review-agent-governance
Requires human approval before an AI agent can post PR reviews, merge, or write to CI configuration.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for review-agent-governance, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Claude Code plugin that requires an explicit human approval signal before an AI agent can post PR reviews or comments, merge, or write to CI configuration. It gates high-impact repo/CI actions behind a human check, joining protect-mcp and signed-audit-trails as agent-governance controls on the action path.
Key features and capabilities
- Human approval gate for PR actions
- Blocks unattended merges/CI writes
- Agent governance controls
Use cases
- Require human sign-off on agent merges
- Protect CI config from agent writes