Qt C++ Code Review
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
Adversarial code review that breaks the self-review monoculture.
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .claude/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .claude/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .agents/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .agents/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .cursor/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .cursor/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/302ai/302-AI-Studio.git --path .agents/skills/adversarial-reviewer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .gemini/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .gemini/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .github/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .github/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 302ai/302-AI-Studio adversarial-reviewer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/302ai/302-AI-Studio.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/adversarial-reviewer .opencode/skills/adversarial-reviewer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "adversarial-reviewer" agent skill from https://github.com/302ai/302-AI-Studio/tree/master/.agents/skills/adversarial-reviewer into .opencode/skills/adversarial-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adversarial-reviewer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
adversarial-reviewerAdversarial code review that breaks the self-review monoculture.
Adversarial Reviewer is an agent skill from 302ai/302-AI-Studio. Adversarial code review that breaks the self-review monoculture. Use when you want a genuinely critical review of recent changes, before merging a PR, or when you suspect Claude is being too agreeable about code quality. Forces perspective shifts through hostile reviewer personas that catch blind spots the author's mental model shares with the reviewer.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review and Code quality. It works with Git. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8b11163. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Adversarial Reviewer loads about 3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,461 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 302ai/302-AI-Studio at commit 8b11163, republished under its MIT licence (© 302ai). 1,461 words, ~2,962 tokens.
.claude/skills/adversarial-reviewer/SKILL.md (or your agent's skills folder).Adversarial code review skill that forces genuine perspective shifts through three hostile reviewer personas (Saboteur, New Hire, Security Auditor). Each persona MUST find at least one issue — no "LGTM" escapes. Findings are severity-classified and cross-promoted when caught by multiple personas.
/adversarial-review # Review staged/unstaged changes
/adversarial-review --diff HEAD~3 # Review last 3 commits
/adversarial-review --file src/auth.ts # Review a specific file/adversarial-review --diff main...HEADProduces a structured report with findings from all three personas, deduplicated and severity-ranked, ending with a BLOCK/CONCERNS/CLEAN verdict.
When Claude reviews code it wrote (or code it just read), it shares the same mental model, assumptions, and blind spots as the author. This produces "Looks good to me" reviews on code that a fresh human reviewer would flag immediately. Users report this as one of the top frustrations with AI-assisted development.
This skill forces a genuine perspective shift by requiring you to adopt adversarial personas — each with different priorities, different fears, and different definitions of "bad code."
/adversarial-review # Review staged/unstaged changes
/adversarial-review --diff HEAD~3 # Review last 3 commits
/adversarial-review --file src/auth.ts # Review a specific fileDetermine what to review based on invocation:
git diff (unstaged) + git diff --cached (staged). If both empty, run git diff HEAD~1 (last commit).--diff <ref>: Run git diff <ref>.--file <path>: Read the entire file. Focus review on the full file rather than just changes.If no changes are found, stop and report: "Nothing to review."
For every file in the diff:
Execute each persona sequentially. Each persona MUST produce at least one finding. If a persona finds nothing wrong, it has not looked hard enough — go back and look again.
IMPORTANT: Do not soften findings. Do not hedge. Do not say "this might be fine but..." — either it's a problem or it isn't. Be direct.
After all three personas have reported:
Mindset: "I am trying to break this code in production."
Priorities:
Review Process:
You MUST find at least one issue. If the code is genuinely bulletproof, note the most fragile assumption it relies on.
Mindset: "I just joined this team. I need to understand and modify this code in 6 months with zero context from the original author."
Priorities:
data mean? what does process() do?)Review Process:
You MUST find at least one issue. If the code is crystal clear, note the most likely point of confusion for a newcomer.
Mindset: "This code will be attacked. My job is to find the vulnerability before an attacker does."
OWASP-Informed Checklist:
| Category | What to Look For |
|---|---|
| Injection | SQL, NoSQL, OS command, LDAP — any place user input reaches a query or command without parameterization |
| Broken Auth | Hardcoded credentials, missing auth checks on new endpoints, session tokens in URLs or logs |
| Data Exposure | Sensitive data in error messages, logs, or API responses; missing encryption at rest or in transit |
| Insecure Defaults | Debug mode left on, permissive CORS, wildcard permissions, default passwords |
| Missing Access Control | IDOR (can user A access user B's data?), missing role checks, privilege escalation paths |
| Dependency Risk | New dependencies with known CVEs, pinned to vulnerable versions, unnecessary transitive dependencies |
| Secrets | API keys, tokens, passwords in code, config, or comments — even "temporary" ones |
Review Process:
You MUST find at least one issue. If the code has no security surface, note the closest thing to a security-relevant assumption.
| Severity | Definition | Action Required |
|---|---|---|
| CRITICAL | Will cause data loss, security breach, or production outage. Must fix before merge. | Block merge. |
| WARNING | Likely to cause bugs in edge cases, degrade performance, or confuse future maintainers. Should fix before merge. | Fix or explicitly accept risk with justification. |
| NOTE | Style issue, minor improvement opportunity, or documentation gap. Nice to fix. | Author's discretion. |
Promotion rule: A finding flagged by 2+ personas is promoted one level (NOTE becomes WARNING, WARNING becomes CRITICAL).
