Review PrSAFE
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
Overview
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
e28854ad0e63OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| gemini-cli | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: review-pr description: Use when asked to review a PR, run a code review loop, or invoke the ralph reviewer against a pull request number or GitHub URL metadata: internal: true --- # Review PR Run the `ralph.reviewer.yml` orchestration loop against a pull request. The loop checks out the PR in an isolated worktree, runs tests, reviews the diff, and produces a structured report. ## Usage ``` /review-pr <PR number or URL> ``` Accepts: `207`, `#207`, or `https://github.com/.../pull/207` ## Execution ### 1. Parse the PR argument Extract the PR number from the argument. Strip `#` prefix or extract from URL path. ### 2. Run the reviewer loop ```bash ralph run -H ralph.reviewer.yml -p "Review PR #<N>" ``` **Bash tool settings:** - `timeout: 600000` (10 minutes) - `run_in_background: true` Use `TaskOutput` with `block: true` to wait for completion. ### 3. Display the report Read and print `.ralph/REVIEW-REPORT.md` to the conversation. If the report file doesn't exist (loop failed before the synthesizer hat), check for and display whatever intermediate files exist: 1. `.ralph/review-scope.md` — what was scoped 2. `.ralph/review-verification.md` — test results 3. `.ralph/review-findings.md` — review findings ### 4. Verify cleanup Check that the review worktree was removed: ```bash ls -d .worktrees/review-<N> 2>/dev/null ``` - If gone: cleanup succeeded, no action needed. - If still present: **warn the user** but do NOT force-remove. Say what's there and let them decide. Also note the presence of intermediate files (`.ralph/review-scope.md`, etc.) — they're useful for debugging but the user may want to clean them up later. ## Error Handling | Situation | Action | |-----------|--------| | Ralph exits non-zero | Display error output. Suggest re-running with `RALPH_DIAGNOSTICS=1` | | Report file missing | Display intermediate files that do exist (scope, verification, findings) | | PR argument missing | Ask the user for the PR number | | PR argument unparseable | Ask the user to provide a bare number, `#N`, or full GitHub URL | ## What This Skill Does NOT Do - Does NOT validate the PR exists (the scoper hat handles that) - Does NOT modify any source code (read-only review) - Does NOT post comments to GitHub - Does NOT own worktree cleanup (verifies only) - Does NOT enable diagnostics by default
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
.claude/skills/ralph-tools/SKILL.md
CLAUDE.md
Gates applied: no_behavioural_pass.
e28854ad0e63full audit observations/trust-audit/skill/mikeyobrien__review-pr.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e28854ad0e63 | SAFE | B | 89 | first audit |
Questions
What does the Review Pr skill do?
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
Is Review Pr safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Review Pr access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Review Pr work with?
Its documentation mentions gemini-cli. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (e28854ad0e63), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.