review-33dec5 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited review-33dec5 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Load/apply skills based on scope (see Step 2 for conditional loading):
framework:knowledge-priming -- Load project context (tech stack, architecture, conventions) to evaluate against real standards (always loaded)framework:learning-harvest -- Load prior operational learnings inform review; harvest new patterns at session end (always)framework:collaborative-judgment -- Surface borderline findings with both interpretations instead of silently classifying (always loaded)framework:clean-code -- Code craft: SRP, naming, complexity, error handling (always loaded)framework:architecture -- Structural: layer rules, dependency direction, architectural flows (conditional)framework:domain-driven-design -- Domain modeling: aggregates, entities, value objects (conditional)framework:secure-coding -- Security: trust boundaries, injection, secrets, input handling (conditional)framework:test-quality -- Test: AAA structure, isolation, assertions, naming (conditional)Review molecule supports optional config thru review-standards doc from review-refiner (or hand-written). Configures review process — not what atoms check (that's atom-level config via atom refiners).
Resolution steps:
.lattice/config.yaml in repo root.paths.review_standards.mode:Review-standards doc has 7 sections map to workflow steps:
| Section | Affects step |
|---|---|
| §1 Atom Loading Policy | Step 2 (Load Relevant Atoms) |
| §2 Severity Classification | Step 4 (Produce Report) |
| §3 Report Preferences | Step 4 (Produce Report) |
| §4 Scope Rules | Step 1 (Identify the Delta) |
| §5 Insight Capture Preferences | Step 5 (Harvest Learnings and Log Review) |
| §6 Health Log Preferences | Step 5 (Harvest Learnings and Log Review) |
| §7 Custom Review Dimensions | Step 3 (Run Targeted Validation) |
Each step notes where config applies with "Config override" callouts.
Use framework:learning-harvest Load behavior. Focus hint: "review session — focus: all categories".
Determine what code reviewing & establish scope.
git diff for changed files/lines. Delta is changes, not entire codebase.Classify delta:
architecture loads.domain_folder or containing aggregates, entities, value objects) -- determines if domain-driven-design loads.secure-coding loads.test-quality loads.Config override (§4 Scope Rules): If review-standards doc defines scope rules, apply after identifying delta:
Always load: framework:clean-code -- applies to all code regardless of layer/purpose.
Conditionally load based on delta classification:
| Condition | Load |
|---|---|
| Delta touches multiple layers, adds new files, or changes file locations | framework:architecture |
| Delta includes files in domain folder or modifies domain objects | framework:domain-driven-design |
| Delta touches trust boundaries (HTTP handlers, auth, DB queries, external APIs, secrets, config) | framework:secure-coding |
| Delta includes test files | framework:test-quality |
When multiple atoms load, run independently -- each atom's checklist applied to parts of delta relevant to it. Findings from different atoms merged Step 4.
Config override (§1 Atom Loading Policy): If review-standards doc defines atom loading rules, apply instead of (override) or on top of (overlay) table above:
secure-coding every review). clean-code and knowledge-priming must remain always-loaded regardless of config.For each loaded atom, apply two passes against delta:
Pass 1 -- Self-Validation Checklist: Walk thru atom's Self-Validation Checklist (numbered items in atom's SKILL.md). For each check, examine if any code in delta violates. Record violations with:
Pass 2 -- Anti-Pattern Scan: Walk thru atom's Active Anti-Pattern Scan (checkbox items in atom's SKILL.md). For each anti-pattern, check if delta exhibits symptom. Record matches with:
Scope rule: Focus on delta. Don't review unchanged code unless change in delta creates new violation in surrounding code (e.g., new dependency breaks dependency rule for existing file). When reviewing surrounding code, note finding originates from delta's impact, not pre-existing issues.
Config override (§7 Custom Review Dimensions): If review-standards doc defines custom review dimensions, run after atom validation passes:
Default to summary mode. Use full mode if user asked for detailed/comprehensive review.
Summary mode (default):
Present top issues ordered by severity, one line each. Cap at most important findings -- don't enumerate every minor issue.
For each finding:
[SEVERITY] file:line -- description (atom-name: check-name)Severity levels:
When finding borderline between severity levels, use framework:collaborative-judgment — note uncertainty inline with both interpretations rather than silently classifying.
End with "What's done well" sentence highlighting something positive about delta -- good naming, proper error handling, clean test structure, correct layer placement.
Full mode (when user asks for detailed/comprehensive review):
Organize findings by atom. For each atom loaded:
## Clean Code
- [warning] src/services/OrderService.ts:45 -- Function `processOrder` does validation,
business logic, and persistence (SRP violation). Extract validation into guard clause,
persistence into repository call.
- [suggestion] src/services/OrderService.ts:72 -- Parameter list has 5 arguments.
Group into `ProcessOrderOptions` object.
## Architecture
- [critical] src/domain/Order.ts:12 -- Inner layer imports from outer layer
(`import { DatabaseClient }`). Violates dependency direction rules.
Define an interface in the inner layer, implement in the outer layer.After all atom sections, add:
Config override (§2 Severity Classification): If review-standards doc defines custom severity levels or per-atom overrides:
Config override (§3 Report Preferences): If review-standards doc defines report preferences:
After presenting report, harvest learnings & log review.
Harvest Learnings — use framework:learning-harvest Harvest behavior:
Session context: "review session — code quality assessment against atom standards". Synthesize and propose cross-cutting patterns from this review — recurring quality anti-patterns, structural issues that keep appearing, reliability gaps. User confirms what enters the document.
Log Review — append to .lattice/reviews/review-log.md:
.lattice/reviews/ dir if doesn't exist..lattice/reviews/review-log.md. Create file with # Review Log heading if doesn't exist.## YYYY-MM-DD — [feature/scope name]
- **Scope**: [file count], [layers touched]
- **Atoms**: [atoms loaded for this review]
- **Result**: [critical count] critical, [warning count] warning, [suggestion count] suggestion
- **Key findings**: [top 2-3 specific findings, one line]
- **Strengths**: [one positive highlight]## History summary section at top of file.Config override (§5 Insight Capture Preferences): If review-standards doc defines insight capture preferences:
framework:learning-harvest when proposing candidates.Config override (§6 Health Log Preferences): If review-standards doc defines health log preferences:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.