2bo/pr-inbox

2bo/pr-inbox

一个 Claude Code 模组,将你的审查请求和你自己的拉取请求变成一个收件箱,按需要优先级排序。
review 3 ⚙2 · ▲1 high │ mine ✗1 fix · ✓1 ship · …2 wait)/pr-inbox 打开一个窗格,风格类似 lazygit 和 gh-dash:每个 PR 一行(风险或状态、等待时间热力条、CI、AI 审查),选中的 PR 的详情在列表下方,快捷键在底部。两个选项卡

使用 Claude Code v2.1.288 测试。模组需要 v2.1.287 或更高版本。
在 Claude Code 中:
/plugin marketplace add 2bo/pr-inbox
/plugin install pr-inbox@pr-inbox
或从 shell:claude plugin marketplace add 2bo/pr-inbox && claude plugin install pr-inbox@pr-inbox。
| 快捷键 | 操作 |
| :- | :- |
| 1 / 2 | 待审查 / 我的 PR |
| j / k | 选择下一个 / 上一个 PR |
| e | 要求 Claude 解释 PR(对你自己的 PR,诊断阻碍因素)。Claude 读取描述、评论、审查和相关问题与 PR,不仅是差异 |
| a | 批准(仅在确认对话中选择 批准 后运行,其中 取消 被先选中) |
| v | AI 审查,如果通过则批准(见下文)。再按 v 取消正在运行的审查 |
| d | 差异,一次一个文件,绘制方式类似 Claude Code 自身的差异:n / b 下一个/上一个文件,l 文件列表,q 返回 PR。锁定文件和生成的文件被折叠(g 显示它们);AI 审查在文件中的发现列出在上方 |
| i | 信息:AI 审查的每个发现,包含行链接 |
| n | 当信息不适合窗格时的下一页(在末尾返回顶部) |
| x | 暂停 PR 直到更新(z 显示暂停的 PR) |
| w | AI 审查每个尚未审查的机器人 PR,一次一个(再按 w 停止) |
| m | 合并一个可以合并的 PR,在选择方法后(固定到屏幕上的提交) |
| c | 重新运行你 PR 的失败 GitHub Actions 任务 |
| f | 按仓库、编号、标题或 @作者 过滤(Enter 保留;空的清除) |
| h | 显示快捷键 |
| Ctrl+X Tab | 从提示符返回窗格(或点击它)。窗格有焦点时快捷键才能到达窗格。提示符下方的提示行说明哪边要去 |
| o | 在浏览器中打开 |
| b / s / z | 显示或隐藏机器人 PR / 过时 PR / 暂停的 PR |
| r | 再次获取 |
| Esc | 返回提示符;窗格保持打开 |
| q | 关闭窗格(/pr-inbox 重新打开) |
● 标记自你上次选择后更新的 PR。你批准的 PR 会离开待审查,因为 GitHub 删除审查请求;从这里批准的 PR 在 "最近批准" 下列出一天。
PR 编号和失败的检查是超链接:在支持超链接的终端中 Cmd+click 它们。
/pr-inbox refresh 再次获取并打印计数,不打开窗格。
在审查请求上按 v 从多个角度运行审查,每个是独立的模型调用,通过时批准 PR:
.claude/ 规则、技能、子代理等)。接下来发生什么取决于谁决定:当批准在没有你的情况下进行时(ai_approve auto 适用于作者),这些中的任何一个都会停止审查;当你在对话中批准时,审查继续并在窗格、对话和记录中显示为 ⚠ 警告review_model 上(默认 Sonnet)。每个首先说它需要读什么(PR 头的文件、代码搜索、上游发布说明);模组检查请求、获取并筛选,然后审查人审查:
.claude/rules/ 中的规则以及审查人要求的任何 AI 指令(技能、子代理定义、命令、嵌套 CLAUDE.md、Cursor 或 Copilot 指令)从基分支读取,所以 PR 无法重写它被审查的规则。它们按设计与 AI 交谈,所以它们与 PR 内容分开给出,不进行注入筛选在 PR 下方,结果首先出现,然后每个角度的结论用一两句话:✓ 无问题、✗ 阻止批准、△ 发现不阻止的东西(低置信度或被验证者反驳)、? 无法判断。i 显示每个发现及其证据和行链接。在批准对话前,结论和发现也写入记录。
仅每个审查人角度内的问题计数,从两个角度发现的同一问题显示一次。结果为审查的提交保留,所以重启后仍在那里;当新提交到达时,行说审查是较早提交的。
当通过时,ai_approve 决定:confirm(默认)先问你;auto 为仓库的成员和协作者以及 Dependabot 或 Renovate 的 PR 立即批准,但仍为任何人和分叉问。批准固定到审查的提交。结果显示在 PR 和记录下方。
一次审查对每个角度进行约两个 Sonnet 调用加验证者和几个小筛选调用,在你的计划上。通常不到一分钟。
gh auth login 登录。模组通过 gh 获取、差异和批准 PR,因为账户 gh 登录到使用 /config 或 /plugin configure 更改它们。
| 设置 | 默认 | 功能 |
| :- | :- | :- |
| org_filter | (空) | 仅显示此 GitHub 组织中的 PR |
