{ "source": "cso", "tree": "review", "public_mode": "Security", "mode": "security", "mandatory": true, "visibility": "primary", "replacement": "$review --mode Security --module cso", "source_path": "cso/SKILL.md.tmpl", "base_sha": "bb57306d98c97011b0919c6132705a15b1579781", "blob_sha": "413fb099597b55dadca116e45a202aa693a94b74", "normalized_render_sha256": "59017ba27aaa93a62bda7ddca3c995f7231edb3fa86009e555b724b43fc1afd7", "target": "skills/review/references/legacy/cso.md", "overlays": [ 679, 2030 ], "contract": { "question_order": "Preserve the source workflow order; gather prerequisites before consequential questions.", "pressure": "Preserve the source forcing questions, recommendation pressure, and one-question-at-a-time cadence.", "smart_skips": "Skip only when the source condition is false, and name every skipped module with evidence.", "stop_approval_gates": "Preserve every STOP, hard gate, approval boundary, and no-mutation-before-approval rule.", "evidence": "Ground conclusions in inspected code, commands, browser/device observations, or source artifacts.", "artifacts": "Produce every report, plan, log, screenshot, manifest, or handoff required by the source.", "mutation": "Use the source mutation boundary; never broaden writes, commits, pushes, merges, or deploys.", "exit": "Preserve source completion checks, unresolved-decision reporting, and explicit blocked exits.", "voice": "Direct builder voice; match the user language and retain source-specific tone constraints." } }