2bo/pr-inbox

レビューリクエストの受け取り箱(最も古いものから順に、AI概要、リスク、リリースへの影響を含む)と独自のプルリクエスト(最初に対処が必要なもの)。ペインから説明と承認をサポート
2bo/pr-inbox

Claude Code モジュール。レビューリクエストと独自のプルリクエストをインボックスに変え、次に必要なもので並べ替えます。
review 3 ⚙2 · ▲1 high │ mine ✗1 fix · ✓1 ship · …2 wait)を表示します/pr-inbox は lazygit と gh-dash のようなペインを開きます。PR ごとに 1 行(リスク、待機時間のヒートバー、CI、AI レビュー)、選択した PR の詳細はリスト下、キーは下の行。2 つのタブ

Claude Code v2.1.288 でテストしました。モジュールは v2.1.287 以降が必要です。
Claude Code で:
/plugin marketplace add 2bo/pr-inbox
/plugin install pr-inbox@pr-inbox
またはシェルから:claude plugin marketplace add 2bo/pr-inbox && claude plugin install pr-inbox@pr-inbox。
| キー | アクション |
| :- | :- |
| 1 / 2 | レビュー待ち / 自分の PR |
| j / k | 次 / 前の PR を選択 |
| e | Claude に PR について説明させます(自分の PR の場合、何がブロックしているかを診断します)。Claude は説明、コメント、レビュー、リンクされた問題と PR を読みます。差分だけではなく |
| a | 承認(確認ダイアログで 承認 を選択した後のみ実行。キャンセル が先に選択されます)|
| v | AI レビュー。通過した場合は承認(下記参照)。v を再度押すと実行中のレビューをキャンセル |
| d | 差分。1 ファイルずつ。Claude Code の差分のように描画:n / b 次/前のファイル、l ファイル リスト、q PR に戻る。ロック ファイルと生成されたファイルは折りたたみ(g で表示)。AI レビューの検出結果はファイルに表示 |
| i | 情報:AI レビューのすべての検出。行へのリンク付き |
| n | ペインに収まらないとき情報の次ページ(最後で最上部に戻る)|
| x | PR を更新までスヌーズ(z はスヌーズされた PR を表示)|
| w | まだレビューされていないボット PR をすべて AI レビュー。1 つずつ(w を再度押すと停止)|
| m | マージ可能な PR の 1 つをマージ。方法を選択した後(画面上のコミットに固定)|
| c | 自分の PR の失敗した GitHub Actions ジョブを再実行 |
| f | リポジトリ、番号、タイトル、@author でフィルタ(Enter で保持。空で削除)|
| h | キーを表示 |
| Ctrl+X Tab | プロンプトからペインに戻る(またはクリック)。キーはペインがフォーカスを持つ間のみ到達。プロンプト下のヒント行が方向を示します |
| o | ブラウザで開く |
| b / s / z | ボット PR / 古い PR / スヌーズされた PR を表示または非表示 |
| r | 再度フェッチ |
| Esc | プロンプトに戻る。ペインは開いたまま |
| q | ペインを閉じる(/pr-inbox で再度開く)|
● は最後に選択してから更新された PR をマークします。承認した PR はレビュー待ちから削除(GitHub がレビューリクエストを削除)します。ここから承認した PR は「最近承認済み」の下に 1 日リストされます。
PR 番号と失敗したチェックはハイパーリンク:ハイパーリンク対応ターミナルで Cmd+click。
/pr-inbox refresh は再度フェッチしてカウント出力。ペイン不開く。
レビューリクエストで v を実行。複数の視点からレビュー。各は独立したモデル呼び出し。通過時に PR を承認:
.claude/ ルール、スキル、サブエージェント等)。次に起こることは誰が決定するかに依存:承認が無しで進む場合(ai_approve auto は作成者に適用)。これらはレビューを停止。対話で承認する場合。レビューは継続。ペイン、対話、トランスクリプトで ⚠ 警告として表示review_model で(デフォルト Sonnet)。各は最初に他に何が必要か言います(PR 頭のファイル、コード検索、上流リリース ノート)。モジュールはリクエスト、フェッチ、スクリーン。レビュアーはレビュー:
.claude/rules/ のルール、レビュアーが求めるあらゆる AI 指示(スキル、サブエージェント定義、コマンド、ネストされた CLAUDE.md、Cursor または Copilot 指示)は基ブランチから読みます。PR は審査を受けるルールを再書き込みできません。設計により AI と通信するため、PR コンテンツとは別に与えられ、注入についてスクリーン されませんPR 下。結果は最初。各視点の結論は 1 ~ 2 文:✓ 問題なし、✗ 承認ブロック、△ ブロック しない もの 検出(低信頼度または検証者が反論)、? 判断できない。i はすべての検出。その証拠と行リンク。承認ダイアログ前。結論と検出もトランスクリプトに書きます。
各レビュアー視点内の問題のみカウント。2 つの視点から検出された同じ問題は 1 回表示。結果は審査されたコミットのため保持されます。再起動後も存在。新しいコミットが到着すれば。行は古いコミットをレビューと言います。
通過するとき。ai_approve 決定:confirm(デフォルト)。最初にあなたに問い合わせ。auto は立刻承認。リポジトリのメンバーと協力者の PR。Dependabot または Renovate。他はまず問い合わせ。フォーク。承認は審査されたコミットに固定。結果は PR と トランスクリプト 下。
1 レビュー は 視点 ごと 約 2 Sonnet 呼び出し + 検証者 + 複数の小さなスクリーン呼び出し。あなたの計画で。通常 1 分以下。