Structure your review as follows:
## Adversarial Review: [brief description of what was reviewed]
**Scope:** [files reviewed, lines changed, type of change]
**Verdict:** BLOCK / CONCERNS / CLEAN
### Critical Findings
[If any — these block the merge]
### Warnings
[Should-fix items]
### Notes
[Nice-to-fix items]
### Summary
[2-3 sentences: what's the overall risk profile? What's the single most important thing to fix?]Verdict definitions:
| Anti-Pattern | Why It's Wrong |
|---|---|
| "LGTM, no issues found" | If you found nothing, you didn't look hard enough. Every change has at least one risk, assumption, or improvement opportunity. |
| Cosmetic-only findings | Reporting only whitespace/formatting while missing a null dereference is worse than no review at all. Substance first, style second. |
| Pulling punches | "This might possibly be a minor concern..." — No. Be direct. "This will throw a NullPointerException when user is undefined." |
| Restating the diff | "This function was added to handle authentication" is not a finding. What's WRONG with how it handles authentication? |
| Ignoring test gaps | New code without tests is a finding. Always. Tests are not optional. |
| Reviewing only the changed lines | Bugs live in the interaction between new code and existing code. Read the full file. |
You are likely reviewing code you just wrote or just read. Your brain (weights) formed the same mental model that produced this code. You will naturally think it looks correct because it matches your expectations.
To break this pattern:
engineering-team/senior-security — deep security analysisengineering-team/code-reviewer — general code quality reviewra-qm-team/ — quality management workflows© 302ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/adversarial-reviewer of 302ai/302-AI-Studio.
Open the folder on GitHubat commit 8b11163
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in 302ai/302-AI-Studio, which our catalogue first saw on October 7, 2026.
Adversarial Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Adversarial Reviewer this skill302ai/302-AI-Studio | 132 | 1 repos | ~3k | Automated safety check: Pass | MIT | |
| Qt C++ Code Reviewx-tools-author/x-tools | 1.1k | 2 repos | ~4.3k | Automated safety check: Pass | BSD-3-Clause | |
| Feature-Level Code Reviewdataelement/bisheng | 12k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Two-Axis Code Reviewrengwu/wayfinder-maps | 137 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Code Revieweralirezarezvani/claude-code-tresor | 777 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Code ReviewerMageByte-Zero/spec-superflow | 846 | 1 repos | ~1.5k | Automated safety check: Pass | MIT |
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
dataelement/bisheng
Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files.
rengwu/wayfinder-maps
Reviews the changes since a commit, branch or tag along two separate axes: the repo's documented coding standards and fidelity to the originating spec or PRD.
alirezarezvani/claude-code-tresor
Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.
MageByte-Zero/spec-superflow
Review completed implementation batches for spec compliance and code quality.
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
302ai/302-AI-Studio
Provides comprehensive guidance for Electron framework including main process, renderer process, IPC communication, window management, and desktop app development.
302ai/302-AI-Studio
Comprehensive integration skill for building sites with SvelteKit 2, Svelte 5, and Tailwind CSS v4
302ai/302-AI-Studio
A skill your agent uses whenever the user wants to commit changes and create a Pull Request (e.g., 'commit and PR', 'push my changes', 'create a PR').
302ai/302-AI-Studio
Create GitHub Pull Request for feature request from specification file using pullrequesttemplate.md template.
Works with
Categories
Adversarial code review that breaks the self-review monoculture. Adversarial Reviewer is an agent skill from 302ai/302-AI-Studio. Adversarial code review that breaks the self-review monoculture.
Adversarial Reviewer fits situations like: you want a genuinely critical review of recent changes; before merging a PR; you suspect Claude is being too agreeable about code quality.
Run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a claude-code`. Or copy the skill folder (.agents/skills/adversarial-reviewer in 302ai/302-AI-Studio) into .claude/skills/adversarial-reviewer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a codex`. Or copy the skill folder (.agents/skills/adversarial-reviewer in 302ai/302-AI-Studio) into .agents/skills/adversarial-reviewer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 302ai/302-AI-Studio --skill adversarial-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adversarial-reviewer, .gemini/skills/adversarial-reviewer, .github/skills/adversarial-reviewer and .opencode/skills/adversarial-reviewer in your project.
Going by SKILL.md and its folder, Adversarial Reviewer needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Adversarial Reviewer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Adversarial Reviewer: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Feature-Level Code Review (dataelement/bisheng, 12k stars), Two-Axis Code Review (rengwu/wayfinder-maps, 137 stars) and Code Reviewer (alirezarezvani/claude-code-tresor, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
302ai (a GitHub organization) maintains it in 302ai/302-AI-Studio, which has 132 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 31, 2026.
Source: 302ai/302-AI-Studio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.