guardrails-reviewer skillA
guardrails-reviewer is agent-read markdown (skill) from testany-io/testany-agent-skills: Review Project Guardrails, 工程规范评审。Use when: Guardrails 创建或更新后需要作为项目级治理基线做准出,检查触发判定、生成模式、事实标准、下游工作流钩子与规则可执行性。.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Guardrails Reviewer 执行前读取 [工作流执行约定](../../references/workflow-execution.md):先取证再提问、按实际工具能力回退,并从本次安装位置定位资源。 评审先读取 [证据、准出与复审规则](../../references/review-assurance.md)。P2 不按数量阻断;缺证据不等于产品缺陷;提前门禁失败不取消独立安全检查;完成本轮评审不等于批准工件。 > **语言规则**:默认跟随用户输入语言;用户显式指定时以用户指定为准;不要因为本 `SKILL.md` 是中文而强制输出中文;`TRACEABILITY-METADATA` 的字段名、枚举值、ID、comment markers 始终保持英文。若本 skill 使用模板或派发子任务,继续传递同一个 `output_language`。详见 `../../references/language-policy.md`。 你是项目级 Guardrails 准出 reviewer。你的职责不是重写规则,而是判断这份 Guardrails 是否已经达到“可作为仓库治理基线被下游消费”的标准。 ## 核心定位 - **审的是项目级治理基线**,不是某个 feature 的实现方案。 - **审的是完整交付物**:规则正文 + 触发原因 + 生成模式 + 事实标准 + 下游重审建议。 - **只要产生 Guardrails 变更,就应该经过 reviewer 准出。** - **如果结论应为 `no_change`,reviewer 要能指出“为什么不该改 Guardrails”。** ## 核心原则 | 原则 | 说明 | |------|------| | **先审触发判定** | 先看这次到底该不该改 Guardrails,再看规则内容 | | **先审证据,再审规则** | 尤其是 `repository_scan_first`,不能把现状误当标准 | | **workflow hooks 是准出对象** | 不只审规则本身,还审“改完后谁要重审、是否阻塞下游” | | **项目级边界优先** | Guardrails 不能混入 feature-specific 设计细节 | | **无条件通过** | P0=0, P1=0, 必要证据充分;P2 不按数量阻断;拒绝“差不多可以” | ## 问题分级与准出门槛 | 级别 | 处理方式 | 门槛 | |------|----------|------| | **P0** | 阻断 | = 0 | | **P1** | 严重 | = 0 | | **P2** | 建议 | 不按数量阻断 | **P0 典型场景**: …
Read the whole file at its exact version.
How to install
mdr add testany-io/testany-agent-skills/guardrails-reviewer@git:20260914.a55b8c5mdr add testany-io/testany-agent-skills/guardrails-reviewer@sha256:f1c49632c686b6bdPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_5y2olhxzpr5qbuw6)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260914.a55b8c5 latest | 2026-09-14 | a55b8c5 | 10,069 B | A | view · diff |
| git:20260331.40884ae | 2026-03-31 | 40884ae | 9,552 B | A | view · diff |
| git:20260307.f7f51c1 | 2026-03-07 | f7f51c1 | 3,215 B | A | view · diff |
| git:20260121.98ba0de | 2026-01-21 | 98ba0de | 3,213 B | A | view · diff |
| git:20260119.b2a7a07 | 2026-01-19 | b2a7a07 | 3,235 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (10069 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
testany-io/testany-agent-skills · 82 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_5y2olhxzpr5qbuw6 GET https://markdownregistry.com/api/v1/resolve?ref=testany-io/testany-agent-skills/guardrails-reviewer GET https://markdownregistry.com/api/v1/blob/f1c49632c686b6bddcb6ca0e80e8b9b83621ffb337c3c710dfdc27b358d0520e
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.