auto-review-loop-6b7b24 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited auto-review-loop-6b7b24 (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Autonomously iterate: review → implement fixes → re-review, until the external reviewer gives a positive assessment or MAX_ROUNDS is reached.
review-stage/AUTO_REVIEW.md (cumulative log) (fall back to `./AUTO_REVIEW.md` for legacy projects)gpt-5.4 — Model used via a secondary Codex agent. Must be an OpenAI model (e.g., gpt-5.4, o3, gpt-4o)--reviewer: oracle-pro only when the user explicitly requests Oracle; if Oracle is unavailable, warn and fall back to Codex xhigh.true, pause after each round's review (Phase B) and present the score + weaknesses to the user. Wait for user input before proceeding to Phase C. The user can: approve the suggested fixes, provide custom modification instructions, skip specific fixes, or stop the loop early. When false (default), the loop runs fully autonomously.true, (1) read EXPERIMENT_LOG.md and findings.md instead of parsing full logs on session recovery, (2) append key findings to findings.md after each round.medium uses normal Codex xhigh review through spawn_agent / send_input; hard adds Reviewer Memory and Debate Protocol; nightmare adds direct repository-reading adversarial verification by an independent reviewer.💡 Override: /auto-review-loop "topic" — compact: true, human checkpoint: true, difficulty: hardFor difficulty: hard and difficulty: nightmare, maintain review-stage/REVIEWER_MEMORY.md.
REVIEWER_MEMORY.md contents under ## Your Reviewer Memory (persistent across rounds).Memory update section in the reviewer response.Memory update into REVIEWER_MEMORY.md before writing REVIEW_STATE.json.nightmare, launch an additional fresh adversarial reviewer with direct repository/file-reading instructions. It should read NARRATIVE_REPORT.md or review-stage/AUTO_REVIEW.md for the author's claims, then verify those claims against code, logs, result files, and paper drafts instead of trusting executor summaries.In hard and nightmare modes, the reviewer must actively look for omissions, unsupported claims, cherry-picked evidence, metric mistakes, and weaknesses the executor may have downplayed.
For difficulty: hard and nightmare, use the Debate Protocol after a critical review:
send_input.Long-running loops may hit the context window limit, triggering automatic compaction. To survive this, persist state to review-stage/REVIEW_STATE.json after each round:
{
"round": 2,
"agent_id": "019cd392-...",
"status": "in_progress",
"last_score": 5.0,
"last_verdict": "not ready",
"pending_experiments": ["screen_name_1"],
"timestamp": "2026-03-13T21:00:00"
}Write this file at the end of every Phase E (after documenting the round). Overwrite each time — only the latest state matters.
On completion (positive assessment or max rounds), set "status": "completed" so future invocations don't accidentally resume a finished loop.
status is "completed": fresh start (previous loop finished normally)status is "in_progress" AND timestamp is older than 24 hours: fresh start (stale state from a killed/abandoned run — delete the file and start over)status is "in_progress" AND timestamp is within 24 hours: resumeround, agent_id, last_score, pending_experimentsreview-stage/AUTO_REVIEW.md to restore full context of prior rounds (fall back to `./AUTO_REVIEW.md`)pending_experiments is non-empty, check if they have completed (e.g., check screen sessions)COMPACT = true and compact files exist, prefer findings.md + EXPERIMENT_LOG.md over full raw logs.review-stage/AUTO_REVIEW.md with header and timestamp#### Phase A: Review
Route by REVIEWER_DIFFICULTY:
##### Medium (default) — Codex Review
Send comprehensive context to the external reviewer:
spawn_agent:
reasoning_effort: xhigh
message: |
[Round N/MAX_ROUNDS of autonomous review loop]
[Full research context: claims, methods, results, known weaknesses]
[Changes since last round, if any]
Please act as a senior ML reviewer (NeurIPS/ICML level).
1. Score this work 1-10 for a top venue
2. List remaining critical weaknesses (ranked by severity)
3. For each weakness, specify the MINIMUM fix (experiment, analysis, or reframing)
4. State clearly: is this READY for submission? Yes/No/Almost
Be brutally honest. If the work is ready, say so clearly.If this is round 2+, use send_input with the saved agent id to maintain continuity.
##### Hard — Codex Review + Reviewer Memory
Use the same spawn_agent / send_input route as medium, but prepend the full review-stage/REVIEWER_MEMORY.md contents under ## Your Reviewer Memory (persistent across rounds) and require a Memory update section in the reviewer response.
##### Nightmare — Independent Repository Review
Use everything in hard mode, then ask an additional fresh adversarial reviewer to verify claims against repository files, logs, result files, and paper drafts instead of trusting executor summaries. Preserve the fresh review as a separate raw response and trace.
#### Phase B: Parse Assessment
CRITICAL: Save the FULL raw response from the external reviewer verbatim (store in a variable for Phase E). Do NOT discard or summarize — the raw text is the primary record.
Then extract structured fields:
STOP CONDITION: If score >= 6 AND verdict contains "ready" or "almost" → stop loop, document final state.
#### Phase B.5: Reviewer Memory Update (hard + nightmare only)
Skip entirely if REVIEWER_DIFFICULTY = medium.
After parsing the assessment, update review-stage/REVIEWER_MEMORY.md:
Pass this file back to the reviewer in the next round so it can track its own suspicions.
