codex/skills/review-adjudication/SKILL.md
Convert review claims into minimal, intent-anchored counterexamples. Verify current behavior, branch liability, AC-v2 horizon relation, novelty, kernel impact, and the only legal disposition. Use for review findings, PR comments, CAS findings, terminal holdouts, CEX-v1, or deciding whether a valid issue belongs in the current campaign. Never issue direct code-mutation authority or hand raw review prose to an implementer.
npx skillsauth add tkersey/dotfiles review-adjudicationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Separate:
observed fact
review claim
repair suggestion
branch liability
intent entailment
counterexample novelty
kernel impact
legal disposition
Output one counterexample / CEX-v1 or a rejected/blocked record.
A valid diff-local issue is not automatically campaign scope.
current artifact state
review mode
AC-v2 ID/fingerprint/horizon
accepted kernel/law refs when present
review claim and source refs
current code/proof evidence
known counterexample classes
If AC-v2 is required but absent or stale:
disposition = blocked
discovery
kernel_review
conformance
terminal_holdout
Broad search is allowed. Findings still require AC relation before admission.
Evaluate AC/CEX/CEB/MBK/RC consistency. Do not review delivery implementation.
Only named RAP-v1 apertures are in review scope.
Allowed outputs:
existing-law violation
missing law proof
orphan construct
stale artifact state
novel in-horizon CEX
outside-horizon proposal
clean
Broad adversarial search is allowed once. No direct mutation authority.
counterexample:
counterexample_version: CEX-v1
counterexample_id:
campaign_id:
batch_id:
aperture_id:
review_mode:
artifact_state:
base:
head:
dirty_fingerprint:
review_receipt:
claim:
statement:
source_refs: []
suggested_repair:
observation:
actor:
operation:
pre_state:
minimal_trace: []
expected:
actual:
externally_visible_difference:
reproduction_or_proof:
validity:
confirmed |
refuted |
stale |
unknown
liability:
introduced_by_current_diff |
exposed_and_required_by_current_acceptance |
preexisting_but_blocks_current_invariant |
adjacent_preexisting |
reviewer_preference |
unknown
intent:
contract_id:
contract_fingerprint:
horizon_fingerprint:
acceptance_refs: []
compatibility_refs: []
forbidden_refs: []
non_goal_refs: []
kernel_law_refs: []
relation:
directly_entailed |
compatibility_required |
forbidden_state_witness |
contract_invalidating |
outside_horizon |
unrelated |
unknown
witness:
scope_effect:
none |
narrows |
expands |
invalidates_contract
novelty:
new_equivalence_class |
new_witness_existing_class |
duplicate |
refuted |
stale |
unknown
existing_class_ref:
kernel_impact:
existing_law_violation |
additional_witness |
missing_semantic_distinction |
missing_proof |
orphan_realization |
stale_artifact_state |
no_kernel_impact |
unknown
disposition:
enter_kernel |
attach_witness |
invalidate_realization |
return_to_contract |
capture_followup |
reject |
blocked
mutation_authority:
allowed: no
reason:
Mutation authority is always no at the finding level.
The controller grants realization authority only after a batch is sealed and the kernel/design gates pass.
A confirmed actionable CEX must identify the smallest trace that distinguishes expected from actual behavior:
actor
operation
pre-state
transition sequence
observable result
A broad code smell, speculative risk, or preferred repair is not a minimal trace.
disposition = reject
disposition = blocked
disposition = reject
disposition = capture_followup
disposition = return_to_contract
novelty = new_equivalence_class
disposition = enter_kernel
disposition = invalidate_realization
No direct patch authorization.
disposition = attach_witness
No new code distinction or test family.
disposition = reject
or attach_witness only when it materially strengthens proof
disposition = attach_witness
Proof-only by default.
disposition = invalidate_realization
new_equivalence_class requires a witness that an existing class cannot explain.
Similarity to a different file, function, or review comment is not novelty.
new_witness_existing_class cannot authorize:
new branch
new helper
new state
new protocol case
new fallback
new public symbol
new wound-specific test family
Before classification:
Do not accept stale review text as current evidence.
python3 codex/skills/review-adjudication/tools/counterexample_gate.py cex.json
Return:
counterexample ID
validity / liability
intent relation / anchors
minimal trace
novelty / existing class
kernel impact
disposition
mutation authority = no
source/proof refs
no.tools
Invokes Apple's macOS 27 fm command-line tool from a local Mac to use the on-device system model or Private Cloud Compute, including instructions, image prompts, schema-constrained JSON, and noninteractive automation. Use when the user asks to run Apple Foundation Models through fm, compare system versus pcc, generate structured output, or automate fm without Swift or an app.
development
Compile historical Codex sessions into governed counterfactual evidence, evaluate an existing owner-applied candidate through blinded paired HCTP trials, and fold observable evidence into RUN, OBSERVE, or STOP. Use for `$hylo`, CRF extraction, counterfactual replay, source-governed direct or historical trials, sealed evidence, paired baseline/candidate evaluation, causal frontiers, or evidence-governed improvement.
testing
Ensure a `ledger` command is available on PATH; materialize, validate, record, replay, and project requested Actuating artifacts without taking semantic or execution authority; coordinate the shared Learnings/Synesthesia/Negative Ledger lifecycle checkpoint and repo-local source-memory reconciliation; address Universalist plans and receipts; and perform pure artifact validation.
testing
Classify and quotient review findings, failing tests, incidents, bug reports, migration failures, and other witnessed falsifiers against accepted intent and the current Construction. Author counterexample-set/v1 without selecting repairs, counting review credit, or granting mutation.