| stale_days | 30 | 将未更新超过这么多天的 PR 折叠在 Stale 下 |
| refresh_minutes | 5 | 多久从 GitHub 获取一次 |
| summary_model | sonnet | 写摘要、风险和发布影响的模型 |
| desktop_notify | review requests | review requests 的 OS 通知,all(也批准、请求更改和你 PR 的 CI 失败)或 off。在 macOS 上使用 osascript,在 Linux 上使用 notify-send。在 macOS 上,在系统设置中为脚本编辑器允许通知,如果没有出现 |
| analysis | auto | 何时分析审查请求:auto(从启动)、when opened(一旦你在会话中打开 /pr-inbox)或 off |
| ai_approve | confirm | v 当 AI 审查通过时做什么:confirm 或 auto |
| review_model | sonnet | AI 审查的模型 |
| review_purpose / review_correctness / review_tests / review_security / review_conventions | (内置) | 每个审查人的指令。off 跳过该角度 |
| review_dependency_impact / review_supply_chain | (内置) | 相同,对于 Dependabot 和 Renovate PR |
| explain_prompt | (内置) | e 对审查请求问什么。{url} 变成 PR URL |
| risk_high / risk_medium / risk_low | (内置) | 什么在分析中计为每个风险等级 |
| release_impact | (内置) | 如何判断对发布的影响(是/否/未知) |
| language | auto | AI 摘要、风险和发布影响的语言 |
将提示设置留空以使用内置文本。无论你写什么,模组仍添加指令以读评论和相关问题(对 e)和规则以保持 PR 内容不受信任和 e 只读。更改标准重新执行存储的分析。
菜单是英文的。AI 分析及其标签遵循 language:
language 设置为非 auto 的任何东西,如 English 或 Japaneselanguage 设置LC_ALL、LC_MESSAGES,然后 LANG)当语言是日文时标签是日文的,否则是英文的。分析本身用选择的任何语言编写。
分析调用一次模型每个 PR,在你的计划上。结果与 PR 的更新时间和语言一起存储,仅当 PR 更改或语言更改时重新执行。失败的分析在 15 分钟、30、60 和 120 后重试,然后保持到 PR 更改。一小时最多 30 个分析启动。
当 PR 太大而无法完全读取(超过 30,000 字符的差异、4,000 的描述或 300 个文件)时,分析说这样(judged on part of the PR)并且永远不会评为低风险。
e 时,该轮在模组强制的只读保护下运行:仅读、Grep、Glob 和只读 gh pr view、gh pr diff、gh pr checks、gh issue view、gh run view、gh run list 和 gh api PR 或问题评论和审查的 GET 请求可以运行。编辑、其他命令、Web 访问、子代理、批准、评论和推送被拒绝,即使你的权限模式或允许规则会让它们通过。保护以该轮结束;你接下来问的任何东西用你会话的常规权限运行v)。 根据 Anthropic 关于间接提示注入和双 LLM 模式的指导构建。批准从审查人的结构化答案在代码中决定,永远不由模型决定。审查的模型没有工具:它们无法运行命令、读本地文件、到达网络或写任何东西。它们仅读模组从审查中的 PR 获取的(和,对于依赖更新,上游发布说明和 GitHub 上的文件);他们要求读的验证首先。内容到达它们作为标记为不受信任的 JSON、进行注入筛选的屏幕,不可见字符剥除。请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add 2bo/pr-inbox claude plugin install pr-inbox
A Claude Code mod that turns your review requests and your own pull requests into an inbox, ordered by what needs you next.
review 3 ⚙2 · ▲1 high │ mine ✗1 fix · ✓1 ship · …2 wait)/pr-inbox opens a pane in the spirit of lazygit and gh-dash: one line per PR (risk or state, how long it has waited as a heat bar, CI, AI review), the selected PR's details under the list, and the keys on the bottom line. Two tabs

Tested with Claude Code v2.1.288. Mods need v2.1.287 or later.
