Agent skill

Adversarial Reviewer

by 302ai in 302ai/302-AI-Studio

Adversarial code review that breaks the self-review monoculture.

MITAuto-check passedDevelopment

Install Adversarial Reviewer

skills CLI
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .claude/skills/adversarial-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
adversarial-reviewer
GitHub stars
132
Used in
1 other repo
Token cost
~3k tokens
SKILL.md length
1,461 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Adversarial code review that breaks the self-review monoculture.

  • Works in 4 steps: Gather the Changes → Read the Full Context → Run All Three Personas → …
  • You want a genuinely critical review of recent changes
  • SKILL.md covers Description, Features, Usage and Examples, plus 10 more sections
  • Calls git

What it does

Adversarial Reviewer is an agent skill from 302ai/302-AI-Studio. Adversarial code review that breaks the self-review monoculture. Use when you want a genuinely critical review of recent changes, before merging a PR, or when you suspect Claude is being too agreeable about code quality. Forces perspective shifts through hostile reviewer personas that catch blind spots the author's mental model shares with the reviewer.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Code quality. It works with Git. The licence is MIT.

When your agent uses it

  • You want a genuinely critical review of recent changes
  • Before merging a PR
  • You suspect Claude is being too agreeable about code quality

Example prompts

  • “/adversarial-reviewer”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather the Changes
  2. Read the Full Context
  3. Run All Three Personas
  4. Deduplicate and Synthesize

What it can do on your machine

Read from SKILL.md and the folder at commit 8b11163. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adversarial Reviewer loads about 3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,461 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 302ai/302-AI-Studio at commit 8b11163, republished under its MIT licence (© 302ai). 1,461 words, ~2,962 tokens.

Download SKILL.mdSave it as .claude/skills/adversarial-reviewer/SKILL.md (or your agent's skills folder).
name
adversarial-reviewer
description
Adversarial code review that breaks the self-review monoculture. Use when you want a genuinely critical review of recent changes, before merging a PR, or when you suspect Claude is being too agreeable about code quality. Forces perspective shifts through hostile reviewer personas that catch blind spots the author's mental model shares with the reviewer.
tier
STANDARD
category
Engineering / Code Quality
dependencies
None (prompt-only, no external tools required)
author
ekreloff
version
1.0.0
license
MIT

Adversarial Code Reviewer

Description

Adversarial code review skill that forces genuine perspective shifts through three hostile reviewer personas (Saboteur, New Hire, Security Auditor). Each persona MUST find at least one issue — no "LGTM" escapes. Findings are severity-classified and cross-promoted when caught by multiple personas.

Features

  • Three adversarial personas — Saboteur (production breaks), New Hire (maintainability), Security Auditor (OWASP-informed)
  • Mandatory findings — Each persona must surface at least one issue, eliminating rubber-stamp reviews
  • Severity promotion — Issues caught by 2+ personas are promoted one severity level
  • Self-review trap breaker — Concrete techniques to overcome shared mental model blind spots
  • Structured verdicts — BLOCK / CONCERNS / CLEAN with clear merge guidance

Usage

/adversarial-review              # Review staged/unstaged changes
/adversarial-review --diff HEAD~3  # Review last 3 commits
/adversarial-review --file src/auth.ts  # Review a specific file

Examples

Example: Reviewing a PR Before Merge
/adversarial-review --diff main...HEAD

Produces a structured report with findings from all three personas, deduplicated and severity-ranked, ending with a BLOCK/CONCERNS/CLEAN verdict.

Problem This Solves

When Claude reviews code it wrote (or code it just read), it shares the same mental model, assumptions, and blind spots as the author. This produces "Looks good to me" reviews on code that a fresh human reviewer would flag immediately. Users report this as one of the top frustrations with AI-assisted development.

This skill forces a genuine perspective shift by requiring you to adopt adversarial personas — each with different priorities, different fears, and different definitions of "bad code."

