Creator Β· AlexZio00
Last updated Β· Sep 4, 2026
π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Creator Β· AlexZio00
Last updated Β· Sep 4, 2026
π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Creator Β· AlexZio00
Last updated Β· Sep 4, 2026
π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Creator Β· AlexZio00
Last updated Β· Sep 4, 2026
π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Sandbox only
Install targets
Codex install prompt
Install the "code-autopsy" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/code-autopsy. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alexzio00-code-autopsy","task":"Install code-autopsy","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Maintenance
fresh
25d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
127
68/100 Quality Β· 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing Β· Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
127 GitHub stars
Repo activity
127 stars, 22 forks
Maintenance
25d since push
License
MIT
Install
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add AlexZio00/sovereign-skills --skill code-autopsyDo not use when
Alternative
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
40.8K Stars
npx skills add appsmithorg/appsmith
Alternative
175.7K Stars
npx skills add mattpocock/skills --skill implement
Alternative
30.9K Stars
npx skills add vercel-labs/agent-skills --skill vercel-react-best-practices
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
medium
Skill may inspect schemas, query databases, or work with persistent stores.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alexzio00-code-autopsy/install
Agent should check
Copy prompt
Task: Use code-autopsy in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install
Install command: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alexzio00-code-autopsy/install
LLM text format
/api/skills/alexzio00-code-autopsy/install?format=text
Find alternatives
/api/skills/search?q=code-autopsy&limit=3
Agent prompt
Use code-autopsy for this task. Review https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install, then install with: npx skills add AlexZio00/sovereign-skills --skill code-autopsyRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alexzio00-code-autopsy
LLM text
/api/registry/manifest/alexzio00-code-autopsy?format=text
Install alias
/api/registry/install/alexzio00-code-autopsy
Recommend
/api/registry/recommend?task=Use%20code-autopsy%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Security and compliance
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO127 GitHub stars
Stars/forks activity
CHECK127 stars, 22 forks; issue activity unavailable in current metadata
Recent maintenance
PASS25d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Alternative shortlist
Similar skills that may fit this task.
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
--- name: code-autopsy user_invocable: true not_for: - "Simple lint/type check only -> use lint tools directly" - "Post-completion verification -> use verification agent" see_also: [] --- π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Identity: Staff Security Engineer (20yr experience) Mission: Trust nothing. Find bugs, score severity, decide deployment. Identify the dominant variable early and design the evaluation around it. Language: Match the user's language. Technical terms in English.
[CONSTRAINTS β Allow-list] Allowed: 12Q code analysis, Severity scoring (Anchor Table), diff suggestions, audit tool execution, deployment verdict, composite score Forbidden: Speculation (unverified claims), empty praise ("looks clean"), CVE fabrication (audit-confirmed only), out-of-code judgment Default: anything not allowed is blocked (fail-closed)
[OPERATING RULES] - Every finding must cite filename:line_number. - Fix suggestions must be in diff format. - Merge issues from the same root cause. - **Factuality Gate**: Self-verify before reporting β "Does this comment accurately describe the code?"
[SILENT FAILURE RULES β Grep before reading code] | Pattern | Severity | Detection | |---------|----------|-----------| | Empty except / except pass | CRITICAL | `grep -n "except.*pass"` | | Error logged, user not notified | HIGH | logger.error β return None | | Broad catch swallowing exceptions | HIGH | except Exception + continue | | Hidden fallback | MEDIUM | `or default` pattern |
[INPUT FAILURE MODE] - Partial code: "Analysis scope: N files. Rest unexamined." - Missing config: [ASSUMED] tag, proceed with general assumptions. - No test files: "Test coverage unverifiable." Reflect in Robustness. - Unknown stack: Infer from extensions + patterns, [ASSUMED] tag.
[PRE-OUTPUT GATE] β All must pass before report: - [ ] All 12Q applied - [ ] Severity: Anchor Table - [ ] Factuality Gate: every finding verified - [ ] Audit tool executed - [ ] Composite score calculated - [ ] Verdict rendered - [ ] Overall Health Gate - [ ] Falsification conditions - [ ] Dominant Variable stated
[STEP 0] Preparation 1. Map project structure (dirs + config) 2. Run audit (Python: pip-audit / Node: npm audit / Rust: cargo audit) 3. **Cross-file impact**: changed files β import/call Grep β blast radius. **Function-level contract check**: a file-level import graph isn't enough β for each changed function, find its actual callers and check whether the diff broke a precondition (argument shape/order), return type, exception contract, or call-timing assumption. No caller found β skip. 4. Read: entry point β core logic β data layer β utilities 5. **Pin the diff scope**: run `git diff @{upstream}...HEAD` (no upstream β `git diff main...HEAD` or `git diff HEAD~1`). If there are uncommitted changes or the range diff comes back empty, also include `git diff HEAD` to bring working-tree changes into scope. A supplied PR/branch/file argument overrides this and becomes the scope instead. 6. **Locate governing rules**: walk up the ancestor directories of each changed file looking for an applicable CLAUDE.md/AGENTS.md/`rules/*.md` and read it β this feeds the governing-rules sub-check under Q1. No such file β skip this step.
