Codex CLI
sundial-org/awesome-openclaw-skills
Use OpenAI Codex CLI for coding tasks. An agent skill from sundial-org/awesome-openclaw-skills.
Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install avelikiy/great_cto skeptical-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skeptical-triage .claude/skills/skeptical-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .claude/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install avelikiy/great_cto skeptical-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skeptical-triage .agents/skills/skeptical-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .agents/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install avelikiy/great_cto skeptical-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skeptical-triage .cursor/skills/skeptical-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .cursor/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/avelikiy/great_cto.git --path skills/skeptical-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install avelikiy/great_cto skeptical-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skeptical-triage .gemini/skills/skeptical-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .gemini/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install avelikiy/great_cto skeptical-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skeptical-triage .github/skills/skeptical-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .github/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add avelikiy/great_cto --skill skeptical-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install avelikiy/great_cto skeptical-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skeptical-triage .opencode/skills/skeptical-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skeptical-triage" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/skeptical-triage into .opencode/skills/skeptical-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skeptical-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skeptical-triageRuns a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.
A finding goes through three skeptical review rounds followed by an impartial arbiter that turns the votes into a confidence score. Round one asks whether the premise is true, for example whether an outside attacker can actually reach the flagged code path. Round two checks that every cited defense really exists by finding its implementation line with grep. Round three looks for angles the earlier rounds missed, such as error paths, race windows and test pollution.
Each round returns a small JSON record with a VALID, INVALID or UNCERTAIN verdict, its reasoning and the key fact it rests on, and later rounds see the earlier ones. A table says when to apply the pattern: P0 and P1 review findings, security audit results, flaky-test verdicts and architecture trade-off disputes. It is skipped for hard findings such as a secret committed to source or a confirmed CVE, and for advisory items. The price is a few extra model turns.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0e9df12. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepBashGlobFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skeptical Triage loads about 2.1k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 901 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Bash, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from avelikiy/great_cto at commit 0e9df12, republished under its MIT licence (© avelikiy). 901 words, ~2,101 tokens.
.claude/skills/skeptical-triage/SKILL.md (or your agent's skills folder).Filter false positives from multi-angle review, security audit, QA regression flags, or any high-stakes judgment before it turns into a blocker.
Three rounds of skeptical self-review + an impartial arbiter, with a confidence score from the vote.
| Caller | Finding type | Apply triage? |
|---|---|---|
/review | Angle 2/4/7/9 P0/P1 (security, SQL, privacy, concurrency) | Yes |
/review --deep | Any angle P0/P1 | Yes |
security-officer | CSO audit P0/P1 | Yes |
security-officer | Secret in source/git, confirmed CVE | No — hard finding |
qa-engineer | Flaky-test verdict (is this a regression or flake?) | Yes |
architect | ADR trade-off dispute (option A vs. B when both look reasonable) | Yes |
| Any | P2/advisory | No |
Run these sequentially. Each round sees prior reasoning. Arbiter sees all rounds.
Question: is the premise true?
Output: {round: 1, verdict: VALID|INVALID|UNCERTAIN, reasoning: "...", crux: "single key fact"}
Question: are claimed defenses real and sufficient?
Grep to find its actual implementation line.MAX_BUF_SIZE is not a verified bound — #define MAX_BUF_SIZE 64 is.If you cannot point to the line that enforces the defense, it does not exist.
Output: same JSON shape, with grep_used: true/false.
Question: what did Rounds 1-2 not consider?
Output: same JSON shape.
Input: all 3 rounds + original finding/question + source code.
Question: final call — which side has the stronger evidence?
verdict: VALID|INVALID (no UNCERTAIN — make the call).crux — the key fact the verdict turns on.Output:
{
"verdict": "VALID",
"crux": "memcpy at auth.c:142 copies network-controlled len bytes into 64-byte stack buffer with no bound check",
"reasoning": "Rounds 1 and 3 verified attacker reach; Round 2 found no size check in 50 LOC radius; arbiter confirms no caller clamps len."
}Burn these into every round's prompt:
#define / const declaration.confidence = valid_rounds_before_arbiter / 3100% (VVV) — 3/3 rounds VALID. Arbiter rubber-stamps unless it finds something brand-new.67% (VVI or VIV or IVV) — majority VALID. Arbiter breaks tie with new evidence.33% (IIV or IVI or VII) — majority INVALID. Arbiter usually confirms INVALID.0% (III) — 3/3 INVALID. Arbiter rarely overrides.Arbiter overrides the final verdict; confidence reflects the round vote for transparency. Record both in the output so humans can see where the arbiter diverged.
