Caveman ReviewSAFE
šŖØ why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
One-line PR comments. Location, problem, fix. No throat-clearing.
What it does
Generates code review comments in L: . . format. One line per finding. Severity emoji: š“ bug, š” risk, šµ nit, ā question. Drops "I noticed that...", hedging, and restating what the diff already shows. Keeps exact line numbers, backticked symbols, and concrete fixes.
Auto-clarity: drops terse mode for CVE-class security findings, architectural disagreements, and onboarding contexts where the author needs the why. Resumes terse for the rest.
Output only ā does not approve, request changes, or run linters.
How to invoke
/caveman-review
Also triggers on "review this PR", "code review", "review the diff".
Example output
L42: š“ bug: user can be null after .find(). Add guard before .email. L88-140: šµ nit: 50-line fn does 4 things. Extract validate/normalize/persist. L23: š” risk: no retry on 429. Wrap in withBackoff(3). L107: ā q: why drop the cache here? Reads on next request will miss.
See also
SKILL.mdā full LLM-facing instructions- Caveman README ā repo overview
05e982541721OBSERVED Ā· 2026-09-23What it tells the agent
The instruction file, verbatim from the audited commit ā this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: caveman-review
description: >
Compressed code review - one line per finding with location, problem and fix.
Use for /caveman-review, "review this PR", or "review the diff".
---
Write code review comments terse and actionable. One line per finding. Location, problem, fix. No throat-clearing.
## Rules
**Format:** `L<line>: <problem>. <fix>.` ā or `<file>:L<line>: ...` when reviewing multi-file diffs.
**Severity prefix (optional, when mixed):**
- `š“ bug:` ā broken behavior, will cause incident
- `š” risk:` ā works but fragile (race, missing null check, swallowed error)
- `šµ nit:` ā style, naming, micro-optim. Author can ignore
- `ā q:` ā genuine question, not a suggestion
**Drop:**
- "I noticed that...", "It seems like...", "You might want to consider..."
- "This is just a suggestion but..." ā use `nit:` instead
- "Great work!", "Looks good overall but..." ā say it once at the top, not per comment
- Restating what the line does ā the reviewer can read the diff
- Hedging ("perhaps", "maybe", "I think") ā if unsure use `q:`
**Keep:**
- Exact line numbers
- Exact symbol/function/variable names in backticks
- Concrete fix, not "consider refactoring this"
- The *why* if the fix isn't obvious from the problem statement
## Examples
ā "I noticed that on line 42 you're not checking if the user object is null before accessing the email property. This could potentially cause a crash if the user is not found in the database. You might want to add a null check here."
ā
`L42: š“ bug: user can be null after .find(). Add guard before .email.`
ā "It looks like this function is doing a lot of things and might benefit from being broken up into smaller functions for readability."
ā
`L88-140: šµ nit: 50-line fn does 4 things. Extract validate/normalize/persist.`
ā "Have you considered what happens if the API returns a 429? I think we should probably handle that case."
ā
`L23: š” risk: no retry on 429. Wrap in withBackoff(3).`
## Auto-Clarity
Drop terse mode for: security findings (CVE-class bugs need full explanation + reference), architectural disagreements (need rationale, not just a one-liner), and onboarding contexts where the author is new and needs the "why". In those cases write a normal paragraph, then resume terse for the rest.
## Boundaries
Reviews only ā does not write the code fix, does not approve/request-changes, does not run linters. Output the comment(s) ready to paste into the PR. "stop caveman-review" or "normal mode": revert to verbose review style.Trust audit
SAFEgrade B Ā· trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
05e982541721full audit observations/trust-audit/skill/juliusbrussee__caveman-review.json Ā· Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 05e982541721 | SAFE | B | 89 | first audit |
Questions
What does the Caveman Review skill do?
šŖØ why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.
Is Caveman Review safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Caveman Review access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (05e982541721), read on 2026-09-23. The repository is watched, and a new audit runs when it changes ā this is the first audit.