Table of Contents

  1. Quick Start
  2. Review Workflow
  3. The Three Personas
  4. Severity Classification
  5. Output Format
  6. Anti-Patterns
  7. When to Use This

Quick Start

/adversarial-review              # Review staged/unstaged changes
/adversarial-review --diff HEAD~3  # Review last 3 commits
/adversarial-review --file src/auth.ts  # Review a specific file

Review Workflow

Step 1: Gather the Changes

Determine what to review based on invocation:

  • No arguments: Run git diff (unstaged) + git diff --cached (staged). If both empty, run git diff HEAD~1 (last commit).
  • --diff <ref>: Run git diff <ref>.
  • --file <path>: Read the entire file. Focus review on the full file rather than just changes.

If no changes are found, stop and report: "Nothing to review."

Step 2: Read the Full Context

For every file in the diff:

  1. Read the full file (not just the changed lines) — bugs hide in how new code interacts with existing code.
  2. Identify the purpose of the change: bug fix, new feature, refactor, config change, test.
  3. Note any project conventions from CLAUDE.md, .editorconfig, linting configs, or existing patterns.
Step 3: Run All Three Personas

Execute each persona sequentially. Each persona MUST produce at least one finding. If a persona finds nothing wrong, it has not looked hard enough — go back and look again.

IMPORTANT: Do not soften findings. Do not hedge. Do not say "this might be fine but..." — either it's a problem or it isn't. Be direct.

Step 4: Deduplicate and Synthesize

After all three personas have reported:

  1. Merge duplicate findings (same issue caught by multiple personas).
  2. Promote findings caught by 2+ personas to the next severity level.
  3. Produce the final structured output.

The Three Personas

Persona 1: The Saboteur

Mindset: "I am trying to break this code in production."

Priorities:

  • Input that was never validated
  • State that can become inconsistent
  • Concurrent access without synchronization
  • Error paths that swallow exceptions or return misleading results
  • Assumptions about data format, size, or availability that could be violated
  • Off-by-one errors, integer overflow, null/undefined dereferences
  • Resource leaks (file handles, connections, subscriptions, listeners)

Review Process:

  1. For each function/method changed, ask: "What is the worst input I could send this?"
  2. For each external call, ask: "What if this fails, times out, or returns garbage?"
  3. For each state mutation, ask: "What if this runs twice? Concurrently? Never?"
  4. For each conditional, ask: "What if neither branch is correct?"

You MUST find at least one issue. If the code is genuinely bulletproof, note the most fragile assumption it relies on.


Persona 2: The New Hire

Mindset: "I just joined this team. I need to understand and modify this code in 6 months with zero context from the original author."

Priorities:

  • Names that don't communicate intent (what does data mean? what does process() do?)
  • Logic that requires reading 3+ other files to understand
  • Magic numbers, magic strings, unexplained constants
  • Functions doing more than one thing (the name says X but it also does Y and Z)
  • Missing type information that forces the reader to trace through call chains
  • Inconsistency with surrounding code style or project conventions
  • Tests that test implementation details instead of behavior
  • Comments that describe what (redundant) instead of why (useful)

Review Process:

  1. Read each changed function as if you've never seen the codebase. Can you understand what it does from the name, parameters, and body alone?
  2. Trace one code path end-to-end. How many files do you need to open?
  3. Check: would a new contributor know where to add a similar feature?
  4. Look for "the author knew something the reader won't" — implicit knowledge baked into the code.

You MUST find at least one issue. If the code is crystal clear, note the most likely point of confusion for a newcomer.


Show full SKILL.md (650 more words)Show less
Persona 3: The Security Auditor

Mindset: "This code will be attacked. My job is to find the vulnerability before an attacker does."

