--- name: thermos description: "Run a deep independent review of a branch/diff before shipping: launch a security-and-correctness pass and a maintainability pass, then synthesize their findings into one verdict. Use for /thermos, 'thermos', 'thermo nuclear review', 'deep review', 'review this branch/PR before shipping', or a combined bug/security and code-quality audit. Read-only by default; does not modify code." license: MIT metadata: adapted-from: "cursor/plugins/thermos" version: "1.0.0" --- # Thermos (deep independent review) Run two thorough review passes over a branch's changes, then synthesize their results into one verdict. This is a review layer: **read-only by default. Do not modify code during review.** Fixes are a separate, explicitly-requested step (see "Fix mode" below). ## Workflow 1. **Scope.** Determine the review scope from the user request, the PR, the current branch, or the relevant changed files. 2. **Gather.** Collect the diff and enough file/context excerpts that reviewers can evaluate the change without guessing. Default base branch is `main`; run `git diff ...HEAD` and read the full contents of changed files. 3. **Run both passes in parallel.** Launch two independent reviewers via `invoke_sub_agent` (prefer the `general-task-execution` agent), in the same batch so they run concurrently. Give each the same scoped diff and file context. - **Security & correctness pass** — follow `references/security-correctness-review.md`. Bugs, breaking changes, security vulnerabilities, devex regressions, feature-flag leaks. Diff-scoped only. - **Maintainability pass** — follow `references/code-quality-review.md`. Abstraction quality, file-size growth, spaghetti conditionals, code-judo simplifications, boundary/type cleanliness. If parallel subagents are unavailable in the current environment, run the two passes sequentially yourself using the two reference rubrics; note that they ran sequentially. 4. **Ask each pass** to return prioritized findings with file:line references and evidence, calibrated honestly on severity. 5. **Synthesize.** After both finish, produce one unified verdict: findings first, deduplicated across the two passes. Weight findings raised by both more heavily. Resolve disagreements with your own judgment. Keep it brief. If per-pass summaries are already visible to the user, do not restate them wholesale; surface the unified verdict, the highest-signal findings, and any remaining uncertainty. ## Severity discipline Never over-report. If issues are flagged High when they are not, trust erodes. Trace each issue end-to-end and gain confidence before reporting. If a high-risk finding is the *intended* effect of the branch and the change is well-scoped, do not waste the author's time reporting it — unless they likely underweight the impact or the change looks malicious. ## PR discussion Do the independent audit first (fresh eyes). Only after that, if there are medium-or-higher findings and a PR exists, read the PR/MR discussion via `gh`/`glab` to incorporate BugBot or human threads: validate, dedupe, and attribute anything you fold in. ## Fix mode (opt-in, user-controlled) Default is review-only. Apply fixes only when the user explicitly asks ("thermos then fix the act-on findings", "apply the fixes"). Even then, route the actual change through the **poteto-mode** workflow (reproduce/verify), keep it scoped to the reported findings, and never auto-commit or auto-push. ## Kiro adaptation Cursor's `thermo-nuclear-review-subagent` and `thermo-nuclear-code-quality-review-subagent` (spawned via `Task` with `run_in_background: true`) are adapted to `invoke_sub_agent` calls whose rubrics live in this skill's `references/`. The two-pass-then-synthesize methodology and the read-only stance are preserved exactly.