Skills executor-critique
๐Ÿ“ฆ

executor-critique

Content revision r1 Medium Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Audit and Repair Initiative Artifacts

Conflicting documents can carry incorrect decisions into later development phases. This skill coordinates independent audits, scoped repairs, and fresh re-audits before phase clearance.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 69 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "executor-critique" from https://skillstore.io/skills/atri10-executor-critique.md and its manifest at https://skillstore.io/api/skills/atri10-executor-critique/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "executor-critique". Audit a specification whose interface name differs from the architecture contract.

Expected outcome:

  • Verdict: FAIL.
  • High finding H1: The specification and architecture use different names for the same interface.
  • Evidence: The audit quotes both conflicting passages and records their actual file locations.
  • Proposed repair: The controller identifies the authoritative contract and routes a fix to the incorrect document.

Using "executor-critique". Re-audit a repair that removed a requirement instead of satisfying it.

Expected outcome:

  • Original finding: NOT ADDRESSED.
  • New high finding: The repair deleted the requirement and weakened the artifact.
  • Verdict: FAIL.
  • Next step: Restore the requirement and repair its cause, or escalate for an explicit human decision.

Using "executor-critique". Start an audit when a required upstream document cannot be opened.

Expected outcome:

  • Verdict: BLOCKED.
  • Audit file: None.
  • Reason: A required upstream document is missing or unreadable.
  • Next step: Supply the exact required document before dispatching the auditor again.

Security Audit

Medium Risk
v1 โ€ข 10/5/2026 Open versioned report

All 162 static alerts are false positives: Markdown formatting, ordinary review questions, and fixed helper references. One semantic finding identifies conflicting repair-log ownership that can lose audit evidence when multiple artifact repairers are dispatched. No evidence found of malicious prompt injection or exfiltration; helper implementations are outside this package and remain unverified.

4
Files scanned
1,221
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Conflicting Ownership of a Shared Repair Log
The template dispatches one repairer per artifact but derives the repair log only from component and round. Each repairer receives exclusive ownership and whole-file rewrite instructions, risking lost evidence or blocked repairs when several artifacts need fixes.
The same component-round log is described as exclusively owned by each artifact repairer, with no locking or aggregation protocol. Helper behavior is unverified, so actual concurrent overwrites are not demonstrated.

Risk Factors

โš™๏ธ External commands (50)
component-auditor-prompt.md:50-93 component-auditor-prompt.md:93 component-auditor-prompt.md:96-130 component-auditor-prompt.md:130-131 component-auditor-prompt.md:131-139 component-auditor-prompt.md:139-141 component-auditor-prompt.md:141-145 component-auditor-prompt.md:145-146 component-auditor-prompt.md:146 component-auditor-prompt.md:198-199 component-auditor-prompt.md:199-200 component-auditor-prompt.md:200-202 component-auditor-prompt.md:202-209 component-auditor-prompt.md:209-210 component-auditor-prompt.md:210-211 component-auditor-prompt.md:211-212 component-auditor-prompt.md:212-214 component-auditor-prompt.md:214-216 component-auditor-prompt.md:216-239 component-reauditor-prompt.md:78-79 component-reauditor-prompt.md:79-83 component-reauditor-prompt.md:84-86 component-reauditor-prompt.md:86-89 component-reauditor-prompt.md:89 component-reauditor-prompt.md:90-125 component-reauditor-prompt.md:125-126 component-reauditor-prompt.md:126-128 component-reauditor-prompt.md:128-129 component-reauditor-prompt.md:129-135 component-reauditor-prompt.md:135-139 component-reauditor-prompt.md:139-149 component-reauditor-prompt.md:149 component-reauditor-prompt.md:156-164 component-reauditor-prompt.md:164-165 component-reauditor-prompt.md:165-180 component-reauditor-prompt.md:180-182 component-reauditor-prompt.md:182-192 component-repairer-prompt.md:67-68 component-repairer-prompt.md:68-88 component-repairer-prompt.md:88-96 component-repairer-prompt.md:96-115 component-repairer-prompt.md:115-121 component-repairer-prompt.md:121-123 component-repairer-prompt.md:123-129 component-repairer-prompt.md:129-130 component-repairer-prompt.md:130-131 component-repairer-prompt.md:132-136 component-repairer-prompt.md:136-137 component-repairer-prompt.md:137-142 component-repairer-prompt.md:142-143
๐Ÿ“ Filesystem access (9)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/atri10-executor-critique/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/atri10-executor-critique/security.svg)](https://skillstore.io/skills/atri10-executor-critique?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/atri10-executor-critique?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/atri10-executor-critique/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/atri10-executor-critique.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