OWASP-Informed Checklist:

CategoryWhat to Look For
InjectionSQL, NoSQL, OS command, LDAP — any place user input reaches a query or command without parameterization
Broken AuthHardcoded credentials, missing auth checks on new endpoints, session tokens in URLs or logs
Data ExposureSensitive data in error messages, logs, or API responses; missing encryption at rest or in transit
Insecure DefaultsDebug mode left on, permissive CORS, wildcard permissions, default passwords
Missing Access ControlIDOR (can user A access user B's data?), missing role checks, privilege escalation paths
Dependency RiskNew dependencies with known CVEs, pinned to vulnerable versions, unnecessary transitive dependencies
SecretsAPI keys, tokens, passwords in code, config, or comments — even "temporary" ones

Review Process:

  1. Identify every trust boundary the code crosses (user input, API calls, database, file system, environment variables).
  2. For each boundary: is input validated? Is output sanitized? Is the principle of least privilege followed?
  3. Check: could an authenticated user escalate privileges through this change?
  4. Check: does this change expose any new attack surface?

You MUST find at least one issue. If the code has no security surface, note the closest thing to a security-relevant assumption.

Severity Classification

SeverityDefinitionAction Required
CRITICALWill cause data loss, security breach, or production outage. Must fix before merge.Block merge.
WARNINGLikely to cause bugs in edge cases, degrade performance, or confuse future maintainers. Should fix before merge.Fix or explicitly accept risk with justification.
NOTEStyle issue, minor improvement opportunity, or documentation gap. Nice to fix.Author's discretion.

Promotion rule: A finding flagged by 2+ personas is promoted one level (NOTE becomes WARNING, WARNING becomes CRITICAL).

Output Format

Structure your review as follows:

markdown
## Adversarial Review: [brief description of what was reviewed]

**Scope:** [files reviewed, lines changed, type of change]
**Verdict:** BLOCK / CONCERNS / CLEAN

### Critical Findings
[If any — these block the merge]

### Warnings
[Should-fix items]

### Notes
[Nice-to-fix items]

### Summary
[2-3 sentences: what's the overall risk profile? What's the single most important thing to fix?]

Verdict definitions:

  • BLOCK — 1+ CRITICAL findings. Do not merge until resolved.
  • CONCERNS — No criticals but 2+ warnings. Merge at your own risk.
  • CLEAN — Only notes. Safe to merge.

Anti-Patterns

What This Skill is NOT
Anti-PatternWhy It's Wrong
"LGTM, no issues found"If you found nothing, you didn't look hard enough. Every change has at least one risk, assumption, or improvement opportunity.
Cosmetic-only findingsReporting only whitespace/formatting while missing a null dereference is worse than no review at all. Substance first, style second.
Pulling punches"This might possibly be a minor concern..." — No. Be direct. "This will throw a NullPointerException when user is undefined."
Restating the diff"This function was added to handle authentication" is not a finding. What's WRONG with how it handles authentication?
Ignoring test gapsNew code without tests is a finding. Always. Tests are not optional.
Reviewing only the changed linesBugs live in the interaction between new code and existing code. Read the full file.
The Self-Review Trap

You are likely reviewing code you just wrote or just read. Your brain (weights) formed the same mental model that produced this code. You will naturally think it looks correct because it matches your expectations.

To break this pattern:

  1. Read the code bottom-up (start from the last function, work backward).
  2. For each function, state its contract before reading the body. Does the body match?
  3. Assume every variable could be null/undefined until proven otherwise.
  4. Assume every external call will fail.
  5. Ask: "If I deleted this change entirely, what would break?" — if the answer is "nothing," the change might be unnecessary.

When to Use This

  • Before merging any PR — especially self-authored PRs with no human reviewer
  • After a long coding session — fatigue produces blind spots; this skill compensates
  • When Claude said "looks good" — if you got an easy approval, run this for a second opinion
  • On security-sensitive code — auth, payments, data access, API endpoints
  • When something "feels off" — trust that instinct and run an adversarial review

Cross-References

  • Related: engineering-team/senior-security — deep security analysis
  • Related: engineering-team/code-reviewer — general code quality review
  • Complementary: ra-qm-team/ — quality management workflows

© 302ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/adversarial-reviewer of 302ai/302-AI-Studio.

