posting-review-summary

作者: bitwarden

在所有内联评论发布后,使用此技能发布最终总结评论。在代码审查的最后一步应用,在所有发现项处理完毕后…

npx skills add https://github.com/bitwarden/ai-plugins --skill posting-review-summary

Posting Review Summary

Context Detection

Check contexts in this order — use the first match:

ContextHow to DetectAction
Agent ModeSticky comment context provided in prompt (comment ID + <!-- bitwarden-code-review --> marker)Write summary to /tmp/review-summary.md
GitHub Actions (tag mode)mcp__github_comment__update_claude_comment available AND no sticky comment contextUpdate sticky comment via MCP tool
Local reviewNeither agent mode context nor MCP tool availableWrite to review-summary.md in working directory

FORBIDDEN: Do not use gh pr comment to create summary comments.

PR Metadata Assessment

If PR title, description, or test plan is genuinely deficient, add as a finding in the Code Review Details collapsible section.

Rules

  • DO NOT comment on minor improvements
  • DO NOT comment on adequate-but-imperfect metadata
  • NEVER add as an inline comment
  • DO NOT exceed 3 lines of feedback on the PR Metadata Assessment

Examples

Genuinely deficient means:

  • Title is literally "fix bug", "update", "changes", or single word
  • Description is empty or just "See Jira"
  • UI changes with zero screenshots
  • No test plan AND changes are testable

Adequate (DO NOT flag):

  • Title describes the change even if imperfect: "Fix login issue for SSO users"
  • Description exists and explains the change, even briefly
  • Test plan references Jira task with testing details

Format

- ❓ **QUESTION**: PR title could be more specific
  - Suggested: "Fix null check in UserService.getProfile"

Summary Format

## 🤖 Bitwarden Claude Code Review

**Overall Assessment:** APPROVE / REQUEST CHANGES

[Up to 4 neutral sentences describing what was reviewed]

<details>
<summary>Code Review Details</summary>

[Findings grouped by severity - see ordering below]

[Optional PR Metadata Assessment - only for truly deficient metadata]

</details>

Dependency Changes Table

When the PR diff includes dependency manifest file changes, add a Dependency Changes subsection inside the <details> block, after the findings list and before the optional PR Metadata Assessment.

Only render this table when there are meaningful version changes — not for lock file-only churn with no manifest changes.

### Dependency Changes

| Package           | Change                | Ecosystem |
| ----------------- | --------------------- | --------- |
| `@foo/bar`        | New (1.2.0)           | npm       |
| `lodash`          | 3.x → 4.x (**major**) | npm       |
| `Newtonsoft.Json` | 13.0.1 → 13.0.3       | NuGet     |
| `old-package`     | Removed               | npm       |

Bold the word "major" for major version bumps. Mark new additions as "New (version)" and removals as "Removed".

Findings in Details Section

Ordering: Group findings by severity in this exact order:

  1. ❌ : CRITICAL
  2. ⚠️ : IMPORTANT
  3. ♻️ : DEBT
  4. 🎨 : SUGGESTED
  5. ❓ : QUESTION

Omit empty categories entirely.

Format per finding:

- [emoji]: [One-line description]
  - `filename.ts:42`

Example:

<details>
<summary>Code Review Details</summary>

- ❌ : SQL injection in user query builder
  - `src/auth/queries.ts:87`
- ⚠️ : Missing null check on optional config
  - `src/config/loader.ts:23`

</details>

Output Execution

Agent Mode (Sticky Comment)

When sticky comment context is provided in the prompt (comment ID + marker):

  1. Write the summary to /tmp/review-summary.md using the Write tool
  2. Append \n\n<!-- bitwarden-code-review --> at the end of the file content
  3. Do NOT use mcp__github_comment__update_claude_comment
  4. Do NOT use gh pr comment or gh api

The workflow post-step will read this file and update the placeholder comment automatically.

GitHub Actions (Tag Mode)

Use mcp__github_comment__update_claude_comment to update the sticky comment with the summary.

Local

Write summary to review-summary.md in working directory.

来自 bitwarden 的更多技能

analyzing-git-sessions
bitwarden
分析指定时间范围或提交区间内的Git提交与变更,生成结构化摘要,用于代码审查、回顾、工作日志或会话记录等场景。
official
figma-to-angular
bitwarden
该技能将Figma设计规范转化为在Bitwarden Clients单体仓库中完全实现的Angular组件,并附带Storybook故事。输出结果应在视觉上与设计一致,同时遵循所有代码库约定。
official
agent-access
bitwarden
通过aac从用户的Bitwarden保管库中检索登录凭据、API密钥和机密(用户名、密码、TOTP)。当您需要凭据来登录…时使用。
official
action-audit
bitwarden
审计整个组织中的 GitHub Actions 使用情况。搜索特定操作(事件模式)或扫描所有工作流文件以查找不合规的操作…
official
action-remediate
bitwarden
Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal…
official
analyzing-code-security
bitwarden
此技能应在用户要求“分析代码中的安全问题”、“检查OWASP漏洞”、“对照CWE Top 25审查代码”、“查找…”时使用。
official
applying-bitwarden-branding
bitwarden
Apply Bitwarden brand standards — logo usage, color palette, typography, iconography, and capitalization rules — grounded in bitwarden.com/brand and the…
official
architecting-solutions
bitwarden
在团队层面进行解决方案架构设计,同时与Bitwarden的整体架构保持一致性。涵盖安全思维、架构判断力、……
official