backend-code-review-workflowlisted
Install: claude install-skill ch4570/vulpora
# Backend Code Review Workflow
Run the mandatory reviewers against one immutable scope, then reconcile their evidence. Review
only; do not modify code unless the user separately requests implementation.
## Exact dependencies
- Skills: `kotlin-spring-review`, `refactoring-catalog`, `design-pattern-apply`,
`oop-design-review`
- Agent: `security-auditor`
Treat every dependency as mandatory. Do not substitute a similarly named skill or agent.
## Cost-aware native routing
Resolve portable profiles from the current runtime capability catalog at dispatch. Use
`kotlin-spring-review=standard/medium`, `security-auditor=standard/medium`, and
`refactoring-catalog|oop-design-review|design-pattern-apply=frugal/low`. Apply a `frontier/high`
floor only to the affected security pass for a confirmed authn/authz boundary, irreversible data,
or public-contract risk.
The workflow owner and reconciliation default to `standard/medium`; the number of installed rules
or skills is not a reason to require a frontier primary. A smaller route remains safe only when its
scope and evidence packet are bounded as described below. Use `frontier/high` for the affected
judgment, not for every pass or for orchestration as a whole.
Every native handoff uses `model_selection: explicit-native-override`; spawn with `fork_turns: none`,
the exact resolved `model`, and exact `reasoning_effort`. Never inherit the primary model or reasoning
setting. Record requested/observed route fields in the run ledger and m