From 80d539178589f052abc97335f1efee47f934992c Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:55:01 -0400 Subject: [PATCH] Document the security-review subsystem in the root README The root README covered only the router and omitted the security-review/ subsystem entirely (Path A skill, review.sh gate, Path B nightly sweep, global hooks). Add a Security Review section summarizing both paths and linking the subsystem README + DEPLOY-R720 runbook. --- README.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/README.md b/README.md index bdc29bd..3f282c3 100644 --- a/README.md +++ b/README.md @@ -113,6 +113,16 @@ All connections authenticated under Composio user `amoussa`: The connector node is restricted to **one tool call per run** — a load-bearing rule learned from a 1.9M-token incident with meta-tool routing. +## Security Review + +The `security-review/` subsystem is a high-recall, anti-complacency security gate. It is **separate from the router** — it does not route through `run.py` or LangGraph. One pure-code script, `review.sh`, owns the **block decision** (confirmed critical/high → block); no agent decides. + +- **Path A — interactive:** the `/sh-security-review` Claude Code skill (Max-covered). Narrow fresh-context detector fan-out + a proof-or-kill verifier; emits the structured finding schema for `review.sh` to gate. +- **Path B — unattended:** a nightly two-tier sweep on the `sh-secrev` R720 VM. Tier 1 runs deterministic scanners (`review.sh --scanners-only`) over every Sea-Haven-Industries org repo; Tier 2 is a budget-bounded agentic pass (`run_headless.py`) on a round-robin rotation. Clean-clone auto-discovery via a read-only GitHub PAT; **ALARM-only** Slack (a clean night posts nothing). +- **Git hooks:** global pre-commit / pre-push hooks (`install-hooks.sh --global`) gate every local repo via `review.sh --scanners-only`. + +See `security-review/README.md` for full detail and `security-review/DEPLOY-R720.md` for the VM runbook. + ## Setup 1. Install dependencies: `pip install -r requirements.txt`