bundled-skills/debate-review/SKILL.md
Two-model debate review of a GitHub PR, GitLab MR, Azure DevOps PR, or local working tree, posted as inline comments or printed. Use for any PR/MR review request, or a local review before a PR exists.
npx skillsauth add FrancoStino/opencode-skills-antigravity debate-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Two models argue before anything is posted. A main reviewer finds issues. A debate reviewer tries to
knock them down and may add its own. The main reviewer then makes the final call, and one review with
inline comments lands on the PR or MR. It posts from the user's own gh, glab or az account as a
non-approval review or comment. It never approves and never requests changes.
You are the orchestrator. You run one command and relay the result. You do not review the diff yourself, and you do not touch the PR.
node "<skill-dir>/scripts/review-pr.mjs" --local [--base <ref>]
node "<skill-dir>/scripts/review-pr.mjs" <pr-url | number> [--dry-run]
--local from the repo (or --repo-dir). Do not invent a URL. Relay stdout. --local never talks to a forge and rejects non-UTF-8 Git paths rather than decoding them lossily.<pr-url> is a GitHub /pull/N, GitLab /-/merge_requests/N, or Azure DevOps
/_git/<repo>/pullrequest/N URL (dev.azure.com or the legacy *.visualstudio.com). A bare number
resolves against the cwd's origin, including Azure DevOps https and ssh.dev.azure.com:v3/ remotes.--dry-run prints a live PR review instead of posting it. It does not combine with --local.az logged in (az login) with access to the project. No extension is required,
the script talks to the REST API through az rest. A review there is N inline comment threads plus
one closed summary thread, since Azure DevOps has no single review object; the alert blockquotes
render as plain quotes, which still read.review-main and review-debate. If either is missing
the script says so. Add them with delegate-setup. Pick two different implementers, since the debate
is only worth something when the second model doesn't share the first one's blind spots (main
claude or grok, debate codex at high effort is a good pair). For a one-off, pass
--main <implementer> or --debate <implementer>. Only implementers whose relay has --read-only
are accepted. These two lanes belong to the reviewer. Don't point them at a lane you use for other
work, such as a plan-debate lane.3 means this head sha already has a debate-review. Re-run with --force to post again.All flags: --help. Contracts: references/schema.md. What gets posted:
references/comment-format.md. The reviewer briefs live in assets/prompts/
and the script fills them in; you don't need to read them.
Each posted comment carries a <!-- debate-review:<id> status=... --> marker. babysit-pr handles
GitHub and GitLab rounds (verify, fix blockers, reply, resolve). It cannot harvest Azure DevOps yet,
so relay Azure findings directly to the user. Don't act on the findings yourself unless asked.
~/.cache/debate-review/<owner>__<repo>/<N>/<head>/ holds run.json (all three documents, timings,
what was posted) plus main/, debate/, and final/, each with the brief sent and the relay's
result.json.
--local writes under ~/.cache/debate-review/local/<repo>/<branch>/<head>/ instead.
delegate-skills with review-main and review-debate lanes and authenticated gh/glab.scripts/) not included; see upstream for full runtime. Posts a single COMMENT review only.Adapted from amElnagdy/review-skills (MIT) — docs-only, runtime not bundled.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.