Skip to content
Back to skills

Review Session

ASecurity

Review what changed in this session with RepoPilot before claiming work is done or that tests pass. Use after edits to tests, CI config, auth, or request handling, and whenever you are about to say "all tests pass".

  • 23 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsrustsecurity

Security analysis

A100/100

Scanned October 4, 2026

npx -y skills add MykytaStel/repopilot --skill review-session --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review Session?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Review Session
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mykytastel-review-session/badge)](https://www.skillsdirectory.com/skills/mykytastel-review-session)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: review-session
description: Review what changed in this session with RepoPilot before claiming work is done or that tests pass. Use after edits to tests, CI config, auth, or request handling, and whenever you are about to say "all tests pass".
---

# Review the session with RepoPilot

RepoPilot compares the repository with the snapshot taken when this session
started. It is deterministic and local: the same change gives the same answer.

1. Run `repopilot review --since-snapshot`.
2. Read `Decision`, then the `Definitely sensitive` and `Maybe sensitive` lists.
3. For every `integrity.*` signal — a focused, skipped, or removed test, a test
   that lost assertions, or a new suppression — either restore the check or
   state plainly in your reply why the change is intended. A green test run does
   not answer these signals: the run is what changed.
4. For security signals (auth check removed, untrusted input reaching a sink),
   confirm the guard still exists on that path or fix it.

Do not report the work as complete while a weakened check or a removed
safeguard is open and unexplained. Other sensitive signals, such as a changed
workflow or dependency, are context for the reviewer: mention them, but they
do not need to be undone.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…