kill-argument
Two-thread adversarial review: a fresh reviewer constructs the strongest 200-word rejection memo, then a second fresh reviewer defends the paper point-by-point and surfaces still-unresolved critical issues
Install / Use
npx skills add wanshuiyin/Auto-claude-code-research-in-sleep --skill kill-argumentInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of kill-argument
kill-argument scores 98/100 on our quality scale, 81st of 2,855 Development & Engineering skills we index (top 3%).
Its SKILL.md is 24 KB long, well organised into 25 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
With 16,644 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 9 days ago, so kill-argument is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
kill-argument compared with similar skills
All 4 of these similar skills score higher than kill-argument; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| kill-argument (this skill)by wanshuiyin | 98 | 16.6k | 9d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.8k | 12d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | 1d ago | CLAUDE.md |
| rufloby ruvnet | 100 | 73.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.1k | today | CLAUDE.md |
Frequently asked questions
- How do I install kill-argument?
- Run
npx skills add wanshuiyin/Auto-claude-code-research-in-sleep --skill kill-argument. The install tabs above show the steps for each supported agent. - Which AI agents does kill-argument work with?
- It is written for OpenAI Codex, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is kill-argument safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is kill-argument still maintained?
- The repository was last updated 9 days ago, so kill-argument is actively maintained.
Skill content
View source on GitHubname: kill-argument description: "Two-thread adversarial review: a fresh reviewer constructs the strongest 200-word rejection memo, then a second fresh reviewer defends the paper point-by-point and surfaces still-unresolved critical issues. Use when user says "kill argument", "adversarial review", "hostile review", "rebuttal preparation", "reviewer-2 simulation", or before submitting a theory paper that has already passed standard review rounds." argument-hint: "[paper-directory]" allowed-tools: Bash(*), Read, Write, Edit, Grep, Glob, mcp__codex__codex
Kill Argument Exercise: Adversarial Attack-Defense Review
🔒 Do not wrap this skill in
/loop,/schedule, orCronCreate. It is verdict-bearing — it produces an adversarial accept/reject verdict (attack → adjudication). Re-firing it on a wall-clock timer adds no new signal (the attack changes only when the paper changes). Schedule the external wait that precedes it — draft stable → then run this once before submission. Seeshared-references/external-cadence.md.
Stress-test the headline claims of a paper against the strongest possible rejection argument: $ARGUMENTS
Why This Exists
Standard score-based reviews (/research-review, /auto-paper-improvement-loop) tend to produce balanced weakness lists. Each weakness gets ~equal attention, ranked CRITICAL > MAJOR > MINOR. Empirically, this misses one specific failure mode: the single most damaging argument a reviewer would write in a rejection paragraph — the one sentence that, if a senior area chair reads it, kills the paper.
A balanced reviewer might list "scope-overclaim risk" as MAJOR alongside 3-5 other MAJORs, never quite committing. An adversarial reviewer must commit: their entire job is to convince the area chair to reject in 200 words.
This skill runs that adversarial pass deliberately, then forces a second fresh reviewer to defend point-by-point, classify each rejection as already-fixed / partially-fixed / still-unresolved, and surface what's actually load-bearing.
Empirical motivation: in a real submission run, after several rounds of standard improvement (score 7-8/10), the kill-argument exercise surfaced framing weaknesses that no prior review caught (e.g., a setting being mostly conditional rather than truly general, or a baseline being irrelevant to real systems). Author rebuttal forced explicit scope qualifications in abstract and discussion that weren't visible from the score-based reviews alone.
How This Differs From Other Review Skills
| Skill | What it asks the reviewer | Output |
|-------|---------------------------|--------|
| Standard peer review | "Score this paper, list weaknesses by severity" | balanced weakness list |
| /research-review | "Deep technical review of methods + claims" | structured deep critique |
| /proof-checker | "Is this theorem actually proved?" | per-step proof obligation audit |
| /paper-claim-audit | "Does the paper report numbers truthfully?" | per-claim evidence verification |
| /citation-audit | "Are citations real and used in correct context?" | per-entry KEEP/FIX/REPLACE/REMOVE |
| /kill-argument | "Write the single strongest rejection paragraph; then defend it." | attack memo + per-point defense + unresolved surfaced |
This skill is complementary, not a replacement. Run after standard reviews when you want to know what the worst-case reviewer paragraph would look like, before camera-ready or rebuttal preparation.
