PlugMyPlugin
โ† Browse

review-agent-governance

wshobson โ˜… 242

This plugin gates PR reviews, issue comments, merges, CI workflow edits, and other sensitive review-surface actions behind mandatory human approval, using Cedar policies and Ed25519-signed receipts for audit compliance. It prevents AI agents from taking unvetted actions that affect code review integrity and other contributors by requiring an explicit approval flag or slash command before high-impact tool calls execute.

Security DevOps free runs shell

Install

> /plugin marketplace add wshobson/agents/tree/HEAD/plugins/review-agent-governance
> /plugin install review-agent-governance

Source: https://github.com/wshobson/agents/tree/HEAD/plugins/review-agent-governance

What it's made of

2 commands ยท 1 agent ยท 1 skill ยท 2 hooks

Commands
2
Agents
1
Skills
1
MCP servers
0
Hooks
2 ยท PostToolUse, PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
evaluate.sh sign.sh
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (wshobson).