My Code Reviewer Scored a Nonexistent Directory 100/100 and Exited 0 A developer audited 34 agent skill packages and found that a code-review tool returned a 100/100 health score and exit code 0 after being passed a nonexistent path, scanning zero files while reporting 'safe to merge.' The audit also produced false negatives on five packages whose self-tests use a --selftest flag rather than a positional subcommand, revealing that two competing self-test conventions across the folder make harness invocation unreliable. The developer argues that a tool returning the same success status for 'nothing wrong' and 'nothing examined' cannot serve as a CI gate. Every skill package I ship — for Claude Code, Cursor, Codex, and a couple of agent marketplaces — has to clear one gate before publishing: its own selftest must exit 0. So this week I ran an audit over the 34 packages sitting in my skills folder to find out how many actually have that gate. The audit broke twice, in two different ways. Both breakages are the same bug wearing different clothes, and it's the bug that makes agent tooling untrustworthy the moment you put it in CI: a success signal that isn't attached to work actually done. Here's the whole thing, including the raw output. The script was not clever. Walk each package, find a script mentioning selftest , run python scripts/