atri10. (2026). executor-critique security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/atri10-executor-critique/audits/1

BibTeX citation

@techreport{atri10-atri10-executor-critique-2026, author = {atri10}, title = {executor-critique security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/atri10-executor-critique/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "executor-critique security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "atri10" date-released: "2026-10-05" url: "https://skillstore.io/skills/atri10-executor-critique/audits/1" identifiers: - type: other value: "skillstore:atri10-executor-critique:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Review Requirements Before Planning

Compare specifications with charter goals, architecture decisions, and verification criteria before authorizing implementation planning.

Detect Architecture Drift in Code

Review implementation boundaries and interface signatures against architecture and design artifacts before execution clearance.

Verify Repairs Before Release Handoff

Use a fresh reviewer to inspect repair diffs, verify finding closure, and check current-tree handoff evidence.

Try These Prompts

Audit a Charter
Audit the charter for [INITIATIVE_ID] using the charter catalog. Dispatch an independent auditor and require evidence for every finding.
Compare Specifications with Upstream Decisions
Audit the specification component for [INITIATIVE_ID]. Supply its complete artifact set, charter, active architecture decisions, and verification criteria.
Repair Assigned Findings
Repair [FINDING_IDS] in [ARTIFACT_FILE] from [AUDIT_FILE]. Preserve requirements, log evidence, and do not commit. Give each repairer a unique log.
Re-Audit the Final Round
Dispatch a fresh R03 re-auditor for [INITIATIVE_ID] and [COMPONENT]. Supply prior findings, repair logs, and the repair diff. Escalate unresolved findings to a human.

Best Practices

  • Supply the complete artifact set and required upstream evidence before dispatching an auditor.
  • Use separate audit, repair, and re-audit agents, with explicit ownership for every artifact and repair log.
  • Verify quoted evidence, preserve unresolved findings, and run the documented helper check before reporting phase clearance.

Avoid

  • Letting the controller approve its own work or accepting a repair log as proof of closure.
  • Deleting requirements, weakening exact values, or granting an agent-created waiver to obtain a passing verdict.
  • Dispatching several artifact repairers with exclusive ownership of the same repair log.

Frequently Asked Questions

Which AI tools does this skill target?
The package targets Claude, Codex, and Claude Code. Execution requires an environment with agent dispatch support and the related Executor helpers.
Does the package include its helper scripts?
No. It contains the skill document and three prompt templates. Helper implementations are referenced but are not included here.
What makes an audit pass?
The documented contract requires zero HIGH and zero MEDIUM findings. The referenced helper checks reported verdicts against counts and supporting records.
Can a repairer change upstream contracts?
No. Upstream contract findings belong to the controller, which must amend the source through an initiative ruling.
How many audit rounds are allowed?
The workflow allows R01 through R03. Unresolved findings after R03 go to a human rather than another repair round.
Can multiple artifacts be repaired independently?
The template assigns one repairer per artifact. Define separate repair logs or a designated log writer to prevent conflicting ownership.

Developer Details

Author

atri10

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6d0b11444384184b7ae743742a7e233a9a705cd9

Maintenance freshness

10/6/2026

Usage

0 downloads ยท 1 views

More from atri10

View all
View all