-
Notifications
You must be signed in to change notification settings - Fork 0
feat: reusable Claude PR review workflow and shared review skill #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
bokobza
wants to merge
3
commits into
main
Choose a base branch
from
jeremy/feat/no-ref/claude-review-workflow
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+200
−0
Open
Changes from all commits
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,111 @@ | ||
| --- | ||
| name: code-review | ||
| allowed-tools: Bash(gh issue view:*), Bash(gh search:*), Bash(gh issue list:*), Bash(gh pr comment:*), Bash(gh pr diff:*), Bash(gh pr view:*), Bash(gh pr list:*), Bash(gh api:*), mcp__github_inline_comment__create_inline_comment | ||
| description: Code review a pull request | ||
| --- | ||
|
|
||
| Provide a code review for the given pull request. | ||
|
|
||
| **Agent assumptions (applies to all agents and subagents):** | ||
| - All tools are functional and will work without error. Do not test tools or make exploratory calls. Make sure this is clear to every subagent that is launched. | ||
| - Only call a tool if it is required to complete the task. Every tool call should have a clear purpose. | ||
|
|
||
| To do this, follow these steps precisely: | ||
|
|
||
| 1. Launch a haiku agent to check if any of the following are true: | ||
| - The pull request is closed | ||
| - The pull request is a draft | ||
| - The pull request does not need code review (e.g. automated PR, trivial change that is obviously correct) | ||
|
|
||
| If any condition is true, stop and do not proceed. | ||
|
|
||
| Note: Still review Claude generated PRs. This review runs on every push, so a PR that was reviewed earlier is reviewed again for its new head commit. | ||
|
|
||
| 2. Launch a haiku agent to return a list of file paths (not their contents) for all relevant CLAUDE.md files including: | ||
| - The root CLAUDE.md file, if it exists | ||
| - Any CLAUDE.md files in directories containing files modified by the pull request | ||
|
|
||
| 3. Launch a sonnet agent to view the pull request and return a summary of the changes | ||
|
|
||
| 4. Launch 4 agents in parallel to independently review the changes. Each agent should return the list of issues, where each issue includes a description and the reason it was flagged (e.g. "CLAUDE.md adherence", "bug"). The agents should do the following: | ||
|
|
||
| Agents 1 + 2: CLAUDE.md compliance sonnet agents | ||
| Audit changes for CLAUDE.md compliance in parallel. Note: When evaluating CLAUDE.md compliance for a file, you should only consider CLAUDE.md files that share a file path with the file or parents. | ||
|
|
||
| Agent 3: Opus bug agent (parallel subagent with agent 4) | ||
| Scan for obvious bugs. Focus only on the diff itself without reading extra context. Flag only significant bugs; ignore nitpicks and likely false positives. Do not flag issues that you cannot validate without looking at context outside of the git diff. | ||
|
|
||
| Agent 4: Opus bug agent (parallel subagent with agent 3) | ||
| Look for problems that exist in the introduced code. This could be security issues, incorrect logic, etc. Only look for issues that fall within the changed code. | ||
|
|
||
| **CRITICAL: We only want HIGH SIGNAL issues.** Flag issues where: | ||
| - The code will fail to compile or parse (syntax errors, type errors, missing imports, unresolved references) | ||
| - The code will definitely produce wrong results regardless of inputs (clear logic errors) | ||
| - Clear, unambiguous CLAUDE.md violations where you can quote the exact rule being broken | ||
|
|
||
| Do NOT flag: | ||
| - Code style or quality concerns | ||
| - Potential issues that depend on specific inputs or state | ||
| - Subjective suggestions or improvements | ||
|
|
||
| If you are not certain an issue is real, do not flag it. False positives erode trust and waste reviewer time. | ||
|
|
||
| In addition to the above, each subagent should be told the PR title and description. This will help provide context regarding the author's intent. | ||
|
|
||
| 5. For each issue found in the previous step by agents 3 and 4, launch parallel subagents to validate the issue. These subagents should get the PR title and description along with a description of the issue. The agent's job is to review the issue to validate that the stated issue is truly an issue with high confidence. For example, if an issue such as "variable is not defined" was flagged, the subagent's job would be to validate that is actually true in the code. Another example would be CLAUDE.md issues. The agent should validate that the CLAUDE.md rule that was violated is scoped for this file and is actually violated. Use Opus subagents for bugs and logic issues, and sonnet agents for CLAUDE.md violations. | ||
|
|
||
| 6. Filter out any issues that were not validated in step 5. This step will give us our list of high signal issues for our review. | ||
|
|
||
| 7. Output a summary of the review findings to the terminal: | ||
| - If issues were found, list each issue with a brief description. | ||
| - If no issues were found, state: "No issues found. Checked for bugs and CLAUDE.md compliance." | ||
|
|
||
| If `--comment` argument was NOT provided, stop here. Do not post any GitHub comments. | ||
|
|
||
| If `--comment` argument IS provided and NO issues were found, post the summary comment and stop. End the body with the marker `<!-- trufin-claude-review -->` so later runs can find it. If an earlier run already left a comment on this PR that contains that marker and was written by the same author as this run (find it with `gh api repos/<owner>/<repo>/issues/<PR>/comments`), update that comment in place with `gh api --method PATCH repos/<owner>/<repo>/issues/comments/<id> -f body=...` instead of posting a new one. A comment without the marker belongs to someone else: never edit it. | ||
|
|
||
| If `--comment` argument IS provided and issues were found, continue to step 8. | ||
|
|
||
