Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when relevant, optionally rebase in-house PRs, and report who should review. Supports full, changed-only, behind-only, and conflict-only scopes for cheap daily runs. Use when the user runs /pr-sweep (or /pr-inbound-sweep), or asks to "sweep PRs", "sweep inbound PRs", "security-check outside PRs", "rebase outsider PRs", "rebase our PRs", "approve waiting CI on PRs", "daily PR sweep", or "prep external PRs for review".
74
93%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Low
Low-risk findings worth noting
Prep PRs for review. Fan out one subagent per PR (cap 100). Default is dry-run (report only). Mutating steps require --apply (or the user saying "apply" / "go ahead").
| Invocation | Behavior |
|---|---|
/pr-sweep | All open non-draft PRs (full audit) |
/pr-sweep 12 34 56 | Only those PR numbers |
/pr-sweep --apply | Full set, then rebase and push (--force-with-lease) |
/pr-sweep --apply 12 34 | Rebase and push listed PRs only |
/pr-sweep --outside-only | Action target = outside authors only (default for mutations) |
/pr-sweep --include-in-house | Also rebase/update in-house branches (still never merge) |
/pr-sweep --behind | Only PRs behind base / BEHIND / not up to date |
/pr-sweep --conflicts | Only CONFLICTING / DIRTY / dirty merge state |
/pr-sweep --changed | Only PRs changed since last snapshot (or updatedAt within 24h if no snapshot) |
/pr-sweep --daily | Recommended daily recipe: --changed ∪ --behind ∪ --conflicts ∪ new outside PRs; security-scan new outside; lighter pass on the rest |
/pr-sweep --apply --daily --include-in-house | Daily apply: prep outside + rebase ours when behind/conflicting |
Combine freely: --apply --daily --include-in-house. Explicit PR numbers always win over filters.
git push --force-with-lease + CI approve for PRs that pass security and are marked actionable, in the same turn. --apply on the invocation is consent — do not wait for a second yes. Still never merge a PR and never comment on a PR. A local rebase with no push is a failed apply. Record results in SWEEP-*.md only./loop (same machine, session-scoped, expires ~7d)/loop 1d /pr-sweep --apply --daily --include-in-houseOr dry-run every morning and apply only when you say go:
/loop 1d /pr-sweep --daily --include-in-house/loop intervals: Nm / Nh / Nd (min 60s). Cancel with scheduler_list → scheduler_delete <id>.
/pr-sweep --daily --include-in-house # dry-run first
/pr-sweep --apply --daily --include-in-house # after skimming plan--daily processesBuild the action set as the union of:
updatedAt newer than last snapshot sweptAt, or head SHA changed vs snapshot.mergeStateStatus is BEHIND or not up to date with default branch.mergeable == CONFLICTING or mergeStateStatus in DIRTY, BLOCKED with dirty indicators.security: clean).Skip from action set (still note counts in report):
security: alert from prior snapshot until human clearsblocked-conflicts in the last 24h with no updatedAt change (avoid thrashing)changeset-release/*, pure Renovate) unless --include-botsCost target: daily should touch tens, not all open history. Full /pr-sweep remains the weekly deep scan.
--changed / --daily)Path: .agent/pr-sweep/snapshot.json
{
"repo": "TanStack/ai",
"sweptAt": "2026-08-10T18:00:00Z",
"defaultBranch": "main",
"defaultBranchSha": "abc…",
"prs": {
"1069": {
"author": "mikemikimike",
"outside": true,
"headSha": "def…",
"updatedAt": "2026-08-10T04:01:40Z",
"security": "clean",
"mergeable": "MERGEABLE",
"mergeStateStatus": "UNSTABLE",
"lastAction": "approve-ci",
"lastActionAt": "2026-08-10T17:30:00Z"
}
}
}Write/update after every run (dry-run or apply). Diff against this file for --changed. If missing, treat all open PRs as new for one full pass, then write the snapshot.
gh auth status
gh repo view --json nameWithOwner,defaultBranchRef,ownerStop if not authenticated. Confirm you are in the target repo (or pass owner/repo if the user named one).
