--- name: patch-review description: Review a pinned local Git patch for candidate security regressions with bounded offline analysis and analyst validation. --- # Patch security review Run `scripts/review.py review` with a local repository and base/head refs. Inspect the pinned commits, changed entrypoints, candidate paths, and unknowns. Validate each candidate's exploit preconditions and disconfirming evidence manually. A candidate is a prompt for investigation, not a confirmed vulnerability. Never execute source or tests from the reviewed repository as part of this workflow. Write reports only to a private directory controlled by the analyst. A recorded analyst identity is an unverified assertion; the package supplies no attestation.