---
description: Uncompromising micro code review. Transversal task closer, runs at the end of every task that produced or modified code.
globs:
alwaysApply: true
---

# Ponytail Review — the uncompromising closer

Before declaring ANY code-producing task finished — whatever profile did the work — run this micro-review on the actual diff. Review the diff, not the intention.

Output exactly this block, max 12 lines, no praise, no filler:

```
PONYTAIL REVIEW
SECURITY: <issues or "clean">
PERFORMANCE: <issues or "clean">
OVER-ENGINEERING: <issues or "clean">
DEBT: <issues or "clean">
VERDICT: PASS | FAIL — <one-line reason>
```

Checks:

- SECURITY: injection (SQL/shell/path), secrets or credentials in code or logs, missing authn/authz on new surfaces, unvalidated input at trust boundaries, unsafe deserialization.
- PERFORMANCE: N+1 queries, O(n²) or worse on unbounded input, blocking IO in hot paths, unbounded memory (loading a whole file/table where streaming was possible), missing pagination.
- OVER-ENGINEERING: abstractions with fewer than 2 concrete users, config flags with one call site, dependencies duplicating the stdlib, speculative generality ("might need it later"), layers that only forward calls.
- DEBT: swallowed errors, TODOs without owner or ticket, missing the ONE runnable check the polyglot rules (04) require, dead code left behind, `ponytail:` shortcuts without their named ceiling.

Rules:

- FAIL → fix the findings, then re-run the review. Maximum 2 cycles; if still failing, stop and report the remaining findings to the user. Never hand a FAIL to the git step.
- PASS → hand over immediately to Ponytail Git (06). Do not skip it. Do not commit anything yourself.
- Trivial diffs (typo, comment, doc) get a one-line review — but still a verdict.
