This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review
Adam Moussa 537e83975b Rewrite nightly sweep as two-tier clean-clone auto-discovery
Replace the opt-in sweep-targets allowlist with zero-wiring discovery: enumerate org
repos via the GitHub REST API (curl + read-only GH_TOKEN, no gh dependency) and mirror
each as a shallow clean clone (git clone --depth=1, default branch from the API) into
~/repo-mirrors. Scanning server-side clones keeps local .env secrets out of scope.

Tier 1 runs deterministic scanners over every repo nightly ($0 Claude); tier 2 runs the
agentic pass over a budget-bounded round-robin rotation with a persistent cycle pointer,
so the draw on the shared Max limits stays bounded and coverage never goes silently
incomplete (COVERAGE ALARM if the rotation falls behind). Skip = committed marker or
central list (marker-skips logged). Redact secrets from Slack; reports mode 600. Raise
the systemd timeout to 6h for the longer two-tier run.
2026-06-16 15:00:00 -04:00
..
hooks Make security-review hooks and skill installable from the repo 2026-06-16 15:00:00 -04:00
skill Make security-review hooks and skill installable from the repo 2026-06-16 15:00:00 -04:00
systemd Rewrite nightly sweep as two-tier clean-clone auto-discovery 2026-06-16 15:00:00 -04:00
DEPLOY-R720.md Tune checkov severity, wire npm audit, add CI backstop + R720 runbook 2026-06-15 15:57:34 -04:00
finding.schema.json Make security-review hooks and skill installable from the repo 2026-06-16 15:00:00 -04:00
install-hooks.sh Make security-review hooks and skill installable from the repo 2026-06-16 15:00:00 -04:00
nightly_sweep.sh Rewrite nightly sweep as two-tier clean-clone auto-discovery 2026-06-16 15:00:00 -04:00
README.md Add security-review gate (review.sh + scanners + pre-commit hook) 2026-06-15 15:52:15 -04:00
review.sh Make security-review hooks and skill installable from the repo 2026-06-16 15:00:00 -04:00
sweep-targets.txt Rewrite nightly sweep as two-tier clean-clone auto-discovery 2026-06-16 15:00:00 -04:00

security-review

The Sea Haven security-review gate. One pure-code script (review.sh), many triggers. See memory project-security-review-agent for the full design.

Pieces

  • review.sh — merges deterministic-scanner findings + agent findings, dedups, applies suppressions (justification required), and makes the block decision (no agent decides). Exit 1 = BLOCK.
  • hooks/pre-commit + install-hooks.sh — fast scanners-only hook for a target repo.
  • The agentic detector/verifier pass is the interactive /sh-security-review slash command (~/.claude/commands/sh-security-review.md), schema at ~/.claude/security-review/finding.schema.json.

Triggers (one script, many entry points)

  • On-demand (primary): run /sh-security-review in a Claude Code session (Max-covered), have it write its schema JSON, then review.sh --agent-findings out.json <repo> to gate.
  • Pre-commit: install-hooks.sh <repo> — fast deterministic scanners abort the commit early.
  • CI (Phase 3): the same review.sh runs headless as the unbypassable backstop.

Scanners

review.sh runs whatever is installed and logs the rest with install commands (no silent skips). Currently wired: cfn-lint. To give the deterministic layer teeth, install:

pipx install semgrep        # SAST: injection / authz / xss
brew install gitleaks       # hardcoded secrets
pipx install pip-audit      # vulnerable Python deps
pipx install checkov        # IaC / IAM misconfig

Each needs a small normalizer added to review.sh (map its JSON to the finding schema) when installed.

Status

review.sh gate validated against the local testbed: 16 findings, correct dedup of distinct same-CWE findings, suppression-without-justification rejected and surfaced, BLOCK on confirmed crit/high.