Caveman Review Skill Security Audit
What the author says it does (original text)
>
No obvious risks found in this check
- Files checked
- 2
- Risks found
- 0
Inside this skill
The Skill compresses code-review findings into one-line comments containing a location, problem, and proposed fix, with optional severity prefixes.
View source
Write code review comments terse and actionable. One line per finding. Location, problem, fix. No throat-clearing.**Format:** `L<line>: <problem>. <fix>.` — or `<file>:L<line>: ...` when reviewing multi-file diffs.**Severity prefix (optional, when mixed):**- `🔴 bug:` — broken behavior, will cause incident- `🟡 risk:` — works but fragile (race, missing null check, swallowed error)- `🔵 nit:` — style, naming, micro-optim. Author can ignore- `❓ q:` — genuine question, not a suggestionFor security findings, architectural disagreements, and onboarding situations, the Skill instructs the reviewer to suspend terse mode and provide a normal explanatory paragraph.
View source
Drop terse mode for: security findings (CVE-class bugs need full explanation + reference), architectural disagreements (need rationale, not just a one-liner), and onboarding contexts where the author is new and needs the "why". In those cases write a normal paragraph, then resume terse for the rest.Its stated boundary is generating paste-ready review comments only; it does not modify code, run linters, or approve or request changes on the user's behalf.
View source
Reviews only — does not write the code fix, does not approve/request-changes, does not run linters. Output the comment(s) ready to paste into the PR. "stop caveman-review" or "normal mode": revert to verbose review style.Output only — does not approve, request changes, or run linters.File reference map
References: 1Files and check records2 files
Coverage and gaps
Content covered in each file
These are the source ranges included in this check, not a guarantee that every issue has been resolved.
SKILL.mdFull text includedREADME.mdFull text included
This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.
README.mdSupporting fileSKILL.mdInstructions
- Lines read
- 87
- File checksum (to compare versions)
- 0daf53dbe8e8dea59d3a513b7dd8a827fd2e1cb4b40cb38b8f852f25ab1a1afb