pr-review
Reviews pull requests with scope validation, requirements compliance, and line comments Skill: pr-review Owner: athola Summary: Reviews pull requests with scope validation, requirements compliance, and line comments Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:20:39.575Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:40:42.486Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:57:35.890Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:05:27.217Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-sanctum-pr-review- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-sanctum-pr-review/snapshot"
Documentation
CLAWHUB
145,762 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: pr-review
description: |
Reviews pull requests with scope validation, requirements compliance, and line comments
version: 1.9.8
triggers:
- pr
- review
- scope
- github
- gitlab
- code-quality
- knowledge-capture
- cross-platform
- reviewing GitHub or GitLab PRs
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/sanctum", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.leyline:git-platform", "night-market.sanctum:shared", "night-market.sanctum:git-workspace-review", "night-market.sanctum:version-updates", "night-market.pensive:unified-review", "night-market.imbue:proof-of-work", "night-market.imbue:justify", "night-market.memory-palace:review-chamber", "night-market.scribe:slop-detector", "night-market.scribe:doc-generator"]}}}
source: claude-night-market
source_plugin: sanctum
---
> **Night Market Skill** — ported from [claude-night-market/sanctum](https://github.com/athola/claude-night-market/tree/master/plugins/sanctum). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
## Table of Contents
- [Core Principle](#core-principle)
- [When to Use](#when-to-use)
- [Scope Classification Framework](#scope-classification-framework)
- [Classification Examples](#classification-examples)
- [Workflow](#workflow)
- [Phase 1: Establish Scope Baseline](#phase-1-establish-scope-baseline)
- [Phase 2: Gather Changes](#phase-2-gather-changes)
- [Phase 3: Requirements Validation](#phase-3-requirements-validation)
- [Phase 1.5: Version Validation (MANDATORY)](#phase-15-version-validation-mandatory)
- [Phase 4: Code Review with Scope Context](#phase-4-code-review-with-scope-context)
- [Phase 4.5: Additive Bias Audit](#phase-45-additive-bias-audit)
- [Phase 5: Backlog Triage](#phase-5-backlog-triage)
- [Phase 6: Generate Report](#phase-6-generate-report)
- [Phase 7: Knowledge Capture](#phase-7-knowledge-capture)
- [Quality Gates](#quality-gates)
- [Anti-Patterns to Avoid](#anti-patterns-to-avoid)
- [Don't: Scope Creep Review](#dont-scope-creep-review)
- [Don't: Perfect is Enemy of Good](#dont-perfect-is-enemy-of-good)
- [Don't: Blocking on Style](#dont-blocking-on-style)
- [Don't: Reviewing Unchanged Code](#dont-reviewing-unchanged-code)
- [Integration with Other Tools](#integration-with-other-tools)
- [Exit Criteria](#exit-criteria)
# Scope-Focused PR Review
Review pull/merge requests with discipline: validate against original requirements, prevent scope creep, and route out-of-scope findings to issues on the detected platform.
**Platform detection is automatic** via `leyline:git-platform`. Use `gh` for GitHub, `glab` for GitLab. Check session context for `git_platform:`.
## Core Principle
**A PR review validates scope compliance, not code perfection.**
The goal is to validate the implementation meets its stated requirements without introducing regressions. Improvements beyond the scope belong in future PRs.
## When To U_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-sanctum-pr-review",
"version": "1.9.19",
"publishedAt": 1787750439575
}modules/comment-guidelines.md
# Code Comment Quality Guidelines
Guidance on when and how to write effective code comments that add value without bloat.
## Core Philosophy: Why, Not What
Good comments explain **why** code exists, not **what** it does. The code already shows what it does.
