security-hardening-review-opslisted
Install: claude install-skill F-e-u-e-r/opus-pack
# Security-hardening review operations
How the PR #83 skill-vetting campaign was run — reviewer orchestration and
delivery-governance lessons, most surfaced by the maintainer steering the
process. These are **project observations and applications**, not replacements
for the installed `cross-model-review`, `delegation-and-review`, and
`operational-rigor` doctrine; the stop-condition and model-selection rules defer
to those (OPS-1/3/4/5/7/12 cite a canonical rule), while OPS-2/6/8/9/10/11 are marked
project observations with no canonical counterpart. Evidence note: unlike the
other three skills, several OPS incidents are **history-only, sourced from the
session transcript and the gitignored `internal/gate-b-2026-07-25/` ledger —
NOT independently repo-verifiable**; the canonical-rule citations (to the
installed skills) and the `reviews/2026-07-25-skill-vetting-*.md` design records
DO resolve.
## Reviewer orchestration
### OPS-1 — one pass under-samples; run ≥2 blind passes per family
- **Trigger:** treating a single reviewer pass (even a strong model at max
effort) as full coverage of a family's lens.
- **Do:** run at least two independent, mutually-blind passes per reviewing
family. A **pass** = one reviewer result; a **campaign round** = one packet →
fix cycle. A family's lens is "clean" only after two CONSECUTIVE passes surface
nothing new (delegation-and-review §3's miss-costly-audit rule — one clean pass
is not convergence); reset the counter whenever a pass f