Skills executor-review
๐Ÿ“ฆ

executor-review

Content revision r1 Medium Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Review Tasks and Branches with Persistent Verdicts

Implementation reviews lose traceability when findings exist only in conversation. This skill structures task, fix, and branch reviews around contract references and persistent verdict files.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 68 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "executor-review" from https://skillstore.io/skills/atri10-executor-review.md and its manifest at https://skillstore.io/api/skills/atri10-executor-review/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "executor-review". Review a task whose error path lacks the behavior required by its brief.

Expected outcome:

  • Specification verdict: FAIL. The required error response is missing.
  • Code quality: NEEDS_FIXES. Finding I1 cites the changed error path and its requirement.
  • Gate: FAIL. The saved verdict identifies the review round and exact commit range.

Using "executor-review". Re-review a fix that resolves one finding but breaks an affected caller.

Expected outcome:

  • Prior finding I1: ADDRESSED. The fix changes the documented root cause.
  • New important finding I1: An affected caller still uses the previous contract.
  • Gate: FAIL. The next round receives the new finding ID and supporting location.

Using "executor-review". Perform a final branch review when the architecture phase was explicitly skipped.

Expected outcome:

  • Architecture conformance: NOT RUN. No architecture contract was authored.
  • Merge assessment: The missing architecture checks remain visible and need human consideration.
  • Recommended verification: Exercise the branch integration paths in the separate verification phase.

Security Audit

Medium Risk
v1 โ€ข 10/5/2026 Open versioned report

All 208 static findings are false positives involving Markdown, legitimate review commands, fixed sibling references, or protective secret-handling guidance. No evidence found of credential exfiltration, destructive intent, or audit-targeting prompt injection in the four reviewed files. Two semantic risks remain: security findings can be parked without mandatory human approval, and the main workflow hardcodes the final-review fork base.

4
Files scanned
2,189
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

Medium
Security Findings Lack Mandatory Human Approval at the Round Cap
The breaker allows real findings to be parked when downstream work does not depend on them. Tasks can then be marked complete with parked findings. Only credential incidents have an explicit immediate human stop rule, leaving other security findings without mandatory human approval before deferral.
The workflow explicitly permits parking real correctness findings and completing tasks. Final triage provides another check, but human approval is not required for every security deferral.
Medium
Hardcoded Fork Base Can Produce an Incorrect Final Review Range
The main workflow uses git merge-base main HEAD for final packaging. The final reviewer template requires the recorded fork base instead. For initiatives forked from another branch, this mismatch can review the wrong changes and undermine the final gate.
The two documented commands directly disagree about base selection. The final template explicitly explains why hardcoding main yields an incorrect range for other fork bases.

Risk Factors

โš™๏ธ External commands (50)
final-reviewer-prompt.md:54 final-reviewer-prompt.md:147-148 final-reviewer-prompt.md:148 final-reviewer-prompt.md:150-157 final-reviewer-prompt.md:157-164 final-reviewer-prompt.md:164-165 final-reviewer-prompt.md:165-166 final-reviewer-prompt.md:166-168 final-reviewer-prompt.md:168 final-reviewer-prompt.md:222 final-reviewer-prompt.md:255-256 final-reviewer-prompt.md:256-257 final-reviewer-prompt.md:257-264 final-reviewer-prompt.md:264-279 final-reviewer-prompt.md:436-447 final-reviewer-prompt.md:447-448 final-reviewer-prompt.md:448-450 final-reviewer-prompt.md:450-452 final-reviewer-prompt.md:452-460 final-reviewer-prompt.md:460-461 final-reviewer-prompt.md:461 final-reviewer-prompt.md:463-466 final-reviewer-prompt.md:466-482 final-reviewer-prompt.md:482-490 final-reviewer-prompt.md:490 final-reviewer-prompt.md:491-493 final-reviewer-prompt.md:493-498 final-reviewer-prompt.md:498-504 final-reviewer-prompt.md:504-524 final-reviewer-prompt.md:524-539 final-reviewer-prompt.md:539-547 final-reviewer-prompt.md:547-566 final-reviewer-prompt.md:600 final-reviewer-prompt.md:601-605 re-review-prompt.md:85-119 re-review-prompt.md:119-121 re-review-prompt.md:121-124 re-review-prompt.md:124-125 re-review-prompt.md:125-132 re-review-prompt.md:132-135 re-review-prompt.md:135-137 re-review-prompt.md:137-227 re-review-prompt.md:304-324 re-review-prompt.md:324-330 re-review-prompt.md:330 re-review-prompt.md:333-336 re-review-prompt.md:336-343 re-review-prompt.md:343-383 re-review-prompt.md:383-402 re-review-prompt.md:435-437
๐Ÿ“ Filesystem access (5)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/atri10-executor-review/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/atri10-executor-review/security.svg)](https://skillstore.io/skills/atri10-executor-review?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/atri10-executor-review?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/atri10-executor-review/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/atri10-executor-review.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

