The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To run a manual Claude Code review on selected pull requests, add a workflow under .github/workflows/, store its authentication credential as a GitHub Actions secret, and grant only the permissions needed for review. The example below follows Anthropic’s documented anthropics/claude-code-action@v1 workflow pattern; adapt its triggers, output, and access controls to your repository before using it. Public-repository pull requests from forks will not receive ordinary repository secrets, so this setup will not authenticate for those runs.
What this workflow does—and what it does not
Claude Code Action runs inside your repository’s GitHub Actions workflow. It can respond to a trigger phrase such as @claude, or run automatically when a configured GitHub event occurs. A checked-in workflow with a specific pull-request trigger and review prompt makes the automated behavior explicit and lets the repository team control its scope. Manual setup requires repository administrator access. Anthropic documents this Action separately from its automatic Claude Code Review feature and cloud-hosted Claude Code sessions; they are not interchangeable workflows. Anthropic’s GitHub Actions documentation
The workflow is review assistance, not a merge approval or a guarantee that defects will be found. Anthropic advises: “Grant the workflow only the permissions it needs, and review Claude’s changes before merging.” The documentation does not provide an independently measured accuracy rate.
Set up a pull-request review workflow
- Choose the GitHub App. Install Anthropic’s Claude GitHub App, or create a custom GitHub App if your organization needs a narrower installation permission set. Anthropic says the standard App’s shared permissions cannot be reduced during installation; its custom-App option is documented for organizations that want only the relevant Contents, Issues, and Pull requests permissions.
- Add authentication. Store an
ANTHROPIC_API_KEYor, where appropriate, aCLAUDE_CODE_OAUTH_TOKENin GitHub Secrets. Do not put credentials in the workflow file or repository. Anthropic also documents OIDC federation for supported enterprise provider routes. - Create a workflow file. Add a YAML workflow in
.github/workflows/. The following illustrates Anthropic’s documented review pattern; confirm current action inputs and required permissions against the live documentation before adopting it:
name: Claude PR review
on:
pull_request:
types: [opened, synchronize, ready_for_review, reopened]
jobs:
review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: read
id-token: write
steps:
- uses: actions/checkout@v4
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: "/plugin install code-review@claude-plugins-officialnReview this pull request. Use --comment to post inline findings."
claude_args: "--allowedTools mcp__github_inline_comment__create_inline_comment"
This represents the documented pattern, not a universal security prescription: confirm whether each permission and input remains necessary for your chosen authentication and output behavior, and adjust it to your repository’s policies. The documentation’s example uses read access for Contents, Pull requests, and Issues, plus id-token: write for default GitHub App authentication.
#1 Best Overall
Choose triggers deliberately
The example runs on pull requests that are opened, synchronized with new commits, marked ready for review, or reopened. Anthropic says its documented review workflow skips draft and closed pull requests, pull requests judged not to need review, and pull requests that already have a Claude comment. Narrowing events reduces unnecessary runs; if instead you use comment-driven behavior, configure a phrase filter so unrelated comments do not start work.
Decide where findings appear
Without comment configuration, findings are available in the workflow run log rather than posted on the pull request. To request inline findings, include --comment in the review prompt and grant the mcp__github_inline_comment__create_inline_comment tool through claude_args, as shown in Anthropic’s example. Check the permissions and output behavior for the exact workflow you deploy rather than adding write access by assumption.
Separate App permissions from workflow-token permissions
Two distinct access controls are involved:
- GitHub App installation permissions govern what the installed App can access. Anthropic says the standard App has a shared set that includes read/write access to Actions, Checks, Contents, Discussions, Issues, Pull requests, repository hooks, and Workflows, as well as read access to Members, Metadata, and Statuses. A custom App can use a narrower documented set for organizations that require it.
- Workflow
permissionscontrols the job’sGITHUB_TOKENaccess. Set it at workflow or job level to the minimum required. GitHub recommends least-required access. GitHub’s guidance on authenticating withGITHUB_TOKEN
These controls are not substitutes for each other. Limit both according to the actual task; a comment feature does not by itself justify granting broad write access. Verify the live Action requirements and the permissions of the App you install.
Handle secrets and fork pull requests safely
GitHub does not pass ordinary repository secrets to workflows triggered by pull requests from forks in public repositories. A secret-authenticated run therefore cannot authenticate on those fork PRs using the usual repository secret. GitHub also does not automatically forward secrets to reusable workflows. GitHub’s documentation on using secrets in workflows
Choose an explicit policy for contributions from forks, such as having a maintainer trigger a review through a trusted path. Do not expose a privileged credential to untrusted pull-request code merely to make automated reviews run universally. OIDC is an alternative for supported cloud authentication; Anthropic documents federation for Amazon Bedrock, Google Cloud Agent Platform, and Microsoft Foundry integrations. Availability and configuration depend on the provider route and organization setup.
Control who can trigger reviews and prevent loops
The Action checks the actor that triggered it. On issue and pull-request events, the user generally needs repository write access unless you configure exceptions. Bot actors are rejected by default to reduce automation loops; named exceptions require explicit configuration. Keep the event scope and, for comment-driven workflows, the trigger phrase filter narrow enough to avoid runs on irrelevant activity.
Rank #4
Keep the action interface and supply-chain policy current
Anthropic’s current examples use anthropics/claude-code-action@v1. For older beta workflows, its migration guidance says to replace @beta with @v1, remove the old mode input, replace direct_prompt with prompt, and move CLI settings such as max_turns and model into claude_args. Re-check the official documentation when upgrading because inputs, permissions, examples, and model defaults can change. The documentation does not prescribe a pinned commit SHA; teams with supply-chain controls should set their own pinning policy and verify the selected revision.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteUnderstand the cost and review limits
Each run uses GitHub Actions minutes and model tokens. Consumption depends on the prompt and response length, task complexity, and codebase size; the documentation does not establish a stable per-review price. Anthropic says OAuth-authenticated runs use the subscription rather than API billing. No adoption, productivity, or defect-detection statistic is established by the cited official documentation.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

