Add pr-fix skill for bounded PR review repair - #53
Conversation
Automated reviewers re-review on every push and report a fresh slice each time; ocms-go PR 170 went 5, 3, 1, 2, 2 findings over five pushes. Bound the loop by policy instead of out-reviewing the reviewer. - global/skills/pr-fix: one skill for Claude Code and Codex with a bash+jq runner (collect, triage, check, review, status, close, record-push, pre-push); state in .audit/pr-<N>/ shared by both - Local gate runs codex exec review --base in an ephemeral read-only process before every push, at most twice per round; two fix pushes, then triage-only - P2 rule: a one-line fix or a reply, never a rewrite - global/hooks/pre-push: push gate armed once a round starts, chains to the repository's own hook - global/tests/pr-fix-test.sh: 139 offline assertions with stub gh and codex binaries - global/CLAUDE.md: PR Review Findings section; tighten the Claude review workflow prompt to changed lines and high-confidence issues
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (1)ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 66715fe6bd
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 66715fe6bd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Address the 12 connector findings on PR #53 and the local gate's follow-ups, one hunk each: - collect: print thread bodies only from the review bot or OWNER, MEMBER and COLLABORATOR authors (--include-untrusted to override); count connector passes by distinct reviewed commit; pick the badge line as the title; note bot PR comments that are not threads - review: read [P1] tags from JSON titles; NUL-safe untracked files; accept origin/<base> - status: escalate on the computed round and while the connector has not reviewed the head; fall back to the thread path for the P2 rule - state: private ~/.local/state fallback keyed by repository path, 0700/0600; newest state wins for a reused branch name; reopened threads drop their cached closure; pushes mark the head pending - close: retries skip threads already closed - pre-push: match the destination ref, no network lookups, common git dir for worktrees - tests: 160 assertions, portable stat and sed
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eccf2a1a9a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Address the 9 connector findings on PR #53 and the local gate's follow-ups, one hunk each. This is the second and last fix push under the two-push policy. - claude-code-review.yml: the reviewer no longer reads PR comments - pre-push: gate only pushes to the PR's base or head repository (the wrapper forwards the remote name and URL) - review: empty or unrecognised reviewer output is a failed review; output files are unique per process - record-push --undo restores head and pending; `override` grants one more fix push and is honoured by collect, status and the gate - check runs from the repository root - close persists a posted reply before resolving so retries skip it; collect keeps that bookkeeping unless the thread was reopened - tests: 172 assertions; portable stat detection; deterministic snapshot count
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9a1cf419cb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Fix pr-fix follow-ups deferred from PR #53
Purpose
Automated reviewers (chatgpt-codex-connector) re-review a pull request on every push and report a fresh slice of findings each time. On ocms-go PR 170 five pushes produced 5, 3, 1, 2, 2 findings, with a 78-message whole-repository audit in between. This adds a workflow that bounds the loop by policy instead of trying to out-review the reviewer.
Key changes
global/skills/pr-fix/: one skill in the shared Agent Skills format for Claude Code (/pr-fix <PR>) and Codex ($pr-fix <PR>). The bash+jq runnerscripts/pr-fix.shprovidescollect,triage,check,review,status,close,record-pushandpre-push; state lives in.audit/pr-<N>/and is shared by both tools.codex exec review --basein an ephemeral read-only process before every push, at most twice per round; two fix pushes per PR, then triage-only unless the user saysoverride.global/hooks/pre-push: push gate armed once a findings round has started, fails open without gh/jq/runner, chains to the repository's own hook.global/CLAUDE.md: new PR Review Findings section.claude-code-review.yml: prompt limited to changed lines and high-confidence correctness/security issues.## Code Review Rulesblock for target repositories, a~/.codex/AGENTS.mdparagraph.Test evidence
sh global/tests/pr-fix-test.sh: 139/139 assertions pass (stubgh/codex, temp git repos).sh global/tests/statusline-cwd-test.sh: 22/22.pr-fix.sh collect 170against ocms-go reproducespasses=5 round=5 cap_reached=true unresolved=3; a measuredcodex exec review --base masteron PR 170's first commit caught 3 of the 5 findings of the pass it replaced in 105 s;developer_instructionsconfirmed honoured byexec review.