Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add WhatIfWeDigDeeper/agent-skills --skill pr-commentsgit clone --depth 1 https://github.com/WhatIfWeDigDeeper/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/whatifwedigdeeper/agent-skills/pr-comments)<a href="https://agentmods.dev/skills/whatifwedigdeeper/agent-skills/pr-comments"><img src="https://agentmods.dev/badge/skills/whatifwedigdeeper/agent-skills/pr-comments/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/whatifwedigdeeper/agent-skills/pr-comments"><img src="https://agentmods.dev/badge/skills/whatifwedigdeeper/agent-skills/pr-comments.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00115 | $0.12529 |
| Opus 5 | $0.00057 | $0.06265 |
| Sonnet 5 | $0.00023 | $0.02506 |
| Haiku 4.5 | $0.00012 | $0.01253 |
Grade A, and why
pr-comments scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 530 lines — stays where its author put it; the contents beside it link to each section on GitHub.
PR Review: Implement and Respond to Review Comments
Work through open PR review threads — implement valid suggestions, explain why invalid ones won't be addressed, and close the loop by resolving threads and committing with commenter credit.
Arguments
The argument is the text following the skill invocation (in Claude Code: /pr-comments 42); other assistants may pass it differently.
- Optional PR number (e.g.
42or#42). If omitted, detect from the current branch. --manualrestores the confirmation gates skipped by the default auto mode (Step 7 and Step 13); it is sticky.--max Ncaps bot-review loop iterations (default 10).--all(auto mode only) disables the Step 6d nits-only halt: every comment, including a pure-nit round, is auto-fixed as before. It is a boolean (no value) and is ignored under--manual(manual already gates every round at Step 7).- If
$ARGUMENTSishelp,--help,-h, or?, print usage and exit.
Parse and validate before any shell call. You must now execute references/argument-parsing.md for the full strip/precedence/stickiness/validation rules — Step 1 below restates the validation order, and the validation itself is a Security model mitigation (see Security model).
| Invocation | Mode | Iterations |
|---|---|---|
/pr-comments |
auto | 10 |
/pr-comments 42 |
auto | 10 |
/pr-comments --max 5 |
auto | 5 |
/pr-comments --max 1 |
auto | 1 (one pass, no looping) |
/pr-comments --manual |
manual | n/a |
/pr-comments --manual 42 |
manual | n/a |
/pr-comments --manual --auto |
manual | n/a (--manual is sticky) |
/pr-comments --max 5 42 |
auto | 5 |
/pr-comments --all |
auto | 10 (nits-only halt disabled) |
A digit token after --auto is read as the cap, not a PR number (--auto 42 → cap 42, no PR) — to pair --auto with a PR number, use 42 --auto. See references/argument-parsing.md → "--auto + PR-number disambiguation".
Tool choice rationale
What ships with it
13 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/argument-parsing.md 4.0 KB
- references/bot-polling.md 35 KB
- references/bot-review-surfaces.md 5.3 KB
- references/commenter-ref.md 3.6 KB
- references/consistency-scans.md 5.0 KB
- references/error-handling.md 2.0 KB
- references/graphql-queries.md 2.1 KB
- references/instruction-rule-check.md 1.8 KB
- references/nit-gate.md 7.3 KB
- references/reply-formats.md 6.8 KB
- references/report-templates.md 4.1 KB
- references/security-model.md 6.1 KB
- references/security.md 4.8 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 530 lines · 115 tokens per session scan A 7f368b50ff1e
pr-comments is a skill published in the GitHub repository WhatIfWeDigDeeper/agent-skills (2 stars, last pushed 16d ago), licensed MIT. It adds 115 tokens to every session and 12,529 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
understand-diff
Use when you need to analyze git diffs or pull requests to understand what changed, affected components, and risks.
pre-publish-review
Nuclear-grade 12-agent pre-publish release gate. Runs /get-unpublished-changes to detect all changes since last npm release, spawns up to 10 ultrabrain agents for deep per-change analysis, invokes /review-work (orchestrator manual QA plus one gate reviewer) for holistic review, and 1 oracle for overall release…
work-with-pr
Full PR lifecycle in a fresh task-owned git worktree: implement via the ulw-loop skill with mandatory evidence-bound manual QA → reviewer-readable English PR → verification loop (CI + Cubic, where Cubic is skipped only when its quota is exhausted) → merge by default → worktree cleanup. Decomposes one task into the…
pr-review
Address feedback left on a GitHub pull request: fetch unresolved review threads, make agreed Elixir/Phoenix code fixes, reply, and resolve. Use for a PR URL/number or reviewer comments. NOT for pre-PR review, findings triage, or CI monitoring.
phx-pr-review
Address feedback left on a GitHub pull request: fetch unresolved review threads, make agreed Elixir/Phoenix code fixes, reply, and resolve. Use for a PR URL/number or reviewer comments. NOT for pre-PR review, findings triage, or CI monitoring.
resolve-pr-comments
Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments. Handles both change requests (fix or skip) and reviewer questions (explain using reasoning recalled from past Claude Code transcripts). Use when the user asks to "resolve PR comments", "fix review comments", "address PR…