Adds the unified-review integration that fuses CRG graph context with the ai-code-review scoring methodology and gstack-review fix-first workflow: - scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage, redundancy_rate, high_risk_density, vulnerability_risk) with good/warn/fail grades, plus dedupe_findings (fingerprint merge, multi-source confidence boost, PR quality score) and report data builder - tools/scoring_tools.py + main.py: three new MCP tools (score_review_tool, dedupe_findings_tool, generate_report_tool) - assets/report-template.html: self-contained HTML report template - skills.py + skills/unified-review/: new read-only unified-review skill with language/manual-review/specialist checklists - docs and CHANGELOG updated; tests added (test_scoring, test_report, test_unified_review) and test_skills updated for 5 skills
820 B
820 B
Red Team Specialist (conditional)
Focus: find what the primary and specialist reviewers MISSED. Only dispatched when the diff is large (>200 lines) or a specialist found a critical issue.
Think like an attacker and a chaos engineer:
- Cross-cutting concerns the specialist checklists do not cover
- Integration boundary failures (service-to-service, module-to-module)
- Failure modes: what breaks in production under load, restart, partial failure
- Silent data corruption paths (wrong results without errors)
- Error handling that swallows failures
- Trust boundary violations
- Race conditions and edge cases the primary review missed
Be adversarial. No compliments — just the problems. Tag findings with
"source":"red-team". Output NO FINDINGS when nothing new is found.