The 2026-07-09 directory reorg moved this repo under seahaven/, but the
hook templates' default REVIEW_SH path still pointed at the old
location. Every install-hooks.sh --global run since then re-installed
hooks that fail open ("review.sh not found — skipping gate") on every
push. The live hooks on this machine were re-pointed manually
2026-07-15; this fixes the source so the next install doesn't regress.
Refs: INFRA-107
The pre-push/pre-commit hooks defaulted SH_REVIEW_SH to the orchestrator checkout
(orchestrator/security-review/review.sh). With the gate re-homed here, default to
$HOME/Documents/repositories/security-review/review.sh so push-time gating does
not lapse when orchestrator is deprecated. Live global hook re-pointed to match.
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.
Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.