PR numbers named in chat during a review-prs run should be clickable so the maintainer can open each PR in the browser while deciding on it. Defines the PR link convention once in the intro and uses it at both chat sites: the closing-comment draft label and the final summary table.
Co-Authored-By: Claude <noreply@anthropic.com>
In the last review-prs run, closing comments were posted to GitHub without the maintainer ever seeing their full text - the AskUserQuestion options carried one-line paraphrases and the actual comment bytes first appeared inside the gh pr close --comment command. The old wording ("AskUserQuestion presenting the draft closing comment") was satisfiable by a summary. The Close arm now prints each draft verbatim in chat (fenced block, PR number as label) before the AskUserQuestion, and the step's completion criterion binds every posted comment to be byte-identical to a printed draft or to the maintainer's custom text.
Co-Authored-By: Claude <noreply@anthropic.com>
The uv-audit bug has no automatic guard outside the bundled-entry
case, so the hazard has to live in the audit process instead. The
sweep only queries names matching PYPI_NAME_RE, so a display name
with a space is skipped outright; renaming it into a PyPI-shaped name
starts it being queried, which is how 'uv audit' became 'uv-audit'
and picked up an unrelated third-party package by rocshers.
The gotcha tells the auditor to fetch PyPI metadata for any renamed
entry and add a null override when the package isn't the linked
project. It also records two broader checks that were measured
against the full list and rejected, so a future audit doesn't spend
time re-proposing them: the repo-backlink check misses this case
entirely since uv-audit declares no repo URL, as do 26 legitimate
entries, and it flags 10 benign org moves; the name-versus-repo-name
check returns 46 hits that are all legitimate, including uv-build
with the shape identical to uv-audit.
Co-Authored-By: Claude <noreply@anthropic.com>
Project now requires Python >=3.14; the pin fails live (verified during
PR review), and plain uv run / make resolves correctly without it.
Co-Authored-By: Claude <noreply@anthropic.com>
The "most diffs sit on stale bases" claim was a one-time artifact of
the shortlist reform, not a durable fact about future PRs. Reworded to
state that diff context lines show the base the PR was written on,
which may have changed since, while keeping conflict-to-Merge-arm
routing.
Co-Authored-By: Claude <noreply@anthropic.com>
Two live review-prs runs surfaced fixes:
- Merge conflicts move from the screen-out rules to a local-merge path
in the Merge arm; 7/10 PRs conflicted only from the reform's stale
bases, and one such PR had already been merged this way.
- Target use case is now resolved from the current README instead of
stale diff context, since most PR bases no longer match live
sections.
- Judge gets a third verdict: no fitting use case is a structure
question, carried to Act for the maintainer to decide.
- Act's Close step gets a batching and checklist note, and the whole
step gets an explicit completion criterion after a verdict nearly
fell out of the question batches.
- Drop the "claude reviewed" label mechanism entirely: the fetch
filter, the Park arm, and the labeled-open terminal state.
Co-Authored-By: Claude <noreply@anthropic.com>
Superseded by the rewritten .claude/skills/review-prs/SKILL.md
committed just before (9ce2a21); leaving it in place would keep a
stale second copy of the PR-review instructions.
Co-Authored-By: Claude <noreply@anthropic.com>
The old review-pending-prs command carried a stale copy of CONTRIBUTING.md's rejection rules (100-star bar, "too niche") that contradicted the current shortlist model. This skill screens from the diff only, delegates admission judgment to the audit-the-list skill, then acts on GitHub: merge with section reconcile, AskUserQuestion-gated closes.
Co-Authored-By: Claude <noreply@anthropic.com>
The pypi downloads sweep looks up counts by README display name; when
the display name differs from the canonical package, the row silently
measures an unrelated squatter or a dead predecessor. Document the
failure mode in both the fetcher's docstring and the audit skill so
famous entries with off-looking counts get identity-verified before
being cited.
Co-Authored-By: Claude <noreply@anthropic.com>
Multi-day reviews need to survive reboots, which system /tmp does not
guarantee. ./tmp is git-ignored so the generated pages never land in
commits.
Co-Authored-By: Claude <noreply@anthropic.com>
Adds a header row (name, downloads, fetched_at) to data/pypi_downloads.tsv
and stamps every row with the sweep date, so audits can tell evidence age
and skip re-fetching when the cache is less than 7 days old. The sweep
itself costs ~1s, so freshness is checked by the reader (audit-the-list
skill) instead of skip logic in the fetch script. SKILL.md documents the
7-day freshness rule.
