Install
$ agentstack add skill-contextosai-skills-review-change ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Change Review
Review the behavioral delta, not the typography of the diff.
Protocol
- Determine the review range and read applicable
AGENTS.md. Inspect status so
uncommitted user work is not mistaken for the target change.
- Reconstruct intent from the request, commits, tests, and changed call sites.
State ambiguity when intent affects whether behavior is defective.
- Inventory changed surfaces: API/schema, state, authorization, side effects,
concurrency, errors/retries, configuration, observability, and release.
- For each surface, state the invariant before and after the change. Trace the
changed value/control flow beyond edited lines into callers and consumers.
- Inspect the risky counter-paths: absent/empty/malformed input, denied access,
duplicate/retry, partial failure, timeout/cancellation, stale state, concurrent execution, upgrade/downgrade, and rollback. Use only relevant paths.
- Read tests as executable claims. Check whether assertions would fail for the
suspected regression; test presence alone is not coverage.
- Validate each finding against the actual diff and surrounding code. A
finding must identify a reachable trigger, violated invariant, user impact, and a bounded location introduced or exposed by the change.
- Rank by impact and likelihood using
references/finding-rubric.md. Omit
speculative concerns, pre-existing unrelated issues, and style preferences.
Finding bar
Emit a finding only when all are true:
- The reviewed change introduces or exposes it.
- A realistic execution path reaches it.
- The consequence is incorrect behavior, vulnerability, data loss, meaningful
degradation, or an operational failure.
- The developer can act on it locally.
- The evidence is specific enough to falsify.
If a concern is plausible but unproven, perform another read-only check. If it remains uncertain, describe it as an open question outside the findings and state what evidence is missing.
Output
Lead with findings ordered by priority. For each, use one concise paragraph: [P#] imperative title, reachable scenario, consequence, and why current code does not prevent it. Cite the smallest useful changed-line range.
Then give a short review summary and testing gaps. If no findings meet the bar, say so explicitly and name residual risks or unverified surfaces.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: contextosai
- Source: contextosai/skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.