Install
$ agentstack add skill-droodotfoo-agent-skills-adversarial-reviewer ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Adversarial Reviewer
Review code through three hostile personas, each determined to find what others miss.
Personas
- Saboteur -- What breaks in production? Race conditions, edge cases, resource exhaustion, cascading failures.
- New Hire -- What's unmaintainable? Unclear naming, missing docs, implicit assumptions, magic numbers.
- Security Auditor -- What's the attack surface? OWASP-informed: injection, auth bypass, data exposure, privilege escalation.
See [personas.md](./personas.md) for detailed persona descriptions and self-review techniques.
Mandatory Findings
Each persona MUST find at least one issue. If a persona finds nothing, dig deeper -- no clean passes allowed. This forces thorough examination rather than rubber-stamping.
Severity Promotion
When 2+ personas independently flag the same issue, promote its severity by one level:
- LOW -> MEDIUM
- MEDIUM -> HIGH
- HIGH -> CRITICAL
Cross-persona agreement signals systemic risk.
Review Process
- Read the code completely before commenting
- Run each persona independently -- do not let one persona's findings bias another
- Collect findings, check for cross-persona overlap, apply severity promotion
- Deliver consolidated report grouped by severity
Verdict
After review, issue exactly one verdict:
- BLOCK -- CRITICAL or 3+ HIGH issues found. Do not merge.
- CONCERNS -- HIGH or multiple MEDIUM issues. Merge after addressing.
- CLEAN -- Only LOW issues. Safe to merge.
What You Get
- A consolidated adversarial review report with findings from three independent personas (Saboteur, New Hire, Security Auditor), grouped by severity (CRITICAL/HIGH/MEDIUM/LOW).
- Cross-persona overlap analysis with automatic severity promotion when multiple personas flag the same issue.
- A single verdict (BLOCK, CONCERNS, or CLEAN) indicating merge readiness.
Output Format
## Adversarial Review: [file/component]
### CRITICAL
- [Saboteur] ...
- [Security Auditor] ...
### HIGH
- [New Hire] ...
### MEDIUM / LOW
- ...
### Cross-Persona Overlaps
- Issue X flagged by Saboteur + Security Auditor (promoted: HIGH -> CRITICAL)
### Verdict: BLOCK | CONCERNS | CLEAN
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: DROOdotFOO
- Source: DROOdotFOO/agent-skills
- License: MIT
- Homepage: https://droo.foo/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.