risk-based-review skillA
risk-based-review is agent-read markdown (skill) from yeaight7/agent-powerups: Use when reviewing a PR or your own change plan and you need to decide how much scrutiny it deserves -- the diff touches auth, payments, crypto, migrations, or core shared code, or you are unsure where to focus limited review attention..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
## Purpose Not all code changes deserve the same level of scrutiny. A typo fix in a README is low risk; a change to the authentication middleware is critical. Allocate review attention based on the danger of the change, and state that judgment before giving feedback. ## When to Use - Reviewing a PR and deciding how deep to go - The diff touches auth, payments, cryptography, or database migrations - The change hits core business logic, shared utilities, or public APIs - Sanity-checking your own plan before implementing a sensitive change ## Inputs - The diff or PR under review (and its file list) - Repository access to inspect history and ownership of touched paths ## Workflow 1. **Size the change first.** Pull the file list and line counts so the risk call rests on real scope, not a guess. ```bash gh pr view --json files,additions,deletions # files touched + size gh pr diff --stat # per-file churn ``` 2. **Check churn and ownership on touched paths.** Frequently-changed or single-owner files raise risk. ```bash git log --oneline -10 -- path/to/changed/file # recent history …
Read the whole file at its exact version.
How to install
mdr add yeaight7/agent-powerups/risk-based-review@git:20260606.6c21432mdr add yeaight7/agent-powerups/risk-based-review@sha256:0b73a35e895e56b9Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_73zozs2gp2no2ja5)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260606.6c21432 latest | 2026-06-06 | 6c21432 | 3,647 B | A | view · diff |
| git:20260502.ede956a | 2026-05-02 | ede956a | 999 B | A | view · diff |
| git:20260502.d5844de | 2026-05-02 | d5844de | 138 B | B | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (3647 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
yeaight7/agent-powerups · 6 stars · license Apache-2.0 · pushed 2026-09-21 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_73zozs2gp2no2ja5 GET https://markdownregistry.com/api/v1/resolve?ref=yeaight7/agent-powerups/risk-based-review GET https://markdownregistry.com/api/v1/blob/0b73a35e895e56b98065a624268ea7697dd62d5ad4490fb2c8acfe8f7878f00d
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.