Replace the opt-in sweep-targets allowlist with zero-wiring discovery: enumerate org repos via the GitHub REST API (curl + read-only GH_TOKEN, no gh dependency) and mirror each as a shallow clean clone (git clone --depth=1, default branch from the API) into ~/repo-mirrors. Scanning server-side clones keeps local .env secrets out of scope. Tier 1 runs deterministic scanners over every repo nightly ($0 Claude); tier 2 runs the agentic pass over a budget-bounded round-robin rotation with a persistent cycle pointer, so the draw on the shared Max limits stays bounded and coverage never goes silently incomplete (COVERAGE ALARM if the rotation falls behind). Skip = committed marker or central list (marker-skips logged). Redact secrets from Slack; reports mode 600. Raise the systemd timeout to 6h for the longer two-tier run. |
||
|---|---|---|
| .. | ||
| hooks | ||
| skill | ||
| systemd | ||
| DEPLOY-R720.md | ||
| finding.schema.json | ||
| install-hooks.sh | ||
| nightly_sweep.sh | ||
| README.md | ||
| review.sh | ||
| sweep-targets.txt | ||
security-review
The Sea Haven security-review gate. One pure-code script (review.sh), many triggers.
See memory project-security-review-agent for the full design.
Pieces
review.sh— merges deterministic-scanner findings + agent findings, dedups, applies suppressions (justification required), and makes the block decision (no agent decides). Exit 1 = BLOCK.hooks/pre-commit+install-hooks.sh— fast scanners-only hook for a target repo.- The agentic detector/verifier pass is the interactive
/sh-security-reviewslash command (~/.claude/commands/sh-security-review.md), schema at~/.claude/security-review/finding.schema.json.
Triggers (one script, many entry points)
- On-demand (primary): run
/sh-security-reviewin a Claude Code session (Max-covered), have it write its schema JSON, thenreview.sh --agent-findings out.json <repo>to gate. - Pre-commit:
install-hooks.sh <repo>— fast deterministic scanners abort the commit early. - CI (Phase 3): the same
review.shruns headless as the unbypassable backstop.
Scanners
review.sh runs whatever is installed and logs the rest with install commands (no silent skips).
Currently wired: cfn-lint. To give the deterministic layer teeth, install:
pipx install semgrep # SAST: injection / authz / xss
brew install gitleaks # hardcoded secrets
pipx install pip-audit # vulnerable Python deps
pipx install checkov # IaC / IAM misconfig
Each needs a small normalizer added to review.sh (map its JSON to the finding schema) when installed.
Status
review.sh gate validated against the local testbed: 16 findings, correct dedup of distinct same-CWE findings, suppression-without-justification rejected and surfaced, BLOCK on confirmed crit/high.