Skip to content

feat(skill): add review-prs skill for mcp-toolbox - #3743

Merged
twishabansal merged 11 commits into
mainfrom
docs/add-review-prs-skill
Aug 3, 2026
Merged

feat(skill): add review-prs skill for mcp-toolbox#3743
twishabansal merged 11 commits into
mainfrom
docs/add-review-prs-skill

Conversation

@twishabansal

@twishabansal twishabansal commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Description

Adds a review-prs maintainer skill for mcp-toolbox. Given a PR number or link, it delivers a propose-only review against the team's Reviewer's Checklist: title/description conventions, linked issue, correctness and edge cases, breaking changes, refactor purity, architecture, tests, docs, security, and new dependencies. Findings are grouped by severity with a suggested verdict and a paste-ready draft comment.

The skill is strictly propose-only: it never runs gh pr review, gh pr comment, gh pr edit, gh pr merge, or applies labels. It reads source-of-truth conventions live from CONTRIBUTING.md, DEVELOPER.md, and the maintainer playbook rather than from memory.

twishabansal and others added 2 commits July 29, 2026 10:11
Add the `review-prs` maintainer Agent Skill: a propose-only PR review that
checks title/description conventions, linked issue, correctness (including
type-conversion at the MCP boundary), breaking changes, refactor purity,
architecture (BaseTool embedding), tests, docs, security, and dependencies,
grouped by severity with a paste-ready comment. Never mutates the PR.

Bundles the maintainer playbook as a reference via a relative `references/`
symlink (Agent Skills convention) and links the authoritative repo sources
(CONTRIBUTING.md, DEVELOPER.md, PR template, labels.yaml) rather than the
agent-specific style-guide symlinks.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new maintainer skill review-prs to the toolbox, providing a comprehensive guide (SKILL.md) on how to review GitHub pull requests against the team's checklist. It also updates the main README to list this new skill and adds a reference to the maintainer playbook. The review feedback correctly identifies a grammatically incomplete sentence in the testing section of the new skill document and provides a clear suggestion to resolve it.

Comment thread skills/maintainer/review-prs/SKILL.md Outdated
twishabansal and others added 7 commits July 29, 2026 14:24
Reviewers reject a new source when the database speaks a wire protocol
an existing source already supports, since each copy then has to absorb
every later fix. That rule was only enforced during review and never
written down, so contributors learned it after implementing.
An audit of the review threads on all 2,362 human-authored PRs surfaced
conventions the skill did not encode, and one it got backwards.

The correction: policy PRs were described as carrying little code risk,
which is the exact framing that would have waved through #2473, a
supply-chain attack shipped under a docs typo title. A docs-shaped title
now explicitly does not lower the read bar.

Added as review dimensions: source reuse, tool and parameter
descriptions read as LLM prompts, the AgentError vs ClientServerError
split, integration test placement, and the CLA failure that AI
co-author trailers cause.

Added as a suppression list: the four settled decisions that look like
defects by general Go standards, so a reviewer stops spending findings
relitigating them. Verdicts are also calibrated against the roughly
4.5:1 ratio of approvals to changes-requested the team actually votes.
The skill cited both docs by repo-root path, so an installed copy had no
way to reach them. Symlink them into references/ alongside the playbook
so all three source-of-truth docs travel with the skill and still track
main.
@twishabansal twishabansal changed the title docs(skills): add review-prs skill for mcp-toolbox feat(skills): add review-prs skill for mcp-toolbox Jul 31, 2026
@twishabansal twishabansal changed the title feat(skills): add review-prs skill for mcp-toolbox feat(skill): add review-prs skill for mcp-toolbox Jul 31, 2026
@twishabansal
twishabansal marked this pull request as ready for review July 31, 2026 09:07
@twishabansal
twishabansal requested a review from a team as a code owner July 31, 2026 09:07
@twishabansal
twishabansal requested a review from Yuan325 July 31, 2026 09:14
@twishabansal
twishabansal merged commit 5b7bacc into main Aug 3, 2026
26 checks passed
@twishabansal
twishabansal deleted the docs/add-review-prs-skill branch August 3, 2026 05:54
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🧨 Preview deployments removed.

Cloudflare Pages environments for pr-3743 have been deleted.

Yuan325 added a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)


### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))


### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
github-actions Bot pushed a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to rodineyw/mcp-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to Jaleel-zhu/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to pepe57/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants