Agent skill

Adversarial Codebase Audit

by ben-manes in ben-manes/caffeine

Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

Apache-2.0Auto-check: notesDevelopment

Install Adversarial Codebase Audit

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-adversarial -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-adversarial --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-adversarial .claude/skills/audit-adversarial && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-adversarial
GitHub stars
18k
Token cost
~1.9k tokens
SKILL.md length
557 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

  • Works in 8 steps: Inventory source files → Launch parallel hostile reviewers → Validate completeness → …
  • Looking for bugs that familiarity with a codebase hides
  • SKILL.md covers Target, Step 1: Inventory source files, Step 2: Launch parallel… and Step 3: Validate completeness, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This skill, written for the Caffeine cache repository, reviews the whole source tree with deliberately no project context. It lists the Java files in scope (the core, Guava, JCache and simulator modules plus the examples), groups them into several subsystems and spawns parallel subagents that review from first principles with a hostile mindset. Design documents and other .claude docs are withheld on purpose.

Reviewers get a prompt that casts them as senior concurrency experts looking for flaws. An agent that finds nothing must give a coverage summary, and each report goes to a separate evaluator subagent that sees only the report and looks for what was missed. The reviewer then defends or drops each point, and the findings are deduplicated and consolidated. An argument can narrow the target; otherwise all the listed source folders are reviewed.

When your agent uses it

  • Looking for bugs that familiarity with a codebase hides
  • Reviewing concurrent Java code with several independent reviewers
  • Cross-checking earlier audits with a fresh, context-free pass

Example prompts

  • “Run the adversarial audit on the whole Caffeine source tree.”
  • “Do a hostile review of just the jcache module.”
  • “Have fresh reviewers look at the simulator code with no design docs.”

Requirements

  • A checkout of the Caffeine repository with its Java sources
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Agent

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Inventory source files
  2. Launch parallel hostile reviewers
  3. Validate completeness
  4. 5: Evaluator challenge (per reviewer)
  5. Consolidate and deduplicate
  6. Adjudicate against design docs
  7. Triage confirmed findings
  8. Report

What it can do on your machine

Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adversarial Codebase Audit loads about 1.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 557 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 557 words, ~1,906 tokens.

Download SKILL.mdSave it as .claude/skills/audit-adversarial/SKILL.md (or your agent's skills folder).
name
audit-adversarial
description
Hostile full-codebase review by parallel adversarial agents with no design context — finds bugs that domain familiarity masks
allowed-tools
Read, Grep, Glob, Bash, Agent
argument-hint
[subsystem or file to focus on, default: all source files]
context
fork
disable-model-invocation
true

Run a hostile adversarial review of the Caffeine source code. Unlike the other audit skills which use the auditor agent (with design context), this skill deliberately gives reviewers NO project context — they review with fresh eyes and a hostile mindset.

Target

$ARGUMENTS

If no argument, review all source files in caffeine/src/main/java/, guava/src/main/java/, jcache/src/main/java/, simulator/src/main/java/, and examples/*/src/main/java/. The adapters hold the same quality bar as the core. The examples are sketches: report one failing at what it shows, not hardening it leaves to the user (ruled-out.md §examples).

Step 1: Inventory source files

List all Java source files in scope. Group into 6-8 subsystems for parallel review — core subsystems plus one group per non-core module (examples reviewed against the contracts of the third-party libraries they compose).

Step 2: Launch parallel hostile reviewers

Spawn 4-6 subagents simultaneously. Each reviews one subsystem. Critically: DO NOT give them design-decisions.md, synchronization.md, or any .claude/docs. They should review from first principles only.

Each agent gets this prompt (adapted to their subsystem):

You are a senior Java concurrency expert performing a hostile code review.
A competitor built this library and it's gaining adoption over your work.
You want to find every flaw to demonstrate it's not production-worthy.

Your reputation is on the line. Be ruthless but precise — cite methods,
trace code paths, construct failing scenarios.