| Comment Type | Value | Example |
|--------------|-------|---------|
| **Why** | High | "Use exponential backoff to handle transient API failures" |
| **What** | Low | "Loop through the array" |
| **Context** | High | "AWS Lambda has 15-min timeout, so max 3 retries" |
| **Obvious** | Negative | "Increment counter by 1" |
## When Comments Are Warranted
### Require Comments For
| Scenario | Reason | Example |
|----------|--------|---------|
| **Non-obvious behavior** | Future readers will wonder why | Edge case handling |
| **Business logic decisions** | Domain knowledge not in code | "Tax calculated per 2024 regulations" |
| **Performance optimizations** | Why this approach over simpler one | "O(1) lookup vs O(n) iteration" |
| **Workarounds** | Temporary fixes need context | "TODO: Remove after #123 fixed" |
| **Algorithm complexity** | Complex logic needs explanation | Mathematical formulas |
| **External constraints** | Dependencies, APIs, limits | "API rate limit: 100 req/min" |
### Don't Require Comments For
| Scenario | Alternative |
|----------|-------------|
| Self-explanatory code | Good naming |
| Simple CRUD operations | Patterns speak |
| Well-named functions | Function name = documentation |
| Standard patterns | Convention over comment |
## Examples
### Good Comments (Explain Why)
```python
def retry_with_backoff(max_attempts=3):
"""Retry with exponential backoff for transient failures.
AWS Lambda has a 15-minute timeout, so max_attempts=3 prevents
exceeding this limit with our 1s/2s/4s backoff strategy.
"""
...
# Use set for O(1) membership testing instead of list O(n)
# Critical for processing 100k+ items in batch jobs
seen_ids = set()
```
### Bad Comments (Explain What - Avoid These)
```python
# Bad: Restates code
i = 0 # Set i to 0
# Bad: Obvious from code
if user_input == "": # Check if user_input is empty string
return DEFAULT_VALUE
# Bad: Redundant docstring
def add(a, b):
"""Add two numbers and return the result."""
return a + b
```
## Anti-Patterns
### Over-Commenting (Bloat)
**Problem**: Too many comments obscure code and become maintenance burden.
**Symptoms**:
- Comment-to-code ratio > 1:3
- Comments on every line
- Comments restating variable names
**Solution**: Improve code clarity instead. Better names, smaller functions.
### Stale Comments (Out of Sync)
**Problem**: Comments that don't match current code behavior are worse than no comments.
**Symptoms**:
- Function behavior changed, comment didn't
- TODO comments for completed work
- References to deleted code
**Solution**: Update comments with code changes. Delete outdated TODOs.
### Commented-Out Code
**Problem**: Dead code clutters codebase and conmodules/educational-insights.md
---
name: educational-insights
description: >-
Enrich PR review findings with educational context:
why the fix matters, proof via best-practice links,
and teachable moments that grow the implementer.
parent_skill: sanctum:pr-review
category: review-infrastructure
tags: [education, insights, best-practices, teaching]
estimated_tokens: 300
---
# Educational Insights for PR Review Findings
Every finding in a PR review is a learning opportunity.
Each reported issue, suggestion, or error MUST include
educational context so the review improves both the code
and the person who wrote it.
## The Three Pillars
Each finding includes three educational elements:
| Pillar | Purpose | Content |
|--------|---------|---------|
| **Why It Matters** | Explain the principle | 1-2 sentences on the underlying concept |
| **Proof** | Link to authoritative source | URL to docs, standard, or guide |
| **Teachable Moment** | Generalize the lesson | How this pattern applies beyond this PR |
## Enriched Finding Format
Every finding entry (BLOCKING, IN-SCOPE, SUGGESTION)
MUST use this extended format:
```markdown
1. [S1] Missing input validation on user-supplied path
- **Location**: `api/handlers.py:45`
- **Issue**: Path traversal possible via `../` in filename
- **Why**: Unsanitized file paths allow directory traversal
attacks (CWE-22). An attacker can read or overwrite
files outside the intended directory.
- **Proof**: [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal)
- **Teachable Moment**: Always normalize paths with
`os.path.realpath()` and verify they stay within the
expected root. This applies to any function accepting
file paths from external input.
- **Fix**:
```python
real = os.path.realpath(user_path)
if not real.startswith(allowed_root):
raise ValueError("Path outside allowed directory")
```
```
## How to Source Proof Links
Use authoritative references in this priority order:
1. **Language/framework docs** (python.org, docs.rs,
developer.mozilla.org)
2. **Security standards** (OWASP, CWE, NIST)
3. **Style guides** (PEP 8, Google Style Guide, Effective Go)
4. **Well-known articles** (Martin Fowler, Dan Abramov,
Kent Beck)
5. **RFCs and specifications** (IETF RFCs, W3C specs)
When no authoritative URL exists, cite the principle by
name (e.g., "Liskov Substitution Principle") and briefly
explain it inline.
