# Review Change

> Review a code change for concrete correctness, security, data-integrity, compatibility, concurrency, and operability regressions by reconstructing intent and checking affected invariants and boundary paths. Use for local diffs, commits, branches, patches, or pull requests when the user wants actionable review findings. Report only defects introduced or exposed by the change with precise evidence;…

- **Type:** Skill
- **Install:** `agentstack add skill-contextosai-skills-review-change`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [contextosai](https://agentstack.voostack.com/s/contextosai)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [contextosai](https://github.com/contextosai)
- **Source:** https://github.com/contextosai/skills/tree/main/skills/review-change

## Install

```sh
agentstack add skill-contextosai-skills-review-change
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Change Review

Review the behavioral delta, not the typography of the diff.

## Protocol

1. Determine the review range and read applicable `AGENTS.md`. Inspect status so
   uncommitted user work is not mistaken for the target change.
2. Reconstruct intent from the request, commits, tests, and changed call sites.
   State ambiguity when intent affects whether behavior is defective.
3. Inventory changed surfaces: API/schema, state, authorization, side effects,
   concurrency, errors/retries, configuration, observability, and release.
4. For each surface, state the invariant before and after the change. Trace the
   changed value/control flow beyond edited lines into callers and consumers.
5. Inspect the risky counter-paths: absent/empty/malformed input, denied access,
   duplicate/retry, partial failure, timeout/cancellation, stale state,
   concurrent execution, upgrade/downgrade, and rollback. Use only relevant
   paths.
6. Read tests as executable claims. Check whether assertions would fail for the
   suspected regression; test presence alone is not coverage.
7. Validate each finding against the actual diff and surrounding code. A
   finding must identify a reachable trigger, violated invariant, user impact,
   and a bounded location introduced or exposed by the change.
8. Rank by impact and likelihood using `references/finding-rubric.md`. Omit
   speculative concerns, pre-existing unrelated issues, and style preferences.

## Finding bar

Emit a finding only when all are true:

- The reviewed change introduces or exposes it.
- A realistic execution path reaches it.
- The consequence is incorrect behavior, vulnerability, data loss, meaningful
  degradation, or an operational failure.
- The developer can act on it locally.
- The evidence is specific enough to falsify.

If a concern is plausible but unproven, perform another read-only check. If it
remains uncertain, describe it as an open question outside the findings and
state what evidence is missing.

## Output

Lead with findings ordered by priority. For each, use one concise paragraph:
`[P#] imperative title`, reachable scenario, consequence, and why current code
does not prevent it. Cite the smallest useful changed-line range.

Then give a short review summary and testing gaps. If no findings meet the bar,
say so explicitly and name residual risks or unverified surfaces.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [contextosai](https://github.com/contextosai)
- **Source:** [contextosai/skills](https://github.com/contextosai/skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-contextosai-skills-review-change
- Seller: https://agentstack.voostack.com/s/contextosai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
