codex/skills/adversarial-reviewer/SKILL.md
Authority-gated adversarial review for non-trivial code artifacts. Surface only material, current, owned, witness-backed findings; require countercases, soundness rows, authority clearance, verification paths, and change-agenda consistency before remediation. Trigger for exhaustive review, fresh-eyes second pass, re-review after fixes, patch hardening, de novo challenge, or material fixed-point review. Not for trivial wording, implementation, or final readiness without a review question.
npx skillsauth add tkersey/dotfiles adversarial-reviewerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill is the primary falsifier. It does not implement fixes. It makes the next required changes explicit only after each finding clears evidence, scope, authority, no-finding, soundness, and verification gates.
Find material defects in the current artifact set without flooding downstream implementation with plausible-but-unowned, stale, low-value, overbroad, wrong-layer, or insufficiently witnessed findings.
A review finding is not valid because it is clever, severe-sounding, invariant-framed, or easy to patch. A finding becomes a material finding only when current artifacts prove a defect or verification gap that this review surface owns, the strongest no-finding countercase is defeated, the minimum acceptable fix or validation is known, and the authority gate clears it.
Use Authority-Gated v2 mode for real code, plan, or artifact review. It requires:
Operate in FULL-SCOPE, DE NOVO, ADVERSARIAL, MATERIAL, AUTHORITY-GATED, NO-FINDING-FIRST, WITNESS-BEARING, INVARIANT-GRADED, SOUNDNESS-LEDGERED, HAZARD-SEEKING, DIRECTION/OWNERSHIP-AWARE, VERIFICATION-PATHED, PARSIMONIOUS, STALE-PROOF, and FAIL-CLOSED mode.
Dense review language is not evidence. A candidate finding becomes useful only when a doctrine word becomes a row, gate, or proof obligation.
For every material finding, make the doctrine artifact explicit:
| Field | Meaning |
|---|---|
| doctrine_cue | invariant, canonical, unwitnessed-guarantee, illegal-inhabitant, partial-handler, fixed-point, traceable, etc. |
| executable_artifact | the ledger row, gate, witness, no-finding countercase, or proof path created by that doctrine cue |
| evidence_ref | concrete current artifact, command, test, line, diff, or packet |
| minimum_acceptable_fix | smallest change or validation that would close the artifact |
| demotion_case | why this would be ornamental if the artifact is missing |
Convert unwitnessed guarantee and illegal inhabitant into explicit review ledger rows with code/test evidence.
The Soundness Ledger must include rows for any material possibility of:
unwitnessed-guaranteeillegal-inhabitantpartial-handlernon-canonical-witnessbroken-preservationstuck-progressIf none exist, say none found and name the reviewed constructor/producer and eliminator/consumer surfaces that made the absence credible.
Use custom read-only Codex agents when available. If they are unavailable, emit root-equivalent authority packets using the same packet schema.
Recommended custom agents under codex/agents/:
adv_review_evidence_authorityadv_review_soundness_authorityadv_review_invariant_scope_authorityadv_review_hazard_footgun_authorityadv_review_complexity_remediation_authorityadv_review_verification_authorityadv_review_finding_skepticA candidate may appear in Material Findings only if all are true:
evidence_of_defect and evidence_of_remedy or validation_probe refs.If any item fails, route the candidate to Non-Finding Ledger, Verification Gaps, Residual Uncertainty, proof-only, validate-first, defer, or blocked instead of material finding.
For every candidate, construct the strongest no-finding case before accepting it.
A no-finding case may be:
Material Findings require the no-finding case to be defeated. A preserved no-finding case must appear in Non-Finding Ledger or Authority Veto Ledger.
soundness_ledger:
- id: "S1"
kind: unwitnessed-guarantee | illegal-inhabitant | partial-handler | non-canonical-witness | broken-preservation | stuck-progress | none-found
claim_or_guarantee: "..."
constructor_or_producer: "..."
eliminator_or_consumer: "..."
current_or_missing_witness: "..."
evidence_ref: "..."
minimum_acceptable_fix_or_validation: "..."
status: open | closed | downgraded | not-found
Each agenda row must include:
candidate_idrecommended_changeminimum_acceptable_fixevidence_of_defectevidence_of_remedy or validation_proberemediation_posture: validating-check-only | accretive-remediation | structural-remediationwhat_not_to_broaden_intoverification_pathUse tail-weighted sections:
Before producing a downstream handoff, answer:
candidate_count:
material_finding_count:
non_finding_count:
validation_item_count:
soundness_rows_open:
all_material_findings_have_witness: yes | no
all_material_findings_have_no_finding_countercase_defeated: yes | no
all_agenda_items_have_verification_path: yes | no
change_agenda_allowed: yes | no
Reviewer Bottom Line must be the final section and must list: Act Now, Validate First, No Finding, Blocked, and Exact Next Move.
tools
Invokes Apple's macOS 27 fm command-line tool from a local Mac to use the on-device system model or Private Cloud Compute, including instructions, image prompts, schema-constrained JSON, and noninteractive automation. Use when the user asks to run Apple Foundation Models through fm, compare system versus pcc, generate structured output, or automate fm without Swift or an app.
development
Compile historical Codex sessions into governed counterfactual evidence, evaluate an existing owner-applied candidate through blinded paired HCTP trials, and fold observable evidence into RUN, OBSERVE, or STOP. Use for `$hylo`, CRF extraction, counterfactual replay, source-governed direct or historical trials, sealed evidence, paired baseline/candidate evaluation, causal frontiers, or evidence-governed improvement.
testing
Ensure a `ledger` command is available on PATH; materialize, validate, record, replay, and project requested Actuating artifacts without taking semantic or execution authority; coordinate the shared Learnings/Synesthesia/Negative Ledger lifecycle checkpoint and repo-local source-memory reconciliation; address Universalist plans and receipts; and perform pure artifact validation.
testing
Classify and quotient review findings, failing tests, incidents, bug reports, migration failures, and other witnessed falsifiers against accepted intent and the current Construction. Author counterexample-set/v1 without selecting repairs, counting review credit, or granting mutation.