Multi-Model Adversarial Review
cursor/plugins
Runs one read-only reviewer subagent per configured model against a diff to challenge a change, then synthesizes a single verdict without applying any fixes.
Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ben-manes/caffeine audit-adversarial --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-adversarial .claude/skills/audit-adversarial && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .claude/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarialType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ben-manes/caffeine audit-adversarial --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/audit-adversarial .agents/skills/audit-adversarial && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .agents/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ben-manes/caffeine audit-adversarial --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/audit-adversarial .cursor/skills/audit-adversarial && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .cursor/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ben-manes/caffeine.git --path .claude/skills/audit-adversarial--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ben-manes/caffeine audit-adversarial --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/audit-adversarial .gemini/skills/audit-adversarial && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .gemini/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ben-manes/caffeine audit-adversarialInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/audit-adversarial .github/skills/audit-adversarial && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .github/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ben-manes/caffeine audit-adversarial --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/audit-adversarial .opencode/skills/audit-adversarial && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-adversarial" agent skill from https://github.com/ben-manes/caffeine/tree/master/.claude/skills/audit-adversarial into .opencode/skills/audit-adversarial/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-adversarial", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-adversarialRuns a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.
This skill, written for the Caffeine cache repository, reviews the whole source tree with deliberately no project context. It lists the Java files in scope (the core, Guava, JCache and simulator modules plus the examples), groups them into several subsystems and spawns parallel subagents that review from first principles with a hostile mindset. Design documents and other .claude docs are withheld on purpose.
Reviewers get a prompt that casts them as senior concurrency experts looking for flaws. An agent that finds nothing must give a coverage summary, and each report goes to a separate evaluator subagent that sees only the report and looks for what was missed. The reviewer then defends or drops each point, and the findings are deduplicated and consolidated. An argument can narrow the target; otherwise all the listed source folders are reviewed.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashAgentFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Adversarial Codebase Audit loads about 1.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 557 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, AgentAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 557 words, ~1,906 tokens.
.claude/skills/audit-adversarial/SKILL.md (or your agent's skills folder).Run a hostile adversarial review of the Caffeine source code. Unlike the other audit skills which use the auditor agent (with design context), this skill deliberately gives reviewers NO project context — they review with fresh eyes and a hostile mindset.
$ARGUMENTS
If no argument, review all source files in caffeine/src/main/java/,
guava/src/main/java/, jcache/src/main/java/, simulator/src/main/java/,
and examples/*/src/main/java/. The adapters hold the same quality bar as the
core. The examples are sketches: report one failing at what it shows, not
hardening it leaves to the user (ruled-out.md §examples).
List all Java source files in scope. Group into 6-8 subsystems for parallel review — core subsystems plus one group per non-core module (examples reviewed against the contracts of the third-party libraries they compose).
Spawn 4-6 subagents simultaneously. Each reviews one subsystem. Critically: DO NOT give them design-decisions.md, synchronization.md, or any .claude/docs. They should review from first principles only.
Each agent gets this prompt (adapted to their subsystem):
You are a senior Java concurrency expert performing a hostile code review.
A competitor built this library and it's gaining adoption over your work.
You want to find every flaw to demonstrate it's not production-worthy.
Your reputation is on the line. Be ruthless but precise — cite methods,
trace code paths, construct failing scenarios.
Rules:
- Dig deep. Zero findings are allowed ONLY with a coverage proof listing
files inspected, methods traced, interleavings attempted, and attack
surfaces checked. If coverage is shallow, keep looking.
- Every finding must include: exact location, concrete evidence, a
falsifiable scenario, and confidence (high/medium).
- Only report issues provable with code evidence
- Construct concrete interleavings, inputs, or scenarios
- Do not critique style — focus on correctness and robustness
- Do not accept "by design" — if the design has consequences, document them
- Read the actual source code before making claims
- Look for what's MISSING, not just what's wrong
Attack surfaces:
1. Memory model violations — insufficient access modes, missing happens-before
2. State corruption interleavings — weight divergence, deque corruption, stuck drain status
3. Resource leaks under failure — OOME/SOE leaving unrecoverable state
4. Silent data loss — values dropped without notification
5. Specification violations — ConcurrentMap contract, Javadoc promises
6. Denial of service — O(n) operations on O(1) paths
7. Sentinel value collisions — can valid input equal an internal sentinel?
8. Validation gaps — inputs accepted at parse time but rejected later
9. API surprises — public methods returning nonsensical values
10. Notification asymmetries — some paths notify, equivalent paths don't
11. Third-party API contract misuse — error/dispose paths, duplicate keys,
empty batches, cancellation semantics assumed rather than verified
Rate each finding: critical/high/medium/low
Format: numbered list with file:method, description, evidenceIf any agent returns zero findings, require a coverage summary from that agent (scope inspected, attack surfaces checked, interleavings attempted). Re-launch with a more specific prompt only if coverage is shallow. Zero findings with thorough coverage proof is acceptable.
For each reviewer that returned findings OR a zero-findings coverage proof, spawn a separate evaluator subagent. The evaluator gets ONLY the reviewer's report — no source code, no design docs.
You are a hostile evaluator reviewing another auditor's report of a Java
cache library. Your job is to find what the auditor MISSED.
1. For each confirmed invariant, construct a 2-thread interleaving that
would violate it. If you cannot, explain what prevents it.
2. For each zero-finding claim, identify the most likely bug category
the auditor could have missed given their stated coverage.
