Review
Explicit readonly review of one frozen target with durable all-lens evidence
$review-phase is an explicit-only readonly workflow graph. Its bootstrap recomputes one route,
loads exactly one flat gate, persists that gate's outcome, then stops or re-enters the router. One
completed review freezes the smallest certain target, evaluates every mandatory lens once, retains
one immutable report, returns routing evidence, and stops. Delivery owns every repair, debugging,
debt, documentation, and closeout transition.
Use it for a delivery Git/diff target or a standalone plan, spec, or documentation bundle. External GitHub and Codex PR reviewer integration is a separate capability.
Invocation Boundary
Delivery persists review_due context and stops. The operator explicitly invokes $review-phase
with that context; delivery does not invoke the skill itself. Review retains its report, returns
review_routed, and stops. Delivery resumes only through a separate explicit invocation that
consumes the retained routing output. Standalone callers invoke review directly and receive the
same retained report contract without a delivery resume. Standalone callers enter review_due
with accepted bounds and a supported target before normalization and the mode-specific guard.
Runtime Graph
The router is the only runtime route authority. It evaluates failures, budget exhaustion, operator checkpoints, conflicts, missing context, delivery-owned states, retained completion, and the four executable gates in one ordered table. Each trace loads the bootstrap, router, and exactly one selected gate. Gate-specific references load only when that gate needs them.
Target Adapters
Review expands to the full repository only when the caller requests that scope.
- Delivery Git/diff: record locator, actual base, merge-base or fixed-point SHA, head or dirty identity, inclusive scope, and canonical patch hash.
- Standalone artifact bundle: freeze selected plan, spec, or documentation bytes in deterministic order; record locator, ordered file identities, inclusive scope, ordered bundle hash, and the absence of a Git fixed point. The normalized target does not embed raw bytes.
Both adapters enter the same review graph and use the same lenses, report, routing, and freshness rules. Standalone mode never reads or changes delivery counters.
Four Gates
prepare-reviewvalidates bounds and target before any budget decision, reconstructs retained delivery ordinals, freezes target and governing-source bytes, and writesreview_running. Standalone review reads no delivery counter.run-reviewinvokes$autoreviewonce, runs Standards, skill adherence and scoped skills, architecture, simplify, and Spec against the same snapshot, parent-verifies candidates, runs bounded readonly validation, and writes one immutable local report. Missing required RED/GREEN evidence is a finding, not work for review to create.retain-reportvalidates the report schema, identities, freshness, uniqueness, commit envelope, and retained-ref containment. A fresh retry reuses the same local report instead of rerunning lenses.return-routerevalidates retained authority, derives one route from report findings, writes the returned routing outcome, and stops. A separate explicit delivery invocation consumes it.
Gate files never load siblings directly. Every nonterminal outcome returns through the router.
Runtime Handoff And Cold Resume
Delivery appends review-owned review-handoff-v1 records to the validated caller-provided delivery
handoff, so it creates no second delivery authority. Standalone review writes one deterministic
repository-local handoff at
.devpunks/review-phase/handoffs/<review_lineage_id>/<review_run_id>.md. Standalone handoffs remain
uncommitted and outside the reviewed bytes and report-retention envelope.
Each complete record carries phase, status, scope, artifact locators and hashes, validation, review state, next-route suggestion, blockers, and resume identity. On cold resume, direct current evidence outranks fresh workflow artifacts, which outrank the latest applicable handoff; route suggestions remain lowest authority. Conflicting records cannot authorize another append.
Stateful gate exits and retained-ref checkpoints write a record when storage and run identity are valid. Already-authoritative exhaustion, not-due state, pre-storage failures or blockers, conflicts, and identical terminal rediscovery are explicit idempotent no-write outcomes.
Skill-Adherence Evidence
Review compares plan implementation_skill_guidance, unchanged worker guidance, and exactly one
IMPLEMENTATION-NOTES.md record per guidance item. Each record identifies the skill, uses
loaded, applied, or not_applicable, and points to how and where it was assessed. Review checks
every claim against the frozen changed artifacts; missing, extra, and contradicted claims are
findings.
Durable Report
Completed reports live under Project Review Reports at:
apps/wiki/content/docs/project/reviews/<review-scope-slug>-<UTC>-<snapshot12>-review-report.md
The report records identity, bounds, normalized target, snapshot and source hashes, explicit lens outcomes, stable findings, routing, and validation. Its contents become immutable at creation. A local report consumes no delivery review until its commit is present on a verified retained ref.
Delivery Routing And Budget
Routing precedence is:
- Runtime evidence routes to debugging.
- Other in-scope blockers route to implementation.
- Broad architecture debt routes to debt follow-up and may remain secondary beside either route above.
- With no blocker, route to documentation ingest or closeout.
Delivery may retain reviews 1, 2, and 3, each opening at most its corresponding durable repair
epoch. Resume of an already recorded review_run_id reuses that route without another increment.
Resume, rebase, commit, retry, handoff, and same-goal bounds revision preserve lineage and counters.
Only an explicitly new delivery goal with materially changed accepted bounds resets them.
Fixes 1 and 2 must return to review_due. Fix 3 proceeds only to the required focused validation.
Failure stays in repair epoch 3; success records the clean delivery handoff linked to immutable
review 3. There is no review 4. A later delivery review invocation returns
review_budget_exhausted without creating a report or changing state, includes exact current-route
evidence, and cannot block clean continuation.
Failure Boundary
Retryable pre-retention or partial failure returns to review_due without a report or counter
change. Retryable retention failure stays report_retention_pending and reuses the complete local
report while target and source hashes remain fresh. Invalid bounds, unsupported targets, and
non-retryable contract or infrastructure failures enter review_failed with exact evidence and no
completed pass.