Install
$ agentstack add skill-victorrentea-human-review-publish-demo ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
/publish-demo
Run this one command, and nothing else:
for c in "${CLAUDE_PLUGIN_ROOT:-/nonexistent}/skills/human-review" "${HUMAN_REVIEW_HOME:-/nonexistent}" \
"$(readlink -f .claude/skills/human-review 2>/dev/null)" ".claude/skills/human-review" \
"$HOME/workspace/human-review/skills/human-review"; do
[ -x "$c/scripts/publish-demo.sh" ] && { "$c/scripts/publish-demo.sh" --push $ARGS; break; }
done
$ARGS is empty unless the user named something:
- a slug — pass it as the first positional argument;
- a source directory other than
.human-review— pass--src DIR; - "don't push yet" / "let me look first" — drop
--pushand pass--cardinstead.
The script derives the slug from the project directory, copies the snapshot, leaves behind the run's own dot-prefixed bookkeeping and *.raw.webm, refuses any file over 50 MB, rewrites that snapshot's card in demo/index.html from review.html and content.json, then commits and pushes.
Then print these three, substituting the slug the script reported, and say they take about a minute to appear because three workflows fire on the push:
https://victorrentea.github.io/human-review//
https://github.com/victorrentea/human-review/releases/download/demo/human-review-.zip
docker run --rm -p 8642:80 ghcr.io/victorrentea/human-review:
That is the whole job. Do not read the report, do not open the page, do not check the deploy, do not describe the change set, do not hand-edit demo/index.html — the card is rendered from the snapshot precisely so that nobody keeps it up to date by hand. If the script exits non-zero, show its stderr and stop.
Not this skill: publishing screenshots of a review — one full-page image per tab, light and dark, for readers who should not have to run anything — is /human-review-publish-demo. This one publishes the live page.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: victorrentea
- Source: victorrentea/human-review
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.