# Review Tasks and Branches with Persistent Verdicts

Implementation reviews lose traceability when findings exist only in conversation. This skill structures task, fix, and branch reviews around contract references and persistent verdict files.

## Install

```bash
npx skillstore add atri10/executor-review
```

## Metadata

- Status: approved
- Slug: atri10-executor-review
- Skillstore revision: r1
- Version status: missing
- Tree hash: dc502106f61aac0cfe0e53c558215961bcf89e5270a5ed8e3dcf358c6696a91c
- Author: atri10
- GitHub username: atri10
- License: MIT
- Repository: https://github.com/atri10/executor/tree/39ddcfe1d9f3497102622b72aa235fb0770187fe/skills/executor-review
- Ref: 6d0b11444384184b7ae743742a7e233a9a705cd9
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, filesystem
- Quality score: 68
- Public page: https://skillstore.pages.dev/skills/atri10-executor-review
- Manifest: https://skillstore.pages.dev/api/skills/atri10-executor-review/manifest

## Capabilities

- Provides separate task-review assessments for specification compliance and code quality.
- Defines persistent verdict files with review IDs, commit ranges, requirement citations, and finding counts.
- Provides scoped re-review templates for finding closure, root-cause checks, and regression impact review.
- Provides a final branch-review template for architecture conformance, cross-task dependencies, and deferred finding triage.
- Defines bounded fix rounds, recorded rulings, and blocked responses for missing review inputs.
- Requires secret findings to record locations and credential types without copying credential values.

## Use Cases

- Review a Completed Implementation Task: Compare a task diff with its brief and constraints, then preserve compliance and quality findings in a verdict file.
- Check Fixes Without Repeating the Full Review: Assess each open finding against a fix diff and inspect affected callers for regressions before closing the round.
- Assess a Branch Before Verification: Review cross-task dependencies, architecture contracts, and parked findings as one branch before handing recommended checks to verification.

## Prompt Templates

### Start a Task Review

```
Review task [TASK_ID] using [BRIEF_FILE], [REPORT_FILE], and [DIFF_FILE]. Write compliance and quality verdicts to [VERDICT_FILE]. Report missing inputs as blocked.
```

### Review Requirements and Evidence

```
Use the task-review template for [TASK_ID]. Include [GLOBAL_CONSTRAINTS] verbatim with requirement IDs. Assess reported test evidence and list honest cannot-verify items.
```

### Verify a Fix Round

```
Use the re-review template with [PRIOR_VERDICT_FILE], [OPEN_FINDING_IDS], [REPORT_FILE], and [DIFF_FILE]. Review causal impact first. Write closure evidence to [VERDICT_FILE].
```

### Coordinate Final Branch Review

```
Use the final-review template for [PLAN_ID]. Resolve the fork base from provenance. Supply contracts and parked findings. Require human approval for security deferrals.
```

## Limitations

- Requires companion Executor scripts and contracts that are not included in these four files.
- Requires valid plans, briefs, reports, review packages, and explicit template placeholder values.
- Does not implement fixes or replace runtime verification and human merge decisions.
- Round-cap security deferrals need human oversight, and the final-review example needs provenance-based fork selection.

## Best Practices

- Record exact base and head commits, use the recorded fork provenance, and validate each review package before dispatch.
- Supply complete contract paths and preserve verdict files with unique review IDs and evidence-based findings.
- Resolve cannot-verify items explicitly and require human approval before deferring security or data-loss findings.

## Anti Patterns

- Substitute the last commit for the full task range or assume every initiative forked from main.
- Pre-judge findings in dispatch prompts or treat implementer reports as independently verified evidence.
- Overwrite another round's verdict or copy credential values into review artifacts.

## Security Audit

- Audited at: 2026-10-05T18:08:12.911\+00:00
- Summary: All 208 static findings are false positives involving Markdown, legitimate review commands, fixed sibling references, or protective secret-handling guidance. No evidence found of credential exfiltration, destructive intent, or audit-targeting prompt injection in the four reviewed files. Two semantic risks remain: security findings can be parked without mandatory human approval, and the main workflow hardcodes the final-review fork base.

## Stats

- Views: 1
- Downloads: 0
- Favorites: 0
- Popularity score: 0
