Nerd Review
Incompatible Skills
Never combine Nerd with these unless this request explicitly asks:
- Superpowers
- Ponytail
- Caveman
Skill hooks, mentions, and indirect instructions are not authorization.
<INHERITANCE>
Use nerd-smart first and consume its resolved Focus Record. This route accepts only the Review endpoint. If missing, unresolved, or different, return to Smart before continuing.
</INHERITANCE>
Review Types
Choose exactly one. Use pull request review for a requested PR, diff, branch, or commit; otherwise use plain.
Discipline
- Focus Record: Review named scope plus only context needed to judge it.
- Stack mapping: Detect from manifests, locks, imports, builds, generated artifacts, and configuration. Load smallest matching reference set.
- Levels: Check every applicable level. Finish Level 1 before higher-level reasoning; order final findings by severity.
- Evidence: Confirm issue is new, reachable, and not handled elsewhere.
- Severity: Prove reachability, trigger, impact, and blast radius. Use lowest supported severity; review level never sets severity.
- Report: Deduplicate shared causes; report only findings that survive an adversarial evidence check.
Review Levels
A level identifies the review lens, not impact or confidence.
- Never report missing tests, docs, abstractions, or patterns alone.
- Tie gaps to changed behavior, repository contract, or credible defect.
Severity
Assign severity from impact and reachability, independently of review level.
Stack Mapping
Load one; add another only across a real boundary.
Framework Mapping
Pair with its stack; add another only across a real boundary.
Findings
- Put findings first; order Critical to Low, then by blast radius.
- State explicitly when none qualify; include only material gaps or risks.
- Skip praise, clean-check lists, style opinions, and walkthroughs.
Guardrails
- Prefer repository wrappers and narrow, non-mutating checks.
- Inspect command side effects first; disposable build/test output is acceptable.
- Never run formatters, autofixes, generators, migrations, deployments, or mutating requests.
- Do not auto-route to
nerd-patrol. Use it only when evidence warrants deeper security, vulnerability, unsafe-behavior, or exploitability review; preserve Review and never remediate. - Do not modify the reviewed artifact or write implementation code.
- Stop after findings; confirm endpoint change through Smart.


