All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

sectionsshared-code-reuse.md

≈586 tokens on demand. Your agent reads this file only when SKILL.md points to it.

<!-- AUTO-GENERATED from shared-code-reuse.md.tmpl — do not edit directly --> <!-- Regenerate: bun run gen:skill-docs -->

Reuse a skipped shared-code advisory only with complete structural evidence:

  1. Read the evidence. Read all supporting callers and the helper destination. Establish first-party authored provenance and whether the current extraction is worthwhile; the checker cannot decide that. Retain evidence_paths/helper_target.
  2. Run the checker. From the repository root, pass the current finding as literal JSON on stdin. Replace REVIEW_START with this pass's captured token and the example paths/symbol with actual evidence. Keep the quoted delimiter.
"$HOME/.claude/skills/gstack/bin/gstack-review-log" --check-shared-libs REVIEW_START <<'GSTACK_SHARED_LIBS_REUSE_JSON'
{"advisory":true,"severity":"INFORMATIONAL","evidence_paths":["src/caller-a.ts","src/caller-b.ts"],"helper_target":{"path":"src/shared.ts","symbol":"sharedHelper"}}
GSTACK_SHARED_LIBS_REUSE_JSON
  1. Act on its result. Read the JSON. Only reusable: true permits suppression. False, command failure or unreadable output requires fresh source review and a new decision, never suppression. Do not supply your own snapshot, prior record or coverage.
  2. Persist through the logger. The logger recomputes final coverage; never supply proof yourself. Real defects retain normal Fix-First handling independently.

What a reusable result proves (do not reconstruct these checks yourself):

  • Identity: sharedLibsFingerprint plus the actual repo, raw branch and current snapshot. The checker reads REVIEW_START without consuming/replacing it. Sanitized branch names are not identity.
  • Prior decision: completed/converged review, verified binding, explicit Skip and logger-versioned snapshot_covered_paths; older unversioned coverage needs a fresh decision.
  • Source: canReuseSharedLibsAdvisory requires every supporting path's raw file byte-for-byte with its blob. Exclude assume-unchanged, skip-worktree and sparse index entries; symlinks/ancestors, submodules, ignored/outside or unreadable files; active/unknown Git filters, encodings and line conversion.
  • Safe inspection: disables fsmonitor and optional locks; never uses external diff/textconv. Unknown evidence fails closed.

Source: SKILL.md on GitHub

3 warnings3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The skill performs automated code reviews by executing local scripts and dispatching subagents. It includes logic for autonomous decision-making in specific environments, bypassing human oversight for certain steps. It also transmits telemetry and diff data to external services (Codex) and processes untrusted user-supplied content through a security wrapper.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.