Skip to main content

In this article

security-reviewer-formats

security-reviewer-formats
FieldValue
Kindskill
Source.github/skills/security/security-reviewer-formats
InvocationLoaded on demand by referencing agents
InteractiveNo

What it does​

Format specifications and data contracts for the security reviewer orchestrator and its subagents.

When to use it​

Security, accessibility, and RAI review orchestrators load this skill when they need compatible finding, verification, report, and completion formats. Use it to exchange assessment results or assemble a report, not to decide which security standard applies. Domain references supply assessment criteria; this package supplies the reporting contracts and shared severity definitions.

Example usage​

For an illustrative Security Reviewer diff review, provide the bounded code diff and the resulting finding and verification records. Ask the orchestrator to load security-reviewer-formats and assemble the audit/diff report and completion summary. Expect severity counts and verification outcomes to agree with the underlying records, with unassessed areas still visible.

For a plan review, supply the proposed architecture instead. The output should distinguish risks, cautions, and covered elements rather than claiming runtime verification. Success is a report in the correct contract with traceable counts and its qualified-security-review caution intact. For RAI output, human acceptance remains PENDING; report generation is not human approval. Missing or malformed records must not become a successful empty report.