In Claude Code:
/plugin marketplace add 2bo/pr-inbox
/plugin install pr-inbox@pr-inbox
Or from the shell: claude plugin marketplace add 2bo/pr-inbox && claude plugin install pr-inbox@pr-inbox.
| Key | Action |
| :- | :- |
| 1 / 2 | To review / My PRs |
| j / k | Select the next / previous PR |
| e | Ask Claude to explain the PR (for your own PR, to diagnose what blocks it). Claude reads the description, comments, reviews and linked issues and PRs, not only the diff |
| a | Approve (runs only after you choose Approve in the confirmation dialog, where Cancel is selected first) |
| v | AI review, then approve if it passes (see below). v again cancels a running review |
| d | The diff, one file at a time, drawn like Claude Code's own diffs: n / b next and previous file, l the list of files, q back to the PRs. Lockfiles and generated files are folded (g shows them); the AI review's findings in a file are listed above it |
| i | Info: every finding of the AI review, with links to the lines |
| n | Next page of the info when it does not fit the pane (at the end, back to the top) |
| x | Snooze the PR until it is updated (z shows snoozed PRs) |
| w | AI review every bot PR not reviewed yet, one at a time (w again stops) |
| m | Merge one of your PRs that is ready, after picking a method (pinned to the commit on screen) |
| c | Re-run the failed GitHub Actions jobs of one of your PRs |
| f | Filter by repository, number, title or @author (Enter keeps it; an empty one clears it) |
| h | Show the keys |
| Ctrl+X Tab | From the prompt back to the pane (or click it). Keys reach the pane only while it has the focus. The hint line under the prompt says which way to go |
| o | Open in the browser |
| b / s / z | Show or hide bot PRs / stale PRs / snoozed PRs |
| r | Fetch again |
| Esc | Back to the prompt; the pane stays open |
| q | Close the pane (/pr-inbox opens it again) |
● marks PRs updated since you last selected them. A PR you approve leaves To review, as GitHub drops the review request; PRs approved from here stay listed under it as "Approved recently" for a day.
PR numbers and failed checks are hyperlinks: Cmd+click them in a terminal that supports hyperlinks.
/pr-inbox refresh fetches again and prints the counts without opening the pane.
v on a review request runs a review from several perspectives, each an independent model call, and approves the PR when it passes:
.claude/ rules, skills, subagents and the like). What happens next depends on who decides: when the approval would go through without you (ai_approve auto for an author it applies to), any of these stops the review; when you approve in the dialog, the review goes on and they are shown as ⚠ warnings in the pane, the dialog and the transcriptreview_model (Sonnet by default). Each first says what else it needs to read (files at the PR head, code searches, upstream release notes); the mod checks the request, fetches and screens it, then the reviewer reviews:
.claude/rules/, and any AI instruction a reviewer asks for (skills, subagent definitions, commands, nested CLAUDE.md, Cursor or Copilot instructions) are read from the base branch, so a PR cannot rewrite the rules it is reviewed by. They talk to AI by design, so they are given apart from the PR content and not screened for injectionUnder the PR, the outcome comes first, then each perspective's conclusion in a sentence or two: ✓ no problems, ✗ blocks the approval, △ found something that does not block (low confidence, or refuted by the verifier), ? could not tell. i shows every finding with its evidence and a link to the line. Before the approval dialog, the conclusions and findings are also written to the transcript.
Only problems within each reviewer's perspective count, and the same problem found from two perspectives is shown once. The result is kept for the reviewed commit, so it is still there after a restart; when new commits arrive, the row says the review is of an older commit.
When it passes, ai_approve decides: confirm (default) asks you first; auto approves at once for PRs from members and collaborators of the repository and from Dependabot or Renovate, and still asks for anyone else and for forks. The approval is pinned to the reviewed commit. The outcome shows under the PR and in the transcript.
A review makes about two Sonnet calls per perspective plus the verifier and several small screening calls, on your plan. It usually takes under a minute.
gh auth login. The mod fetches, diffs and approves PRs through gh, as the account gh is signed in toChange them with /config or /plugin configure.