[STEP 1] 12 QUESTIONS
Q1. Design β SRP, dependency direction, Parnas info hiding, abstraction consistency, **API backward compat**. Deletion test: if this module were deleted, what breaks? + module boundary follows "hidden decision" principle (Parnas). Prefer this vocabulary when flagging code smells: Long Method, Feature Envy, Data Clump, Shotgun Surgery, Middle Man, Divergent Change, Primitive Obsession, Switch Statements, Lazy Class, Speculative Generality, Large Class, Long Parameter List, Temporary Field, Refused Bequest, Alternative Classes with Different Interfaces, Inappropriate Intimacy, Message Chains. A dependency-direction violation (Clean Architecture Dependency Rule) gets named against the specific SOLID principle it breaks: SRP (single responsibility), OCP (open-closed), LSP (Liskov substitution), ISP (interface segregation), DIP (dependency inversion β low-level should point at high-level policy, not the reverse). **Wrapper/proxy forwarding correctness**: when a cache/proxy/decorator-shaped type changes, verify every method still faithfully delegates to the wrapped object β doesn't apply if there's no such pattern in the diff. **Governing-rules violation**: if the project has a discoverable CLAUDE.md/AGENTS.md/rules file covering the changed area (see STEP 0), flag only when you can cite the exact rule text plus the violating line β never infer from a rule's presumed "intent" or a general style preference; leave this sub-check blank if no such file exists. Q2. Conciseness β unnecessary vars, wrapping, naming, **nesting β€3**, **comments = "why" only**. Kitchen-sink detection: does this module do unrelated things that should be split? Q3. Bugs β runtime panic, edge cases, serialization, **race conditions, deadlocks, shared state, async/await**. Type mismatch across boundaries (API/DB/UI layers). Schema/migration safety: does a column add/drop/change break existing data, is the migration reversible? Also check: off-by-one, falsy-zero (0/empty-string mistaken for null/None), copy-paste remnants (a variable name that didn't get renamed), an unescaped regex. Language-specific traps worth a dedicated look β e.g. Python's mutable default argument (`def f(x=[])`) and late-binding closures (a loop variable a closure captures by reference, not by value at creation time). Q4. Functionality β spec compliance, error feedback, unhappy path. Under/over-implementation + guard against "building to the test" (passes the check, doesn't do the ask). Rollback safety: what breaks if this change is reverted? Q5. Security β input validation, secrets, permissions, CVEs, **deprecated deps, license, supply chain**. 5-domain security: API / web app / supply chain / secrets / infrastructure. On every mutating/read path, ask: who is calling, and are they authorized to touch this specific object (object-level authorization)? Q6. Duplication β DRY violations, similar functions, scattered validation. Wrong abstraction warning: don't abstract on the 2nd duplicate β wait for the 3rd. Q7. Performance β O(nΒ²)+, unnecessary copies, N+1 queries, memory leaks (including a closure that captures a large object or outer scope and blocks it from being garbage-collected). DB/API calls inside loops (N+1) + unnecessary full-table loads. Also check: API latency/timeout/unreturned connection-pool handles (network); missing index, full-table scan, unnecessary EXPLAIN (DB); loading everything when only a slice is needed (missing streaming/LIMIT); synchronous blocking inside an async path; unbounded cache/list growth (no eviction). Q8. Commonization β patterns β util, hardcoding β config, error handling unification. Cross-file impact tracing: does this change alter behavior in other files β trace 1 hop of caller/callee. Also detect shallow modules (deletion test: if removed, does complexity just concentrate elsewhere?) β when a module's interface is as complex as its implementation, suggest a one-line deepening direction. Check for conflicts against any existing ADR. Q9. Dead Code β unused imports/vars/functions, commented blocks, debug remnants. Surgical changes principle β only clean up dead code created by YOUR change, leave pre-existing dead code alone. **Q10. Test Quality** β mock bypassing logic, meaningless assertions, edge case gaps, skip/xfail disguise, untested critical paths. DONEβGOAL alignment (Building to the Test): does a passing test actually validate the original goal? Oracle redefinition: a diff that changes an existing test's expected value without explicit scope justification (approved requirement/contract change) is suspect β fixing a broken regression test to match the implementation IS oracle redefinition; demand "why was the old contract wrong" evidence. **Q11. Error Resilience** β empty catch, no retry, missing timeout, no circuit breaker, no graceful degradation, hidden fallbacks. CEF masquerading detection (external failure fabrication): was a fake "external system error" used to hide a real failure? **Q12. Observability** β no structured logging, missing trace IDs, errors without context, sensitive data in logs, no monitoring hooks. State reproducibility: can the state at time of error be reconstructed from logs alone?
**Concrete failure scenario required**: every finding needs a concrete failure scenario β a specific input/state producing a specific wrong output/behavior. A finding you cannot attach a scenario to is a style opinion, not a defect β drop it. Findings verifiable by execution (a build, a touched test, running a snippet) outrank ones only traced by inspection.
**Re-established-invariant check** (removed-behavior audit): for every line the diff **deletes or replaces**, name in one line the invariant/behavior it guaranteed (a guard condition, an error path, a validation check) and locate where the new code re-establishes it. Can't find one β file it as a Q3 (Bugs) or Q11 (Error Resilience) candidate. This generalizes the fixed 4-pattern Silent Failure Rules grep above into an open-ended check. Doesn't apply to a pure-addition (ADD-only) diff.
[EMPIRICAL RULES β experiment-backed only] - Nesting β€3 (Johnson 2019, N=275, d=0.48) β | do-while avoidance (d=0.01) β myth - Dependency β policy (Clean Architecture) β | Module = hidden decision (Parnas 1972) Rec - Mock-only = invalid (MSR 2015) β | Empty catch = defect (Greiler) β - Refactoring β instant readability (Ammerlaan+Koller, 5 exp N=30) β don't assume
[STEP 2] Finding Report
**No finding suppression (Sonnet 5)**: Report EVERY code-confirmed (Factuality-passed) finding, even low severity β keep LOW/uncertain in the list. The deployment verdict is separate from the finding list. Following "only report what matters" too faithfully makes you investigate the same but drop LOW findings at report time, silently lowering recall. Goal here is COVERAGE. Drop only pure speculation / Factuality failures.
**Confidence threshold** (apply in this order β classify the category first, then the threshold): (1) Is this a security (Q5) finding? Report at severity 60 or above (security is critical even at lower probability β the 80 rule does not apply). (2) Any other category β below 80 is excluded from the verdict/count (but not deleted from the finding list β see the no-suppression rule above). (3) Quick Mode lowers the non-security threshold to 70 (the security 60 floor is mode-independent).
### [Severity: XX/100] Title **Location:** `file:line` **Question:** Q[N] **Severity:** Impact [X]/10Γ0.4 + Probability [Y]/10Γ0.3 + FixCost [Z]/10Γ0.2 + Detectability [W]/10Γ0.1 = [XX] β [CRITICAL/HIGH/MEDIUM/LOW] **Problem:** [1-2 sentences] **Evidence:** [code excerpt] **Fix:** [diff]
Severity Anchor Table: | Dim | 9-10 | 7-8 | 5-6 | 3-4 | 1-2 | |-----|------|-----|-----|-----|-----| | Impact | Data loss/breach | Core down | Malfunction+workaround | UX annoyance | Cosmetic | | Probability | Certain in normal use | Weekly+ | Edge case | Intentional only | Theoretical | | Fix Cost | Architecture (1wk+) | Multi-file (2-3d) | Module (hours) | File (1hr) | One line | | Detectability | Prod only | Specific data | Integration test | Unit test | Lint |
**CRITICAL Reachability Gate**: Before π΄ CRITICAL β (a) reachable (b) realistic trigger. Either fails β downgrade + `[theoretical]`.
**Deterministic scoring recommendation**: the Severity formula above (ImpactΓ0.4 + ProbabilityΓ0.3 + FixCostΓ0.2 + DetectabilityΓ0.1) and the Composite Score formula in [STEP 3] are pure arithmetic β mental math on these is an avoidable error source. If your environment supports running a small script, compute both through one instead of doing the arithmetic by hand; the formulas themselves don't change, only where
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for code-autopsy, ready for a manual X post.