Rules:
- Dig deep. Zero findings are allowed ONLY with a coverage proof listing
  files inspected, methods traced, interleavings attempted, and attack
  surfaces checked. If coverage is shallow, keep looking.
- Every finding must include: exact location, concrete evidence, a
  falsifiable scenario, and confidence (high/medium).
- Only report issues provable with code evidence
- Construct concrete interleavings, inputs, or scenarios
- Do not critique style — focus on correctness and robustness
- Do not accept "by design" — if the design has consequences, document them
- Read the actual source code before making claims
- Look for what's MISSING, not just what's wrong

Attack surfaces:
1. Memory model violations — insufficient access modes, missing happens-before
2. State corruption interleavings — weight divergence, deque corruption, stuck drain status
3. Resource leaks under failure — OOME/SOE leaving unrecoverable state
4. Silent data loss — values dropped without notification
5. Specification violations — ConcurrentMap contract, Javadoc promises
6. Denial of service — O(n) operations on O(1) paths
7. Sentinel value collisions — can valid input equal an internal sentinel?
8. Validation gaps — inputs accepted at parse time but rejected later
9. API surprises — public methods returning nonsensical values
10. Notification asymmetries — some paths notify, equivalent paths don't
11. Third-party API contract misuse — error/dispose paths, duplicate keys,
    empty batches, cancellation semantics assumed rather than verified

Rate each finding: critical/high/medium/low
Format: numbered list with file:method, description, evidence

Step 3: Validate completeness

If any agent returns zero findings, require a coverage summary from that agent (scope inspected, attack surfaces checked, interleavings attempted). Re-launch with a more specific prompt only if coverage is shallow. Zero findings with thorough coverage proof is acceptable.

Step 3.5: Evaluator challenge (per reviewer)

For each reviewer that returned findings OR a zero-findings coverage proof, spawn a separate evaluator subagent. The evaluator gets ONLY the reviewer's report — no source code, no design docs.

You are a hostile evaluator reviewing another auditor's report of a Java
cache library. Your job is to find what the auditor MISSED.

1. For each confirmed invariant, construct a 2-thread interleaving that
   would violate it. If you cannot, explain what prevents it.
2. For each zero-finding claim, identify the most likely bug category
   the auditor could have missed given their stated coverage.
3. For each finding, check whether the evidence is concrete or hand-wavy.
   Flag findings that assert a bug without a specific interleaving.

Output: prioritized list of challenges for the reviewer to address.

Have the original reviewer address each challenge by re-reading source code. Drop findings the reviewer cannot defend. Add new findings from challenges the reviewer confirms.

Step 4: Consolidate and deduplicate

Collect findings from all agents. Deduplicate (same issue found by multiple agents = higher confidence). Remove findings that are clearly wrong (misreading the code). Keep findings even if they might be "by design" — the point is to surface things domain familiarity masks.

Confidence decay check: If any reviewer's findings are >60% medium-confidence, note this in the report — that reviewer's area may need a more targeted follow-up audit rather than more speculative findings.

Escalation: If any reviewer flagged issues they could not resolve statically (e.g., "depends on JDK internal behavior"), mark these as ESCALATED for dynamic testing (Fray, LinCheck, JCStress) rather than guessing.

Show full SKILL.md (184 more words)Show less

Step 5: Adjudicate against design docs

NOW read .claude/docs/design-decisions.md, .claude/rules/design-decisions.md, the relevant module rules, and .claude/docs/ruled-out.md's standing principles and module section. For JCache, consult the relevant topic in .claude/docs/jsr107-conformance.md and verify surviving conformance claims against its JSR-107 1.1.1 specification and API sources. State any normative source that was not consulted. For each finding, check whether it is an intentional trade-off and reclassify it:

  • confirmed — supported evidence violates an applicable contract or invariant; absence of a design explanation alone is insufficient
  • intentional — documented design decision, not a defect
  • ambiguous — needs more evidence or maintainer input

Keep intentional findings in the report (labeled as such) but do not count them as bugs. The value is surfacing them for review, not asserting they're wrong.

Step 6: Triage confirmed findings

Classify using .claude/docs/finding-taxonomy.md for severity and categories. Additionally tag each confirmed finding:

  • bug — incorrect behavior, provably wrong
  • api-issue — public API returns surprising/incorrect values
  • validation-gap — input accepted when it shouldn't be
  • robustness — works but fragile, could break with minor changes
  • cosmetic — dead code, wasteful patterns, poor diagnostics

Step 7: Report

Write the full report to .local/audits/<model>/audit-adversarial.md (see .claude/docs/audit-output.md).

Format:

# Adversarial Review: Caffeine Source Code

[N] parallel auditors reviewed [M] source files (~K lines).
Findings consolidated, deduplicated, and triaged by severity.