3. For each finding, check whether the evidence is concrete or hand-wavy.
Flag findings that assert a bug without a specific interleaving.
Output: prioritized list of challenges for the reviewer to address.Have the original reviewer address each challenge by re-reading source code. Drop findings the reviewer cannot defend. Add new findings from challenges the reviewer confirms.
Collect findings from all agents. Deduplicate (same issue found by multiple agents = higher confidence). Remove findings that are clearly wrong (misreading the code). Keep findings even if they might be "by design" — the point is to surface things domain familiarity masks.
Confidence decay check: If any reviewer's findings are >60% medium-confidence, note this in the report — that reviewer's area may need a more targeted follow-up audit rather than more speculative findings.
Escalation: If any reviewer flagged issues they could not resolve statically (e.g., "depends on JDK internal behavior"), mark these as ESCALATED for dynamic testing (Fray, LinCheck, JCStress) rather than guessing.
NOW read .claude/docs/design-decisions.md, .claude/rules/design-decisions.md,
the relevant module rules, and .claude/docs/ruled-out.md's standing principles
and module section. For JCache, consult the relevant topic in
.claude/docs/jsr107-conformance.md and verify surviving conformance claims
against its JSR-107 1.1.1 specification and API sources. State any normative
source that was not consulted. For each finding, check whether it is an
intentional trade-off and reclassify it:
Keep intentional findings in the report (labeled as such) but do not count them as bugs. The value is surfacing them for review, not asserting they're wrong.
Classify using .claude/docs/finding-taxonomy.md for severity and categories.
Additionally tag each confirmed finding:
Write the full report to .local/audits/<model>/audit-adversarial.md
(see .claude/docs/audit-output.md).
Format:
# Adversarial Review: Caffeine Source Code
[N] parallel auditors reviewed [M] source files (~K lines).
Findings consolidated, deduplicated, and triaged by severity.
## Likely Bugs
...
## API/Behavioral Issues
...
## Robustness/Validation Gaps
...
## Design/Maintenance Concerns
...
## Summary
[N] likely bugs, [M] API issues, [K] validation gaps, [J] concerns.
[N] evaluator challenges received across [M] reviewers.© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/audit-adversarial of ben-manes/caffeine.
Open the folder on GitHubat commit e972fb0
Adversarial Codebase Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Adversarial Codebase Audit this skillben-manes/caffeine | 18k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | |
| Multi-Model Adversarial Reviewcursor/plugins | 10k | 8 repos | ~1.3k | Automated safety check: Pass | None | |
| Multi-Persona Code Revieweric-tramel/moraine | 117 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| O2 Review Loopopenobserve/openobserve | 22k | — | ~3.7k | Automated safety check: Pass | AGPL-3.0 | |
| Subagent-Driven DevelopmentHoangNguyen0403/agent-skills-standard | 571 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Clawteamwin4r/ClawTeam-OpenClaw | 1.5k | — | ~3.1k | Automated safety check: Pass | MIT |
cursor/plugins
Runs one read-only reviewer subagent per configured model against a diff to challenge a change, then synthesizes a single verdict without applying any fixes.
eric-tramel/moraine
Coordinates a delegated review of a Moraine PR or local change by seven focused reviewer subagents, merges their findings and follows up on the fixes.
openobserve/openobserve
Splits a change into planner, coder and independent reviewer roles: you confirm a spec, a subagent implements it, and a separate reviewer checks each round's local WIP commit.
HoangNguyen0403/agent-skills-standard
Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.
win4r/ClawTeam-OpenClaw
Multi-agent swarm orchestration. An agent skill from win4r/ClawTeam-OpenClaw.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
ben-manes/caffeine
Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.
ben-manes/caffeine
Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.
ben-manes/caffeine
Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.
ben-manes/caffeine
Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.
ben-manes/caffeine
Runs three parallel reviewers on a diff or branch, one blind, one design-aware and one matching past bug patterns, then triages their findings.
Works with
Categories
Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings. This skill, written for the Caffeine cache repository, reviews the whole source tree with deliberately no project context. It lists the Java files in scope (the core, Guava, JCache and simulator modules plus the examples), groups them into several subsystems and spawns parallel subagents that review from first principles with a hostile mindset.
Adversarial Codebase Audit fits situations like: looking for bugs that familiarity with a codebase hides; reviewing concurrent Java code with several independent reviewers; cross-checking earlier audits with a fresh, context-free pass.
Run `npx skills add ben-manes/caffeine --skill audit-adversarial -a claude-code`. Or copy the skill folder (.claude/skills/audit-adversarial in ben-manes/caffeine) into .claude/skills/audit-adversarial in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ben-manes/caffeine --skill audit-adversarial -a codex`. Or copy the skill folder (.claude/skills/audit-adversarial in ben-manes/caffeine) into .agents/skills/audit-adversarial in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-adversarial -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-adversarial, .gemini/skills/audit-adversarial, .github/skills/audit-adversarial and .opencode/skills/audit-adversarial in your project.
SKILL.md names no scripts, command-line tools or credentials: Adversarial Codebase Audit is instructions for the agent only. Our summary lists: A checkout of the Caffeine repository with its Java sources. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Agent.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Adversarial Codebase Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Adversarial Codebase Audit: Multi-Model Adversarial Review (cursor/plugins, 10k stars), Multi-Persona Code Review (eric-tramel/moraine, 117 stars), O2 Review Loop (openobserve/openobserve, 22k stars) and Subagent-Driven Development (HoangNguyen0403/agent-skills-standard, 571 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.
Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.