Adversarial Code Review
Multi-perspective adversarial code review with git-isolated worktrees. Two reviewers (Architect + Inspector), cross-validation, and synthesis report. The synthesis is the final arbiter — its verdict takes priority over individual reviewer outputs. Skill: Adversarial Code Review Owner: chpomob Summary: Multi-perspective adversarial code review with git-isolated worktrees. Two reviewers (Architect + Inspector), cross-validation, and synthesis report. The synthesis is the final arbiter — its verdict takes priority over individual reviewer outputs. Tags: latest:0.1.0 Version history: v0.1.0 | 2026-08-03T18:11:17.731Z | auto Initial release of adversarial-code-revi
Rank
62
Safety
84
Downloads
2.7k
Updated
Oct 9, 2026
Version
0.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.7K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.7K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.1.0release · observed Aug 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17435m3chty5jmw4jhpkyhnb58brn8g:adversarial-code-review-2- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chpomob-adversarial-code-review-2/snapshot"
Documentation
CLAWHUB
52,995 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: adversarial-code-review description: "Multi-perspective adversarial code review with git-isolated worktrees. Two reviewers (Architect + Inspector), cross-validation, and synthesis report. The synthesis is the final arbiter — its verdict takes priority over individual reviewer outputs." tags: [adversarial, code-review, multi-model, parallel, review-only, persona, git] version: 1.10.0 license: 0BSD --- # adversarial-code-review Multi-perspective adversarial review of a diff or codebase. Two independent reviewers (**Architect** + **Inspector**) run concurrently and each produce JSON findings, two **cross-review** passes (A reviews B's findings, B reviews A's findings) pressure-test them, and a **synthesis** rapporteur collapses everything into a single ranked report. The review engine, subprocess runner, and personas live in the sibling `adversarial-common` skill — this skill only wires the review flow and the source-gathering modes. ## Installation Requires the `adversarial-common` sibling repo (shared engine). One-line install: curl -fsSL https://raw.githubusercontent.com/chpomob/adversarial-code-review/main/scripts/install.sh | bash or, from an existing checkout: bash scripts/install.sh Both place adversarial-code-review and adversarial-common side by side under `~/.hermes/skills` (override the target with `$1` or `$HERMES_HOME`). ## When to use - Before merging a feature branch (`--diff-git`). - On a standalone patch file (`--diff`). - On a whole directory or single file (`--dir`, `--file`). - On an existing project in place (`--project-dir`). ## Usage ```bash python3 scripts/adversarial_review.py <source> [options] ``` The reviewer command defaults to the `claude-tmux` wrapper (no model pinned — the CLI picks its own best). Override per-run with `--review-cmd` or persistently with `$ACR_REVIEW_CMD`. ### Sources (mutually exclusive) | Flag | Argument | Reviews | |------|----------|---------| | `--diff-git` | — | `<base>..HEAD` inside an isolated git worktree (dirty tree auto-stashed) | | `--diff` | `FILE` | a unified-diff file | | `--dir` | `DIR` | every file under a directory | | `--file` | `FILE` | a single file | | `--project-dir` | `DIR` | an existing project directory in place | ### Options | Flag | Default | Purpose | |------|---------|---------| | `--a-cmd` | `--review-cmd` (or `$ACR_A_CMD`) | Architect model command (overrides `--review-cmd`) | | `--b-cmd` | `--review-cmd` (or `$ACR_B_CMD`) | Inspector model command (overrides `--review-cmd`) | | `--cross-a-cmd` | `--a-cmd` (or `$ACR_CROSS_A_CMD`) | Cross-review A model — Architect reviews Inspector's findings | | `--cross-b-cmd` | `--b-cmd` (or `$ACR_CROSS_B_CMD`) | Cross-review B model — Inspector reviews Architect's findings | | `--synth-cmd` | `--review-cmd` (or `$ACR_SYNTH_CMD`) | Synthesis model command | | `--base` | `$ACR_BASE`, then `main`, then `master` | base ref for `--diff-git` (tried in that order) | | `--feature` | current branch name | slug use
README.md
