Operate CLI reviews inside an agentic coding loop with bounded diffs, current authentication, and fix verification. Use when this operator task needs a current, evidence-backed CodeRabbit workflow. Trigger with "review local changes with CodeRabbit".
Use the native CLI before push and feed findings back into coding. Keep auth, scope, and spend visible.
references/official-docs.md and re-check any time-sensitive contract before execution.coderabbit review --plain is the agent-friendly command.Treat Git-provider sessions, CodeRabbit web sessions, CLI credentials, and CodeRabbit API keys as separate credentials. Use only an already-approved session or secret-manager reference, never print a secret, and do not place credentials in .coderabbit.yaml, source files, logs, or deliverables.
Confirm repo state, diff scope, auth mode, allowance, and excluded files.
Run a bounded plain review and capture findings without secrets.
Classify findings, fix approved items, and rerun changed scope.
Stop on repeats, scope expansion, auth errors, or usage limits.
Require approval before credits, headless keys, wider review scope, or pushing. Keep analysis and drafts local until approval is explicit, and record who approved the action and its scope.
A receipt with scope, mode, dispositions, changed files, rerun result, and risks. Include source dates, unknowns, and the exact boundary between observed fact and recommendation.
| Condition | Response |
|---|---|
| Current contract is unclear or docs disagree | Stop mutation, cite both sources, and request owner resolution. |
| Required access or approval is missing | Produce a draft and evidence plan only. |
| Validation or pilot behavior differs from expectation | Restore the prior state and retain the failed evidence. |
| Output contains secrets or private code | Stop, quarantine the artifact, redact it, and notify the data owner. |
Review staged changes before commit and rerun after a race fix.
Use Codex integration with injected secret auth.
references/official-docs.md.88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.