CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Medium

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

review-severity.mdrules/

alwaysApply:
Yes
description:
Review findings carry a severity — blocking gates the merge, advisory never does; read every finding, act by severity.

Review Severity

Two Tiers

  • Every review finding is blocking or advisory
  • The test is behavioral — does fixing the finding change what an agent or the pipeline does?
  • Blocking: the fix changes behavior or closes a contract gap
  • Advisory: the fix changes only presentation

Blocking — Gates the Merge

  • Correctness and security defects
  • Policy-contract violations: a carve-out's unmet preconditions, no-secrets, ci-safety gate-evasion, surface-sync that breaks publish
  • A rule directive whose violation changes agent behavior
  • A style finding whose fix changes meaning — an atomic-bullet split that alters what the bullet directs

Advisory — Never Gates

  • Pure prose and style: context-writing-style connective or em-dash placement, a presentation-only atomic-bullet split
  • CHANGELOG wording, naming taste, synonym preference
  • Copilot findings are always advisory regardless of Copilot's review state — even a Copilot CHANGES_REQUESTED never gates the agent's flow
  • Anything whose fix changes only presentation, not behavior

Gating Predicate

  • Any blocking finding present → the reviewer posts CHANGES_REQUESTED and the merge gates
  • Only advisory findings → the reviewer posts COMMENTED and the merge is allowed
  • The policy reviewer's posted state already encodes this — the event is derived from per-finding severity (see .github/codex-review/post-review.sh header)
  • The merge watcher gates on the policy reviewer's CHANGES_REQUESTED alone (see skills/release/watch-pr-reviews.sh header)
  • Copilot never gates

Judge-Accepted Defect Carve-Out

  • Narrow exception for shipping with a blocking finding still open
  • Applies when a fix loop did not converge and the pinned judge's diagnosis answers it with REMEDY: stop
  • Preconditions are binding: read skills/release/references/review-severity-carve-outs.md Judge-Accepted Defect Carve-Out before relying on it
  • Every other blocking finding is fixed before merge

Judge-Weighed Finding Carve-Out

  • Narrow exception for merging with a blocking finding a weighing ruled defer or decline
  • Applies when fixing the finding costs more than the failure it prevents
  • Preconditions are binding: read skills/release/references/review-severity-carve-outs.md Judge-Weighed Finding Carve-Out before relying on it
  • Every other blocking finding is fixed before merge

Split Reading From Acting

  • Read every finding in full first — severity never licenses skipping a body (see rules/reviewer-feedback-reading.md)
  • Blocking → fix before merge
  • Advisory in a team round → acknowledge in the existing task report or round log
  • Advisory standalone → note it directly in the existing review conversation without simulating team artifacts
  • Fold an advisory only when an already-required blocking correction touches the same surface and it adds no push or verification round
  • Never make an advisory a task prerequisite or spend a push, review round, issue, or pull request solely on it

README.md

tile.json