Install
$ agentstack add skill-hoiung-sst3-skills-ralph-review-trio ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ralph Review Trio
This skill triggers /ralph-review, which runs three sequential reviewer subagents at increasing depth. If any tier flags a failure, the loop restarts from Tier 1 after fixes.
When to trigger
- An implementation is code-complete on a feature / solo branch.
- All acceptance criteria for the underlying issue are believed satisfied.
- Pre-merge verification is needed before human review or merge-to-main.
- You want structured evidence that each tier's checklist was walked.
When NOT to trigger
- Work-in-progress branches mid-implementation — Ralph assumes the change is complete.
- Documentation-only diffs with no code — Tier 2/3 still run but most checks short-circuit to "doc-only PR" exemption; overkill for a single README edit.
- Hotfix branches where speed dominates verification — use the project's normal PR review.
How it works
/ralph-review
│
▼
Tier 1 — Haiku (surface checks) ─── fail ──> restart
│ pass
▼
Tier 2 — Sonnet (logic checks) ─── fail ──> restart
│ pass
▼
Tier 3 — Opus (deep analysis) ─── fail ──> restart
│ pass
▼
RALPH_PASS → merge OK
A HAIKU_PASS / SONNET_PASS / OPUS_PASS token is emitted by each tier on pass. All three required for overall pass.
Entry point
/ralph-review — defined in ../../commands/ralph-review.md.
Per-tier checklists
../../agents/haiku-reviewer.md— Tier 1 surface checklist../../agents/sonnet-reviewer.md— Tier 2 logic checklist../../agents/opus-reviewer.md— Tier 3 deep-analysis checklist
Extended reference content under references/ (same dir as this SKILL.md) is loaded on demand by each tier when a specific check requires more context.
Outputs
Each tier writes a fenced ## RESULT block with:
## RESULT
mcp_graph_available: yes|no # first line when discussing graph queries
verdict: pass|fail|unknown
files_touched: [paths]
findings: [{path, line, claim, evidence}]
scope_gaps: [list or "none"]
The main agent reads the RESULT block and decides next action (restart, next tier, or PASS).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: hoiung
- Source: hoiung/sst3-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.