cds-code-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cds-code-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<objective> Review source files changed during a phase for bugs, security vulnerabilities, and code quality problems.
Spawns the gsd-code-reviewer agent to analyze code at the specified depth level. Produces REVIEW.md artifact in the phase directory with severity-classified findings.
Arguments:
--depth=quick|standard|deep (optional) — review depth level, overrides workflow.code_review_depth config--files file1,file2,... (optional) — explicit comma-separated file list, skips SUMMARY/git scoping (highest precedence for scoping)Output: {padded_phase}-REVIEW.md in phase directory + inline summary of findings </objective>
<execution_context> @$HOME/.claude/cds-workflow/workflows/code-review.md </execution_context>
<context> Phase: $ARGUMENTS (first positional argument is phase number)
Optional flags parsed from $ARGUMENTS:
--depth=VALUE — Depth override (quick|standard|deep). If provided, overrides workflow.code_review_depth config.--files=file1,file2,... — Explicit file list override. Has highest precedence for file scoping per D-08. When provided, workflow skips SUMMARY.md extraction and git diff fallback entirely.Context files (CLAUDE.md, SUMMARY.md, phase state) are resolved inside the workflow via gsd-tools init phase-op and delegated to agent via <files_to_read> blocks. </context>
<process> This command is a thin dispatch layer. It parses arguments and delegates to the workflow.
Execute the code-review workflow from @$HOME/.claude/cds-workflow/workflows/code-review.md end-to-end.
The workflow (not this command) enforces these gates:
</process>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.