When To Use
- After 1-2 rounds of
/auto-paper-improvement-loopsettled at a stable score, but before submission. Surfaces what additional fixes would close the headline-attack gap. - During rebuttal preparation, to predict reviewer-2's strongest objection so you can prepare the response in advance.
- For theory papers with a high-level title that may oversimplify the actual theorem (the most common reject-attack pattern).
- For papers where a reviewer might attack scope, assumption-vs-claim mismatch, missing proof obligations, or evidence-vs-headline gaps.
This skill is most valuable for theory papers with ≥5 theorem-class environments (so the headline depends on real proof obligations). For empirical papers without theorems, use /research-review instead.
Constants
- REVIEWER_MODEL =
gpt-6-astra(default;gpt-5.5is the capability fallback,gpt-5.4only as an explicit legacy override). Reviewer reasoning effort =ultrafor the attack / defense / adjudication threads (deep-audit tier; capability fallback pershared-references/reviewer-routing.md, never belowxhigh). Beast-mode axis probes stay atxhigh. - CONTEXT_POLICY =
fresh(REVIEWER_BIAS_GUARD). Each thread is a freshmcp__codex__codexcall. Never usemcp__codex__codex-reply. No prior review summary, fix list, or executor explanation enters either prompt. - ATTACK_LENGTH = approximately 200 words (do not exceed 250). Single coherent argument, not a list.
- DEFENSE_DECOMPOSITION = 3-7 atomic rejection points extracted from the attack memo. Each gets its own classification.
- CLASSIFICATION =
answered_by_current_text/partially_answered/still_unresolved. (Names chosen so the adjudicator does not assume "fixed" implies prior history of patching — they read the paper as a fresh reviewer would.) - OUTPUT =
KILL_ARGUMENT.md(human-readable) +KILL_ARGUMENT.json(machine-readable) in the paper directory. - RENDER_HTML = true — When
true(default), auto-renderKILL_ARGUMENT.mdto HTML after writing the report. Uses full Codex review gate (audit-class artifact — full render-fidelity check matches the skill's cross-model audit invariant; the sidecarKILL_ARGUMENT.jsonis also passed to the renderer). Setfalseto skip, or pass— render html: false.
Workflow
Step 1: Discover paper files
Locate the paper directory and inventory the source.
PAPER_DIR="$ARGUMENTS" # e.g., paper-overleaf/ or paper/
cd "$PAPER_DIR"
# Find the LaTeX entry point
ENTRY=$(grep -lE '^\\documentclass' *.tex 2>/dev/null | head -1)
echo "Entry: $ENTRY"
# Find all source files codex should read
find . -name "*.tex" -not -path "./.git/*" 2>/dev/null
find . -name "*.bib" -not -path "./.git/*" 2>/dev/null
find figures/ -name "*.pdf" -o -name "*.png" 2>/dev/null
ls -la *.pdf 2>/dev/null # compiled PDF
If a compiled PDF is missing, the skill should still run on .tex source alone, but the prompt should mention this so the reviewer doesn't waste cycles trying to extract from a non-existent PDF.
Step 2: Attack memo (Thread 1, fresh codex)
Invoke mcp__codex__codex (NOT codex-reply) with the following prompt structure:
mcp__codex__codex:
model: gpt-6-astra
config: {"model_reasoning_effort": "ultra"}
sandbox: read-only
cwd: <paper directory>
prompt: |
You are simulating a hostile NeurIPS / ICLR / ICML reviewer for a paper.
This is a kill-argument adversarial check — your task is NOT to give a
balanced review but to construct the **single strongest argument for
rejecting this paper**.
## Files to read
- LaTeX entry: <ENTRY>
- All section files under sections/ or wherever they live
- Macro files (math_commands.tex, etc.)
