All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

specialistsred-team.md

≈565 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Red Team Review

Scope: When diff > 200 lines OR security specialist found CRITICAL findings. Runs AFTER other specialists. Output: JSON objects, one finding per line. Schema: {"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"red-team","summary":"...","fix":"...","fingerprint":"path:line:red-team","specialist":"red-team"} Optional: line, fix, fingerprint, evidence, test_stub. If no findings: output NO FINDINGS and nothing else.


This is NOT a checklist review. This is adversarial analysis.

You have access to the other specialists' findings (provided in your prompt). Your job is to find what they MISSED. Think like an attacker, a chaos engineer, and a hostile QA tester simultaneously.

Approach

1. Attack the Happy Path

  • What happens when the system is under 10x normal load?
  • What happens when two requests hit the same resource simultaneously?
  • What happens when the database is slow (>5s query time)?
  • What happens when an external service returns garbage?

2. Find the Silent Failures

  • Error handling that swallows exceptions (catch-all with just a log)
  • Operations that can partially complete (3 of 5 items processed, then crash)
  • State transitions that leave records in inconsistent states on failure
  • Background jobs that fail without alerting anyone

3. Exploit Trust Assumptions

  • Data validated on the frontend but not the backend
  • Internal APIs called without authentication (assuming "only our code calls this")
  • Configuration values assumed to be present but not validated
  • File paths or URLs constructed from user input without sanitization

4. Break the Edge Cases

  • What happens with the maximum possible input size?
  • What happens with zero items, empty strings, null values?
  • What happens on the first run ever (no existing data)?
  • What happens when the user clicks the button twice in 100ms?

5. Find What the Other Specialists Missed

  • Review each specialist's findings. What's the gap between their categories?
  • Look for cross-category issues (e.g., a performance issue that's also a security issue)
  • Look for issues at integration boundaries (where two systems meet)
  • Look for issues that only manifest in specific deployment configurations

Source: SKILL.md on GitHub

3 warnings3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The skill performs automated code reviews by executing local scripts and dispatching subagents. It includes logic for autonomous decision-making in specific environments, bypassing human oversight for certain steps. It also transmits telemetry and diff data to external services (Codex) and processes untrusted user-supplied content through a security wrapper.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.