gh auth login でサインイン。モジュールは gh で フェッチ、差分、承認を行う PR。理由は帳 gh はサインイン/config または /plugin configure で変更。
| 設定 | デフォルト | 機能 |
| :- | :- | :- |
| org_filter | (空) | この GitHub 組織の PR のみ表示 |
| stale_days | 30 | これだけ日間 更新されない PR を折りたたみ。Stale 下 |
| refresh_minutes | 5 | GitHub から フェッチ する 頻度 |
| summary_model | sonnet | 概要、リスク、リリース影響を書くモデル |
| desktop_notify | review requests | review requests の OS 通知。all(承認、変更リクエスト、自分の PR の CI 失敗)または off。macOS では osascript。Linux では notify-send。macOS では System Settings でスクリプト エディターに通知を許可。表示されない場合 |
| analysis | auto | レビューリクエスト分析する時:auto(起動から)、when opened(セッションで /pr-inbox 開く一度)または off |
| ai_approve | confirm | v AI レビュー パス時:confirm または auto |
| review_model | sonnet | AI レビューのモデル |
| review_purpose / review_correctness / review_tests / review_security / review_conventions | (組み込み) | 各レビュアーの指示。off スキップ |
| review_dependency_impact / review_supply_chain | (組み込み) | 同じ。Dependabot と Renovate PR |
| explain_prompt | (組み込み) | e レビューリクエスト何か質問。{url} は PR URL |
| risk_high / risk_medium / risk_low | (組み込み) | 分析ごと各リスク レベル カウント |
| release_impact | (組み込み) | リリースへの影響を判定(yes / no / unknown)|
| language | auto | AI 概要、リスク、リリース影響の言語 |
プロンプト設定を空にして組み込みテキスト使用。何を書いても。モジュール指示追加。コメント読み(e の)とリンク問題。ルール PR コンテンツ無信頼 e 読み取り専用。基準変更を存在分析再実行。
メニューは英語。AI 分析とラベルは language に従う:
language 非 auto 設定。例 English または Japaneselanguage 設定LC_ALL、LC_MESSAGES その後 LANG)言語が日本語のとき ラベルは日本語。さもなくば英語。分析は選択言語で書かれます。
分析はモデル呼び出し 1 回 PR ごと。あなたの計画で。結果は PR の更新時間と言語と共に保存。PR 変更または言語変更時のみ再実行。失敗分析は 15 分後、30、60、120 後に再試行。その後 PR 変更まで保留。最大 30 分析開始 / 1 時間。
PR が大きすぎてフル読み取り(30,000 文字超える差分、4,000 説明、300 ファイル)。分析はそう言う(judged on part of the PR)低リスク評価は無い。
e 押すとき。そのターンは モジュール強制の 読み取り専用 ガード下:Read、Grep、Glob と読み取り専用 gh pr view、gh pr diff、gh pr checks、gh issue view、gh run view、gh run list、gh api PR または問題 コメント、レビュー GET リクエスト実行可能。編集、他コマンド、Web アクセス、サブエージェント、承認、コメント、プッシュは拒否。許可モードまたはルール通す場合も。ガード は ターン で終了。次に問う もの セッション の標準 許可で実行v)。 Anthropic の指示に沿って構築。間接プロンプト注入。デュアル LLM パターン。承認は レビュアーの構造化 回答から コード で 決定。モデル では 決定 され ません。レビュー の モデル はツール なし:コマンド実行、ローカル ファイル読み取り、ネットワーク到達、書き込み はできません。モジュール がレビュー PR から フェッチ したもの のみ読み(と、依存アップデート用、上流リリース ノート と GitHub 上のファイル)。読み込み要求は最初に検証。コンテンツは 信頼できない JSON ラベル 付き到達。注入スクリーン。不可視文字削除。まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add 2bo/pr-inbox claude plugin install pr-inbox
A Claude Code mod that turns your review requests and your own pull requests into an inbox, ordered by what needs you next.
review 3 ⚙2 · ▲1 high │ mine ✗1 fix · ✓1 ship · …2 wait)/pr-inbox opens a pane in the spirit of lazygit and gh-dash: one line per PR (risk or state, how long it has waited as a heat bar, CI, AI review), the selected PR's details under the list, and the keys on the bottom line. Two tabs

Tested with Claude Code v2.1.288. Mods need v2.1.287 or later.