## Likely Bugs
...

## API/Behavioral Issues
...

## Robustness/Validation Gaps
...

## Design/Maintenance Concerns
...

## Summary
[N] likely bugs, [M] API issues, [K] validation gaps, [J] concerns.
[N] evaluator challenges received across [M] reviewers.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-adversarial of ben-manes/caffeine.

Open the folder on GitHubat commit e972fb0

Compare with similar skills

Adversarial Codebase Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adversarial Codebase Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adversarial Codebase Audit this skillben-manes/caffeine18k—~1.9kAutomated safety check: NotesApache-2.0
Multi-Model Adversarial Reviewcursor/plugins10k8 repos~1.3kAutomated safety check: PassNone
Multi-Persona Code Revieweric-tramel/moraine117—~1.3kAutomated safety check: PassApache-2.0
O2 Review Loopopenobserve/openobserve22k—~3.7kAutomated safety check: PassAGPL-3.0
Subagent-Driven DevelopmentHoangNguyen0403/agent-skills-standard571—~1.3kAutomated safety check: PassMIT
Clawteamwin4r/ClawTeam-OpenClaw1.5k—~3.1kAutomated safety check: PassMIT

Similar skills

  • Official

    Runs one read-only reviewer subagent per configured model against a diff to challenge a change, then synthesizes a single verdict without applying any fixes.

    10k GitHub starsUsed in 8 repos~1.3k tokens
    DevelopmentAuto-check passed
  • Multi-Persona Code Review

    eric-tramel/moraine

    Coordinates a delegated review of a Moraine PR or local change by seven focused reviewer subagents, merges their findings and follows up on the fixes.

    117 GitHub stars~1.3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • O2 Review Loop

    openobserve/openobserve

    Splits a change into planner, coder and independent reviewer roles: you confirm a spec, a subagent implements it, and a separate reviewer checks each round's local WIP commit.

    22k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    571 GitHub stars~1.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Clawteam

    win4r/ClawTeam-OpenClaw

    Multi-agent swarm orchestration. An agent skill from win4r/ClawTeam-OpenClaw.

    1.5k GitHub stars~3.1k tokensUpdated 3 mo ago
    Agent WorkflowsAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~559 tokensUpdated yesterday
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes
  • Runs three parallel reviewers on a diff or branch, one blind, one design-aware and one matching past bug patterns, then triages their findings.

    18k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Adversarial Codebase Audit

What does Adversarial Codebase Audit do?

Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings. This skill, written for the Caffeine cache repository, reviews the whole source tree with deliberately no project context. It lists the Java files in scope (the core, Guava, JCache and simulator modules plus the examples), groups them into several subsystems and spawns parallel subagents that review from first principles with a hostile mindset.

When should I use Adversarial Codebase Audit?

Adversarial Codebase Audit fits situations like: looking for bugs that familiarity with a codebase hides; reviewing concurrent Java code with several independent reviewers; cross-checking earlier audits with a fresh, context-free pass.

How do I install Adversarial Codebase Audit in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-adversarial -a claude-code`. Or copy the skill folder (.claude/skills/audit-adversarial in ben-manes/caffeine) into .claude/skills/audit-adversarial in your project. Claude Code loads it when a task matches its description.

How do I install Adversarial Codebase Audit in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-adversarial -a codex`. Or copy the skill folder (.claude/skills/audit-adversarial in ben-manes/caffeine) into .agents/skills/audit-adversarial in your project. Codex loads it when a task matches its description.

Can I use Adversarial Codebase Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-adversarial -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-adversarial, .gemini/skills/audit-adversarial, .github/skills/audit-adversarial and .opencode/skills/audit-adversarial in your project.

What does Adversarial Codebase Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Adversarial Codebase Audit is instructions for the agent only. Our summary lists: A checkout of the Caffeine repository with its Java sources. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Agent.

Does Adversarial Codebase Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Adversarial Codebase Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Adversarial Codebase Audit use?

Adversarial Codebase Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adversarial Codebase Audit use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adversarial Codebase Audit?

Skills that share tags, products or a category with Adversarial Codebase Audit: Multi-Model Adversarial Review (cursor/plugins, 10k stars), Multi-Persona Code Review (eric-tramel/moraine, 117 stars), O2 Review Loop (openobserve/openobserve, 22k stars) and Subagent-Driven Development (HoangNguyen0403/agent-skills-standard, 571 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adversarial Codebase Audit?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.