alan-review-pr
supatest-ai/alan-skills
Review GitHub pull requests using Alan's GitHub MCP tools with automated security, correctness, and quality analysis.
What is alan-review-pr?
This skill enables automated code review of GitHub pull requests by fetching PR metadata, diffs, files, and CI status through Alan's GitHub MCP tools, then analyzing changes for security, correctness, performance, error handling, and maintainability issues. Use it to systematically review PRs and post structured findings with actionable fix prompts for agents.
- Fetch PR metadata, unified diff, changed files, existing reviews, and comments using GitHub MCP tools
- Check CI status and link to full logs for failed checks
- Analyze code changes for security, correctness, performance, error handling, and maintainability issues
- Post structured inline comments with severity levels (🔴 blocking, 🟡 important, 🔵 nit) and concrete fix prompts for agents
- Generate a summary review comment with issue counts and links to all findings
- Automatically handle GitHub authentication via MCP server with zero credential setup
How to install alan-review-pr
npx skills add https://github.com/supatest-ai/alan-skills --skill alan-review-pr- Alan MCP server with GitHub tools enabled and configured in the sandbox
- GitHub repository with pull requests to review
- Git repository with a configured remote origin (for resolving owner/repo from PR number)
How to use alan-review-pr
- 1.Provide a PR identifier: PR number (e.g., '42'), PR URL (e.g., 'https://github.com/owner/repo/pull/42'), or reference (e.g., 'owner/repo#42')
- 2.The skill resolves owner, repo, and PR number; if only a number is given, it runs 'git remote get-url origin' to parse the repository
- 3.The skill fetches PR metadata, diff, changed files, existing reviews, comments, and CI status using GitHub MCP tools
- 4.The skill analyzes changes across security, correctness, performance, error handling, maintainability, and test coverage dimensions
- 5.The skill posts inline comments on the PR for each finding (one comment per issue) with severity, description, and a concrete fix prompt
- 6.The skill posts a summary review comment with issue counts and links to all findings; review event is 'REQUEST_CHANGES' if blocking issues exist, otherwise 'COMMENT'
Use cases
- Automated code review on every PR to catch security and logic issues before merge
- Continuous quality gate that posts findings as inline comments with fix instructions
- Security-focused review to identify injection risks, auth bypasses, and secrets in code
- Performance analysis to detect N+1 queries, unbounded operations, and memory issues
- Maintainability checks for function complexity, nesting depth, and test coverage gaps
- Development teams using Alan agents for automated code review
- Security-focused teams reviewing PRs for vulnerabilities and risky patterns
- Teams wanting structured, actionable feedback on pull requests with agent-executable fix prompts
- Repositories using GitHub with CI/CD pipelines
alan-review-pr FAQ
No. The Alan MCP server handles authentication automatically. You do not need GitHub tokens, gh CLI auth, SSH keys, or environment variables. The tools work immediately with zero setup.
Stop and tell the user 'The GitHub MCP tools are not available. Please check the sandbox MCP configuration.' Do not fall back to curl, gh CLI, or other alternatives.
Provide a PR number (e.g., '42'), a full PR URL (e.g., 'https://github.com/owner/repo/pull/42'), or a reference like 'owner/repo#42'. If only a number is given, the skill runs 'git remote get-url origin' to resolve the repository.
The skill analyzes changes for security (injection, auth bypass, secrets), correctness (logic errors, null handling, async issues), performance (N+1 queries, unbounded operations), error handling (silent failures, swallowed errors), maintainability (function complexity, nesting), and test coverage gaps.
The skill only includes findings where confidence is >= 80%, you can point to exact file + line, and you can describe a concrete scenario where it causes a real problem. Linter-catchable issues, speculative risks, and pre-existing problems are skipped.
Full instructions (SKILL.md)
