Pull request review
When a pull request opens, a reviewer reads the diff from your repository, runs a correctness, security, and standards pass, and drafts specific inline comments plus a verdict for you to approve before anything is posted.
What it installs
Agents 1
-
Reviewer Agent
Reads the PR diff, runs the review checklist and security pass, and drafts line-anchored comments and a verdict for approval.
Workflows 1
-
Code review
Read the diff, run the review and security passes, self-check for false positives, then draft comments and a verdict for approval.
Goals 1
-
Every PR reviewed
Keep a substantive review on every pull request so nothing merges unexamined.
Skills 3
-
code-review
Thorough correctness, performance, design, and test-coverage review with specific, actionable, line-anchored comments and a clear verdict; approve on minor issues, escalate schema/API/security changes. Adapted from getsentry/skills/code-review.
-
security-review
Exploitability-first security pass reporting only high-confidence findings: trace attacker-controlled input to a sink, skip framework-mitigated and server-controlled patterns, classify by severity, and report the input path plus fix. Adapted from getsentry/skills/security-review.
-
requesting-code-review
Frame review feedback so it is easy to act on: classify each finding Critical/Important/Minor, fix-then-proceed by class, give the reviewer only the work product not the session history, and review early and often. Adapted from obra/superpowers/requesting-code-review.
Requirements
What this template expects to do its job. Task Machine does not verify these — you decide whether your setup is ready.
- Connected repository — The agent reads the pull request diff, the changed files, and surrounding code from your connected repository. Until repository access is connected, it reviews from the diff and files supplied as attachments.
Get started
Install Pull request review and run it with approvals.
Join the waitlist and we will send early access when the first private beta spots open.
Private beta. We invite teams in batches and never share your email.