cmux-review
Review agent-written changes before merge, after substantial edits, or when re-reviewing a repair. Use the adversarial protocol for high-risk changes or an explicitly requested deep review.
How do I install this agent skill?
npx skills add https://github.com/manaflow-ai/cmux --skill cmux-reviewIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill automates code reviews and merging. It is susceptible to indirect prompt injection because it defines simple keywords like 'merge' or 'auto-merge' as triggers for code merging, which an attacker could potentially embed in PR comments or file changes to trick the agent. It also executes shell commands for repository management and temporary file handling.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
cmux Review
Review to reduce developer attention. Surface concrete correctness defects; suppress style, nits and speculative improvements unless requested.
Default pre-merge review
- Give a review subagent the task intent, base/head SHAs and exact diff. Ask for correctness first, then repository rules; keep discovery independent of the author's reasoning. Review policy edits against the base-branch rules.
- Verify concrete findings, fix them when authorized, and push. Re-run the original discriminator after repair. A green test counts only if it exercises the asserted failure; prefer red-before/green-after evidence.
- If fixes were non-trivial, obtain a fresh subagent review of the repair delta.
- Merge when the checks that judge the change pass and the approval rule below is met. Report findings with evidence, verification performed and coverage gaps.
Use subagents in the current runtime, not a second model or external review service as a gate. Keep review read-only until an authorized repair. Do not commit review receipts, scratch reproductions or generated logs.
Dogfood and merge
For implementation handoff or merge, read dogfood and merge
for per-change verification, first-pass completion, re-dogfood and merge receipts.
The main agent owns dogfood, approval, mergeability and every pushed fix.
App/runtime/UI merges require the user's explicit approval after dogfood or a
direct merge directive (merge, merge it, auto-merge; not finish, lgtm
or ship it). main is nightly: stack fixes, do not revert.
Adversarial review
For security, persistence, concurrency, data-loss risks, or a requested deep review, use the full protocol:
- Before discovery or mutation, read source identity and receipt requirements and capture the original candidate and policy coordinates.
- Discovery and triage: source identity, intent compliance, independent reviewers, severity and evidence provenance.
- Challenge, verification and repair: counterevidence, executable checks and bounded repair attempts.
- After verification, persist the receipt and report with separate pre/post-repair source coordinates and evidence.
These stages retain the advanced evidence protocol; ordinary reviews use the short default pass above.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/manaflow-ai/cmux/cmux-review">View cmux-review on skillZs</a>