| 8. Create a list of all comments that you plan on leaving. This is only for you to make sure you are comfortable with the comments. Do not post this list anywhere. | ||
|
|
||
| Then fetch the inline comments already on the PR with `gh api repos/<owner>/<repo>/pulls/<PR>/comments` and drop from your list any issue an earlier run already reported — the same file, the same lines, and the same underlying problem. A different problem on a line that already carries a comment is still worth reporting. An issue that was fixed since it was reported needs no new comment. | ||
|
|
||
| 9. Post inline comments for each issue using `mcp__github_inline_comment__create_inline_comment` with `confirmed: true`. For each comment: | ||
| - Provide a brief description of the issue | ||
| - For small, self-contained fixes, include a committable suggestion block | ||
| - For larger fixes (6+ lines, structural changes, or changes spanning multiple locations), describe the issue and suggested fix without a suggestion block | ||
| - Never post a committable suggestion UNLESS committing the suggestion fixes the issue entirely. If follow up steps are required, do not leave a committable suggestion. | ||
|
|
||
| **IMPORTANT: Only post ONE comment per unique issue. Do not post duplicate comments.** | ||
|
|
||
| Use this list when evaluating issues in Steps 4 and 5 (these are false positives, do NOT flag): | ||
|
|
||
| - Pre-existing issues | ||
| - Something that appears to be a bug but is actually correct | ||
| - Pedantic nitpicks that a senior engineer would not flag | ||
| - Issues that a linter will catch (do not run the linter to verify) | ||
| - General code quality concerns (e.g., lack of test coverage, general security issues) unless explicitly required in CLAUDE.md | ||
| - Issues mentioned in CLAUDE.md but explicitly silenced in the code (e.g., via a lint ignore comment) | ||
|
|
||
| Notes: | ||
|
|
||
| - Use gh CLI to interact with GitHub (e.g., fetch pull requests, create comments). Do not use web fetch. | ||
| - Create a todo list before starting. | ||
| - You must cite and link each issue in inline comments (e.g., if referring to a CLAUDE.md, include a link to it). | ||
| - If no issues are found and `--comment` argument is provided, post a comment with the following format: | ||
|
|
||
| --- | ||
|
|
||
| ## Code review | ||
|
|
||
| No issues found. Checked for bugs and CLAUDE.md compliance. | ||
|
|
||
| --- | ||
|
|
||
| - When linking to code in inline comments, follow the following format precisely, otherwise the Markdown preview won't render correctly: https://github.com/anthropics/claude-code/blob/c21d3c10bc8e898b7ac1a2d745bdc9bc4e423afe/package.json#L10-L15 | ||
| - Requires full git sha | ||
| - You must provide the full sha. Commands like `https://github.com/owner/repo/blob/$(git rev-parse HEAD)/foo/bar` will not work, since your comment will be directly rendered in Markdown. | ||
| - Repo name must match the repo you're code reviewing | ||
| - # sign after the file name | ||
| - Line range format is L[start]-L[end] | ||
| - Provide at least 1 line of context before and after, centered on the line you are commenting about (eg. if you are commenting about lines 5-6, you should link to `L4-7`) | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,72 @@ | ||
| name: Claude Review | ||
|
|
||
| # Reusable workflow: reviews the calling repository's pull request with the | ||
| # code-review skill in this repo (.claude/skills/code-review). Findings are | ||
| # posted as inline comments on the diff, with a summary comment when nothing | ||
| # is found. Runs against the Claude subscription behind CLAUDE_CODE_OAUTH_TOKEN | ||
| # (org secret), so the only added cost is Actions minutes. | ||
| # | ||
| # Call it from a repo with: | ||
| # | ||
| # on: | ||
| # pull_request: | ||
| # types: [opened, synchronize, reopened, ready_for_review] | ||
| # jobs: | ||
| # review: | ||
| # uses: TruFin-io/.github/.github/workflows/claude-review.yml@main | ||
| # secrets: inherit | ||
|
|
||
| on: | ||
| workflow_call: | ||
| inputs: | ||
| model: | ||
| description: Model for the orchestrating agent; review sub-agents pick their own tier | ||
| type: string | ||
| default: claude-opus-5 | ||
| secrets: | ||
| CLAUDE_CODE_OAUTH_TOKEN: | ||
| required: true | ||
|
|
||
| jobs: | ||
| review: | ||
| # Drafts are skipped; marking a PR ready for review triggers the first run. | ||
| if: github.event.pull_request.draft == false | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 30 | ||
| # One review at a time per PR. A new push queues behind the running | ||
| # review instead of cancelling it. | ||
| concurrency: | ||
| group: claude-review-${{ github.event.pull_request.number }} | ||
| cancel-in-progress: false | ||
| permissions: | ||
| contents: read | ||
| pull-requests: write | ||
| issues: write | ||
| steps: | ||
| - uses: actions/checkout@v6 | ||
| with: | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
|
|
||
| - name: Fetch the shared review skill | ||
| uses: actions/checkout@v6 | ||
| with: | ||
| repository: TruFin-io/.github | ||
| path: .trufin-shared | ||
| persist-credentials: false | ||
|
|
||
| - name: Install the skill into the reviewed repo | ||
| run: | | ||
| mkdir -p .claude/skills | ||
| rm -rf .claude/skills/code-review | ||
| cp -r .trufin-shared/.claude/skills/code-review .claude/skills/code-review | ||
|
|
||
| - uses: anthropics/claude-code-action@v1 | ||
| with: | ||
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | ||
| github_token: ${{ github.token }} | ||
| allowed_bots: "dependabot[bot]" | ||
| prompt: "/code-review --comment ${{ github.repository }}/pull/${{ github.event.pull_request.number }}" | ||
| # The action starts the inline-comment MCP server only when | ||
| # --allowedTools names it, even though the skill frontmatter does too. | ||
| claude_args: --model ${{ inputs.model }} --allowedTools "mcp__github_inline_comment__create_inline_comment" | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.