## Insight Depth by Classification
| Classification | Insight Depth | Proof Required |
|---------------|--------------|----------------|
| **BLOCKING** | Full (why, impact, and fix) | Yes, with link |
| **IN-SCOPE** | Standard (why and fix) | Yes, with link |
| **SUGGESTION** | Brief (why and alternative) | Optional |
| **BACKLOG** | One-liner rationale | No |
BLOCKING and IN-SCOPE findings always include proof links.
SUGGESTION findings include them when a well-known source
exists. BACKLOG items need only a brief rationale since
they becmodules/github-comments.md
# GitHub PR Comment Patterns
Reusable patterns for posting comments to GitHub PRs via the `gh` CLI.
## Key API Differences
| Endpoint | Use Case | Notes |
|----------|----------|-------|
| `gh pr comment` | General PR comments | Simple, always works |
| `gh api .../reviews` | Inline comments on diff lines | Use `-F` for integers |
| `gh pr review` | Summary with approve/request changes | Final submission |
## Common Mistakes
### Wrong: Individual Comments Endpoint with `line` parameter
```bash
# This will FAIL with HTTP 422
gh api repos/{owner}/{repo}/pulls/{pr}/comments \
-X POST \
-f path='file.rs' \
-f line=63 \ # ERROR: "line" is not a permitted key
-f body='Comment'
```
### Right: Reviews Endpoint with Comments Array
```bash
# This works correctly
gh api repos/{owner}/{repo}/pulls/{pr}/reviews \
--method POST \
-f event="COMMENT" \
-f body="Review summary" \
-f 'comments[][path]=file.rs' \
-F 'comments[][line]=63' \ # Use -F for integers!
-f 'comments[][body]=Inline comment text'
```
## Pattern: Single Inline Comment
```bash
gh api repos/{owner}/{repo}/pulls/{pr_number}/reviews \
--method POST \
-f event="COMMENT" \
-f body="See inline comment." \
-f 'comments[][path]=src/auth/jwt.rs' \
-F 'comments[][line]=63' \
-f 'comments[][side]=RIGHT' \
-f 'comments[][body]=**[IN-SCOPE]** JWT secondary secret
This fallback secret poses a security risk.
**Recommendation:** Fail-fast on missing JWT_SECRET.'
```
## Pattern: Multiple Inline Comments
For multiple comments, use JSON input via `--input -`:
```bash
gh api repos/{owner}/{repo}/pulls/{pr_number}/reviews \
--method POST \
--input - <<'EOF'
{
"event": "COMMENT",
"body": "Review with inline comments",
"comments": [
{
"path": "src/auth.rs",
"line": 26,
"side": "RIGHT",
"body": "**[IN-SCOPE]** Basic email validation"
},
{
"path": "src/routes.rs",
"line": 45,
"side": "RIGHT",
"body": "**[SUGGESTION]** Consider rate limiting"
}
]
}
EOF
```
**Note:** The indexed array syntax (`comments[0][path]`) does NOT work with `gh api` - it creates an object instead of an array. Always use JSON input for multiple comments.
## Pattern: General PR Comment (Not Inline)
For findings not on diff lines or when inline fails:
```bash
gh pr comment $PR_NUMBER --body '## Detailed Findings
### IN-SCOPE (Should fix before merge)
#### 1. JWT Fallback Secret (`src/auth/jwt.rs:62-63`)
**Risk**: If deployed without `JWT_SECRET`, tokens use known secret.
**Fix**: Fail-fast on missing secret.
#### 2. Basic Email Validation (`src/routes/auth.rs:26`)
**Risk**: Accepts invalid emails like `@@` or `test@`.
**Fix**: Use proper email validation.'
```
## Pattern: Submit Review with Summary
```bash
# Determine event based on findings
EVENT="COMMENT" # or "REQUEST_CHANGES" or "APPROVE"
gh pr review $PR_NUMBER \
--event $EVENT \
--body "$(cat <<'EOF'
## PR Review Summary
### Blocking Issues (2)
- [B1] MiAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-sanctum-pr-review",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-sanctum-pr-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:23:56.378Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-sanctum-pr-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-sanctum-pr-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T08:23:56.378Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceUrl": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:23:56.378Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceUrl": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:20:39.575Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-sanctum-pr-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-sanctum-pr-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceUrl": "https://clawhub.ai/athola/nm-sanctum-pr-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:20:39.575Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