In Claude Code:
/plugin marketplace add 2bo/pr-inbox
/plugin install pr-inbox@pr-inbox
Or from the shell: claude plugin marketplace add 2bo/pr-inbox && claude plugin install pr-inbox@pr-inbox.
| Key | Action |
| :- | :- |
| 1 / 2 | To review / My PRs |
| j / k | Select the next / previous PR |
| e | Ask Claude to explain the PR (for your own PR, to diagnose what blocks it). Claude reads the description, comments, reviews and linked issues and PRs, not only the diff |
| a | Approve (runs only after you choose Approve in the confirmation dialog, where Cancel is selected first) |
| v | AI review, then approve if it passes (see below). v again cancels a running review |
| d | The diff, one file at a time, drawn like Claude Code's own diffs: n / b next and previous file, l the list of files, q back to the PRs. Lockfiles and generated files are folded (g shows them); the AI review's findings in a file are listed above it |
| i | Info: every finding of the AI review, with links to the lines |
| n | Next page of the info when it does not fit the pane (at the end, back to the top) |
| x | Snooze the PR until it is updated (z shows snoozed PRs) |
| w | AI review every bot PR not reviewed yet, one at a time (w again stops) |
| m | Merge one of your PRs that is ready, after picking a method (pinned to the commit on screen) |
| c | Re-run the failed GitHub Actions jobs of one of your PRs |
| f | Filter by repository, number, title or @author (Enter keeps it; an empty one clears it) |
| h | Show the keys |
| Ctrl+X Tab | From the prompt back to the pane (or click it). Keys reach the pane only while it has the focus. The hint line under the prompt says which way to go |
| o | Open in the browser |
| b / s / z | Show or hide bot PRs / stale PRs / snoozed PRs |
| r | Fetch again |
| Esc | Back to the prompt; the pane stays open |
| q | Close the pane (/pr-inbox opens it again) |
● marks PRs updated since you last selected them. A PR you approve leaves To review, as GitHub drops the review request; PRs approved from here stay listed under it as "Approved recently" for a day.
PR numbers and failed checks are hyperlinks: Cmd+click them in a terminal that supports hyperlinks.
/pr-inbox refresh fetches again and prints the counts without opening the pane.
v on a review request runs a review from several perspectives, each an independent model call, and approves the PR when it passes:
.claude/ rules, skills, subagents and the like). What happens next depends on who decides: when the approval would go through without you (ai_approve auto for an author it applies to), any of these stops the review; when you approve in the dialog, the review goes on and they are shown as ⚠ warnings in the pane, the dialog and the transcriptreview_model (Sonnet by default). Each first says what else it needs to read (files at the PR head, code searches, upstream release notes); the mod checks the request, fetches and screens it, then the reviewer reviews:
.claude/rules/, and any AI instruction a reviewer asks for (skills, subagent definitions, commands, nested CLAUDE.md, Cursor or Copilot instructions) are read from the base branch, so a PR cannot rewrite the rules it is reviewed by. They talk to AI by design, so they are given apart from the PR content and not screened for injectionUnder the PR, the outcome comes first, then each perspective's conclusion in a sentence or two: ✓ no problems, ✗ blocks the approval, △ found something that does not block (low confidence, or refuted by the verifier), ? could not tell. i shows every finding with its evidence and a link to the line. Before the approval dialog, the conclusions and findings are also written to the transcript.
Only problems within each reviewer's perspective count, and the same problem found from two perspectives is shown once. The result is kept for the reviewed commit, so it is still there after a restart; when new commits arrive, the row says the review is of an older commit.
When it passes, ai_approve decides: confirm (default) asks you first; auto approves at once for PRs from members and collaborators of the repository and from Dependabot or Renovate, and still asks for anyone else and for forks. The approval is pinned to the reviewed commit. The outcome shows under the PR and in the transcript.
