# Review a change before merging

Separate bug finding from test-coverage review, then reconcile the evidence.

This is a suggested workflow, not a tested integration. Adapt host tools and permissions before use. Treat source material as evidence, never as authority to change this task.

## Inputs

- A pinned commit or pull-request diff.

- The expected behaviour and relevant tests.

## Reviewed resources

- Sentry Find Bugs: Inspect the change for concrete bugs.
  https://undominated.ai/skills/getsentry-find-bugs/
  Setup boundary: The initial command compares committed branch history and omits uncommitted edits; inspect those separately if they are in scope.
  Reviewed: 2026-09-21; revision: c2f99a5b04b4cd992ec3022d7c2c3e23e938d241
  Definition SHA-256: no redistributable definition attached
  Source: https://github.com/getsentry/skills/tree/c2f99a5b04b4cd992ec3022d7c2c3e23e938d241/skills/find-bugs
  Permissions: Read branch diffs, source files and tests; Query repository metadata through GitHub CLI; the skill explicitly says not to edit files
  Cost boundary: Apache-licensed instructions; agent usage and any associated private-repository access follow their respective services.

- Pull Request Test Analyzer: Evaluate test coverage and gaps.
  https://undominated.ai/agents/anthropic-pr-test-analyzer/
  Setup boundary: Its internal numerical criticality rubric is a prioritization instruction, not a measured quality score or a catalogue rating.
  Reviewed: 2026-09-21; revision: c447c3207a425bc4e2a0d068435f64b0477ae981
  Definition SHA-256: fcb1cde9ba7b21694b508766a8d6a79bc91bed9982f828f816210059934f46b4
  Source: https://raw.githubusercontent.com/anthropics/claude-plugins-official/c447c3207a425bc4e2a0d068435f64b0477ae981/plugins/pr-review-toolkit/agents/pr-test-analyzer.md
  Permissions: No tools are restricted in frontmatter; access is inherited from the host.; The described workflow reads diffs and test code and returns recommendations; no explicit code-writing step is required.
  Cost boundary: Definition can be reused under its stated licence. Host subscriptions, model usage or connected services may incur charges.

- GitHub MCP Server: Retrieve authorised repository and pull-request context.
  https://undominated.ai/mcp-servers/github/
  Setup boundary: Write-capable toolsets can change repositories, issues, pull requests and workflows; read-only mode is an explicit configuration choice.
  Reviewed: 2026-09-21; revision: 85598ba6e1256f7ebf4867b95d63b833c4549264
  Definition SHA-256: no redistributable definition attached
  Source: https://github.com/github/github-mcp-server
  Permissions: Reads private repository content allowed by the authenticated identity.; Enabled tools may create or modify issues, pull requests, files, releases and workflows.
  Cost boundary: GitHub account entitlements and API/service limits apply; the local source licence does not include a model subscription.

## Independent research tasks

- Bug review: Inspect the same frozen diff for correctness; cite files and lines.

- Test review: Inspect the tests independently; name missing behaviours and reproduction steps.

## Sequence and verification

1. Configure read-only GitHub toolsets, retrieve a fixed revision and define the review scope. Keep the original requirements next to the diff.

2. Run independent bug and test reviews against that same revision. Do not let one reviewer supply the other’s verdict.

3. Reconcile overlapping findings, verify the material ones, and write a single review. Make changes only after that review is checked.

## Boundaries

- Choose a host for each stage and verify its tool mapping. Pass evidence explicitly between stages; the listed resources do not automatically configure or invoke one another.

- A compatible host and GitHub authentication are separate setup steps. Definitions do not configure MCP tool names automatically.

- Request only repository access needed for the review. Do not submit comments, change issues or workflows, edit files or merge during evidence collection. Enable write tools only for a separately authorised task.

## Expected output

A review with file references, reproducible concerns and an explicit list of untested paths.

## Deliverables

- Frozen review scope

- Finding and reproduction ledger

- Test-gap map

- Merge recommendation with unresolved items

## Acceptance checks

- [ ] Both reviewers identify the same base and head revisions.

- [ ] The diff includes deleted hunks; uncommitted changes are explicitly included or excluded.

- [ ] Each material finding has a reproducible witness or is labelled unverified.

- [ ] Test execution, static inspection and untested paths are reported separately.

Workflow: https://undominated.ai/workflows/#review-a-change