# adversarial-code-review Multi-perspective adversarial code review with git-isolated worktrees. Two independent reviewers (Architect + Inspector) each produce JSON findings, two cross-review passes pressure-test them, and a synthesis rapporteur collapses everything into a single ranked report. For Hermes Agent, Claude Code, Codex, or any LLM CLI. ## How it works ``` ARCHITECT ──→ reviews code (architecture, security, concurrency) INSPECTOR ──→ reviews code (bugs, edge cases, error handling) CROSS_1 ────→ challenges INSPECTOR findings with ARCHITECT perspective CROSS_2 ────→ challenges ARCHITECT findings with INSPECTOR perspective SYNTHESIS ──→ ranks, cross-validates, produces final report ``` ## Comparison | Feature | adversarial-code-review | adverse (addyosmani) | alecnielsen/adversarial-review | agent-review-panel | |---------|------------------------|---------------------|-------------------------------|-------------------| | Cross-model debate | ✅ Architect↔Inspector | ❌ Single-reviewer | ❌ Single-round | ✅ 4-6 panel | | Git worktree isolation | ✅ | ❌ | ❌ | ❌ | | Cross-review rounds | ✅ 2 rounds of devil's advocate | ❌ | ❌ | ❌ | | JSON findings with schema | ✅ | ❌ | ❌ | ❌ | | --project-dir mode | ✅ Review existing codebase | ❌ | ❌ | ❌ | ## Quick start ```bash # Review changes on a branch python3 scripts/adversarial_review.py --diff-git # Review a whole project directory python3 scripts/adversarial_review.py --project-dir /path/to/project \ --a-cmd "claude-tmux --model best" \ --b-cmd "codex exec -C /path/to/project" ``` ## Output Artifacts land in `--out` (default `.adversarial-review`): - `final.json` — machine-readable verdict (`APPROVE|REQUEST_CHANGES|REJECT`) - `review.md` — ranked report with per-finding evidence - `01_architect.txt` … `05_synthesis.txt` — per-phase raw output ## Dependencies - Python ≥ 3.11 - Git ≥ 2.5 - Two LLM CLIs (one for architect, one for inspector) Uses `adversarial-common` as the shared engine. ## License 0BSD — see [LICENSE](LICENSE).
_meta.json
{
"ownerId": "kn7e26az9x7m8bgwfwg90q1wkh8bsqw0",
"slug": "adversarial-code-review-2",
"version": "0.1.0",
"publishedAt": 1785780677731
}references/ai-quota-apis.md
# AI CLI Quota APIs — Direct programmatic access
**Updated 2026-07-31** — Standalone CLI startup and explicit endpoint inventory.
All five providers share the optional external adapter
`~/.hermes/plugins/hermes-quota-status/quota_api.py`.
## Architecture
```
quota_api.py ← shared module (token reading + API calls)
├── check-ai-quota.py ← CLI script (human + JSON output)
└── hermes-quota-status/__init__.py ← Hermes TUI statusbar plugin
```
The CLI imports the adapter lazily. Importing `check-ai-quota.py` and running
`--help` therefore require only the Python standard library. A quota check still
requires the `hermes-quota-status` plugin; if it is absent, the CLI reports a
per-provider error in its normal human or JSON output without a traceback.
No tmux scraping or URL-embedded API keys are used. Each direct request reveals
the caller's IP address, request timing, and association with the authenticated
account to the target provider. Credentials are sent in headers and are never
intentionally printed. The provider-specific caveats below are additional to
that baseline disclosure.
## Claude Code (Pro subscription)
- **Token**: `~/.claude/.credentials.json` → `claudeAiOauth.accessToken`
- **Endpoint**: `https://api.anthropic.com/api/oauth/usage`
- **Status**: First-party Anthropic endpoint, but undocumented and
community-discovered; it is not a supported public API contract and may change.
- **Auth**: `Authorization: Bearer <token>`
- **Privacy**: Sends the Claude OAuth credential to Anthropic and requests
subscription utilization and reset times.
- **Response**:
```json
{
"five_hour": {"utilization": 27.0, "resets_at": "2026-06-12T18:30:00Z"},
"seven_day": {"utilization": 10.0, "resets_at": "2026-06-19T09:00:00Z"}
}
```
- **Note**: Claude returns utilization as percentages (0-100). The old code had a
scale="fraction" bug that inflated sub-1% values to 80%. Fixed 2026-06-12.
## Codex (ChatGPT Plus subscription)
- **Token**: `~/.codex/auth.json` → `tokens.access_token`
- **Endpoint**: `https://chatgpt.com/backend-api/wham/usage`
- **Status**: First-party/official ChatGPT service endpoint used for Codex
account usage, but not a documented public developer API contract.