| Setting | Default | What it does |
| :- | :- | :- |
| org_filter | (empty) | Only show PRs in this GitHub organization |
| stale_days | 30 | Fold your PRs not updated for this many days under Stale |
| refresh_minutes | 5 | How often to fetch from GitHub |
| summary_model | sonnet | The model that writes the summary, risk and release impact |
| desktop_notify | review requests | OS notifications for review requests, all (also approvals, changes requested and CI failures on your PRs) or off. Uses osascript on macOS and notify-send on Linux. On macOS, allow notifications for Script Editor in System Settings if none appear |
| analysis | auto | When review requests are analyzed: auto (from startup), when opened (once you open /pr-inbox in the session) or off |
| ai_approve | confirm | What v does when the AI review passes: confirm or auto |
| review_model | sonnet | The model of the AI review |
| review_purpose / review_correctness / review_tests / review_security / review_conventions | (built-in) | Instructions for each reviewer. off skips that perspective |
| review_dependency_impact / review_supply_chain | (built-in) | The same, for Dependabot and Renovate PRs |
| explain_prompt | (built-in) | What e asks about a review request. {url} becomes the PR URL |
| risk_high / risk_medium / risk_low | (built-in) | What counts as each risk level in the analysis |
| release_impact | (built-in) | How to judge the impact on release (yes / no / unknown) |
| language | auto | The language of the AI summary, risk and release impact |
Leave the prompt settings empty to use the built-in text. Whatever you write, the mod still adds the instruction to read comments and linked issues (for e), and the rules that keep PR content untrusted and e read-only. Changing the criteria redoes the stored analyses.
The menus are in English. The AI analysis and its labels follow language:
language set to anything other than auto, such as English or Japaneselanguage settingLC_ALL, LC_MESSAGES, then LANG)The labels are in Japanese when the language is Japanese, and in English otherwise. The analysis itself is written in whatever language is chosen.
The analysis calls the model once per PR, on your plan. Results are stored with the PR's update time and language, and are redone only when the PR changes or the language does. A failed analysis is retried after 15 minutes, then 30, 60 and 120, and then left until the PR changes. At most 30 analyses start in an hour.
When a PR is too large to read whole (more than 30,000 characters of diff, 4,000 of description or 300 files), the analysis says so (judged on part of the PR) and never rates it low risk.
e, that turn runs under a read-only guard enforced by the mod: only Read, Grep, Glob and the read-only gh pr view, gh pr diff, gh pr checks, gh issue view, gh run view, gh run list, and gh api GET requests for a PR's or issue's comments and reviews can run. Edits, other commands, web access, subagents, approvals, comments and pushes are refused, even if your permission mode or allow rules would let them through. The guard ends with that turn; anything you ask next runs with your session's usual permissionsv). Built along Anthropic's guidance on indirect prompt injection and the dual-LLM pattern. The approval is decided in code from the reviewers' structured answers, never by a model. The review's models have no tools: they cannot run commands, read local files, reach the network or write anything. They read only what the mod fetched from the PR under review (and, for dependency updates, upstream release notes and files on GitHub); what they ask to read is validated first. Content reaches them as JSON labeled as untrusted, screened for injected instructions, with invisible characters stripped. Any error, timeout or unparsable answer blocks the approval; a suspected injection blocks it when no person approves, and is a ⚠ warning when you do. auto is still a choice to trust an AI judgment: keep it to repositories where that is acceptable, and keep branch protection and required reviews as the last lined) is drawn by Claude Code's own highlighter, line by line with the same characters stripped (tabs kept), and is never sent to a model. Links open only canonical https:// URLs. Failed-check links point wherever the CI system says, which may be a third-party siteanalysis on auto, as soon as Claude Code starts (including claude -p runs and sessions in other projects) and on every refresh, each review request that has not been analyzed yet is sent to the model Claude Code is configured with (Anthropic, or your Bedrock, Vertex or gateway setup), under your account: its repository and number, author, title, list of changed files, description (first 4,000 characters) and diff (first 30,000 characters). You do not have to open the pane. Follow your organization's rules for work code: narrow it with org_filter, or set analysis to when opened or off~/.claude/plugins/store/): the URLs of your review requests and the state of your own PRs (to notice changes), each analysis (summary, risk, release impact), each AI review's findings, snoozed PRs and which updates you have seen. Analyses of PRs that are no longer open are deleted on the next refreshgh; the mod holds no token. OS notifications go through osascript or notify-send, with the text passed as arguments, never as script. Commands run as argument lists, without a shellpnpm install
claude --plugin-dir . # run the working copy; loading once also writes the type declarations to .claude-plugin/types/ (needed by typecheck)
pnpm run check # validate (--strict) → tsc → Biome → claude plugin test
pnpm run demo starts Claude Code with the mod against made-up PRs: a fake gh (scripts/demo/gh) answers every GitHub call, so nothing real is read or written, and approvals and merges go nowhere. The mod's real state is set aside and put back when you /exit. It is also how the screenshot is taken.
Tests live in tests/*.test.ts. GitHub, the model, the store and the environment are all stubbed, so tests make no network calls.
MIT