Review DeltaSAFE
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Overview
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
a9c894db76a7OBSERVED · 2026-10-06What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: review-delta description: Review only changes since last commit using impact analysis. Token-efficient delta review with automatic blast-radius detection. argument-hint: "[file or function name]" --- # Review Delta Review only the changed code and its blast radius. ## Steps 1. Call `get_minimal_context_tool(task="review changes")`. If it returns `status: not_ready`, call `build_or_update_graph_tool()` and continue. 2. Call `detect_changes_tool(detail_level="minimal")` for risk-scored changed functions, test gaps and affected flows. Changes come from `git diff` against `HEAD~1`; if the argument names a file, pass it in `changed_files`. 3. Call `get_review_context_tool(detail_level="minimal")` when you need source snippets for the changed areas and `review_guidance` (untested functions, wide blast radius, inheritance changes). 4. For each untested high-risk function, confirm with `query_graph_tool(pattern="tests_for", target="<function>")`. 5. Use `detail_level="standard"` only for a high-risk item the minimal output leaves unclear. Do not load whole files unless a snippet is not enough. ## Report - Summary: one line - Risk: low, medium or high, from the blast radius - Issues: bugs, missing tests, style - Blast radius: impacted files and functions - Recommendations
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
a9c894db76a7full audit observations/trust-audit/skill/tirth8205__review-delta.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | a9c894db76a7 | SAFE | B | 89 | first audit |
Questions
What does the Review Delta skill do?
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Is Review Delta safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Review Delta access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Review Delta?
Its own instructions reference review_guidance. Dependencies are pinned to exact versions.
How current is this page?
The grade is for one exact copy of the source (a9c894db76a7), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.