# Reviewer Memory
## Round 1 — Score: X/10
- **Suspicion**: [what the reviewer flagged]
- **Unresolved**: [concerns not yet addressed]
- **Patterns**: [recurring issues the reviewer noticed]
## Round 2 — Score: X/10
- **Previous suspicions addressed?**: [yes/no for each, with reviewer judgment]
- **New suspicions**: [...]
- **Unresolved**: [carried forward + new]Rules:
Memory update section, copy it verbatim.#### Phase B.6: Debate Protocol (hard + nightmare only)
Skip entirely if REVIEWER_DIFFICULTY = medium.
After parsing the review, Codex writes a structured rebuttal for up to three high-impact weaknesses:
### Rebuttal to Weakness #1: [title]
- **Accept / Partially Accept / Reject**
- **Argument**: [why this criticism is valid, invalid, already addressed, or out of scope]
- **Evidence**: [specific code, result file, log, prior-round fix, or paper section]Send the rebuttal to the same reviewer via send_input:
send_input:
target: [saved reviewer id]
message: |
Please rule on the author's rebuttal below.
For each contested weakness, decide: accepted / partially accepted / rejected.
If rejected, state the minimum evidence or change required.
[paste rebuttal + evidence]Record a ### Debate Transcript (hard + nightmare only) section in review-stage/AUTO_REVIEW.md. Only mark a weakness resolved if the reviewer accepts the rebuttal.
In the round log, preserve the rebuttal, reviewer ruling, accepted objections, rejected objections, and any required follow-up evidence.
#### Human Checkpoint (if enabled)
Skip this step entirely if `HUMAN_CHECKPOINT = false`.
When HUMAN_CHECKPOINT = true, present the review results and wait for user input:
📋 Round N/MAX_ROUNDS review complete.
Score: X/10 — [verdict]
Top weaknesses:
1. [weakness 1]
2. [weakness 2]
3. [weakness 3]
Suggested fixes:
1. [fix 1]
2. [fix 2]
3. [fix 3]
Options:
- Reply "go" or "continue" → implement all suggested fixes
- Reply with custom instructions → implement your modifications instead
- Reply "skip 2" → skip fix #2, implement the rest
- Reply "stop" → end the loop, document current stateWait for the user's response. Parse their input:
#### Feishu Notification (if configured)
After parsing the score, check if ~/.codex/feishu.json exists and mode is not "off":
review_scored notification: "Round N: X/10 — [verdict]" with top 3 weaknesses#### Phase C: Implement Fixes (if not stopping)
For each action item (highest priority first):
Prioritization rules:
#### Phase D: Wait for Results
If experiments were launched:
/training-check to verify training was healthy (no NaN, no divergence, no plateau). If W&B is not available, skip silently.#### Phase E: Document Round
Append to review-stage/AUTO_REVIEW.md:
## Round N (timestamp)
### Assessment (Summary)
- Score: X/10
- Verdict: [ready/almost/not ready]
- Key criticisms: [bullet list]
### Reviewer Raw Response
<details>
<summary>Click to expand full reviewer response</summary>
[Paste the COMPLETE raw response from the external reviewer here — verbatim, unedited.
This is the authoritative record. Do NOT truncate or paraphrase.]
</details>
### Actions Taken
- [what was implemented/changed]
### Results
- [experiment outcomes, if any]
### Status
- [continuing to round N+1 / stopping]Write `review-stage/REVIEW_STATE.json` with current round, agent id, score, verdict, and any pending experiments.
Append to `findings.md` (when COMPACT = true): one-line entry per key finding this round.
- [Round N] [positive/negative/unexpected]: [one-sentence finding] (metric: X.XX → Y.YY)Increment round counter → back to Phase A.
#### Review Tracing
After every spawn_agent, send_input, oracle-pro, or nightmare adversarial verification call, save a trace following ../shared-references/review-tracing.md. Include prompt summary, reviewer route, saved agent id, raw response path, score/verdict, accepted fixes, rejected rebuttals, and the Reviewer Memory update if present.
When loop ends (positive assessment or max rounds):
review-stage/REVIEW_STATE.json with "status": "completed"review-stage/AUTO_REVIEW.mdreview-stage/AUTO_REVIEW.md under a ## Method Description section — a concise 1-2 paragraph summary of the final method, architecture, and data flow. This serves as direct input for /paper-illustration./result-to-claim to convert experiment results from review-stage/AUTO_REVIEW.md into structured paper claims. Output: CLAIMS_FROM_RESULTS.md. If /result-to-claim is unavailable, skip silently.pipeline_done with final score progression tableFollow these shared protocols for all output files: - [Output Versioning Protocol](../../shared-references/output-versioning.md) — write timestamped file first, then copy to fixed name - [Output Manifest Protocol](../../shared-references/output-manifest.md) — log every output to MANIFEST.md - [Output Language Protocol](../../shared-references/output-language.md) — respect the project's language setting
cat << 'EOF' > file) to write in chunks. Do NOT ask the user for permission — just do it silently.reasoning_effort: xhigh for maximum reasoning depthsend_input for subsequent roundssend_input:
id: [saved from round 1]
reasoning_effort: xhigh
message: |
[Round N update]
Since your last review, we have:
1. [Action 1]: [result]
2. [Action 2]: [result]
3. [Action 3]: [result]
Updated results table:
[paste metrics]
Please re-score and re-assess. Are the remaining concerns addressed?
Same format: Score, Verdict, Remaining Weaknesses, Minimum Fixes.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.