Owner adversarial review
Owner Mode for AI agents, implemented as Agent Skills: domain judgment, deliberate choice, and responsibility for work that must hold up in real use.
npx -y skills add XHdW/owner-mode --skill owner-adversarial-reviewAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 16 days oldThe repository was created 16 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Adversarial review: use when the user invokes $owner-adversarial-review or requests adversarial or multi-agent review; or when current evidence suggests a concrete material failure mechanism, false-pass path, or overlooked alternative in an identifiable direction, assumption, design, implementation, experiment plan, evidence package, or completion claim, with enough consequence to change direction, scope, completion, or a hard-to-reverse decision.
SKILL.md
5.2 KB, as published. Nobody here has run it
Owner Adversarial Review
Construct the strongest artifact-specific, falsifiable case that an identifiable target could fail while appearing sound. Preserve the user's goals, values, authority, risk boundaries, and final product decision.
Bind the Verdict to a Target
Name the proposition or artifact under attack, the claim it is meant to support, and the review window:
- Direction: whether a proposed path solves the wrong problem, depends on an unwarranted belief, or ignores a materially different route.
- Design or implementation: whether a mechanism, interface, state transition, integration, recovery path, or experiment plan fails under a concrete condition.
- Evidence: whether tests, metrics, reviews, or observations can pass while the claimed behavior remains false.
- Completion: whether substantial work appears done while omitting the real workflow, a boundary, maintenance, recovery, or an essential hard part.
Bind artifact claims to a commit, diff, document version, exact file set, content identity, explicit design proposition, or another reproducible snapshot. A materially changed target receives a new verdict. The target is sufficiently bound when another reviewer can inspect the same state and identify the same claim under attack.
Search Before Committing to an Attack
Inspect the raw target and available evidence before arguing. Prefer a proof, observation, experiment, test, use, or authoritative source whenever it can resolve the disputed claim directly.
Generate materially different candidate failure mechanisms privately, then select one. A candidate earns attention by connecting target evidence to a plausible trigger, a failure mechanism, material consequence, and a feasible observation that could refute it. Discard generic possibilities and rhetorical severity unsupported by an artifact-specific path.
Read references/attack-lenses.md when the strongest mechanism is unclear or the target is cross-boundary, high consequence, or capable of false passing. Use the lenses to widen candidate search, then keep only the strongest attack.
Before selection, inspect whether the review window, attack lens, or admissible evidence makes an outcome-relevant failure class invisible or predetermines the verdict. Include one materially different frame when it could change the attack, then return to the target.
Steelman the selected failure case:
What is the strongest concrete way this target could fail while appearing successful?
The attack is ready for adjudication when it states the load-bearing claim, snapshot evidence, trigger-to-consequence mechanism, and cheapest discriminating observation.
Choose Independence by Decision Value
Use an internal challenge when direct evidence can resolve the dispute and perspective separation is unlikely to change the attack. Use one fresh-context challenger when anchoring, hidden interactions, or the implementer's context could plausibly change the verdict.
Give the challenger the smallest self-sufficient package containing the user outcome, bound target, observable success conditions, current evidence, material unknowns, and user-set goals, values, non-goals, authorization, data boundaries, and risk constraints. Withhold the main agent's defense, implementation preference, suspected answer, and persuasive framing while preserving the user's intent. Require one strongest specific and falsifiable attack grounded in the target, plus the cheapest observation that could refute it.
For an explicit multi-agent request or a major unresolved dispute that warrants separate adjudication, read references/multi-agent-protocol.md. If fresh context is unavailable, perform the strongest internal attack and identify it as internal.
Resolve Against Evidence
Test the selected attack through the cheapest decisive reality check available within the current authorization. Classify every substantive claim as sustained, refuted, unresolved pending named evidence, or a user-owned value or risk choice. Evidence outranks consensus.
Act on the verdict within the current authorization: change a failed direction or repair a sustained defect; gather available evidence for an unresolved factual claim; preserve the target when the attack is refuted; or return the evidence-backed verdict and named next action for review-only work.
The review is complete when every substantive attack claim is classified and every authorized, decision-changing action is completed or surfaced to the user. Reopen only for new evidence, a materially changed target, or a new load-bearing hypothesis. Keep the review machinery internal unless it changes direction, scope, risk, or the completion claim.