Source of truth, from supatest-ai/alan-skills.
name: alan-review-pr version: 1.0.0 description: Review a GitHub pull request using Alan's GitHub MCP tools
MANDATORY: Use Alan MCP Tools
The Alan MCP server provides GitHub tools that are ALREADY in your tool list.
They work exactly like Read, Bash, Edit — you call them as tool invocations.
They are named with the prefix mcp__alan__github_.
Authentication is handled automatically by the MCP server. You do NOT need GitHub tokens, gh CLI auth, SSH keys, .netrc files, environment variables, or any credentials. The tools work immediately with zero setup.
NEVER do any of the following for GitHub API access:
curlorwgetto api.github.comghCLI commands (gh pr, gh api, etc.)env | grepor scanning for tokens/secretscat ~/.netrc,git credential, orssh -T git@github.com- Any attempt to find, construct, or configure GitHub authentication
- Installing packages or CLIs for GitHub access
If an MCP tool call fails, report the error to the user. Do NOT fall back to CLI alternatives.
Verify tools are available
Before starting, confirm you can see mcp__alan__github_* tools in your
available tools. If they are NOT available, STOP and tell the user:
"The GitHub MCP tools are not available. Please check the sandbox MCP configuration."
Tool parameters
All GitHub PR tools require these parameters:
owner(string): GitHub org or username, e.g. "supatest-ai"repo(string): Repository name, e.g. "alan"prNumber(integer): PR number, e.g. 42
Example tool call:
Tool: mcp__alan__github_get_pull_request
Parameters: { "owner": "supatest-ai", "repo": "alan", "prNumber": 42 }
Resolving owner/repo
If the user only provides a PR number, run git remote get-url origin to get
the remote URL, then parse owner and repo from it. This is the ONLY git CLI
command you should run for GitHub operations. Everything else uses MCP tools.
Available GitHub MCP tools
| Tool name | Purpose |
|---|---|
mcp__alan__github_get_pull_request | Get PR details (title, state, labels, merge status) |
mcp__alan__github_get_pr_diff | Get unified diff of a PR |
mcp__alan__github_list_pr_comments | List all comments on a PR |
mcp__alan__github_list_pr_reviews | List all reviews on a PR |
mcp__alan__github_list_pr_files | List changed files with additions/deletions |
mcp__alan__github_get_issue | Get issue details |
mcp__alan__github_get_ci_status | Get CI check run status for a ref |
mcp__alan__github_add_comment | Add a comment to an issue or PR |
mcp__alan__github_create_pr_review | Submit a review (APPROVE/REQUEST_CHANGES/COMMENT) |
mcp__alan__github_add_labels | Add labels to an issue or PR |
mcp__alan__github_merge_pull_request | Merge a PR |
mcp__alan__github_close_issue | Close an issue or PR |
mcp__alan__github_request_reviewers | Request reviewers on a PR |
Task: Review a Pull Request
Input
The user will provide one of:
- A PR number (e.g. "42" or "#42")
- A PR URL (e.g. "https://github.com/owner/repo/pull/42")
- A reference like "owner/repo#42"
Workflow
-
Resolve owner/repo/prNumber from the input. If only a PR number is given, run
git remote get-url originto parse owner and repo. -
Fetch PR metadata — call
mcp__alan__github_get_pull_requestwith{ owner, repo, prNumber }to get title, description, state, labels, branches. -
Fetch the diff — call
mcp__alan__github_get_pr_diffto get the unified diff. -
Fetch changed files — call
mcp__alan__github_list_pr_filesto see files modified/added/deleted with line counts. -
Fetch existing reviews — call
mcp__alan__github_list_pr_reviewsto see prior review state. -
Fetch existing comments — call
mcp__alan__github_list_pr_commentsfor ongoing discussion context. -
Check CI status — call
mcp__alan__github_get_ci_statuswith the head branch or SHA. If a check failed, include the html_url link so the user can view full logs (the tool does not return log output). -
Read source files — for complex changes, use the Read tool to read full source files (not just the diff) for context.
-
Analyze — identify issues INTRODUCED by this PR only (not pre-existing). For each finding, determine: severity, file path, start/end line, title, description, and a concrete fix prompt for agents.
-
Post review — call