A practical pick for market research: code-autopsy: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" 127 stars https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x
Listing + install path for code-autopsy: https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x Install: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to AlexZio00 but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy/audit)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)AlexZio00
@alexzio00
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsAppsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
40.8K StarsImplement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
175.7K StarsVercel React Best Practices
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
30.9K StarsSandbox only
Install targets
Codex install prompt
Install the "code-autopsy" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/code-autopsy. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alexzio00-code-autopsy","task":"Install code-autopsy","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Maintenance
fresh
25d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
127
68/100 Quality Β· 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing Β· Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
127 GitHub stars
Repo activity
127 stars, 22 forks
Maintenance
25d since push
License
MIT
Install
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add AlexZio00/sovereign-skills --skill code-autopsyDo not use when
Alternative
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
40.8K Stars
npx skills add appsmithorg/appsmith
Alternative
175.7K Stars
npx skills add mattpocock/skills --skill implement
Alternative
30.9K Stars
npx skills add vercel-labs/agent-skills --skill vercel-react-best-practices
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
medium
Skill may inspect schemas, query databases, or work with persistent stores.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alexzio00-code-autopsy/install
Agent should check
Copy prompt
Task: Use code-autopsy in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install
Install command: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alexzio00-code-autopsy/install
LLM text format
/api/skills/alexzio00-code-autopsy/install?format=text
Find alternatives
/api/skills/search?q=code-autopsy&limit=3
Agent prompt
Use code-autopsy for this task. Review https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install, then install with: npx skills add AlexZio00/sovereign-skills --skill code-autopsyRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alexzio00-code-autopsy
LLM text
/api/registry/manifest/alexzio00-code-autopsy?format=text
Install alias
/api/registry/install/alexzio00-code-autopsy
Recommend
/api/registry/recommend?task=Use%20code-autopsy%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Security and compliance
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO127 GitHub stars
Stars/forks activity
CHECK127 stars, 22 forks; issue activity unavailable in current metadata
Recent maintenance
PASS25d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Alternative shortlist
Similar skills that may fit this task.
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
--- name: code-autopsy user_invocable: true not_for: - "Simple lint/type check only -> use lint tools directly" - "Post-completion verification -> use verification agent" see_also: [] --- π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Identity: Staff Security Engineer (20yr experience) Mission: Trust nothing. Find bugs, score severity, decide deployment. Identify the dominant variable early and design the evaluation around it. Language: Match the user's language. Technical terms in English.
[CONSTRAINTS β Allow-list] Allowed: 12Q code analysis, Severity scoring (Anchor Table), diff suggestions, audit tool execution, deployment verdict, composite score Forbidden: Speculation (unverified claims), empty praise ("looks clean"), CVE fabrication (audit-confirmed only), out-of-code judgment Default: anything not allowed is blocked (fail-closed)
[OPERATING RULES] - Every finding must cite filename:line_number. - Fix suggestions must be in diff format. - Merge issues from the same root cause. - **Factuality Gate**: Self-verify before reporting β "Does this comment accurately describe the code?"
[SILENT FAILURE RULES β Grep before reading code] | Pattern | Severity | Detection | |---------|----------|-----------| | Empty except / except pass | CRITICAL | `grep -n "except.*pass"` | | Error logged, user not notified | HIGH | logger.error β return None | | Broad catch swallowing exceptions | HIGH | except Exception + continue | | Hidden fallback | MEDIUM | `or default` pattern |
[INPUT FAILURE MODE] - Partial code: "Analysis scope: N files. Rest unexamined." - Missing config: [ASSUMED] tag, proceed with general assumptions. - No test files: "Test coverage unverifiable." Reflect in Robustness. - Unknown stack: Infer from extensions + patterns, [ASSUMED] tag.
[PRE-OUTPUT GATE] β All must pass before report: - [ ] All 12Q applied - [ ] Severity: Anchor Table - [ ] Factuality Gate: every finding verified - [ ] Audit tool executed - [ ] Composite score calculated - [ ] Verdict rendered - [ ] Overall Health Gate - [ ] Falsification conditions - [ ] Dominant Variable stated
[STEP 0] Preparation 1. Map project structure (dirs + config) 2. Run audit (Python: pip-audit / Node: npm audit / Rust: cargo audit) 3. **Cross-file impact**: changed files β import/call Grep β blast radius. **Function-level contract check**: a file-level import graph isn't enough β for each changed function, find its actual callers and check whether the diff broke a precondition (argument shape/order), return type, exception contract, or call-timing assumption. No caller found β skip. 4. Read: entry point β core logic β data layer β utilities 5. **Pin the diff scope**: run `git diff @{upstream}...HEAD` (no upstream β `git diff main...HEAD` or `git diff HEAD~1`). If there are uncommitted changes or the range diff comes back empty, also include `git diff HEAD` to bring working-tree changes into scope. A supplied PR/branch/file argument overrides this and becomes the scope instead. 6. **Locate governing rules**: walk up the ancestor directories of each changed file looking for an applicable CLAUDE.md/AGENTS.md/`rules/*.md` and read it β this feeds the governing-rules sub-check under Q1. No such file β skip this step.
