All skills
bitwarden avatar

/posting-bitwarden-review-comments

@70bda85 official
by bitwardenbitwarden/ai-plugins155 stars
20

Use this skill when emitting inline review comments, whether posted to a GitHub pull request or written to a local file under caller-declared local-file output. Apply when formatting comments following Bitwarden engineering standards with severity emojis, clear explanations, and actionable suggestions. Use after findings are classified and ready to emit. DO NOT USE when posting summary comments.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/posting-bitwarden-review-comments

This session only. Nothing lands on disk.

SKILL.md

≈108 tokens always: the name and description. ≈922 when used: this file.

Posting Bitwarden Review Comments

Destination Detection

Check destinations in this order — use the first match:

Destination How to Detect Action
Local output in effect An OUTPUT: local files line in the prompt's leading directive block, or a caller that passes local files as the destination in effect. Check this first, and never key it on which tools happen to be available Write to review-inline-comments.md in working directory
Local target, no GitHub destination The review target is local changes and no caller declared a GitHub destination Write to review-inline-comments.md in working directory
GitHub pull request Neither of the above Post via mcp__github_inline_comment__create_inline_comment

Under either local destination, format every finding exactly as below and write them all to the one file — do not post, whatever comment tools happen to be available.

Comment Posting Protocol

  1. MUST Analyze all changes before emitting anything
  2. MUST Use inline comments for code-specific findings
  3. MUST Use the Bitwarden finding format
  4. FORBIDDEN: Do NOT add "Strengths", "Highlights", or positive observations sections.
  5. FORBIDDEN Do NOT post praise-only inline comments
  6. FORBIDDEN: Do NOT post PR metadata issues (title, description, test plan) as inline comments. These go in the summary only.

Finding Format

CRITICAL: Never use # followed by numbers - GitHub will autolink it to unrelated issues/PRs.

  1. Writing "#1" creates a clickable link to issue/PR #1 (not your finding)
  2. "Issue" is also wrong terminology (use "Finding")
  3. Use "Finding" + space + number (no # symbol); aim for under 30 words in sentence

CORRECT FORMAT:

  • Finding 1: Memory leak detected
  • Finding 2: Missing error handling

WRONG (DO NOT USE):

  • ❌ Issue #1 (wrong term + autolink)
  • ❌ #1 (autolink only)
  • ❌ Issue 1 (wrong term only)

Inline Comments

Every inline comment MUST:

  1. Reference specific line(s)
  2. State the problem - what breaks or what's the risk?
  3. Provide actionable fix (for ❌ and ⚠️)
  4. Be brief yet clear
  5. Use collapsed sections for comments over 5 lines
  6. Include both opening <details> AND closing </details> tags

Visibility Rule: Only severity + one-line description visible; everything else inside <details> tags.

Template for long comments

[emoji] **[SEVERITY]**: [One-line issue description]

<details>
<summary>Details and fix</summary>

[Code example or specific fix]

[Rationale explaining why]

Reference: [docs link if applicable]
</details>

Summary Output

Invoke Skill(posting-review-summary) for all summary formatting and posting.

Source: SKILL.md on GitHub

1 warning14d4 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides guidelines for formatting and posting code review comments to GitHub pull requests or local files according to specific engineering standards. No malicious patterns were detected.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at 70bda85. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 4 weeks ago
  • github
  • code-review
  • bitwarden
  • pull-requests
  • comments
  • inline-comments
  • engineering-standards

README badge

README badge for bitwarden/ai-plugins/posting-bitwarden-review-comments

Formats inline code review comments for GitHub pull requests using Bitwarden's engineering standards, including severity emojis, finding numbering, and actionable fixes. Use this skill after classifying review findings and ready to post line-specific comments (not summary-level feedback).

Generated from the current SKILL.md.

When should I use this skill versus the summary skill?
Use this skill for inline comments on specific code lines following Bitwarden standards. Use the posting-review-summary skill for PR-level summary comments, metadata issues (title, description), and overall findings.
What format should I use for finding numbers?
Use 'Finding 1', 'Finding 2', etc. with a space and no # symbol. The # prefix causes GitHub to autolink to unrelated issues or PRs.
Can I post praise or positive observations as inline comments?
No. Praise-only inline comments and 'Strengths' or 'Highlights' sections are forbidden. Post only findings with actionable issues or risks.
How should I format inline comments longer than 5 lines?
Use a collapsed `<details>` section with the severity emoji and one-line description visible, and the full explanation, code examples, and rationale hidden inside the details tags.
What information must every inline comment include?
Each inline comment must reference specific line(s), state the problem and its risk, provide an actionable fix for severity levels that require one, and be brief yet clear.

Generated from the current SKILL.md. These answers refresh after source changes.