atri10. (2026). executor-review security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/atri10-executor-review/audits/1

BibTeX citation

@techreport{atri10-atri10-executor-review-2026, author = {atri10}, title = {executor-review security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/atri10-executor-review/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "executor-review security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "atri10" date-released: "2026-10-05" url: "https://skillstore.io/skills/atri10-executor-review/audits/1" identifiers: - type: other value: "skillstore:atri10-executor-review:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Review a Completed Implementation Task

Compare a task diff with its brief and constraints, then preserve compliance and quality findings in a verdict file.

Check Fixes Without Repeating the Full Review

Assess each open finding against a fix diff and inspect affected callers for regressions before closing the round.

Assess a Branch Before Verification

Review cross-task dependencies, architecture contracts, and parked findings as one branch before handing recommended checks to verification.

Try These Prompts

Start a Task Review
Review task [TASK_ID] using [BRIEF_FILE], [REPORT_FILE], and [DIFF_FILE]. Write compliance and quality verdicts to [VERDICT_FILE]. Report missing inputs as blocked.
Review Requirements and Evidence
Use the task-review template for [TASK_ID]. Include [GLOBAL_CONSTRAINTS] verbatim with requirement IDs. Assess reported test evidence and list honest cannot-verify items.
Verify a Fix Round
Use the re-review template with [PRIOR_VERDICT_FILE], [OPEN_FINDING_IDS], [REPORT_FILE], and [DIFF_FILE]. Review causal impact first. Write closure evidence to [VERDICT_FILE].
Coordinate Final Branch Review
Use the final-review template for [PLAN_ID]. Resolve the fork base from provenance. Supply contracts and parked findings. Require human approval for security deferrals.

Best Practices

  • Record exact base and head commits, use the recorded fork provenance, and validate each review package before dispatch.
  • Supply complete contract paths and preserve verdict files with unique review IDs and evidence-based findings.
  • Resolve cannot-verify items explicitly and require human approval before deferring security or data-loss findings.

Avoid

  • Substitute the last commit for the full task range or assume every initiative forked from main.
  • Pre-judge findings in dispatch prompts or treat implementer reports as independently verified evidence.
  • Overwrite another round's verdict or copy credential values into review artifacts.

Frequently Asked Questions

What does this skill review?
It structures completed task reviews, scoped fix reviews, and final whole-branch reviews against supplied contracts.
Which AI tools are listed as supported?
The report lists Claude, Codex, and Claude Code. The workflow also requires file access, companion scripts, and reviewer dispatch support.
Are the required scripts included?
No. The four reviewed files reference scripts from a companion Executor skill.
Does review replace running tests?
No. Review checks reported evidence and permits focused checks for specific doubts. A separate verification phase owns broader runtime evidence.
How are fixes tracked?
Each round uses a persistent verdict and finding IDs. Re-review marks prior findings addressed or not addressed and records new breakage.
How should security findings be handled?
Record credential locations and types without copying values. Escalate credential incidents immediately, and require human approval before deferring other security findings.

Developer Details

Author

atri10

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6d0b11444384184b7ae743742a7e233a9a705cd9

Maintenance freshness

10/6/2026

Usage

0 downloads ยท 1 views

File structure

More from atri10

View all
View all