Document the security-review subsystem in the root README
The root README covered only the router and omitted the security-review/ subsystem entirely (Path A skill, review.sh gate, Path B nightly sweep, global hooks). Add a Security Review section summarizing both paths and linking the subsystem README + DEPLOY-R720 runbook.
This commit is contained in:
parent
c217c5656d
commit
80d5391785
1 changed files with 10 additions and 0 deletions
10
README.md
10
README.md
|
|
@ -113,6 +113,16 @@ All connections authenticated under Composio user `amoussa`:
|
|||
|
||||
The connector node is restricted to **one tool call per run** — a load-bearing rule learned from a 1.9M-token incident with meta-tool routing.
|
||||
|
||||
## Security Review
|
||||
|
||||
The `security-review/` subsystem is a high-recall, anti-complacency security gate. It is **separate from the router** — it does not route through `run.py` or LangGraph. One pure-code script, `review.sh`, owns the **block decision** (confirmed critical/high → block); no agent decides.
|
||||
|
||||
- **Path A — interactive:** the `/sh-security-review` Claude Code skill (Max-covered). Narrow fresh-context detector fan-out + a proof-or-kill verifier; emits the structured finding schema for `review.sh` to gate.
|
||||
- **Path B — unattended:** a nightly two-tier sweep on the `sh-secrev` R720 VM. Tier 1 runs deterministic scanners (`review.sh --scanners-only`) over every Sea-Haven-Industries org repo; Tier 2 is a budget-bounded agentic pass (`run_headless.py`) on a round-robin rotation. Clean-clone auto-discovery via a read-only GitHub PAT; **ALARM-only** Slack (a clean night posts nothing).
|
||||
- **Git hooks:** global pre-commit / pre-push hooks (`install-hooks.sh --global`) gate every local repo via `review.sh --scanners-only`.
|
||||
|
||||
See `security-review/README.md` for full detail and `security-review/DEPLOY-R720.md` for the VM runbook.
|
||||
|
||||
## Setup
|
||||
|
||||
1. Install dependencies: `pip install -r requirements.txt`
|
||||
|
|
|
|||
Reference in a new issue