git push --force. Only git push --force-with-lease.security: "alert"). Report and stop that PR.--include-in-house (or explicit PR numbers that happen to be in-house).scripts/, .github/workflows/, lockfiles, or install lifecycle — then light scan only.spawn_subagent with isolation: "worktree"). Do not checkout foreign branches in the main workspace.--apply / "apply" / "go ahead" / "yes" after a dry-run is consent. Write the apply plan into the report and mutate immediately. Do not stop for a second yes, including when more than 5 PRs would be mutated. Daily /loop … --apply likewise fires without re-prompting.git push --force-with-lease onto the PR head remote, then verify gh pr view N --json headRefOid changed. Do not mark the PR done until the remote moved or you recorded push-403..agent/pr-sweep/SWEEP-*.md only. No gh pr comment, no review comments, no issue comments.OWNER_REPO=$(gh repo view --json nameWithOwner --jq '.nameWithOwner')
OWNER=$(echo "$OWNER_REPO" | cut -d/ -f1)
REPO=$(echo "$OWNER_REPO" | cut -d/ -f2)
DEFAULT_BRANCH=$(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')
DEFAULT_SHA=$(git rev-parse origin/$DEFAULT_BRANCH 2>/dev/null || gh api repos/$OWNER/$REPO/commits/$DEFAULT_BRANCH --jq .sha)Build in-house logins (US):
gh api orgs/$OWNER/members --paginate --jq '.[].login' 2>/dev/nulladmin or maintain or push:
gh api repos/$OWNER/$REPO/collaborators --paginate --jq '.[] | select(.permissions.admin or .permissions.maintain or .permissions.push) | .login'CODEOWNERS (and resolve teams when cheap).dependabot[bot], renovate[bot], github-actions[bot], copilot-swe-agent[bot], etc. → in-house.Author is outside if login ∉ US.
gh pr list --state open --limit 200 \
--json number,title,url,author,isDraft,baseRefName,headRefName,headRepository,headRepositoryOwner,isCrossRepository,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,additions,deletions,changedFiles,createdAt,updatedAt,assignees,headRefOid(REST fallback if GraphQL 502s.)
Apply filters in order:
--conflicts → keep only conflicting/dirty.--behind → keep only behind/not up to date.--changed → keep only snapshot-diffed changes (or 24h updatedAt if no snapshot).--daily → union of new-outside ∪ changed ∪ behind ∪ conflicts ∪ waiting-approval (see Daily).If count > 100, process 100 most-recently-updated; list the rest under "Skipped (over budget)".
Spawn up to 100 parallel general-purpose subagents. One PR per agent.
Cheap path (daily / already-clean outside): if snapshot has security: clean and head SHA unchanged and only behind/conflicts flag flipped, skip full gh pr diff malware scan — re-fetch mergeability + checks only.
Each agent returns one JSON object only:
{
"number": 123,
"title": "...",
"url": "https://github.com/...",
"author": "login",
"outside": true,
"draft": false,
"security": "clean|alert|review",
"securityReasons": ["..."],
"relevant": true,
"relevanceReason": "<=120 chars",
"behindBase": true,
"mergeable": "MERGEABLE|CONFLICTING|UNKNOWN",
"rebasePlan": "none|rebase|merge-from-base|blocked-conflicts|blocked-security|n/a-skip",
"ci": {
"overall": "passing|failing|pending|waiting-approval|none",
"needsWorkflowApproval": false,
"failedChecks": [],
"pendingChecks": []
},
"assignForReview": true,
"assignTo": ["login-or-team"],
"priority": "P0|P1|P2|P3",
"actionsPlanned": [
"security-alert",
"rebase",
"push-force-with-lease",
"approve-ci",
"none"
],
"blockers": "<=120 chars or empty",
"summary": "<=160 chars"
}You are auditing GitHub PR <URL> in <OWNER/REPO> for pr-sweep.
Mode: read-only. Do not push, comment, approve, or merge.
1) Fetch:
gh pr view <N> --json title,body,author,isDraft,baseRefName,headRefName,headRepositoryOwner,isCrossRepository,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,files,additions,deletions,commits,url,assignees,headRefOid
gh pr checks <N> 2>/dev/null || true
# Full diff only if: outside AND (new OR security not yet clean in snapshot OR headSha changed)
gh pr diff <N> # when required
2) outside: true if author.login not in: <US_LOGINS_CSV>
3) Security:
- Outside: always for new/changed head; use checklist references/security-checklist.md (next to this SKILL.md)
- In-house: clean by default unless scripts/CI/lockfile/install lifecycle touched
security: alert | review | clean
4) relevant + relevanceReason
5) behindBase + rebasePlan:
- none | rebase | merge-from-base | blocked-conflicts | blocked-security | n/a-skip
- In-house with --include-in-house: rebasePlan is rebase/merge-from-base/blocked-conflicts (not n/a-skip)
- In-house without include: rebasePlan n/a-skip
6) CI: overall + needsWorkflowApproval + failed/pending checks
7) assignForReview, assignTo, priority, actionsPlanned
Return ONLY the JSON object on one line.Write .agent/pr-sweep/SWEEP-YYYY-MM-DD.md (create dirs). Structure:
