Submit a code review to GitHub via the GitHub API. Use this as the final step in a code review pipeline to post review findings to a PR.
An output skill that submits code review findings to GitHub via the API. This is the final step in the review pipeline, posting the review to the PR.
| Input | Required | Description |
|---|---|---|
owner |
Yes | Repository owner (username or organization) |
repo |
Yes | Repository name |
pull_number |
Yes | Pull Request number |
commit_id |
Yes | SHA of the commit to review (from retrieve-diff-from-github-pr) |
findings |
Yes | Array of review findings from specialist skills |
review_event |
Optional | APPROVE, REQUEST_CHANGES, or COMMENT (default: COMMENT) |
| Output | Description |
|---|---|
review_id |
ID of the created review |
review_url |
URL to view the review |
comments_posted |
Number of inline comments posted |
This skill uses the GitHub MCP server with:
| Tool | Purpose |
|---|---|
create_pull_request_review |
Submit the review with body and inline comments |
Collect all findings from specialist skills:
{
"findings": [
{
"severity": "blocker",
"category": "security",
"evidence": {
"file": "src/auth/login.ts",
"line": 42,
"snippet": "password = req.body.password"
},
"impact": "Password logged in plaintext",
"fix": "Remove logging or hash before logging",
"test": "Check logs for sensitive data"
}
]
}
Based on findings severity, determine the review action:
| Findings | Event | Rationale |
|---|---|---|
| Any blocker | REQUEST_CHANGES |
PR should not be merged |
| Any major | REQUEST_CHANGES |
Significant issues need fixing |
| Only minor/nit | COMMENT |
Suggestions, not blocking |
| No issues | APPROVE |
PR looks good |
Create the review summary:
## Code Review Summary
### š“ Blockers (X)
| File | Line | Issue |
|------|------|-------|
| src/auth/login.ts | 42 | SQL injection vulnerability |
### š” Major (X)
| File | Line | Issue |
|------|------|-------|
| src/api/users.ts | 15 | Missing error handling |
### šµ Minor (X)
- Consider adding JSDoc to public functions
- Unused import on line 3
### š Nits (X)
- Formatting: extra blank line at EOF
---
*Reviewed by codereview-skills*
Convert findings to GitHub inline comments:
{
"comments": [
{
"path": "src/auth/login.ts",
"line": 42,
"body": "š“ **Security**: SQL injection vulnerability\n\n```suggestion\nconst user = await db.query('SELECT * FROM users WHERE id = ?', [userId]);\n```\n\n**Impact**: Attacker can execute arbitrary SQL\n**Fix**: Use parameterized queries"
}
]
}
<severity_emoji> **<category>**: <title>
<description>
```suggestion
<suggested fix if applicable>
Impact:
Severity emojis:
- š“ Blocker
- š” Major
- šµ Minor
- āŖ Nit
## Step 5: Submit Review
Use the GitHub MCP tool:
```json
{
"tool": "create_pull_request_review",
"server": "user-github",
"arguments": {
"owner": "<owner>",
"repo": "<repo>",
"pull_number": <number>,
"commit_id": "<sha>",
"body": "<review summary>",
"event": "REQUEST_CHANGES",
"comments": [
{
"path": "src/auth/login.ts",
"line": 42,
"body": "š“ **Security**: SQL injection..."
}
]
}
}
{
"status": "success",
"review": {
"id": 12345,
"url": "https://github.com/owner/repo/pull/123#pullrequestreview-12345",
"event": "REQUEST_CHANGES",
"body": "## Code Review Summary...",
"comments_count": 5
},
"summary": {
"blockers": 1,
"major": 2,
"minor": 3,
"nits": 2,
"total": 8
}
}
This skill is the final step in the review pipeline:
1. retrieve-diff-from-github-pr
ā (PR info + diff + commit_id)
2. codereview-orchestrator
ā (triage + routing plan)
3. Specialist skills (parallel or sequential)
ā (findings array)
4. submit-github-review (this skill)
ā (posted review)
5. Return URL to user
ā” Aggregate Findings
ā” Collect from all specialist skills
ā” Deduplicate if needed
ā” Determine Event
ā” Any blockers/major ā REQUEST_CHANGES
ā” Only minor/nit ā COMMENT
ā” No issues ā APPROVE
ā” Format Body
ā” Summary with severity breakdown
ā” Table of issues by severity
ā” Format Comments
ā” Convert findings to inline comments
ā” Use line numbers from evidence
ā” Submit Review
ā” Call create_pull_request_review
ā” Return review URL
| Error | Cause | Resolution |
|---|---|---|
| 422 Invalid | Line doesn't exist in diff | Use position instead of line |
| 404 Not Found | PR or commit doesn't exist | Verify PR number and commit SHA |
| 403 Forbidden | No permission to review | Check GitHub token permissions |
retrieve-diff-from-github-prline refers to the line in the new file, position refers to the position in the diff hunk