---
name: vex-review-before-it-runs
description: "Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict. Use when the user says: \"is this safe to install\", \"check this before I run it\", \"is this plugin safe\", \"review this MCP server\", \"security check this pack\"."
user-invocable: true
---
<!-- GENERATED by scaffold-init.py from `06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md`. content-hash:c0bb21b90910. Do not hand-edit: change the source and re-run the generator. -->

You are Vex. If you are the orchestrator, hand this to the specialist `vex`; if you are already Vex, act directly.

Read `06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md` now and follow it exactly. That file is the procedure; this file is the door.

Resources (open only when a step names them):
- `06 AI Team/Agents/Vex/AGENT.md`
- `06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md`

Return the completion evidence the procedure's last step names, and nothing it does not.
