# Adversarial review: your context

Copy this file to CONTEXT.md next to SKILL.md and fill in every blank. Never put passwords, access keys or card numbers here.

## Independent reviewer

(Which model, tool or agent reviews the work. Prefer a different model family from the one that builds. If you only have one, write "fresh session, read-only tools".)
Example: a second model from a different vendor, run through its command-line tool with read-only permissions.

Reviewer:
Tools it may use (read-only):
How to dispatch it in parallel (one per section):

## Trigger phrases

(Extra words, in any language you use, that mean "review this before it locks".)
Example: "good to merge?", "sprawdź przed wdrożeniem".

Trigger phrases:

## Where reviews and audits are saved

(A folder in your repository, so reviews live next to the code they judge.)
Example: audits/

Review folder:
Invariant audit folder:

## Locked context

(The decisions every reviewer must respect: architecture choices, hosting, auth design, data model. Link the files that record them.)
Example: decisions/ folder in the repo; auth uses a hosted identity provider; one database per region.

Locked decisions:
Source-of-truth documents (specs, research):

## Money surfaces in your product

(Files, services or endpoints that move, count or record money or credits.)
Example: billing/ module, payment-provider webhook handler, usage-credit ledger table.

## Auth and session surfaces

(Login, token checks, session handling, permission checks, admin impersonation.)
Example: middleware/auth, OAuth callback route, API credential issuance endpoint.

## Tenant boundary

(How one customer's data is separated from another's, and where that separation is enforced.)
Example: every table has a workspace_id column; access policies filter on it.

## Tables and jobs that mutate shared state

(Background jobs, webhook handlers, migrations on busy or money-bearing tables.)
Example: nightly invoice job, order webhook handler, orders table.

## Property-testing library

(The library your stack uses for property-based tests.)
Example: Hypothesis for the Python backend, fast-check for the TypeScript frontend.

## Who signs off accepted residual risk

(The human who may accept a partial mitigation in writing.)
Example: the technical founder.