# PR Sweep — <OWNER/REPO> — <date> — mode: dry-run|apply — scope: full|daily|behind|conflicts|changed
## Security alerts
## Needs human eyes
## Outside PRs — recommended actions
## In-house PRs — recommended actions # when --include-in-house
## Skipped
## Apply planAlso update snapshot.json (even on dry-run) with current head SHAs and merge state.
Print a short chat summary: alert count, would-rebase count (outside / in-house), CI approvals, top assign list (max 5), report path.
If mode is dry-run, stop here (unless user then says apply).
--apply is consent. Write the Apply plan into the report and mutate in this turn. Do not wait for another yes.
Done for a rebase target = default-branch is an ancestor of the remote head SHA (push landed) or result: push-403 is recorded. Local-only rebase = failed apply.
Process PRs that are actionable:
| Author | Security | Flag | Mutate? |
|---|---|---|---|
| outside | clean | default | yes (rebase, approve-ci) |
| outside | alert/review | any | no (report only) |
| in-house | clean | --include-in-house | yes (rebase only; CI approve usually N/A) |
| in-house | — | no flag | no |
If security != "clean" → skip mutations.
spawn_subagent with isolation: "worktree", max 8 concurrent. Embed the push + verify steps in the child prompt (completion criterion: remote SHA changed).
BEFORE=$(gh pr view <N> --json headRefOid --jq .headRefOid)
gh pr checkout <N>
git fetch origin <DEFAULT_BRANCH>
git rebase origin/<DEFAULT_BRANCH>
# only if agent said merge-from-base:
# git merge origin/<DEFAULT_BRANCH>
# conflicts: resolve only clear non-overlapping/import/lockfile/generated cases.
# else: git rebase --abort; result=blocked-conflicts; do not push.
git push --force-with-lease
# Forks: push to the upstream `gh pr checkout` set (often not origin).
# If no upstream: git push --force-with-lease <fork-remote> HEAD:<headRefName>
AFTER=$(gh pr view <N> --json headRefOid --jq .headRefOid)
# MUST: AFTER != BEFORE. If equal, the push did not land — not done.Org-fork 403 (maintainerCanModify false): record push-403, do not retry loops. Still never git push --force.
You are applying pr-sweep to GitHub PR https://github.com/OWNER/REPO/pull/N.
Mode: APPLY in a worktree. Never merge. Never git push --force (lease only). Never comment on the PR.
DONE only when the PR's remote head SHA changed, or you return result=push-403 or blocked-conflicts.
A local rebase with no push is a FAILED apply. Do not stop after rebase.
1. BEFORE=$(gh pr view N --json headRefOid --jq .headRefOid)
2. gh pr checkout N
3. git fetch origin DEFAULT_BRANCH
4. git rebase origin/DEFAULT_BRANCH
Conflicts: resolve only trivial non-overlapping import/lockfile/generated cases.
Else git rebase --abort and return blocked-conflicts (no push).
5. git push --force-with-lease
Forks: push the upstream gh pr checkout configured (often not origin).
No upstream: git push --force-with-lease <fork-remote> HEAD:<headRefName>
6. AFTER=$(gh pr view N --json headRefOid --jq .headRefOid)
If AFTER == BEFORE and rebase was not already-current: push did not land — not done.
Return ONLY JSON:
{"number":N,"pushed":true|false,"newHeadSha":"...","result":"rebased-pushed|already-current|blocked-conflicts|push-403|error","blockers":"","summary":""}gh api -X POST repos/$OWNER/$REPO/actions/runs/<RUN_ID>/approveIf 403/404 → note manual approval needed. Do not re-run failing CI unless asked.
Update the markdown report with Results: mutated, still blocked, assign-for-review table.
Do not gh pr edit --add-assignee unless the user said "assign them".
Offer once (opt-in): publish report as secret gist:
gh gist create .agent/pr-sweep/SWEEP-YYYY-MM-DD.md --desc "PR sweep — <OWNER/REPO> — <date>"Secret is the default — never --public unless asked.
Chat closer: ≤5 lines — alerts, actions taken, top PRs to review, report path, gist URL if created.
origin.triage-github (backlog ranking) or pr-babysit (ongoing CI/comment fixing).7fb4a5f
Also appears in
since Sep 29, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.