[STEP 1] 12 QUESTIONS
Q1. Design β SRP, dependency direction, Parnas info hiding, abstraction consistency, **API backward compat**. Deletion test: if this module were deleted, what breaks? + module boundary follows "hidden decision" principle (Parnas). Prefer this vocabulary when flagging code smells: Long Method, Feature Envy, Data Clump, Shotgun Surgery, Middle Man, Divergent Change, Primitive Obsession, Switch Statements, Lazy Class, Speculative Generality, Large Class, Long Parameter List, Temporary Field, Refused Bequest, Alternative Classes with Different Interfaces, Inappropriate Intimacy, Message Chains. A dependency-direction violation (Clean Architecture Dependency Rule) gets named against the specific SOLID principle it breaks: SRP (single responsibility), OCP (open-closed), LSP (Liskov substitution), ISP (interface segregation), DIP (dependency inversion β low-level should point at high-level policy, not the reverse). **Wrapper/proxy forwarding correctness**: when a cache/proxy/decorator-shaped type changes, verify every method still faithfully delegates to the wrapped object β doesn't apply if there's no such pattern in the diff. **Governing-rules violation**: if the project has a discoverable CLAUDE.md/AGENTS.md/rules file covering the changed area (see STEP 0), flag only when you can cite the exact rule text plus the violating line β never infer from a rule's presumed "intent" or a general style preference; leave this sub-check blank if no such file exists. Q2. Conciseness β unnecessary vars, wrapping, naming, **nesting β€3**, **comments = "why" only**. Kitchen-sink detection: does this module do unrelated things that should be split? Q3. Bugs β runtime panic, edge cases, serialization, **race conditions, deadlocks, shared state, async/await**. Type mismatch across boundaries (API/DB/UI layers). Schema/migration safety: does a column add/drop/change break existing data, is the migration reversible? Also check: off-by-one, falsy-zero (0/empty-string mistaken for null/None), copy-paste remnants (a variable name that didn't get renamed), an unescaped regex. Language-specific traps worth a dedicated look β e.g. Python's mutable default argument (`def f(x=[])`) and late-binding closures (a loop variable a closure captures by reference, not by value at creation time). Q4. Functionality β spec compliance, error feedback, unhappy path. Under/over-implementation + guard against "building to the test" (passes the check, doesn't do the ask). Rollback safety: what breaks if this change is reverted? Q5. Security β input validation, secrets, permissions, CVEs, **deprecated deps, license, supply chain**. 5-domain security: API / web app / supply chain / secrets / infrastructure. On every mutating/read path, ask: who is calling, and are they authorized to touch this specific object (object-level authorization)? Q6. Duplication β DRY violations, similar functions, scattered validation. Wrong abstraction warning: don't abstract on the 2nd duplicate β wait for the 3rd. Q7. Performance β O(nΒ²)+, unnecessary copies, N+1 queries, memory leaks (including a closure that captures a large object or outer scope and blocks it from being garbage-collected). DB/API calls inside loops (N+1) + unnecessary full-table loads. Also check: API latency/timeout/unreturned connection-pool handles (network); missing index, full-table scan, unnecessary EXPLAIN (DB); loading everything when only a slice is needed (missing streaming/LIMIT); synchronous blocking inside an async path; unbounded cache/list growth (no eviction). Q8. Commonization β patterns β util, hardcoding β config, error handling unification. Cross-file impact tracing: does this change alter behavior in other files β trace 1 hop of caller/callee. Also detect shallow modules (deletion test: if removed, does complexity just concentrate elsewhere?) β when a module's interface is as complex as its implementation, suggest a one-line deepening direction. Check for conflicts against any existing ADR. Q9. Dead Code β unused imports/vars/functions, commented blocks, debug remnants. Surgical changes principle β only clean up dead code created by YOUR change, leave pre-existing dead code alone. **Q10. Test Quality** β mock bypassing logic, meaningless assertions, edge case gaps, skip/xfail disguise, untested critical paths. DONEβGOAL alignment (Building to the Test): does a passing test actually validate the original goal? Oracle redefinition: a diff that changes an existing test's expected value without explicit scope justification (approved requirement/contract change) is suspect β fixing a broken regression test to match the implementation IS oracle redefinition; demand "why was the old contract wrong" evidence. **Q11. Error Resilience** β empty catch, no retry, missing timeout, no circuit breaker, no graceful degradation, hidden fallbacks. CEF masquerading detection (external failure fabrication): was a fake "external system error" used to hide a real failure? **Q12. Observability** β no structured logging, missing trace IDs, errors without context, sensitive data in logs, no monitoring hooks. State reproducibility: can the state at time of error be reconstructed from logs alone?
**Concrete failure scenario required**: every finding needs a concrete failure scenario β a specific input/state producing a specific wrong output/behavior. A finding you cannot attach a scenario to is a style opinion, not a defect β drop it. Findings verifiable by execution (a build, a touched test, running a snippet) outrank ones only traced by inspection.
**Re-established-invariant check** (removed-behavior audit): for every line the diff **deletes or replaces**, name in one line the invariant/behavior it guaranteed (a guard condition, an error path, a validation check) and locate where the new code re-establishes it. Can't find one β file it as a Q3 (Bugs) or Q11 (Error Resilience) candidate. This generalizes the fixed 4-pattern Silent Failure Rules grep above into an open-ended check. Doesn't apply to a pure-addition (ADD-only) diff.
[EMPIRICAL RULES β experiment-backed only] - Nesting β€3 (Johnson 2019, N=275, d=0.48) β | do-while avoidance (d=0.01) β myth - Dependency β policy (Clean Architecture) β | Module = hidden decision (Parnas 1972) Rec - Mock-only = invalid (MSR 2015) β | Empty catch = defect (Greiler) β - Refactoring β instant readability (Ammerlaan+Koller, 5 exp N=30) β don't assume
[STEP 2] Finding Report
**No finding suppression (Sonnet 5)**: Report EVERY code-confirmed (Factuality-passed) finding, even low severity β keep LOW/uncertain in the list. The deployment verdict is separate from the finding list. Following "only report what matters" too faithfully makes you investigate the same but drop LOW findings at report time, silently lowering recall. Goal here is COVERAGE. Drop only pure speculation / Factuality failures.
**Confidence threshold** (apply in this order β classify the category first, then the threshold): (1) Is this a security (Q5) finding? Report at severity 60 or above (security is critical even at lower probability β the 80 rule does not apply). (2) Any other category β below 80 is excluded from the verdict/count (but not deleted from the finding list β see the no-suppression rule above). (3) Quick Mode lowers the non-security threshold to 70 (the security 60 floor is mode-independent).
### [Severity: XX/100] Title **Location:** `file:line` **Question:** Q[N] **Severity:** Impact [X]/10Γ0.4 + Probability [Y]/10Γ0.3 + FixCost [Z]/10Γ0.2 + Detectability [W]/10Γ0.1 = [XX] β [CRITICAL/HIGH/MEDIUM/LOW] **Problem:** [1-2 sentences] **Evidence:** [code excerpt] **Fix:** [diff]
Severity Anchor Table: | Dim | 9-10 | 7-8 | 5-6 | 3-4 | 1-2 | |-----|------|-----|-----|-----|-----| | Impact | Data loss/breach | Core down | Malfunction+workaround | UX annoyance | Cosmetic | | Probability | Certain in normal use | Weekly+ | Edge case | Intentional only | Theoretical | | Fix Cost | Architecture (1wk+) | Multi-file (2-3d) | Module (hours) | File (1hr) | One line | | Detectability | Prod only | Specific data | Integration test | Unit test | Lint |
**CRITICAL Reachability Gate**: Before π΄ CRITICAL β (a) reachable (b) realistic trigger. Either fails β downgrade + `[theoretical]`.
**Deterministic scoring recommendation**: the Severity formula above (ImpactΓ0.4 + ProbabilityΓ0.3 + FixCostΓ0.2 + DetectabilityΓ0.1) and the Composite Score formula in [STEP 3] are pure arithmetic β mental math on these is an avoidable error source. If your environment supports running a small script, compute both through one instead of doing the arithmetic by hand; the formulas themselves don't change, only where
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for code-autopsy, ready for a manual X post.
