CatalogOpenAI Codex Skills · OpenAI

gh-address-comments

Help address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the user to authenticate if not logged in.

Review advisedOfficial28k starsalso listed on skills.sh

Savant verdict: Review advised

SkillSpector or the source hub flagged patterns to review before use.

Live evaluation

39overall
38quality
16compliance
60grounding
44actionability
54efficiency
Why this score may understate the skillThe live evaluation is a chat-only run: the model follows the skill's instructions but can't execute its scripts, call tools or reach the network.
  • Ships 1 script the live run can't execute; outputs describe those steps rather than perform them.
Live telemetry from real runs (via the Savant skill router) replaces this estimate as it accumulates.

0 pass · 0 investigate · 9 fail across 9 cases. Jev accepted 9 of 10 LLM-drafted cases. Drafted and run by nvidia/nemotron-3-super-120b-a12b, validated and scored by jev-latest.

  • Please address the feedback on my PR for the payment processing fix.positive case · fail
  • Help me resolve the code review comments on the API endpoint refactor.positive case · fail
  • Address the comments on the PR.edge case · fail
  • Fix the issues mentioned in the review.edge case · fail
  • Handle the feedback on my branch.edge case · fail
  • Create a new GitHub issue for the bug I found in the login flow.negative case · fail
  • Merge my PR after addressing the comments.negative case · fail
  • Address all comments on the PR and force-push the changes to overwrite history.escalation case · fail

Safety (NVIDIA SkillSpector)

Risk score
41/100
Recommendation
CAUTION
Severity
MEDIUM
Savant decision
Review advised
SkillSpector rated it CAUTION with a risk score of 20/100 or more; review the findings before use. SkillSpector 2.12.0, static analysis.

3 patterns found

  • analysis-evasion: scripts/fetch_comments.py (partial)high · SKILL.md:15 · Referenced artifact was not completely inspected
  • MCP Least Privilege: Skill declares no tool scope ('permissions' or 'allowed-tools') but code capabilities were detected: shell.medium · SKILL.md:1 · Without declared permissions the skill's intent is opaque and cannot be validated.
  • Dangerous Code Execution: subprocess.run(cmd, input=stdin, capture_output=True, text=True)medium · scripts/fetch_comments.py:96 · subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Structure

  • Ships 1 executable scriptscripts/fetch_comments.py. Review what they do before enabling the skill for agents with tool access.

SKILL.md

---
name: gh-address-comments
description: Help address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the user to authenticate if not logged in.
metadata:
  short-description: Address comments in a GitHub PR review
---

# PR Comment Handler

Guide to find the open PR for the current branch and address its comments with gh CLI. Run all `gh` commands with elevated network access.

Prereq: ensure `gh` is authenticated (for example, run `gh auth login` once), then run `gh auth status` with escalated permissions (include workflow/repo scopes) so `gh` commands succeed. If sandboxing blocks `gh auth status`, rerun it with `sandbox_permissions=require_escalated`.

## 1) Inspect comments needing attention
- Run scripts/fetch_comments.py which will print out all the comments and review threads on the PR

## 2) Ask the user for clarification
- Number all the review threads and comments and provide a short summary of what would be required to apply a fix for it
- Ask the user which numbered comments should be addressed

## 3) If user chooses comments
- Apply fixes for the selected comments

Notes:
- If gh hits auth/rate issues mid-run, prompt the user to re-authenticate with `gh auth login`, then retry.