Doubt-driven review
Non-trivial when
- Branching logic or cross-module boundary changes
- Properties types/compiler cannot verify
- Irreversible deploy, migration, or public API change
When not to use
- Renames, formatting, obvious one-liners
Cycle
- CLAIM — decision + why it matters (2-3 lines)
- EXTRACT — artifact + contract only (no reasoning journey)
- DOUBT — fresh review with adversarial prompt ("find issues, do not validate")
- RECONCILE — classify: contract misread / actionable / trade-off / noise
- STOP — trivial findings only, 3 cycles max, or user says ship
Reviewer input
Pass ARTIFACT + CONTRACT only—not your CLAIM (avoids agreement bias).
Reconcile precedence
- Contract misread — fix contract, re-run
- Valid actionable — change artifact
- Valid trade-off — document explicitly
- Noise — note and move on
Optional second opinion
Offer cross-model or codex review for high stakes; user decides. Never silent skip.
Related
verify-before-done, test-first-development (RED step as behavioral doubt), gstack/review (post-hoc PR)