mcp__alan__github_create_pr_reviewwith inline comments (one per finding) plus a summary body. See formats below.
Review Dimensions (priority order)
- Security — injection, auth bypass, secrets in code, input validation
- Correctness — logic errors, null handling, async issues, race conditions
- Performance — N+1 queries, unbounded operations, memory issues
- Error Handling — silent failures, empty catch blocks, swallowed errors
- Maintainability — functions >30 lines, deep nesting, magic numbers
- Test Coverage — happy path tested? edge cases? meaningful assertions?
Confidence Filter
Only include findings where:
- You can point to exact file + line
- You can describe a concrete scenario where it causes a real problem
- Confidence >= 80%
Skip: linter-catchable issues, speculative risks, style preferences, pre-existing problems.
Inline Comment Format
Each finding becomes its own inline comment on the PR. Format the body of each comment like this:
<!-- alan-review-comment {"id": "alan_review_{prNumber}_{sequential_4digit}", "file_path": "{path}", "start_line": {start}, "end_line": {end}, "side": "RIGHT"} -->
{severity_icon} **{short_title}**
{detailed_description}
<details>
<summary>Prompt for agents</summary>
\`\`\`
{concrete_fix_instructions_an_AI_agent_can_execute — specify exact file, what to change, and how}
\`\`\`
</details>
<!-- alan-review-badge-begin -->
<a href="{alan_session_url}" target="_blank">
<img src="https://app.tryalan.ai/logo.png" alt="Open in Alan" height="20">
</a>
<!-- alan-review-badge-end -->
Severity icons:
- 🔴 = Blocking (critical bugs, security, data loss — must fix before merge)
- 🟡 = Important (real bugs/risks — should fix before merge)
- 🔵 = Nit (minor quality issues — fix if easy)
Summary Comment Format
The body parameter of the review (top-level summary) should be:
**Alan Review** found {N} potential issues.
| Severity | Count |
|----------|-------|
| 🔴 Blocking | {X} |
| 🟡 Important | {Y} |
| 🔵 Nit | {Z} |
<details>
<summary>View all findings</summary>
### 🔴 Blocking
- **{title}** — \`{file_path}:{line}\` — {one_line_description}
### 🟡 Important
- **{title}** — \`{file_path}:{line}\` — {one_line_description}
### 🔵 Nit
- **{title}** — \`{file_path}:{line}\` — {one_line_description}
</details>
<!-- alan-review-badge-begin -->
<a href="{alan_session_url}" target="_blank">
<img src="https://app.tryalan.ai/logo.png" alt="Open in Alan" height="20">
</a>
<!-- alan-review-badge-end -->
---
*Was this helpful? React with 👍 or 👎 to provide feedback.*
"Open in Alan" Badge URL
Every badge links to the current Alan session. The user/trigger will provide the
session URL. Replace {alan_session_url} in every badge with the actual URL.
If no session URL is provided, fall back to https://app.tryalan.ai.
Posting the Review
Call mcp__alan__github_create_pr_review with:
owner,repo,prNumber: from step 1body: the summary comment aboveevent: "REQUEST_CHANGES" if any 🔴 blocking findings, otherwise "COMMENT"comments: array of inline comments, each with:path: relative file path from repo rootline: the end line number of the findingbody: the formatted inline comment body above
IMPORTANT:
- Always post inline comments (one per finding) — do NOT bundle into one big comment
- Always include the "Prompt for agents" section in every finding
- Always include the "Open in Alan" badge on every comment and the summary
- Replace
{alan_session_url}with the actual session URL in every badge - If zero findings, post an approving review with a clean summary
Related skills
More from supatest-ai/alan-skills and the wider catalog.

alan-test-feature
Automated feature testing with browser capture, S3 upload, and structured test reports.

alan-plan
Create structured implementation plans as Alan artifacts with analysis, clarification, and visual diagrams.

ci-cd-security
Scan GitHub Actions workflows for security vulnerabilities without external tools or execution.

skill-security
Audit AI agent skills for security risks before installing—catches credential theft, prompt injection, malicious code, and intent mismatches.

superdesign
Design UIs, presentations, and graphics on an infinite canvas with multiple leading AI models.

super-search
Search your coding memory for past work, sessions, and implementation details.