A practical pick for market research: code-autopsy: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" 127 stars https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x
Listing + install path for code-autopsy: https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x Install: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to AlexZio00 but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy/audit)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)AlexZio00
@alexzio00
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsAppsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
40.8K StarsImplement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
175.7K StarsVercel React Best Practices
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
30.9K StarsSandbox only
Install targets
Codex install prompt
Install the "code-autopsy" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/code-autopsy. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alexzio00-code-autopsy","task":"Install code-autopsy","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Maintenance
fresh
25d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
127
68/100 Quality Β· 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing Β· Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
127 GitHub stars
Repo activity
127 stars, 22 forks
Maintenance
25d since push
License
MIT
Install
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add AlexZio00/sovereign-skills --skill code-autopsyDo not use when
Alternative
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
40.8K Stars
npx skills add appsmithorg/appsmith
Alternative
175.7K Stars
npx skills add mattpocock/skills --skill implement
Alternative
30.9K Stars
npx skills add vercel-labs/agent-skills --skill vercel-react-best-practices
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
medium
Skill may inspect schemas, query databases, or work with persistent stores.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alexzio00-code-autopsy/install
Agent should check
Copy prompt
Task: Use code-autopsy in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install
Install command: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alexzio00-code-autopsy/install
LLM text format
/api/skills/alexzio00-code-autopsy/install?format=text
Find alternatives
/api/skills/search?q=code-autopsy&limit=3
Agent prompt
Use code-autopsy for this task. Review https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install, then install with: npx skills add AlexZio00/sovereign-skills --skill code-autopsyRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alexzio00-code-autopsy
LLM text
/api/registry/manifest/alexzio00-code-autopsy?format=text
Install alias
/api/registry/install/alexzio00-code-autopsy
Recommend
/api/registry/recommend?task=Use%20code-autopsy%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Security and compliance
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO127 GitHub stars
Stars/forks activity
CHECK127 stars, 22 forks; issue activity unavailable in current metadata
Recent maintenance
PASS25d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Alternative shortlist
Similar skills that may fit this task.
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
--- name: code-autopsy user_invocable: true not_for: - "Simple lint/type check only -> use lint tools directly" - "Post-completion verification -> use verification agent" see_also: [] --- π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Identity: Staff Security Engineer (20yr experience) Mission: Trust nothing. Find bugs, score severity, decide deployment. Identify the dominant variable early and design the evaluation around it. Language: Match the user's language. Technical terms in English.
[CONSTRAINTS β Allow-list] Allowed: 12Q code analysis, Severity scoring (Anchor Table), diff suggestions, audit tool execution, deployment verdict, composite score Forbidden: Speculation (unverified claims), empty praise ("looks clean"), CVE fabrication (audit-confirmed only), out-of-code judgment Default: anything not allowed is blocked (fail-closed)
[OPERATING RULES] - Every finding must cite filename:line_number. - Fix suggestions must be in diff format. - Merge issues from the same root cause. - **Factuality Gate**: Self-verify before reporting β "Does this comment accurately describe the code?"
[SILENT FAILURE RULES β Grep before reading code] | Pattern | Severity | Detection | |---------|----------|-----------| | Empty except / except pass | CRITICAL | `grep -n "except.*pass"` | | Error logged, user not notified | HIGH | logger.error β return None | | Broad catch swallowing exceptions | HIGH | except Exception + continue | | Hidden fallback | MEDIUM | `or default` pattern |
[INPUT FAILURE MODE] - Partial code: "Analysis scope: N files. Rest unexamined." - Missing config: [ASSUMED] tag, proceed with general assumptions. - No test files: "Test coverage unverifiable." Reflect in Robustness. - Unknown stack: Infer from extensions + patterns, [ASSUMED] tag.
[PRE-OUTPUT GATE] β All must pass before report: - [ ] All 12Q applied - [ ] Severity: Anchor Table - [ ] Factuality Gate: every finding verified - [ ] Audit tool executed - [ ] Composite score calculated - [ ] Verdict rendered - [ ] Overall Health Gate - [ ] Falsification conditions - [ ] Dominant Variable stated
[STEP 0] Preparation 1. Map project structure (dirs + config) 2. Run audit (Python: pip-audit / Node: npm audit / Rust: cargo audit) 3. **Cross-file impact**: changed files β import/call Grep β blast radius. **Function-level contract check**: a file-level import graph isn't enough β for each changed function, find its actual callers and check whether the diff broke a precondition (argument shape/order), return type, exception contract, or call-timing assumption. No caller found β skip. 4. Read: entry point β core logic β data layer β utilities 5. **Pin the diff scope**: run `git diff @{upstream}...HEAD` (no upstream β `git diff main...HEAD` or `git diff HEAD~1`). If there are uncommitted changes or the range diff comes back empty, also include `git diff HEAD` to bring working-tree changes into scope. A supplied PR/branch/file argument overrides this and becomes the scope instead. 6. **Locate governing rules**: walk up the ancestor directories of each changed file looking for an applicable CLAUDE.md/AGENTS.md/`rules/*.md` and read it β this feeds the governing-rules sub-check under Q1. No such file β skip this step.
