create-pr

A workflow for creating or updating a GitHub pull request, which is a request for others to review and merge code changes. It prepares the request from the current branch and its complete difference from the target branch.

In plain words
What is it for?
Use it to check the branch and target, review the full change set, handle needed base-branch updates, and prepare the pull request title, description, validation notes, and issue link.
Why use it?
It reduces the chance that a pull request contains accidental files, secrets, unresolved conflicts, or missing validation. It also keeps an existing open request updated instead of creating a duplicate.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/terry-mao/aicodingflow/create-pr
Any agent
npx skills add Terry-Mao/AICodingFlow --skill create-pr
Clone the repo
git clone --depth 1 https://github.com/Terry-Mao/AICodingFlow

Made for: Claude Code, Codex.

Per session 18 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 433 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00018 $0.00433
Opus 5 $0.00009 $0.00217
Sonnet 5 $0.00004 $0.00087
Haiku 4.5 $0.00002 $0.00043

Measured 2d ago against content hash f0b495ec0c08, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

create-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/create-pr/SKILL.md · 50 lines

What it actually says

create-pr

Use this after git-push when the user asks to create, update, or open a pull request. It prepares PR metadata; it does not implement code, commit, push, or modify issues.

Prepare

Inspect the current branch, worktree, and repository default PR base. A dirty worktree must be intentionally excluded before continuing. Review the complete base-to-head diff for accidental files, secrets, conflict markers, generated churn, and missing validation. Sync the base into the branch when needed; if that creates conflicts, resolve, validate, commit, and push the resolution.

Build a concise title and body from the issue, branch, commits, or user request. Include summary, validation, and a known issue link (Closes, Fixes, or Refs). Never invent an issue ID.

Create or update

First check only for an open PR from the current branch. Do not use gh pr view as the existence check because it may resolve a previously merged or closed PR:

pr_url="$(gh pr list --state open --head "$branch" --json url --jq '.[0].url' --limit 1)"

If an open PR exists, read its current body, preserve manual content, and update it:

gh pr edit "$pr_url" --title "$title" --body-file "$body_file"

Otherwise create a new PR. A merged or closed PR with the same branch name is not reusable:

gh pr create --base "$base" --head "$branch" --title "$title" --body-file "$body_file"

Pass generated values as separate quoted arguments; never interpolate untrusted text into shell syntax. If gh is unavailable or unauthenticated, report the exact base, head, title, and body for manual creation.

Report the PR URL, base/head, title, validation, and whether the base was synced.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 50 lines · 18 tokens per session scan A f0b495ec0c08

Subscribe to this mod's changes

create-pr is a skill published in the GitHub repository Terry-Mao/AICodingFlow (165 stars, last pushed 4d ago), licensed MIT. It adds 18 tokens to every session and 433 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

babysit-pr

Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…

openai/codex · 114 tokens

imagegen

Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…

openai/codex · 113 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

next-cache-components-optimizer

Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…

vercel/next.js · 170 tokens