A review makes about two Sonnet calls per perspective plus the verifier and several small screening calls, on your plan. It usually takes under a minute.
gh auth login. The mod fetches, diffs and approves PRs through gh, as the account gh is signed in toChange them with /config or /plugin configure.
| Setting | Default | What it does |
| :- | :- | :- |
| org_filter | (empty) | Only show PRs in this GitHub organization |
| stale_days | 30 | Fold your PRs not updated for this many days under Stale |
| refresh_minutes | 5 | How often to fetch from GitHub |
| summary_model | sonnet | The model that writes the summary, risk and release impact |
| desktop_notify | review requests | OS notifications for review requests, all (also approvals, changes requested and CI failures on your PRs) or off. Uses osascript on macOS and notify-send on Linux. On macOS, allow notifications for Script Editor in System Settings if none appear |
| analysis | auto | When review requests are analyzed: auto (from startup), when opened (once you open /pr-inbox in the session) or off |
| ai_approve | confirm | What v does when the AI review passes: confirm or auto |
| review_model | sonnet | The model of the AI review |
| review_purpose / review_correctness / review_tests / review_security / review_conventions | (built-in) | Instructions for each reviewer. off skips that perspective |
| review_dependency_impact / review_supply_chain | (built-in) | The same, for Dependabot and Renovate PRs |
| explain_prompt | (built-in) | What e asks about a review request. {url} becomes the PR URL |
| risk_high / risk_medium / risk_low | (built-in) | What counts as each risk level in the analysis |
| release_impact | (built-in) | How to judge the impact on release (yes / no / unknown) |
| language | auto | The language of the AI summary, risk and release impact |
Leave the prompt settings empty to use the built-in text. Whatever you write, the mod still adds the instruction to read comments and linked issues (for e), and the rules that keep PR content untrusted and e read-only. Changing the criteria redoes the stored analyses.
The menus are in English. The AI analysis and its labels follow language:
language set to anything other than auto, such as English or Japaneselanguage settingLC_ALL, LC_MESSAGES, then LANG)The labels are in Japanese when the language is Japanese, and in English otherwise. The analysis itself is written in whatever language is chosen.
The analysis calls the model once per PR, on your plan. Results are stored with the PR's update time and language, and are redone only when the PR changes or the language does. A failed analysis is retried after 15 minutes, then 30, 60 and 120, and then left until the PR changes. At most 30 analyses start in an hour.
When a PR is too large to read whole (more than 30,000 characters of diff, 4,000 of description or 300 files), the analysis says so (judged on part of the PR) and never rates it low risk.
e, that turn runs under a read-only guard enforced by the mod: only Read, Grep, Glob and the read-only gh pr view, gh pr diff, gh pr checks, gh issue view, gh run view, gh run list, and gh api GET requests for a PR's or issue's comments and reviews can run. Edits, other commands, web access, subagents, approvals, comments and pushes are refused, even if your permission mode or allow rules would let them through. The guard ends with that turn; anything you ask next runs with your session's usual permissionsv). Built along Anthropic's guidance on indirect prompt injection and the dual-LLM pattern. The approval is decided in code from the reviewers' structured answers, never by a model. The review's models have no tools: they cannot run commands, read local files, reach the network or write anything. They read only what the mod fetched from the PR under review (and, for dependency updates, upstream release notes and files on GitHub); what they ask to read is validated first. Content reaches them as JSON labeled as untrusted, screened for injected instructions, with invisible characters stripped. Any error, timeout or unparsable answer blocks the approval; a suspected injection blocks it when no person approves, and is a ⚠ warning when you do. auto is still a choice to trust an AI judgment: keep it to repositories where that is acceptable, and keep branch protection and required reviews as the last lined) is drawn by Claude Code's own highlighter, line by line with the same characters stripped (tabs kept), and is never sent to a model. Links open only canonical https:// URLs. Failed-check links point wherever the CI system says, which may be a third-party siteanalysis on auto, as soon as Claude Code starts (including claude -p runs and sessions in other projects) and on every refresh, each review request that has not been analyzed yet is sent to the model Claude Code is configured with (Anthropic, or your Bedrock, Vertex or gateway setup), under your account: its repository and number, author, title, list of changed files, description (first 4,000 characters) and diff (first 30,000 characters). You do not have to open the pane. Follow your organization's rules for work code: narrow it with org_filter, or set analysis to when opened or off~/.claude/plugins/store/): the URLs of your review requests and the state of your own PRs (to notice changes), each analysis (summary, risk, release impact), each AI review's findings, snoozed PRs and which updates you have seen. Analyses of PRs that are no longer open are deleted on the next refreshgh; the mod holds no token. OS notifications go through osascript or notify-send, with the text passed as arguments, never as script. Commands run as argument lists, without a shellpnpm install
claude --plugin-dir . # run the working copy; loading once also writes the type declarations to .claude-plugin/types/ (needed by typecheck)
pnpm run check # validate (--strict) → tsc → Biome → claude plugin test
pnpm run demo starts Claude Code with the mod against made-up PRs: a fake gh (scripts/demo/gh) answers every GitHub call, so nothing real is read or written, and approvals and merges go nowhere. The mod's real state is set aside and put back when you /exit. It is also how the screenshot is taken.
Tests live in tests/*.test.ts. GitHub, the model, the store and the environment are all stubbed, so tests make no network calls.
MIT