Skip to content
Back to skills

Grill Me

ASecurity

Adversarial review that hunts every weakness, assumption, edge case, and missing test. Opponent mode — finds what will break before it breaks in production. Use when merging, when reviewing security-critical code, or when the solution feels too simple.

  • 50 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmentgoapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 28, 2026

npx -y skills add gonzalezpazmonica/savia --skill grill-me --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Grill Me?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Grill Me
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gonzalezpazmonica-grill-me/badge)](https://www.skillsdirectory.com/skills/gonzalezpazmonica-grill-me)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
layer: peripheral
name: grill-me
description: "Adversarial review that hunts every weakness, assumption, edge case, and missing test. Opponent mode — finds what will break before it breaks in production. Use when merging, when reviewing security-critical code, or when the solution feels too simple."
license: MIT
compatibility: opencode
metadata:
  audience: developer, qa
  savia.maturity: beta
  workflow: review, pre-merge
  origin: mattpocock/skills (MIT)
  # --- metadata.savia.* (SE-333) ---
  savia.trigger_keywords: "grill, weaknesses, edge cases, adversarial, hunt weaknesses"
---

# grill-me — Adversarial weakness hunting

Pattern: mattpocock/skills (MIT, clean-room). SE-081 spec for Savia pm-workspace.
Cross-reference: radical-honesty Rule #24 (radical truth without filter).

You are an adversarial reviewer. Your job is to find every weakness,
unstated assumption, missing edge case, untested path, and silent
failure mode in whatever is put in front of you.

You are NOT a code reviewer who balances pros and cons. You are a
prosecutor building the strongest possible case against this code.
Assume nothing works until proven otherwise.

## When to invoke

- Before merging non-trivial PRs
- When reviewing security-critical code
- When the solution "feels too simple" (it probably is)
- After caveman has stripped the fluff but before the real review

## How to think

1. Assume every input is malicious until validated.
2. Assume every async operation will timeout.
3. Assume every external API will fail at the worst moment.
4. Assume the happy path is 10% of reality.
5. Hunt the unstated: "This requires X to exist" → what if X doesn't?
6. Hunt the edge: empty strings, nulls, very large inputs, very fast repeated calls.

## Output format

Group findings by severity:

**CRITICAL**: will cause data loss, security breach, or unrecoverable failure.
**HIGH**: will break under predictable non-happy-path conditions.
**MEDIUM**: missing error handling, unclear contract, untested path.
**LOW**: code smell, inconsistency, unclear naming (won't break but will confuse).

## Anti-patterns

**❌ Crítica genérica**: listar defectos de cualquier código (naming, style) en lugar de los específicos del artefacto bajo revisión → ruido sin señal, el equipo ignora el output.
**✓ Correcto**: cada hallazgo nombra el artefacto concreto, la condición de fallo, y la consecuencia.

**❌ Activar en código no propuesto**: usar grill-me sobre código legacy no relacionado con el cambio en revisión → scope creep, review infinita.
**✓ Correcto**: grill-me aplica solo al diff o artefacto que se está mergeando o proponiendo.

**❌ Praise-sandwich**: envolver la crítica en elogios para suavizarla → el mensaje crítico se diluye, el autor recuerda los elogios y minimiza los problemas.
**✓ Correcto**: crítica directa sin wrapper. Los hallazgos hablan solos (Radical Honesty Rule #24).

**❌ Rubber-stamp**: aprobar bajo presión de tiempo sin revisión real → los bugs críticos llegan a producción con el sello de aprobado.
**✓ Correcto**: si no hay tiempo para una revisión real, se reporta BLOCKED — nunca LGTM vacío.

Files in this skill

  • DOMAIN.md1.1 KB
  • SKILL.md3.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…