pull_request_review_write

Create and/or submit, delete review of a pull request. Available methods: - create: Create a new review of a pull request. If "event" parameter is provided, the review is submitted. If "event" is omitted, a pending review is created. - submit_pending: Submit an existing pending review of a pull r...

SERVERGitHub SOURCEoci:ghcr.io/github/github-mcp-server:1.3.0
Medium RISK CLASS
Category Write
Parameters 70 required
Recommended Rate-limitedsee the rule below
Registry record Grade D, identity verified Pull the record →

This record as markdown: /tools/github/pull-request-review-write.md

What pull_request_review_write does on GitHub

AI agents use pull_request_review_write to create or update resources in GitHub, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your GitHub environment.

ParameterTypeRequiredDescription
body string Review comment text
repo string Repository name
event string Review action to perform.
owner string Repository owner
method string The write operation to perform on pull request review.
commitID string SHA of commit to review
pullNumber number Pull request number

Parameters from the server's own tool schema.

Why pull_request_review_write is rated Medium

The tool creates and modifies pull request reviews, which are reversible actions. While it includes a delete operation, deleting a review is a standard reversible write operation on a pull request (reviews can be recreated). This is Write category rather than Destructive because PR reviews are transient artifacts designed to be created, modified, and removed as part of normal workflow.

From the tool's definition Tool description states 'Create and/or submit, delete review of a pull request' with methods including 'create' (new review), 'submit_pending' (submit review), and 'delete_pending' (delete review).

Risk signalsAccepts raw HTML/template content (body)

Questions about pull_request_review_write

What does the pull_request_review_write tool do? +

Create and/or submit, delete review of a pull request. Available methods: - create: Create a new review of a pull request. If "event" parameter is provided, the review is submitted. If "event" is omitted, a pending review is created. - submit_pending: Submit an existing pending review of a pull request. This requires that a pending review exists for the current user on the specified pull request. The "body" and "event" parameters are used when submitting the review. - delete_pending: Delete an existing pending review of a pull request. This requires that a pending review exists for the current user on the specified pull request. It is categorised as a Write tool in the GitHub MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.

What parameters does pull_request_review_write accept? +

pull_request_review_write accepts 7 parameters: body, repo, event, owner, method, commitID, pullNumber. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on pull_request_review_write? +

Register the GitHub MCP server in PolicyLayer and add a rule for pull_request_review_write: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches GitHub. Nothing to install.

What risk level is pull_request_review_write? +

pull_request_review_write is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.

Can I rate-limit pull_request_review_write? +

Yes. Add a rate_limit block to the pull_request_review_write rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block pull_request_review_write completely? +

Set action: deny in the PolicyLayer policy for pull_request_review_write. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides pull_request_review_write? +

pull_request_review_write is provided by the GitHub MCP server (oci:ghcr.io/github/github-mcp-server:1.3.0). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

More on GitHub, and thousands of servers like it.

// THE MCP REGISTRY

PolicyLayer tracks 44,603 MCP servers and 515,000+ tools.

Every server has a live record: who publishes it, whether it answers without auth, its risk grade, every tool classified, the recommended policy. This page is one line of GitHub's. Pull the full record:

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.