merge-github-pr — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited merge-github-pr (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Merge pull requests that meet all required conditions.
@rules/git/general.mdc Merging; it is mandatory on every merge and is verified in step 2 below.skills/code-review-github/scripts/load-issue.sh <NUMBER|URL> — the single deterministic entry point. Never call gh pr view, gh pr checks, or gh api /repos/.../pulls/... directly. Read isDraft, mergeable, mergeStateStatus, reviewDecision, and statusCheckRollup[] off the resulting JSON document.For each PR, derive the verdict from the JSON document loaded in step 1:
@skills/code-review-github/SKILL.md / @skills/process-code-review/SKILL.md), confirm it reports criticalCount + moderateCount == 0, and confirm it reflects the head commit. Because the CR comment is upserted in place (@skills/code-review/SKILL.md Cross-run history — follow-up runs edit the same comment), use its `updatedAt` (not createdAt) for the staleness check: it is current only when updatedAt is at or after the newest commits[].authoredDate (the head commit). A comment whose updatedAt predates the head commit is stale and does not count. If no code-review comment exists, the latest one still carries Critical / Moderate findings, or its updatedAt predates the head commit, do not merge — report that the code-review gate is unmet and that the review must be run (or re-run) to convergence via @skills/code-review-github/SKILL.md + @skills/process-code-review/SKILL.md first. This gate is never waived — not by an explicit merge request, not by the billing exception below, and not by a GitHub reviewDecision == "APPROVED" on its own.isDraft == false. A Draft PR signals the review/fix loop has not converged (@rules/git/general.mdc Draft pull requests): the Draft state mirrors the unmet code-review gate, so do not merge a Draft and report it as skipped. If the PR's code review has in fact converged (0 Critical + 0 Moderate), it must first be promoted out of Draft by @skills/process-code-review/SKILL.md (gh pr ready) before this skill will merge it — never flip a Draft to ready here just to merge it. The billing exception below never relaxes this.mergeable == "MERGEABLE" and mergeStateStatus is not DIRTY or BEHINDstatusCheckRollup[] has a passing state (SUCCESS / NEUTRAL / SKIPPED), with the single billing exception below when the merge was explicitly requestedreviewDecision == "APPROVED"mergeStateStatus != "BEHIND"If any check fails:
#### GitHub Actions billing exception (explicit merge only)
A single, narrow exception relaxes the CI-passing check — only when the caller explicitly requested the merge (an automatic / opportunistic merge never qualifies):
statusCheckRollup[] are GitHub Actions runs that did not execute because of a billing / account-limit problem — typically a state of ERROR (or a workflow that never started) whose detail message is an unambiguous billing notice such as "The job was not started because recent account payments have failed or your spending limit needs to be increased", "billing", or "spending limit". In that case the gate ignores those specific entries and allows the merge.ERROR / FAILURE with no billing wording is a real failure — never assume billing. When in doubt, do not merge: report the ambiguous entry and stop.isDraft == true), a real CI failure (tests, lint, static analysis) on any non-billing entry, mergeStateStatus == "DIRTY" / "BEHIND", an unmergeable state, or reviewDecision != "APPROVED" still blocks the merge regardless of the explicit request.When the merge was not explicitly requested, this exception does not apply — a billing failure blocks like any other failing check.
@rules/git/general.mdc Worktrees / Workspaces), remove it now that the merge is complete:--force.git worktree remove <path> — removes the worktree directory and its metadata.git worktree prune — cleans up any remaining stale worktree metadata.If no worktree was explicitly created for this work unit (the default: agent worked in the shared tree), skip this step entirely.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.