Ask before reviewing code someone else wrote

Commit

peyton-alt21h ago

A review loads the checkout's hooks, MCP servers, skills, and settings, so reviewing a teammate's branch runs whatever that branch configures. Reviews of your own commits (authored and committed by your user.email, counted from your default branch, never from --base) run as before. Anything else needs approval: a terminal confirm that lists what would run, or --trust-target <full sha> pinned to the head. Agents and non-terminal callers get a fixed refusal telling them to ask the user. --show-config lists what would run without running it.

The inventory reads agent config with exact JSON keys (as the agents do) and matches the commit tree case-insensitively (as a macOS or Windows checkout loads it); symlinks and unparseable files count as unknown.

With --target, the profile is chosen and the branch pinned in the caller's checkout, the pinned commit's tree is inspected, and only then is the worktree added (no checkout, no hooks), verified against the pin, and checked out: for someone else's branch with no git hooks, LFS smudge, or submodule recursion, and no .worktreeinclude copy. The re-run inside the worktree reads review settings from the caller's checkout and skips the gate only when the forwarded SHA matches its head.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Entire-Checkpoint: 01M473E034J2GNM6R18TH84MC3 Entire-Checkpoint: 01M47493FFMT3CG642S1JYEGYR Entire-Checkpoint: 01M474HXWPRC0WWMJBMZ892JY7 Entire-Checkpoint: 01M474JDBKTNMVGZDXJTNSHPB4 Entire-Checkpoint: 01M479ZDX6HB3GG7DRBR36G5DP

Checkpoints

Code Review Trust and Security Gates

Claude CodeOpus 5.5
View session
Checkpoint 1
Checkpoint 3
Checkpoint 4
Checkpoint 5

Document the Review Trust Gate

Claude CodeOpus 5.5
View session
Checkpoint 2