Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors)…
Scores
88 out of 100 · grade A
2026-08-22
Works
40% of the score
100/100
Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score
100/100
no commits in the last 12 weeks
Adopted
20% of the score
52/100
6,784 stars on the source repo.
Documented
15% of the score
81/100
3,226 words with worked examples.
Loads cleanly. Every structural check Claude Code needs to register this passed. Last commit today.
What it says it does
Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors) severity/attack_vector/exploitability, and writes the final REPORT.md + REPORT.sarif. Spawned by the c-review skill orchestrator only.
Every number above came out of reading the file and its repository. Nothing is a judgement call, nothing is a model’s opinion, and nothing can be paid for. The full method is published. Source last committed 2026-08-21.
Also in trailofbits/skills
Other artifacts published from the same repository.
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.