Prompt file imported from zhenyumi/bio-agent-reference-pack (
.codex/prompts/review-diff.md). Copyright stays with the author.
Codex review prompt: reference-pack diff
Review the actual staged, unstaged, and relevant untracked changes. Use the approved scope in PLAN.md and the repository rules in AGENTS.md. Preserve concurrent work. Present actionable findings in severity order. Give precise file locations and the failing behavior. If you find no issues, say so. State material validation gaps without inventing risks.
Check the following contracts.
Source-first evidence
The pack locates original sources. It does not provide scientific summaries or reconstructed guidance.
- Reject invented APIs, versions, citations, and thresholds.
- Do not treat routing, prior outputs, project decisions, or successful imports as proof of scientific truth.
- Use downstream instructions for scope and operational constraints.
- Require applicable original evidence for factual claims.
One authored registry and route table
references.yaml uses schema 0.2. Sources own their facts. indexes/routes.yaml is the single authored navigation table.
- Check that IDs are unique.
- Check that aliases are direct and have no chains.
- Check that full portable projections preserve endpoints, review dates, document versions, related-source IDs, and unresolved records.
- Reject silent replacement of unresolved targets with related sources.
Closed compatibility projections
The legacy six-field catalog and generated maps derive from the authored registry and route table.
- Check that every mapped ID exists in the compatibility catalog.
- Check that omissions are explicit.
- Check that aliases inherit target facts.
- Do not let generated views become competing registries.
License and acquisition boundaries
Public access is not redistribution permission. Current acquisition is link-only. LICENSES.md records upstream observations. The user declines a root repository license.
- Check that license observations have evidence.
- Check that each observation uses the appropriate code, documentation, or unknown scope.
- Keep upstream full text, source trees, PDFs, archives, datasets, and retrieval caches out of commits and exports.
Truthful retrieval and reading
A complete bounded GET records exact raw bytes, extracted text, and a SHA-256 hash for each. It also records locators, URLs, UTC observations, headers, document version, and extractor identity. Verification is structural. It cannot prove comprehension or scientific validity.
- Keep evidence in the downstream ignored, untracked cache.
- Report unsupported, inaccessible, partial, and unknown states explicitly.
- Check that reading records bind actual read spans and per-claim citations to the text hash.
Actual environment observations
Declarations, installed metadata, remote or container scope, document version, static API observations, and live probes are distinct observations. Python inspection is static by default. R static inspection is unknown or unsupported.
- Check that fixed live probes disclose import or namespace execution.
- Reject arbitrary evaluation, package installation, and environment restoration.
- Reject claims that imply a successful analysis without evidence.
Safe host installation
- Check the description of shared DSH/Codex installation.
- Check the description of optional DSH-specific shadowing.
- Check the description of OpenCode's owned companion command.
- Require exact destination, safe-path, source-overlap, full-manifest, ownership-receipt, and unchanged-inventory checks before mutation.
- Check that force cannot adopt unknown or modified content.
- Check that update blocks on conflicts.
- Check that uninstall preserves foreign or modified files.
- Check that uninstall reports partial removal.
- Check that stage, backup, and journal recovery is bounded and verified.
- Reject universal crash-atomicity and adversarial-race claims.
Real previews and portable runtime
The installed helper uses only Python 3.10 or newer and the standard library. It resolves its pack relative to the skill. It needs no central checkout or absolute maintainer path. Automatic matching depends on the host.
- Check that dry runs and preflight create no exports, temporary files, bytecode, or network traffic.
- Distinguish DSH
/ref-bio, Codex$ref-bioor picker, and OpenCode/ref-bio.
Privacy and local development
- Keep secrets, private URLs, addresses, absolute local paths, identifiers, and raw data out of committed content.
- Keep local environments, caches, logs, generated outputs, exports, and reports out of committed content.
- Keep all tests, fixtures, evaluations, and their runner ignored and untracked under
.dev/. - Keep the former root tests absent.
- Keep required controls tracked:
- PLAN.md
- AGENTS.md
- references.yaml
- sources.lock.yaml
- indexes/
- policies/
- schemas/
- scripts/
- skills/
- .codex/
- Repository-owned .opencode/
Honest validation and authority
Clean-clone CI uses production validation and in-memory release preflight. Exports are separate steps.
The local suite is optional for a clean clone. A missing local runner causes an error.
Local update review is offline. The unimplemented --online mode exits nonzero.
Explicit link checking is a separate network operation.
The audit and approved scope authorize editing only.
They do not authorize staging, committing, pushing, publishing, or a review request.
Use the architecture guide to assess implementation and documentation consistency. Use the command reference and reading protocol for operational contracts. Check the exact CLI and result fields. Do not treat a design claim as implemented behavior.
