
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Hostile first-reader pass on anything shipped, deemed done, or ready to ship. An agent with the skill writes the critique.
An installable skill for AI agents.
Check whether a newcomer can understand and use what you are about to ship.
Cold-eye is a readiness pass on anything shipped, deemed done, or ready to ship. An agent reads the skill and writes a critique. Verdict first, then a ranked list. The subject does not change.
Get started: pick the agent, install the skill, then run the sample checklist at coldeye.dev/docs/install.
Site: coldeye.dev
You wrote: “Install the package and launch the app.”
Cold-eye finds: the guide names the package but never gives the launch command. A new user cannot finish setup from the instructions given.
You get a ranked finding in the critique file:
**Verdict:** close
1. **F-001** · test 2 · invented
> Install the package and launch the app.
Cold reader: installs the package, then guesses a launch command or stops.
Put: The exact launch command on the next line, and what the reader sees when the app is running.
The guide itself is unchanged.
Save until-ready.md (or the checklist below), then ask:
Use Cold-eye on
until-ready.md. Follow the installed Cold-eye skill. Write the critique. Leave the checklist unchanged.
# Review until ready
Fictional procedure for desk-stamp notes. Labeled example.
1. Open `notes.md`.
2. Read every section.
3. Write findings next to the file as `notes.review.md`.
4. Repeat the review until ready.
The critique lands in until-ready.cold-eye.md. The checklist should be
unchanged. A finding should point at step 4, the unresolved “until
ready” condition. Wording varies by model. A critique alone does not
prove the skill loaded: check the agent's skill list, or ask it to
quote the first heading of SKILL.md.
A writable workspace is required. Package coldeye, skill folder
cold-eye.
npm supplies the skill files. It does not register the skill with the agent.
pnpm add -D coldeye
Copy node_modules/coldeye/skills/cold-eye/ into the same destination
the Get started page names for
your agent.
Updating the npm dependency does not refresh a folder you already copied. Copy again after you bump the package.
MIT. Copyright Catalyst Forge LLC.
FAQs
Hostile first-reader pass on anything shipped, deemed done, or ready to ship. An agent with the skill writes the critique.
The npm package coldeye receives a total of 63 weekly downloads. As such, coldeye popularity was classified as not popular.
We found that coldeye demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.