Skip to content
Back to skills

Hostility Review

ASecurity

Audit an implementation against its plan with a hostile peer agent, debate findings to consensus, and drive fix waves until the auditor runs dry. Use when a done-claim needs verification the implementer cannot game ("hostile review", "adversarial audit", "is this PR faithful", "find the escape hatches") — the loop that beats the laziness bias with its own game theory.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
testingrustgoapi

Works with

  • api

Security analysis

A100/100

Scanned September 8, 2026

npx -y skills add juspay/odu --skill hostility-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hostility Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hostility Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/juspay-hostility-review-odu/badge)](https://www.skillsdirectory.com/skills/juspay-hostility-review-odu)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hostility-review
description: >-
  Audit an implementation against its plan with a hostile peer agent, debate
  findings to consensus, and drive fix waves until the auditor runs dry. Use
  when a done-claim needs verification the implementer cannot game ("hostile
  review", "adversarial audit", "is this PR faithful", "find the escape
  hatches") — the loop that beats the laziness bias with its own game theory.
---

# Hostility review — done is the auditor's empty round

Reviews fail when author and auditor share an incentive: both want "done".
This loop splits them. Five moves; the mechanics live in `/kolu`.

1. **Fresh hostile eyes, zero stake.** The auditor is a different model that
   never saw the brief and doesn't answer for the outcome. It audits the diff
   against the PLAN — not the code against itself — seeded with the ledger of
   previously named cheats. Evidence discipline: every finding cites the code
   and quotes the plan sentence it violates. No vibes.

2. **Verify, then debate.** Trust no finding and no rebuttal: check each
   against the code yourself, concede what's real, refute with evidence,
   loop to consensus per finding. Judgment forks go to the human; evidence
   disputes never do.

3. **Fix waves with predicates.** Each consensus becomes a wave brief whose
   done-whens cannot be satisfied by their letter: greps that return nothing,
   mutations actually performed and observed red, type-level pins. A test
   seam never widens a public API. A claim without its executed check is
   a finding.

4. **Loop until dry.** The implementer's "done" triggers a re-audit of the
   pushed delta — including fresh residue the fixes introduced, and whether
   a fix merely relocated the defect. The campaign ends only on the
   auditor's clean round.

5. **Ratchet and scope.** Every named cheat joins the ledger (the next run
   starts smarter) and graduates, where possible, into a permanent check —
   yesterday's judgment is tomorrow's red build. Effort follows worth:
   framework surface, then production semantics, then app tests — a guard
   of a guard is rarely worth a wave.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…