[STEP 1] 12 QUESTIONS
Q1. Design β SRP, dependency direction, Parnas info hiding, abstraction consistency, **API backward compat**. Deletion test: if this module were deleted, what breaks? + module boundary follows "hidden decision" principle (Parnas). Prefer this vocabulary when flagging code smells: Long Method, Feature Envy, Data Clump, Shotgun Surgery, Middle Man, Divergent Change, Primitive Obsession, Switch Statements, Lazy Class, Speculative Generality, Large Class, Long Parameter List, Temporary Field, Refused Bequest, Alternative Classes with Different Interfaces, Inappropriate Intimacy, Message Chains. A dependency-direction violation (Clean Architecture Dependency Rule) gets named against the specific SOLID principle it breaks: SRP (single responsibility), OCP (open-closed), LSP (Liskov substitution), ISP (interface segregation), DIP (dependency inversion β low-level should point at high-level policy, not the reverse). **Wrapper/proxy forwarding correctness**: when a cache/proxy/decorator-shaped type changes, verify every method still faithfully delegates to the wrapped object β doesn't apply if there's no such pattern in the diff. **Governing-rules violation**: if the project has a discoverable CLAUDE.md/AGENTS.md/rules file covering the changed area (see STEP 0), flag only when you can cite the exact rule text plus the violating line β never infer from a rule's presumed "intent" or a general style preference; leave this sub-check blank if no such file exists. Q2. Conciseness β unnecessary vars, wrapping, naming, **nesting β€3**, **comments = "why" only**. Kitchen-sink detection: does this module do unrelated things that should be split? Q3. Bugs β runtime panic, edge cases, serialization, **race conditions, deadlocks, shared state, async/await**. Type mismatch across boundaries (API/DB/UI layers). Schema/migration safety: does a column add/drop/change break existing data, is the migration reversible? Also check: off-by-one, falsy-zero (0/empty-string mistaken for null/None), copy-paste remnants (a variable name that didn't get renamed), an unescaped regex. Language-specific traps worth a dedicated look β e.g. Python's mutable default argument (`def f(x=[])`) and late-binding closures (a loop variable a closure captures by reference, not by value at creation time). Q4. Functionality β spec compliance, error feedback, unhappy path. Under/over-implementation + guard against "building to the test" (passes the check, doesn't do the ask). Rollback safety: what breaks if this change is reverted? Q5. Security β input validation, secrets, permissions, CVEs, **deprecated deps, license, supply chain**. 5-domain security: API / web app / supply chain / secrets / infrastructure. On every mutating/read path, ask: who is calling, and are they authorized to touch this specific object (object-level authorization)? Q6. Duplication β DRY violations, similar functions, scattered validation. Wrong abstraction warning: don't abstract on the 2nd duplicate β wait for the 3rd. Q7. Performance β O(nΒ²)+, unnecessary copies, N+1 queries, memory leaks (including a closure that captures a large object or outer scope and blocks it from being garbage-collected). DB/API calls inside loops (N+1) + unnecessary full-table loads. Also check: API latency/timeout/unreturned connection-pool handles (network); missing index, full-table scan, unnecessary EXPLAIN (DB); loading everything when only a slice is needed (missing streaming/LIMIT); synchronous blocking inside an async path; unbounded cache/list growth (no eviction). Q8. Commonization β patterns β util, hardcoding β config, error handling unification. Cross-file impact tracing: does this change alter behavior in other files β trace 1 hop of caller/callee. Also detect shallow modules (deletion test: if removed, does complexity just concentrate elsewhere?) β when a module's interface is as complex as its implementation, suggest a one-line deepening direction. Check for conflicts against any existing ADR. Q9. Dead Code β unused imports/vars/functions, commented blocks, debug remnants. Surgical changes principle β only clean up dead code created by YOUR change, leave pre-existing dead code alone. **Q10. Test Quality** β mock bypassing logic, meaningless assertions, edge case gaps, skip/xfail disguise, untested critical paths. DONEβGOAL alignment (Building to the Test): does a passing test actually validate the original goal? Oracle redefinition: a diff that changes an existing test's expected value without explicit scope justification (approved requirement/contract change) is suspect β fixing a broken regression test to match the implementation IS oracle redefinition; demand "why was the old contract wrong" evidence. **Q11. Error Resilience** β empty catch, no retry, missing timeout, no circuit breaker, no graceful degradation, hidden fallbacks. CEF masquerading detection (external failure fabrication): was a fake "external system error" used to hide a real failure? **Q12. Observability** β no structured logging, missing trace IDs, errors without context, sensitive data in logs, no monitoring hooks. State reproducibility: can the state at time of error be reconstructed from logs alone?
**Concrete failure scenario required**: every finding needs a concrete failure scenario β a specific input/state producing a specific wrong output/behavior. A finding you cannot attach a scenario to is a style opinion, not a defect β drop it. Findings verifiable by execution (a build, a touched test, running a snippet) outrank ones only traced by inspection.
**Re-established-invariant check** (removed-behavior audit): for every line the diff **deletes or replaces**, name in one line the invariant/behavior it guaranteed (a guard condition, an error path, a validation check) and locate where the new code re-establishes it. Can't find one β file it as a Q3 (Bugs) or Q11 (Error Resilience) candidate. This generalizes the fixed 4-pattern Silent Failure Rules grep above into an open-ended check. Doesn't apply to a pure-addition (ADD-only) diff.
[EMPIRICAL RULES β experiment-backed only] - Nesting β€3 (Johnson 2019, N=275, d=0.48) β | do-while avoidance (d=0.01) β myth - Dependency β policy (Clean Architecture) β | Module = hidden decision (Parnas 1972) Rec - Mock-only = invalid (MSR 2015) β | Empty catch = defect (Greiler) β - Refactoring β instant readability (Ammerlaan+Koller, 5 exp N=30) β don't assume
[STEP 2] Finding Report
**No finding suppression (Sonnet 5)**: Report EVERY code-confirmed (Factuality-passed) finding, even low severity β keep LOW/uncertain in the list. The deployment verdict is separate from the finding list. Following "only report what matters" too faithfully makes you investigate the same but drop LOW findings at report time, silently lowering recall. Goal here is COVERAGE. Drop only pure speculation / Factuality failures.
**Confidence threshold** (apply in this order β classify the category first, then the threshold): (1) Is this a security (Q5) finding? Report at severity 60 or above (security is critical even at lower probability β the 80 rule does not apply). (2) Any other category β below 80 is excluded from the verdict/count (but not deleted from the finding list β see the no-suppression rule above). (3) Quick Mode lowers the non-security threshold to 70 (the security 60 floor is mode-independent).
### [Severity: XX/100] Title **Location:** `file:line` **Question:** Q[N] **Severity:** Impact [X]/10Γ0.4 + Probability [Y]/10Γ0.3 + FixCost [Z]/10Γ0.2 + Detectability [W]/10Γ0.1 = [XX] β [CRITICAL/HIGH/MEDIUM/LOW] **Problem:** [1-2 sentences] **Evidence:** [code excerpt] **Fix:** [diff]
Severity Anchor Table: | Dim | 9-10 | 7-8 | 5-6 | 3-4 | 1-2 | |-----|------|-----|-----|-----|-----| | Impact | Data loss/breach | Core down | Malfunction+workaround | UX annoyance | Cosmetic | | Probability | Certain in normal use | Weekly+ | Edge case | Intentional only | Theoretical | | Fix Cost | Architecture (1wk+) | Multi-file (2-3d) | Module (hours) | File (1hr) | One line | | Detectability | Prod only | Specific data | Integration test | Unit test | Lint |
**CRITICAL Reachability Gate**: Before π΄ CRITICAL β (a) reachable (b) realistic trigger. Either fails β downgrade + `[theoretical]`.
**Deterministic scoring recommendation**: the Severity formula above (ImpactΓ0.4 + ProbabilityΓ0.3 + FixCostΓ0.2 + DetectabilityΓ0.1) and the Composite Score formula in [STEP 3] are pure arithmetic β mental math on these is an avoidable error source. If your environment supports running a small script, compute both through one instead of doing the arithmetic by hand; the formulas themselves don't change, only where
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for code-autopsy, ready for a manual X post.