- **Auth**: `Authorization: Bearer <token>`
- **Privacy**: Sends the ChatGPT OAuth credential to OpenAI and requests account
rate-limit utilization and reset times.
- **Response**:
```json
{
"rate_limit": {
"primary_window": {"used_percent": 11, "reset_at": 1779762941},
"secondary_window": {"used_percent": 4, "reset_at": 1780313088}
}
}
```
## Gemini / agy (Google AI Studio)
- **Key**: `GOOGLE_API_KEY` env var or `~/.hermes/.env` → `GOOGLE_API_KEY=...`
- **Endpoints**:
- `https://generativelanguage.googleapis.com/v1beta/models`
- `https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash:generateContent`
- **Status**: Both are official Google Generative Language API endpoints. They
are not references/api-input-limits.md
# API Input Size Limits for Adversarial Review
When using `--project-dir` or `--dir` modes, the review script sends ALL source
files concatenated to the reviewer's stdin. API-based reviewers enforce strict
input size limits that cause silent failures if exceeded.
## Limits by provider
| Provider | Max input chars | Limit type | Failure mode |
|----------|----------------|------------|-------------|
| Codex (OpenAI) | 1,048,576 (1 MB) | Hard API limit | `turn/start failed: Input exceeds the maximum length` — exit 1, empty stdout, no visible error in truncated stderr |
| Claude (Anthropic) | ~200K tokens (~800K chars) | Soft per-model | Model refuses with "input too long" |
| Claude-tmux | Depends on model | Varies | Usually works up to ~2M chars with extended thinking |
Codex is the most restrictive: 1 MB of input characters. A project with 85 source
files averages ~600K chars (safe). Adding test files, build artifacts, or library
dependencies pushes it over the limit.
## Debugging checklist when Architect phase exits 1
1. Check `01_architect.txt` in the output artifact directory — if it's 0 bytes,
Codex received no stdin or the input was rejected
2. Look for `input_exceeds_maximum_length` or `input_too_large` in stderr
(it may be buried deep in the output — grep for it)
3. Run `python3 -c "
import os; SKIP={'.git','.venv','__pycache__','node_modules','.pytest_cache','.pio','build','target','test','unity'}; PREFIX={'.adversarial','.omnisense-'}; out=[]
for dp,dirs,files in os.walk('.'):
dirs[:]=[d for d in dirs if d not in SKIP and not any(d.startswith(p) for p in PREFIX)]
for n in files:
if n.startswith('.'): continue
out.append(os.path.relpath(os.path.join(dp,n),'.'))
if len(out)>=200: break
if len(out)>=200: break
total=sum(os.path.getsize(f) for f in out)
print(f'{len(out)} files, {total:,} chars')
"` from the project root to measure the input size
## Fixes
1. Add `test`, `unity` (test framework dirs) to `_SKIP_DIRS`
2. Add `.pio`, `build`, `target` (build artifact dirs) to `_SKIP_DIRS`
3. Ensure `_SKIP_DIR_PREFIX` catches `.adversarial-*` and `.omnisense-*` dot-dirs
4. Verify dot-prefixed individual files (`.omnisense-*.md` specs) are filtered
Aim for ≤ 700K chars to leave headroom for the persona text (~1.5K per role).activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/chpomob/skills/adversarial-code-review-2",
"sourceUrl": "https://clawhub.ai/chpomob/skills/adversarial-code-review-2",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T11:52:36.428Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chpomob-adversarial-code-review-2/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chpomob-adversarial-code-review-2/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T11:52:36.428Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.7K downloads",
"href": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceUrl": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T11:52:36.428Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.0",
"href": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceUrl": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-03T18:11:17.731Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-chpomob-adversarial-code-review-2/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chpomob-adversarial-code-review-2/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.0",
"description": "Initial release of adversarial-code-review v0.1.0. - Introduces a multi-perspective adversarial review workflow using two independent personas (Architect + Inspector) with cross-review and synthesis steps. - Supports reviewing diffs, files, directories, or entire projects with flexible command overrides for each reviewer phase. - Provides comprehensive configuration via CLI options and environment variables, allowing custom model commands per role. - Outputs findings and consolidated reports in both JSON and Markdown/HTML formats for easy consumption by humans and automation. - Enforces model diversity between Architect and Inspector reviewers and explains preferred model pairing strategies.",
"href": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceUrl": "https://clawhub.ai/chpomob/adversarial-code-review-2",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-03T18:11:17.731Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
