From 086c6e1341011dc907cea1cfd6c648033aace52c Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 8 May 2026 11:09:47 -0400 Subject: [PATCH] Update Claude review: tighter prompt, tool restrictions, manual dispatch (#8) * Update Claude review: tighter prompt, tool restrictions, manual dispatch * Add draft PR guard to skip reviews on draft PRs --- .github/workflows/claude-code-review.yaml | 40 ++++++++++++++++++----- 1 file changed, 32 insertions(+), 8 deletions(-) diff --git a/.github/workflows/claude-code-review.yaml b/.github/workflows/claude-code-review.yaml index aa6ff3c..dd78d3f 100644 --- a/.github/workflows/claude-code-review.yaml +++ b/.github/workflows/claude-code-review.yaml @@ -1,8 +1,14 @@ name: Claude Code Review on: + workflow_dispatch: + inputs: + pr_number: + description: Pull request number to review + required: true + type: string pull_request: - types: [opened, synchronize] + types: [opened, ready_for_review] workflow_call: secrets: anthropic_api_key: @@ -15,21 +21,39 @@ permissions: jobs: claude-review: + if: github.event.pull_request.draft == false runs-on: ubuntu-latest timeout-minutes: 10 steps: - uses: actions/checkout@v4 with: - fetch-depth: 0 + fetch-depth: 1 - uses: anthropics/claude-code-action@v1 with: anthropic_api_key: ${{ secrets.anthropic_api_key || secrets.ANTHROPIC_API_KEY }} allowed_bots: '*' prompt: | - Review this pull request. Focus on: - - Code correctness and potential bugs - - Security issues (hardcoded secrets, injection, OWASP top 10) - - Sea Haven conventions: kebab-case resource names, secrets in AWS Secrets Manager (not env vars), Lambda defaults (Python 3.12+, arm64, explicit 60-day log retention) - - README accuracy if changed - Post findings as inline review comments. Be concise — flag real issues, skip nitpicks. + REPO: ${{ github.repository }} + PR NUMBER: ${{ github.event.pull_request.number || github.event.inputs.pr_number }} + + Review this pull request. Only comment on: + - Bugs or logic errors + - Security vulnerabilities (hardcoded secrets, injection, OWASP top 10) + - Breaking changes or regressions + - Sea Haven convention violations: kebab-case resource names, secrets in AWS Secrets Manager (not env vars or SSM), Lambda defaults (Python 3.12+/Node 22.x, arm64, explicit 60-day log retention) + + Do NOT comment on: + - Style, formatting, or naming preferences + - Minor refactoring suggestions + - Performance unless it is a measurable regression + - Things that are already consistent with the existing codebase + + Limit to 5 inline comments maximum. If the PR looks good, leave a single top-level comment saying so — do not force issues where there are none. + + Use `gh pr comment` for top-level feedback. + Use `mcp__github_inline_comment__create_inline_comment` (with `confirmed: true`) for specific code issues. + Only post GitHub comments — do not submit review text as messages. + + claude_args: | + --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)" \ No newline at end of file