review-1b5d7a — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited review-1b5d7a (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are running the /review workflow. Analyze the current branch's diff against main for structural issues that tests don't catch.
git branch --show-current to get the current branch.main, output: "Nothing to review — you're on main or have no changes against main." and stop.git fetch origin main --quiet && git diff origin/main --stat to check if there's a diff. If no diff, output the same message and stop.Read .claude/skills/review/checklist.md.
If the file cannot be read, STOP and report the error. Do not proceed without the checklist.
Read .claude/skills/review/greptile-triage.md and follow the fetch, filter, and classify steps.
If no PR exists, `gh` fails, API returns an error, or there are zero Greptile comments: Skip this step silently. Greptile integration is additive — the review works without it.
If Greptile comments are found: Store the classifications (VALID & ACTIONABLE, VALID BUT ALREADY FIXED, FALSE POSITIVE, SUPPRESSED) — you will need them in Step 5.
Fetch the latest main to avoid false positives from a stale local main:
git fetch origin main --quietRun git diff origin/main to get the full diff. This includes both committed and uncommitted changes against the latest main.
Apply the checklist against the diff in two passes:
Follow the output format specified in the checklist. Respect the suppressions — do NOT flag items listed in the "DO NOT flag" section.
Always output ALL findings — both critical and informational. The user must see every issue.
After all critical questions are answered, output a summary of what the user chose for each issue. If the user chose A (fix) on any issue, apply the recommended fixes. If only B/C were chosen, no action needed.
Pre-Landing Review: No issues found.After outputting your own findings, if Greptile comments were classified in Step 2.5:
Include a Greptile summary in your output header: + N Greptile comments (X valid, Y fixed, Z FP)
~/.gstack/greptile-history.md (type: fp).If the user chooses A, post a reply using the appropriate API from the triage doc and save the pattern to ~/.gstack/greptile-history.md (type: fp).
"Good catch — already fixed in <commit-sha>."~/.gstack/greptile-history.md (type: already-fixed)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.