npx skills add ...
npx skills add bitwarden/ai-plugins --skill posting-review-summary
npx skills add bitwarden/ai-plugins --skill posting-review-summary
Use this skill when posting the final summary comment after all inline comments are posted. Apply as the LAST step of code review after all findings are classified and inline comments are complete. Detects context (agent mode sticky comment, GitHub Actions MCP tool, or local file) and routes output accordingly.
Check contexts in this order โ use the first match:
| Context | How to Detect | Action |
|---|---|---|
| Agent Mode | Sticky comment context provided in prompt (comment ID + <!-- bitwarden-code-review --> marker) | Write summary to /tmp/review-summary.md |
| GitHub Actions (tag mode) | mcp__github_comment__update_claude_comment available AND no sticky comment context | Update sticky comment via MCP tool |
| Local review | Neither agent mode context nor MCP tool available | Write to review-summary.md in working directory |
FORBIDDEN: Do not use gh pr comment to create summary comments.
If PR title, description, or test plan is genuinely deficient, add as a finding in the Code Review Details collapsible section.
Genuinely deficient means:
Adequate (DO NOT flag):
When the PR diff includes dependency manifest file changes, add a Dependency Changes subsection inside the <details> block, after the findings list and before the optional PR Metadata Assessment.
Only render this table when there are meaningful version changes โ not for lock file-only churn with no manifest changes.
Bold the word "major" for major version bumps. Mark new additions as "New (version)" and removals as "Removed".
Ordering: Group findings by severity in this exact order:
Omit empty categories entirely.
Format per finding:
Example:
When sticky comment context is provided in the prompt (comment ID + marker):
/tmp/review-summary.md using the Write tool\n\n<!-- bitwarden-code-review --> at the end of the file contentmcp__github_comment__update_claude_commentgh pr comment or gh apiThe workflow post-step will read this file and update the placeholder comment automatically.
### Dependency Changes
| Package | Change | Ecosystem |
| ----------------- | --------------------- | --------- |
| `@foo/bar` | New (1.2.0) | npm |
| `lodash` | 3.x โ 4.x (**major**) | npm |
| `Newtonsoft.Json` | 13.0.1 โ 13.0.3 | NuGet |
| `old-package` | Removed | npm |- [emoji]: [One-line description]
- `filename.ts:42`<details>
<summary>Code Review Details</summary>
- โ : SQL injection in user query builder
- `src/auth/queries.ts:87`
- โ ๏ธ : Missing null check on optional config
- `src/config/loader.ts:23`
</details>Use mcp__github_comment__update_claude_comment to update the sticky comment with the summary.Write summary to review-summary.md in working directory.