pr-thread-resolver — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited pr-thread-resolver (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Turn unresolved GitHub PR review threads into committed, verified, resolved fixes — natively, with gh + Claude Code's edit/verify loop. No external orchestrator.
Use for hosted PR review threads. Route away:
review-remediation.babysit-pr.gh workflow-log remediation.AGENTS.md/CLAUDE.md; git status --short; capture the head SHA(gh pr view <pr> --json headRefOid -q .headRefOid).
gh api graphql into a compact worklist(see references/gh-graphql.md): thread id, path, line, isResolved, isOutdated, body, any
3. **Triage** each: `Read` the current line. Skip with a reason if already-fixed or stale
(`isOutdated` + code no longer matches); else queue a minimal fix.
4. **Plan**: decide order; serial for shared files, **fan out** for independent threads (below).
5. **Fix**: apply the smallest correct edit. Apply a ```suggestion``` block verbatim **only** on an
exact hunk match; otherwise write a hand-minimal fix.
6. **Verify**: run repo-native gates — focused test for the touched area first, then broad
type-check / lint / build (use `/verify` and `/code-review` as the backbone).
7. **Commit**: scoped, semantically grouped Conventional Commits (see `references/closeout.md`).
8. **Push** the branch once after all intended commits pass verification.
9. **Resolve**: re-fetch head + thread state; resolve via `resolveReviewThread` **only** threads
backed by a committed+pushed+verified fix (or already-fixed at current head).
10. **Re-poll** until zero actionable threads remain or a real blocker appears.
## Parallel resolution
When ≥3 threads touch **disjoint files**, dispatch one read-and-fix `Task` subagent per file/cluster.
Subagent contract: **fix + verify + report only** (file:line, change, verification result) — it does
**not** commit, push, or resolve. The **parent** serializes all staging, commits, pushes, and
`resolveReviewThread` mutations. Workers own disjoint files and never touch another's.
## Resolve safety policy
Resolve a thread ONLY when it maps to a committed, pushed, and verified fix (or is already fixed at
current head). **Never** resolve when: the PR head drifted unexpectedly since you pushed; verification
failed; the thread was skipped, ambiguous, or unmatched. Do not auto-reply by default — reply only
when a thread cannot be fixed cleanly or the user asks for a comment.
## Outputs
Worklist · verified-fix / skipped summary (file:line evidence) · verification commands + results ·
commit SHAs · thread→commit closeout map · terminal status `completed` | `blocked` | `no-op`.
## Resources
- `references/gh-graphql.md` — copy-paste `gh api graphql` queries + the resolveReviewThread mutation.
- `references/closeout.md` — Conventional Commit grouping, forbidden process-wording, head-drift guard.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.