Co-Authored-By: Claude <noreply@anthropic.com>
Broaden argument-hint to cover thematic groups alongside sections,
and backtick tool/skill names for consistency.
Co-Authored-By: Claude <noreply@anthropic.com>
Authored by the parallel fetch-scripts session (its intended 0cffb5f
never landed; the content rode into an audit commit by accident and is
extracted here): fetch_pypi_downloads_via_clickpy.py becomes the
flagless full-README sweep and sole writer of data/pypi_downloads.tsv;
new fetch_pypi_downloads_via_bigquery.py is a print-only cross-check
taking explicit names behind a 400 GB billing cap; audit-the-list
SKILL.md step 2 updated to match.
Co-Authored-By: Claude <noreply@anthropic.com>
fetch_pypi_downloads.py becomes fetch_pypi_downloads_via_clickpy.py and
fetch_pepy_downloads.py becomes fetch_pypi_downloads_via_pepy.py, ahead
of splitting the BigQuery path into its own file. Updates the usage
strings, the cross-file import, and the audit-the-list skill's
references to match. Pure rename, no behavior change.
Co-Authored-By: Claude <noreply@anthropic.com>
Maintainer registered a free pepy API key (PEPY_TECH_API_KEY in the gitignored repo-root .env). fetch_pepy_downloads.py sums the most recent 30 days from the v2 per-day data, throttled to the free tier's 5 requests/minute, and prints TSV without touching the single-source cache file.
The audit-the-list skill's downloads bullet is rewritten in the same commit because the ClickPy-default change made its old --dry-run-first instruction fail; it now documents all three sources (ClickPy, BigQuery, pepy/pypistats) and the never-mix-mirror-counting rule.
Co-Authored-By: Claude <noreply@anthropic.com>
Verb-first naming per maintainer preference. Directory, frontmatter
name, and the audit-the-list reference updated together; template.html
moves with the directory unchanged.
Co-Authored-By: Claude <noreply@anthropic.com>
Packages the audit process proven across the shortlist-reform sweeps
as a reusable skill: resolve scope from the arguments (AskUserQuestion
when ambiguous or absent), fetch live evidence for every entry
(BigQuery downloads, repo state, PyPI metadata), draft verdicts with
restructure-before-cap and tier promotions/demotions, review through
the verdict-preview page, execute one commit per section on explicit
go, and record durable conclusions into CONTRIBUTING.md, CLAUDE.md,
AGENTS.md, and CONTEXT.md. CONTEXT.md gains the Audit glossary term
(the reform sweeps were the first Audits). Rules stay single-sourced in
CONTRIBUTING.md — the skill carries process only.
Co-Authored-By: Claude <noreply@anthropic.com>
Adds a reusable skill that generates the interactive keep/drop review page (seeded verdicts + reasons, maintainer Keep/Drop toggles and reason fields, JSON feedback export) and processes the pasted feedback, so every future prune sweep or batch entry edit reuses the pattern proven in the shortlist-reform reviews. Removes .claude/skills/ and the dead .agents/ line from .gitignore so the skill is tracked, per maintainer direction.
Co-Authored-By: Claude <noreply@anthropic.com>
Improve the PR review command workflow to reduce API calls and clarify
the review process:
- Fetch PR details in single call (combine list + view data)
- Add quick rejection checks before API calls (conflicts, duplicates)
- Simplify terminology (APPROVE/REJECT -> PASS/REJECT)
- Streamline section headers for clarity
- Remove gh pr view from allowed tools (redundant with list)
This reduces unnecessary GitHub API calls and makes the review process
more efficient.
Co-Authored-By: Claude <noreply@anthropic.com>
Add YAML frontmatter with description and allowed-tools permissions to the review-pending-prs command file. This configures tool access restrictions for GitHub PR operations.
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Define allowed Bash operations for gh CLI commands used in PR review
automation workflows.
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplify gh pr list query using --search flag to filter by label,
reorganize rejection criteria with merge conflicts first, and streamline
output format instructions.
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Replace review-pr command with review-pending-prs to enable efficient
batch review of open PRs. New command fetches up to 10 unreviewed PRs,
performs automated checks, and provides bulk actions (close rejected,
label approved, request fixes).
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Replace self-promotion rule with category placement check to better reflect actual review priorities.
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Add local settings with GitHub CLI permissions for PR review
- Add custom /review-pr command for automated PR review workflow
🤖 Generated with Claude Code (https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>