posting-bitwarden-review-comments

Use this skill when posting inline comments to GitHub pull requests. Apply when formatting comments following Bitwarden engineering standards with severity…

npx skills add https://github.com/bitwarden/ai-plugins --skill posting-bitwarden-review-comments

Posting Bitwarden Review Comments

GitHub Comment Posting Protocol

  1. MUST Analyze all changes before posting anything
  2. MUST Use inline comments for code-specific findings
  3. MUST Use the Bitwarden finding format
  4. FORBIDDEN: Do NOT add "Strengths", "Highlights", or positive observations sections.
  5. FORBIDDEN Do NOT post praise-only inline comments
  6. FORBIDDEN: Do NOT post PR metadata issues (title, description, test plan) as inline comments. These go in the summary only.

Finding Format

CRITICAL: Never use # followed by numbers - GitHub will autolink it to unrelated issues/PRs.

  1. Writing "#1" creates a clickable link to issue/PR #1 (not your finding)
  2. "Issue" is also wrong terminology (use "Finding")
  3. Use "Finding" + space + number (no # symbol); aim for under 30 words in sentence

CORRECT FORMAT:

  • Finding 1: Memory leak detected
  • Finding 2: Missing error handling

WRONG (DO NOT USE):

  • ❌ Issue #1 (wrong term + autolink)
  • ❌ #1 (autolink only)
  • ❌ Issue 1 (wrong term only)

Inline Comments

Every inline comment MUST:

  1. Reference specific line(s)
  2. State the problem - what breaks or what's the risk?
  3. Provide actionable fix (for ❌ and ⚠️)
  4. Be brief yet clear
  5. Use collapsed sections for comments over 5 lines
  6. Include both opening <details> AND closing </details> tags

Visibility Rule: Only severity + one-line description visible; everything else inside <details> tags.

Template for long comments

[emoji] **[SEVERITY]**: [One-line issue description]

<details>
<summary>Details and fix</summary>

[Code example or specific fix]

[Rationale explaining why]

Reference: [docs link if applicable]
</details>

Summary Output

Invoke Skill(posting-review-summary) for all summary formatting and posting.

Больше skills от bitwarden

analyzing-git-sessions
bitwarden
Анализирует git-коммиты и изменения в заданном временном интервале или диапазоне коммитов, предоставляя структурированные сводки для проверки кода, ретроспектив, рабочих журналов или сессий…
official
figma-to-angular
bitwarden
Этот навык преобразует спецификацию дизайна Figma в полностью реализованный компонент Angular с историями Storybook в монорепозитории Bitwarden Clients. Результат должен визуально соответствовать дизайну, следуя всем соглашениям кодовой базы.
official
agent-access
bitwarden
Retrieve login credentials, API keys, and secrets (username, password, TOTP) from the user's Bitwarden vault via aac. Use when you need credentials to sign…
official
action-audit
bitwarden
Audit GitHub Actions action usage across an org. Searches for a specific action (incident mode) or sweeps all workflow files for non-compliant action…
official
action-remediate
bitwarden
Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal…
official
analyzing-code-security
bitwarden
Этот навык следует использовать, когда пользователь просит «проанализировать код на предмет проблем безопасности», «проверить на уязвимости OWASP», «просмотреть код на соответствие CWE Top 25», «найти…»
official
applying-bitwarden-branding
bitwarden
Apply Bitwarden brand standards — logo usage, color palette, typography, iconography, and capitalization rules — grounded in bitwarden.com/brand and the…
official
architecting-solutions
bitwarden
Architecting solutions at the team level while staying coherent with Bitwarden's holistic architecture. Covers security mindset, architectural judgment,…
official