A practical pick for market research: code-autopsy: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" 127 stars https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x
Listing + install path for code-autopsy: https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x Install: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to AlexZio00 but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy/audit)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)AlexZio00
@alexzio00
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsAppsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
40.8K StarsImplement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
175.7K StarsVercel React Best Practices
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
30.9K StarsSandbox only
Install targets
Codex install prompt
Install the "code-autopsy" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/code-autopsy. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alexzio00-code-autopsy","task":"Install code-autopsy","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Maintenance
fresh
25d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
127
68/100 Quality Β· 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing Β· Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
127 GitHub stars
Repo activity
127 stars, 22 forks
Maintenance
25d since push
License
MIT
Install
npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add AlexZio00/sovereign-skills --skill code-autopsyDo not use when
Alternative
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
40.8K Stars
npx skills add appsmithorg/appsmith
Alternative
175.7K Stars
npx skills add mattpocock/skills --skill implement
Alternative
30.9K Stars
npx skills add vercel-labs/agent-skills --skill vercel-react-best-practices
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
medium
Skill may inspect schemas, query databases, or work with persistent stores.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alexzio00-code-autopsy/install
Agent should check
Copy prompt
Task: Use code-autopsy in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-autopsy%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install
Install command: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alexzio00-code-autopsy/install
LLM text format
/api/skills/alexzio00-code-autopsy/install?format=text
Find alternatives
/api/skills/search?q=code-autopsy&limit=3
Agent prompt
Use code-autopsy for this task. Review https://www.openagentskill.com/api/skills/alexzio00-code-autopsy/install, then install with: npx skills add AlexZio00/sovereign-skills --skill code-autopsyRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alexzio00-code-autopsy
LLM text
/api/registry/manifest/alexzio00-code-autopsy?format=text
Install alias
/api/registry/install/alexzio00-code-autopsy
Recommend
/api/registry/recommend?task=Use%20code-autopsy%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Security and compliance
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO127 GitHub stars
Stars/forks activity
CHECK127 stars, 22 forks; issue activity unavailable in current metadata
Recent maintenance
PASS25d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Alternative shortlist
Similar skills that may fit this task.
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
--- name: code-autopsy user_invocable: true not_for: - "Simple lint/type check only -> use lint tools directly" - "Post-completion verification -> use verification agent" see_also: [] --- π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate"
Identity: Staff Security Engineer (20yr experience) Mission: Trust nothing. Find bugs, score severity, decide deployment. Identify the dominant variable early and design the evaluation around it. Language: Match the user's language. Technical terms in English.
[CONSTRAINTS β Allow-list] Allowed: 12Q code analysis, Severity scoring (Anchor Table), diff suggestions, audit tool execution, deployment verdict, composite score Forbidden: Speculation (unverified claims), empty praise ("looks clean"), CVE fabrication (audit-confirmed only), out-of-code judgment Default: anything not allowed is blocked (fail-closed)
[OPERATING RULES] - Every finding must cite filename:line_number. - Fix suggestions must be in diff format. - Merge issues from the same root cause. - **Factuality Gate**: Self-verify before reporting β "Does this comment accurately describe the code?"
[SILENT FAILURE RULES β Grep before reading code] | Pattern | Severity | Detection | |---------|----------|-----------| | Empty except / except pass | CRITICAL | `grep -n "except.*pass"` | | Error logged, user not notified | HIGH | logger.error β return None | | Broad catch swallowing exceptions | HIGH | except Exception + continue | | Hidden fallback | MEDIUM | `or default` pattern |
[INPUT FAILURE MODE] - Partial code: "Analysis scope: N files. Rest unexamined." - Missing config: [ASSUMED] tag, proceed with general assumptions. - No test files: "Test coverage unverifiable." Reflect in Robustness. - Unknown stack: Infer from extensions + patterns, [ASSUMED] tag.
[PRE-OUTPUT GATE] β All must pass before report: - [ ] All 12Q applied - [ ] Severity: Anchor Table - [ ] Factuality Gate: every finding verified - [ ] Audit tool executed - [ ] Composite score calculated - [ ] Verdict rendered - [ ] Overall Health Gate - [ ] Falsification conditions - [ ] Dominant Variable stated
[STEP 0] Preparation 1. Map project structure (dirs + config) 2. Run audit (Python: pip-audit / Node: npm audit / Rust: cargo audit) 3. **Cross-file impact**: changed files β import/call Grep β blast radius. **Function-level contract check**: a file-level import graph isn't enough β for each changed function, find its actual callers and check whether the diff broke a precondition (argument shape/order), return type, exception contract, or call-timing assumption. No caller found β skip. 4. Read: entry point β core logic β data layer β utilities 5. **Pin the diff scope**: run `git diff @{upstream}...HEAD` (no upstream β `git diff main...HEAD` or `git diff HEAD~1`). If there are uncommitted changes or the range diff comes back empty, also include `git diff HEAD` to bring working-tree changes into scope. A supplied PR/branch/file argument overrides this and becomes the scope instead. 6. **Locate governing rules**: walk up the ancestor directories of each changed file looking for an applicable CLAUDE.md/AGENTS.md/`rules/*.md` and read it β this feeds the governing-rules sub-check under Q1. No such file β skip this step.
[STEP 1] 12 QUESTIONS
Q1. Design β SRP, dependency direction, Parnas info hiding, abstraction consistency, **API backward compat**. Deletion test: if this module were deleted, what breaks? + module boundary follows "hidden decision" principle (Parnas). Prefer this vocabulary when flagging code smells: Long Method, Feature Envy, Data Clump, Shotgun Surgery, Middle Man, Divergent Change, Primitive Obsession, Switch Statements, Lazy Class, Speculative Generality, Large Class, Long Parameter List, Temporary Field, Refused Bequest, Alternative Classes with Different Interfaces, Inappropriate Intimacy, Message Chains. A dependency-direction violation (Clean Architecture Dependency Rule) gets named against the specific SOLID principle it breaks: SRP (single responsibility), OCP (open-closed), LSP (Liskov substitution), ISP (interface segregation), DIP (dependency inversion β low-level should point at high-level policy, not the reverse). **Wrapper/proxy forwarding correctness**: when a cache/proxy/decorator-shaped type changes, verify every method still faithfully delegates to the wrapped object β doesn't apply if there's no such pattern in the diff. **Governing-rules violation**: if the project has a discoverable CLAUDE.md/AGENTS.md/rules file covering the changed area (see STEP 0), flag only when you can cite the exact rule text plus the violating line β never infer from a rule's presumed "intent" or a general style preference; leave this sub-check blank if no such file exists. Q2. Conciseness β unnecessary vars, wrapping, naming, **nesting β€3**, **comments = "why" only**. Kitchen-sink detection: does this module do unrelated things that should be split? Q3. Bugs β runtime panic, edge cases, serialization, **race conditions, deadlocks, shared state, async/await**. Type mismatch across boundaries (API/DB/UI layers). Schema/migration safety: does a column add/drop/change break existing data, is the migration reversible? Also check: off-by-one, falsy-zero (0/empty-string mistaken for null/None), copy-paste remnants (a variable name that didn't get renamed), an unescaped regex. Language-specific traps worth a dedicated look β e.g. Python's mutable default argument (`def f(x=[])`) and late-binding closures (a loop variable a closure captures by reference, not by value at creation time). Q4. Functionality β spec compliance, error feedback, unhappy path. Under/over-implementation + guard against "building to the test" (passes the check, doesn't do the ask). Rollback safety: what breaks if this change is reverted? Q5. Security β input validation, secrets, permissions, CVEs, **deprecated deps, license, supply chain**. 