Once the arbiter returns:
| Arbiter verdict | Confidence | Severity action |
|---|---|---|
VALID | ≥ 50% | Keep original severity |
VALID | < 50% | Demote: P0→P1, P1→P2 |
INVALID | any | Remove from gate tally, record as [FILTERED] in report for audit |
UNCERTAIN (only if arbiter could not decide) | n/a | Keep original severity, flag for manual CTO review |
Every caller logs triage results to .great_cto/triage-log.jsonl (append-only, one JSON per line):
{
"timestamp": "2026-04-19T12:34:56Z",
"caller": "review|security-officer|qa-engineer|architect",
"finding_id": "SEC-042",
"file": "src/auth.c:142",
"original_severity": "P0",
"rounds": [
{"round": 1, "verdict": "VALID", "crux": "..."},
{"round": 2, "verdict": "VALID", "crux": "...", "grep_used": true},
{"round": 3, "verdict": "INVALID", "crux": "..."}
],
"arbiter": {"verdict": "VALID", "crux": "..."},
"confidence": 0.67,
"final_severity": "P0"
}This log is how we measure whether triage earns its keep. Review it weekly:
# False-positive rate: how many findings the arbiter flipped to INVALID
jq 'select(.arbiter.verdict=="INVALID")' .great_cto/triage-log.jsonl | wc -l
# Average rounds-to-consensus (did we need all 3 or did R1+R2 agree?)
jq '[.rounds[].verdict] | unique | length' .great_cto/triage-log.jsonlIf FP rate < 10% after 50 triages — triage is filtering noise that wasn't there. Lower threshold or skip triage for that angle. If FP rate > 40% — original review prompt is too trigger-happy; tighten the angle rules.
Per triaged finding: ~4 LLM turns (3 rounds + arbiter). At typical review sizes (~5-10 triaged findings per PR), total budget: 20-40 extra turns per /review. Batch when possible — one arbiter can handle multiple findings in a single call if their cruxes are independent.
For cost-sensitive runs (approval-level: auto on a huge PR), consider: triage only P0, leave P1 untriaged. Re-tune based on .great_cto/triage-log.jsonl data.
confidence (the vote) and final_verdict (the arbiter). Humans deserve to see the disagreement.© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/skeptical-triage of avelikiy/great_cto.
Open the folder on GitHubat commit 0e9df12
Skeptical Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skeptical Triage this skillavelikiy/great_cto | 103 | — | ~2.1k | Automated safety check: Notes | MIT | |
| Codex CLIsundial-org/awesome-openclaw-skills | 663 | — | ~2k | Automated safety check: Pass | None | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Code Review Skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Requesting Code ReviewHezaoHezao/poirot | 249 | 5 repos | ~1.6k | Automated safety check: Pass | MIT |
sundial-org/awesome-openclaw-skills
Use OpenAI Codex CLI for coding tasks. An agent skill from sundial-org/awesome-openclaw-skills.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
avelikiy/great_cto
Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.
avelikiy/great_cto
Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.
avelikiy/great_cto
Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.
avelikiy/great_cto
Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.
avelikiy/great_cto
greatcto's own committed aesthetic — the instrument panel. An agent skill from avelikiy/great_cto.
avelikiy/great_cto
Catalogue of known SDLC anti-patterns that greatcto agents must actively reject when reviewing architecture, plans, code, or post-mortems.
Categories
Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers. A finding goes through three skeptical review rounds followed by an impartial arbiter that turns the votes into a confidence score. Round one asks whether the premise is true, for example whether an outside attacker can actually reach the flagged code path.
Skeptical Triage fits situations like: checking a P0 or P1 security review finding before it blocks a release; deciding whether a failing test is a real regression or a flaky test; settling an architecture decision dispute where both options look reasonable; filtering false positives out of a multi-angle code review.
Run `npx skills add avelikiy/great_cto --skill skeptical-triage -a claude-code`. Or copy the skill folder (skills/skeptical-triage in avelikiy/great_cto) into .claude/skills/skeptical-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add avelikiy/great_cto --skill skeptical-triage -a codex`. Or copy the skill folder (skills/skeptical-triage in avelikiy/great_cto) into .agents/skills/skeptical-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill skeptical-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skeptical-triage, .gemini/skills/skeptical-triage, .github/skills/skeptical-triage and .opencode/skills/skeptical-triage in your project.
Going by SKILL.md and its folder, Skeptical Triage needs the command-line tools its instructions call (jq). Our summary lists: The Read, Grep, Bash and Glob tools. Its frontmatter pre-approves these tools: Read, Grep, Bash, Glob.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Skeptical Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Skeptical Triage: Codex CLI (sundial-org/awesome-openclaw-skills, 663 stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Code Review Skill (awesome-skills/code-review-skill, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 103 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 10, 2026.
Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.