Field note · Build v1

The reviewer becomes a pack

Situation. The security reviewer role had done one job and done it well. Its prompt was full of my company: our token model, our tenant column, our deploy script, our secret names. Useful to me, useless to anyone else, and impossible for anyone else to tell me where it was wrong.

What happened. Over a Sunday the role was taken apart into what any team needs and what only Blankitt needs. The first part became five skills in a public repository, in the same shape as the most-installed skills pack for coding agents, which has no security step: write the threat model for a service, review changes against it, audit the secrets, gate the release, and a setup skill that works out how a repository ships. The second part became two files in our own repository that the skills read. Every skill keeps one rule: it reads and reports, and it writes nothing but its own report. The reviewer that found the inbound-report hole on Friday now runs from the public skills plus those two files, which is how I will know the pack still works: it either finds what the old prompt found, or it does not. The pack’s engineering half is scaffolded and installable; the half for people who run systems rather than write them is listed and empty, and stays that way until each skill has been run against a real host.

Next. Install it on the DMARC repository and run each skill against last week’s review. Any gap between what the old role found and what the new skills find is a bug in the pack, and the first issue on its tracker.

Spend in October 2026: £45.00. Spend to date: £45.00. As of 11 October 2026. Cost tracker.

Search

Filter results by project and type.