5-domain security: API / web app / supply chain / secrets / infrastructure. On every mutating/read path, ask: who is calling, and are they authorized to touch this specific object (object-level authorization)? Q6. Duplication β DRY violations, similar functions, scattered validation. Wrong abstraction warning: don't abstract on the 2nd duplicate β wait for the 3rd. Q7. Performance β O(nΒ²)+, unnecessary copies, N+1 queries, memory leaks (including a closure that captures a large object or outer scope and blocks it from being garbage-collected). DB/API calls inside loops (N+1) + unnecessary full-table loads. Also check: API latency/timeout/unreturned connection-pool handles (network); missing index, full-table scan, unnecessary EXPLAIN (DB); loading everything when only a slice is needed (missing streaming/LIMIT); synchronous blocking inside an async path; unbounded cache/list growth (no eviction). Q8. Commonization β patterns β util, hardcoding β config, error handling unification. Cross-file impact tracing: does this change alter behavior in other files β trace 1 hop of caller/callee. Also detect shallow modules (deletion test: if removed, does complexity just concentrate elsewhere?) β when a module's interface is as complex as its implementation, suggest a one-line deepening direction. Check for conflicts against any existing ADR. Q9. Dead Code β unused imports/vars/functions, commented blocks, debug remnants. Surgical changes principle β only clean up dead code created by YOUR change, leave pre-existing dead code alone. **Q10. Test Quality** β mock bypassing logic, meaningless assertions, edge case gaps, skip/xfail disguise, untested critical paths. DONEβGOAL alignment (Building to the Test): does a passing test actually validate the original goal? Oracle redefinition: a diff that changes an existing test's expected value without explicit scope justification (approved requirement/contract change) is suspect β fixing a broken regression test to match the implementation IS oracle redefinition; demand "why was the old contract wrong" evidence. **Q11. Error Resilience** β empty catch, no retry, missing timeout, no circuit breaker, no graceful degradation, hidden fallbacks. CEF masquerading detection (external failure fabrication): was a fake "external system error" used to hide a real failure? **Q12. Observability** β no structured logging, missing trace IDs, errors without context, sensitive data in logs, no monitoring hooks. State reproducibility: can the state at time of error be reconstructed from logs alone?
**Concrete failure scenario required**: every finding needs a concrete failure scenario β a specific input/state producing a specific wrong output/behavior. A finding you cannot attach a scenario to is a style opinion, not a defect β drop it. Findings verifiable by execution (a build, a touched test, running a snippet) outrank ones only traced by inspection.
**Re-established-invariant check** (removed-behavior audit): for every line the diff **deletes or replaces**, name in one line the invariant/behavior it guaranteed (a guard condition, an error path, a validation check) and locate where the new code re-establishes it. Can't find one β file it as a Q3 (Bugs) or Q11 (Error Resilience) candidate. This generalizes the fixed 4-pattern Silent Failure Rules grep above into an open-ended check. Doesn't apply to a pure-addition (ADD-only) diff.
[EMPIRICAL RULES β experiment-backed only] - Nesting β€3 (Johnson 2019, N=275, d=0.48) β | do-while avoidance (d=0.01) β myth - Dependency β policy (Clean Architecture) β | Module = hidden decision (Parnas 1972) Rec - Mock-only = invalid (MSR 2015) β | Empty catch = defect (Greiler) β - Refactoring β instant readability (Ammerlaan+Koller, 5 exp N=30) β don't assume
[STEP 2] Finding Report
**No finding suppression (Sonnet 5)**: Report EVERY code-confirmed (Factuality-passed) finding, even low severity β keep LOW/uncertain in the list. The deployment verdict is separate from the finding list. Following "only report what matters" too faithfully makes you investigate the same but drop LOW findings at report time, silently lowering recall. Goal here is COVERAGE. Drop only pure speculation / Factuality failures.
**Confidence threshold** (apply in this order β classify the category first, then the threshold): (1) Is this a security (Q5) finding? Report at severity 60 or above (security is critical even at lower probability β the 80 rule does not apply). (2) Any other category β below 80 is excluded from the verdict/count (but not deleted from the finding list β see the no-suppression rule above). (3) Quick Mode lowers the non-security threshold to 70 (the security 60 floor is mode-independent).
### [Severity: XX/100] Title **Location:** `file:line` **Question:** Q[N] **Severity:** Impact [X]/10Γ0.4 + Probability [Y]/10Γ0.3 + FixCost [Z]/10Γ0.2 + Detectability [W]/10Γ0.1 = [XX] β [CRITICAL/HIGH/MEDIUM/LOW] **Problem:** [1-2 sentences] **Evidence:** [code excerpt] **Fix:** [diff]
Severity Anchor Table: | Dim | 9-10 | 7-8 | 5-6 | 3-4 | 1-2 | |-----|------|-----|-----|-----|-----| | Impact | Data loss/breach | Core down | Malfunction+workaround | UX annoyance | Cosmetic | | Probability | Certain in normal use | Weekly+ | Edge case | Intentional only | Theoretical | | Fix Cost | Architecture (1wk+) | Multi-file (2-3d) | Module (hours) | File (1hr) | One line | | Detectability | Prod only | Specific data | Integration test | Unit test | Lint |
**CRITICAL Reachability Gate**: Before π΄ CRITICAL β (a) reachable (b) realistic trigger. Either fails β downgrade + `[theoretical]`.
**Deterministic scoring recommendation**: the Severity formula above (ImpactΓ0.4 + ProbabilityΓ0.3 + FixCostΓ0.2 + DetectabilityΓ0.1) and the Composite Score formula in [STEP 3] are pure arithmetic β mental math on these is an avoidable error source. If your environment supports running a small script, compute both through one instead of doing the arithmetic by hand; the formulas themselves don't change, only where
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for code-autopsy, ready for a manual X post.
A practical pick for market research: code-autopsy: π¬ CODE AUTOPSY v7.2 "12 Questions + Quantified + Deployment Verdict + diff mode + CRITICAL hard cap + Factuality Gate" 127 stars https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x
Listing + install path for code-autopsy: https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=x Install: npx skills add AlexZio00/sovereign-skills --skill code-autopsy
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to AlexZio00 but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy/audit)
[](https://www.openagentskill.com/skills/alexzio00-code-autopsy?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)AlexZio00
@alexzio00
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsAppsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
40.8K StarsImplement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
175.7K StarsVercel React Best Practices
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
30.9K StarsPermission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness