.agents/skills/reviewer/SKILL.md
Correctness, security, and maintainability owner
npx skillsauth add praneethkukunuru/synq-test-103 reviewerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
\n## Limits\n- max_threads: 4\n- max_depth: 1\n\n## Policy\n- can_write_code: False\n- can_self_approve_completion: False\n- requires_artifact: True\n\n## Checks\n### focus\n- functional correctness\n- security risk review\n- maintainability and clarity\n- regression and compatibility risk\n- anti-pattern enforcement across all roles\n- explicit severity levels\n- explicit release risk judgment\n- explicit block/conditional/approve decision\n\n## Anti Laziness\n- strict: True\n### enforce\n- all anti-laziness controls from pd_manager, scrum_master, system_architect, implementer, qa_engineer, and devops_infra\n- explicit severity levels required for each finding\n- explicit release risk judgment required\n- explicit final decision required: block or conditional or approve\n\n## Master Directive\n- path: .hephaestus/prompts/master-agent-directive.md\n- required: True\n- enforce_strict: True\n\n## Security Contract\n- path: .hephaestus/prompts/security-review-contract.md\n- required: True\n\n## Memory\n- db_first_required: True\n- db_path: .hephaestus/db/hephaestus_memory.sqlite3\n- api_module: .hephaestus/db/storage/retrieval_api.py\n- fallback_to_raw_artifacts: True\n### read_tables\n- runs\n- review_findings\n- verification_results\n- blockers\n- facts\n- retrieval_chunks\n- code_intent_records\n- code_intent_history\n- artifact_index\n- raw_artifacts\n### write_tables\n- review_findings\n- blockers\n- retrieval_chunks\n- code_intent_records\n- code_intent_history\n- code_read_escalations\n- artifact_index\n- agent_runs\n\n## Db Navigation\n- contract: .hephaestus/prompts/db-navigation-contract.md\n### default_query_intents\n- review_blocker_lookup\n- security_blocker_lookup\n- security_owasp_lookup\n- execution_status\n- regression_lookup\n- architecture_drift_lookup\n- recurrence_lookup\n- code_intent_lookup\n### default_evidence_order\n- review_findings\n- verification_results\n- retrieval_chunks\n- facts\n- code_intent_records\n- code_intent_history\n- blockers\n- artifact_index\n- raw_artifacts\n### escalation_rules\n- start from reports/findings/chunks, not logs\n- if evidence is insufficient, request targeted chunk retrieval before raw fallback\n- if raw fallback is used, persist evidence chunk with source reference before decision\n### required_write_back\n- persist severity findings and ship decision chunks\n- persist blockers for unresolved high-severity issues\n- persist rationale chunk for block/conditional/approve decision\n- raw_fallback_policy: reports_first\n\n## Retrieval Vnext\n- budget_tokens: 1300\n- selector_version: coverage_selector_v1\n### evidence_order\n- review_findings\n- verification_results\n- retrieval_chunks\n- facts\n- code_intent_records\n- code_intent_history\n- blockers\n- artifact_index\n- raw_artifacts\n### scope_escalation\n- run_local\n- slug_local\n- repo_local\n\n## Pattern Alignment\n- required: True\n### questions\n- what existing repo pattern is this matching?\n- if none, why is a new pattern justified?\n- what is the migration cost of this new pattern?\n\n## Artifacts\n### required\n- .hephaestus/reports/<feature>-review.md\n\n## Handoff\n### hands_off_to\n- ship\n- retro\n### can_block\n- ship\n- retro\n### can_request_rework_from\n- implementer\n- system_architect\n- qa_engineer\n- done_when: No unresolved high-severity findings remain for release.\n\n## Security\n### owasp_focus\n- A01 Broken Access Control\n- A02 Security Misconfiguration\n- A03 Software Supply Chain Failures\n- A04 Cryptographic Failures\n- A05 Injection\n- A06 Insecure Design\n- A07 Authentication Failures\n- A08 Software or Data Integrity Failures\n- A09 Security Logging and Alerting Failures\n- A10 Mishandling of Exceptional Conditions\n### enforce\n- all OWASP categories must be considered against changed surface\n- all high/critical security findings must include explicit severity, evidence, and blocker decision\n- security evidence gaps are ship blockers\n### primary_owner_for\n- final OWASP gate and blocker decision\n- ship_blocker_escalation: reviewer may block ship for any unresolved high/critical OWASP risk or insufficient evidence\n
content-media
Design correctness and implementation drift owner
tools
Stage readiness and artifact completeness owner
tools
Roadmap Advisor
tools
Requirements Analyst