Open the folder on GitHubat commit 8b11163

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in 302ai/302-AI-Studio, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Adversarial Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adversarial Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adversarial Reviewer this skill302ai/302-AI-Studio1321 repos~3kAutomated safety check: PassMIT
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
Feature-Level Code Reviewdataelement/bisheng12k—~1kAutomated safety check: PassApache-2.0
Two-Axis Code Reviewrengwu/wayfinder-maps137—~1.8kAutomated safety check: PassMIT
Code Revieweralirezarezvani/claude-code-tresor777—~1.8kAutomated safety check: PassMIT
Code ReviewerMageByte-Zero/spec-superflow8461 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Feature-Level Code Review

    dataelement/bisheng

    Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files.

    12k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Two-Axis Code Review

    rengwu/wayfinder-maps

    Reviews the changes since a commit, branch or tag along two separate axes: the repo's documented coding standards and fidelity to the originating spec or PRD.

    137 GitHub stars~1.8k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Reviewer

    MageByte-Zero/spec-superflow

    Review completed implementation batches for spec compliance and code quality.

    846 GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed

More from 302ai/302-AI-Studio

  • Electron

    302ai/302-AI-Studio

    Provides comprehensive guidance for Electron framework including main process, renderer process, IPC communication, window management, and desktop app development.

    132 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Comprehensive integration skill for building sites with SvelteKit 2, Svelte 5, and Tailwind CSS v4

    132 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Commit And PR

    302ai/302-AI-Studio

    A skill your agent uses whenever the user wants to commit changes and create a Pull Request (e.g., 'commit and PR', 'push my changes', 'create a PR').

    132 GitHub stars~700 tokensUpdated 1 mo ago
    Auto-check passed
  • Create GitHub Pull Request for feature request from specification file using pullrequesttemplate.md template.

    132 GitHub starsUsed in 1 repo~406 tokens
    Auto-check passed

Works with

Categories

Questions about Adversarial Reviewer

What does Adversarial Reviewer do?

Adversarial code review that breaks the self-review monoculture. Adversarial Reviewer is an agent skill from 302ai/302-AI-Studio. Adversarial code review that breaks the self-review monoculture.

When should I use Adversarial Reviewer?

Adversarial Reviewer fits situations like: you want a genuinely critical review of recent changes; before merging a PR; you suspect Claude is being too agreeable about code quality.

How do I install Adversarial Reviewer in Claude Code?

Run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a claude-code`. Or copy the skill folder (.agents/skills/adversarial-reviewer in 302ai/302-AI-Studio) into .claude/skills/adversarial-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Adversarial Reviewer in Codex?

Run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a codex`. Or copy the skill folder (.agents/skills/adversarial-reviewer in 302ai/302-AI-Studio) into .agents/skills/adversarial-reviewer in your project. Codex loads it when a task matches its description.

Can I use Adversarial Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adversarial-reviewer, .gemini/skills/adversarial-reviewer, .github/skills/adversarial-reviewer and .opencode/skills/adversarial-reviewer in your project.

What does Adversarial Reviewer need to run?

Going by SKILL.md and its folder, Adversarial Reviewer needs the command-line tools its instructions call (git).

Does Adversarial Reviewer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Adversarial Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Adversarial Reviewer use?

Adversarial Reviewer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adversarial Reviewer use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adversarial Reviewer?

Skills that share tags, products or a category with Adversarial Reviewer: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Feature-Level Code Review (dataelement/bisheng, 12k stars), Two-Axis Code Review (rengwu/wayfinder-maps, 137 stars) and Code Reviewer (alirezarezvani/claude-code-tresor, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adversarial Reviewer?

302ai (a GitHub organization) maintains it in 302ai/302-AI-Studio, which has 132 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 31, 2026.

Source: 302ai/302-AI-Studio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.