- Compiled PDF: <main.pdf> (if available)
Read the source carefully. Do not consult any prior reviews, fix lists,
or summaries; this must be a fresh, zero-context adversarial pass.
## Your task
Construct the single best argument to reject this paper in approximately
200 words. Your goal is to write the worst-case rejection memo a senior
NeurIPS area chair would produce after reading the paper.
Focus on these axes (pick the most damaging combination, do not list all):
1. Theorem validity: are central theorems actually proved as stated?
2. Assumption-vs-claim mismatch: does the body silently retreat to a
narrower object than the title/abstract advertise?
3. Missing proof obligations: is a fundamental lemma invoked but not
proved (e.g., concentration, generic position, prefactor envelope)
that the headline depends on?
4. Limit-order ambiguity: are limits in K/n/d/eps composed in a way the
paper does not commit to?
5. Claim-vs-evidence gap: is the empirical/numerical evidence too narrow
to support the breadth of the stated theorem or take-away?
6. Scope overclaim: does the title or abstract sell a result substantially
broader than what the body proves?
## Constraints
- Approximately 200 words total (do NOT exceed 250).
- Single argument, not a list — pick the most damaging line of attack
and develop it.
- Cite specific file:line locations or equation numbers when accusing.
- Tone: dispassionate but uncompromising. Do NOT hedge. Do NOT acknowledge
mitigations the paper might have made elsewhere. This is the rejection
paragraph; the defense gets the next pass.
- Do NOT reference prior review rounds, fix lists, or any context outside
the current paper files.
Output: just the rejection memo, nothing else.
Save the returned threadId for the trace; do NOT pass it to Thread 2. Save the attack memo verbatim — both Thread 2 and the human-readable report use it.
Step 2.5 (optional, beast effort): multi-axis attack fan-out
Default OFF. The deliverable of this skill is a verdict — the single
strongest rejection paragraph — and
shared-references/fan-out-pattern.md
is explicit: do not fan out the verdict; fan out only the evidence that
feeds it. The default single-commitment attack (Step 2) is deliberate —
forcing one paragraph produces sharper feedback than a balanced list (see Why
This Exists). Do not replace it with a list.
Under beast effort you may widen the evidence the commitment draws on
without diluting the commitment:
- Axis probes (evidence breadth). Run the six attack axes (theorem
validity / assumption-vs-claim / missing obligation / limit-order /
claim-vs-evidence / scope-overclaim) as separate fresh-codex probes,
each asked for the strongest ~120-word thrust on that axis alone. These
are evidence-gathering, not the verdict. Probes run at
xhigh(notultra) — six serial delegating calls would multiply cost for evidence that the ultra-tier commit re-judges anyway.- These are NOT Claude subagents, and there is deliberately NO
Agentgrant. Each probe is a freshmcp__codex__codexcall — the adversary must be cross-model (non-Claude). Codex MCP is serial (concurrent codex calls hang), so the probes run sequentially — Tier-3 in the fan-out ladder. This is exactly whykill-argumentlists noAgentinallowed-tools: it spawns nothing; it threads codex calls.
- These are NOT Claude subagents, and there is deliberately NO
- Commit (the verdict, still single). A final fresh-codex synthesis reads the six probes plus the paper and must commit to the single most damaging ~200-word rejection paragraph — selecting and fusing at most two axes, NOT listing all six. The Step-2 commitment requirement is unchanged; the probes only ensure no axis was overlooked before committing.
The adjudication (Step 3) then runs against this committed attack exactly as in
the default flow. Cost: beast adds ~6 extra serial codex calls — use it for
the final pre-submission pass on a high-stakes paper, not routinely.
Tracing: record each probe's threadId (axis_probe_thread_ids[]) and the
synthesis threadId in the trace, the same way Steps 2–3 save their thread
ids. The committed attack memo, not the six probes, is what Step 3 consumes.
Step 3: Adjudication memo (Thread 2, fresh codex with attack + paper)
Invoke a second mcp__codex__codex call (still NOT codex-reply — Thread 2 is independent of
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
85.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.4k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.1kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
