branch).
commit-pr-convention
Format rules for commit messages, PR titles, PR bodies and branch names — the prefix vocabulary, the language the repository states in seal/config.md, where a translated body lives, and how to check a title against the repository's own history. Use when: writing a commit message, opening a pull request, naming a…
commit
Commit the current session's changes only, gateway-inline. Session-isolated (never -A, staged set verified against the session list), doc-sync-gated. The gateway runs the commit inline — it already holds the diff, session file list, and change intent; on a mechanical gate hit it judges doc-sync warm in its own context…
git
This skill should be used when the user asks to "commit changes", "create a pull request", "rebase safely", "manage branches", "fix merge conflicts", "undo a commit", "comment on a PR", "create a release", or performs any git/GitHub operations. Provides safety patterns, atomic commit formatting, PR descriptions…
comprehensive-review-pr-enhance
You are a PR optimization expert specializing in creating high-quality pull requests that facilitate efficient code reviews. Generate comprehensive PR descriptions, automate review processes, and ensure PRs follow best practices for clarity, size, and reviewability.
batch-review
Review multiple related change sets for integration coherence and safe merge ordering.