- Home
- Skills
- Code Quality & Review
- git-pr-auditor
More screenshots
Works with the AI tools you already use
Git pr Auditor
Your CI pipeline passes green, the linter is happy, and tests cover the happy path.
Free
git-pr-auditor
Example session with this skill installed
"Audit the diff between main and my feature/auth branch"
- Read your context and instructions
- Compiled the git-pr-auditor
- Generated the document
"PR Audit Report — feature/auth vs main — 12 files, +347/-89 lines
Critical — Security Issues (2):
File Line Issue
───────────────── ──── ──────────────────────────────────────────────
src/auth/login.ts 45 Hardcoded API key sk_live_abc123... in source
src/db/query.ts 12 SQL injection via string concatenation: SELECT
* FROM users WHERE id = ${userId}
Warning — Code Quality (3):
File Line Issue
──────────────────── ──── ───────────────────────────────────────
src/utils/helpers.ts 88 TODO comment: 'handle rate limiting'
src/api/users.ts 34 console.log('debug: user created') in
production
src/auth/tokens.ts 67 Error swallowed: catch block only logs,
doesn't re-throw
Info — Best Practices (4):
File Line Issue
────────────────── ──── ───────────────────────────────────
src/types/index.ts 5 Missing JSDoc on exported interface
Blockers: 2 critical issues MUST be fixed before merge.
Recommendations: 3 warning-level issues worth addressing
git-pr-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The Problem
Your CI pipeline passes green, the linter is happy, and tests cover the happy path. But the PR you just approved has a hardcoded API key on line 45, SQL string concatenation on line 12, and a TODO comment promising to handle the error case "later." By the time someone notices, it's been in production for three weeks and is now part of the "tech debt backlog" that never gets addressed.
What You Get
- Security-focused critical scanning — detects hardcoded secrets, SQL injection patterns, command injection (os.system, exec, shell=True), path traversal, insecure random, XSS via innerHTML/dangerouslySetInnerHTML, and missing auth checks on sensitive endpoints
- Code quality warning detection — flags TODO/FIXME/HACK comments, console.log/print in production code, unused imports, magic numbers, functions over 50 lines, deeply nested conditionals, error swallowing, and race condition patterns
- Multi-file-type categorization — automatically groups changed files (Backend, Frontend, Config, Database, Tests, Docs) and applies category-specific audit rules
- Severity-ranked audit report — produces a structured Markdown report with Critical/Warning/Info tables showing file path, line number, and specific issue description
- Diff-aware analysis — focuses only on what changed, not the entire codebase, so findings are relevant to the specific PR or commit
- Blocker identification — summarizes which issues must be fixed before merge versus which are recommendations for the next sprint
Why This Beats Prompting It Yourself
A linter checks syntax. A code reviewer checks logic. This skill checks for the patterns that fall between — security anti-patterns that compile fine, quality issues that work but create maintenance burden, and style violations that indicate architectural drift. It reads the diff as a security auditor would, not as a syntax checker, catching the issues that neither the compiler nor the linter were designed to find.
Example Session
You: "Audit the diff between main and my feature/auth branch"
Agent: "PR Audit Report — feature/auth vs main — 12 files, +347/-89 lines
Critical — Security Issues (2):
File Line Issue
───────────────── ──── ──────────────────────────────────────────────
src/auth/login.ts 45 Hardcoded API key sk_live_abc123... in source
src/db/query.ts 12 SQL injection via string concatenation: SELECT
* FROM users WHERE id = ${userId}
Warning — Code Quality (3):
File Line Issue
──────────────────── ──── ───────────────────────────────────────
src/utils/helpers.ts 88 TODO comment: 'handle rate limiting'
src/api/users.ts 34 console.log('debug: user created') in
production
src/auth/tokens.ts 67 Error swallowed: catch block only logs,
doesn't re-throw
Info — Best Practices (4):
File Line Issue
────────────────── ──── ───────────────────────────────────
src/types/index.ts 5 Missing JSDoc on exported interface
Blockers: 2 critical issues MUST be fixed before merge. Recommendations: 3 warning-level issues worth addressing in this cycle."
Use Cases
- Pre-merge review on security-sensitive PRs (auth, payments, data access)
- Staged changes audit before committing locally
- CI/CD integration as a pre-merge quality gate
- Onboarding a new contributor by showing them what their diff introduces
- Quick sanity check on hotfix PRs where review time is compressed
Known Limitations
This skill is read-only — it scans diffs and generates reports but never modifies code or commits. It works best when given explicit diff ranges; vague "review this project" requests may produce too broad or too narrow results. Deep semantic analysis (e.g., "will this race condition manifest under load") is beyond its scope.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
5 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 4 months ago
- Free to download with an account