# Review Agent Setup > Configura un gating humano para las acciones de revisión de agentes IA en Claude Code, con un rastro de aprobación auditable criptográficamente y gates aplicados con Cedar. Fuente: https://skillsagentes.com/skills/wshobson/agents/review-agent-setup Markdown: https://skillsagentes.com/skills/wshobson/agents/review-agent-setup.md Repositorio: https://github.com/wshobson/agents Autor: wshobson Licencia: MIT Actualizado: hace 2 meses Coste de contexto: 68 tok instalada, 1.4k tok al activarse, 1.4k tok con todos los archivos del bundle Bundle: 1 archivo, 5 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add wshobson/agents --skill review-agent-setup --agent claude-code # Cursor npx -y skills add wshobson/agents --skill review-agent-setup --agent cursor # Codex npx -y skills add wshobson/agents --skill review-agent-setup --agent codex # Gemini CLI npx -y skills add wshobson/agents --skill review-agent-setup --agent gemini # Windsurf npx -y skills add wshobson/agents --skill review-agent-setup --agent windsurf # Cline npx -y skills add wshobson/agents --skill review-agent-setup --agent cline ``` ## Qué hace - Gatea acciones de revisión de agentes IA (reviews, comentarios, merges de PR, ediciones de CI) tras aprobación humana explícita - Genera un recibo firmado con Ed25519 por cada intento, aprobado o denegado - Aplica una política Cedar que deniega incondicionalmente las acciones de superficie de revisión salvo ventana de aprobación abierta - Ofrece comandos slash /approve-review y /list-pending para gestionar aprobaciones y ver denegaciones recientes - Permite verificar toda la cadena de recibos offline con npx @veritasacta/verify ## Cuándo usarla - El agente revisa, comenta o mergea pull requests con gh pr review/merge - El agente triagea issues, publica releases o modifica configuración de CI - El agente hace push a ramas protegidas (main, master, release, production) - El agente publica en superficies externas como webhooks de Slack o Discord ## Cuándo no - El agente solo edita archivos locales y ejecuta tests (usa protect-mcp en su lugar) ## Qué la activa - "Configura aprobación humana antes de que el agente apruebe PRs" - "Necesito un registro auditable de las revisiones que hace mi agente" - "Quiero bloquear que el agente mergee a main sin mi visto bueno" ## Antes de instalar - Requiere instalar el plugin review-agent-governance, copiar la política Cedar al proyecto y crear un directorio de recibos con clave de firma. - Necesita en el PATH: npx - Variables de entorno: TOOL_INPUT, TOOL_NAME - reads environment config ## Archivos - SKILL.md — 5 KB ## SKILL.md Reproducido tal cual desde wshobson/agents bajo MIT. Esta sección es el documento original y está en inglés. # review-agent-governance — Setup Gate AI agent review actions (PR reviews, comments, merges, CI edits) behind explicit human approval. Every attempt, approved or denied, produces an Ed25519-signed receipt. ## When to use this plugin Install it in projects where a Claude Code agent: - Reviews, comments on, or merges pull requests (`gh pr review`, `gh pr merge`) - Triages issues (`gh issue comment`, `gh issue close`) - Publishes releases (`gh release create`) - Modifies CI configuration (`.github/workflows/`, `.gitlab-ci.yml`) - Pushes to protected branches (`main`, `master`, `release`, `production`) - Posts to external notification surfaces (Slack webhooks, Discord), once you add a rule for the command that posts (the default policy does not gate them) If the agent is only doing local file edits and running tests, this plugin is overkill. Use `protect-mcp` for general tool-call policy enforcement and skip this one. ## One-time setup ### 1. Install the plugin ```bash claude plugin install wshobson/agents/review-agent-governance ``` ### 2. Copy the default policy to your project ```bash cp .claude/plugins/review-agent-governance/policies/review-agent-governance.cedar \ ./review-governance.cedar ``` You can edit this file to match your project's specific rules. See `../agents/review-policy-author.md` for guidance on authoring review policies. ### 3. Create a receipts directory and sign key ```bash mkdir -p ./review-receipts echo "/review-receipts/" >> .gitignore echo "/review-governance.key" >> .gitignore echo "/.review-approved" >> .gitignore if [ ! -e ./review-governance.key ]; then d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./review-governance.key fi ``` protect-mcp 0.7.4 `sign` does not create the key, so the last command creates it, and it never replaces an existing key. Without a key, the receipts are unsigned. To rotate the key, archive `./review-governance.key` and `./review-receipts/receipts.jsonl` first, then run the command again. Give auditors the `publicKey` value from `./review-governance.key`. Do not commit the file, because it also holds the private key. ## Per-session workflow The Cedar policy denies review-surface actions unconditionally. To approve a specific action, open an approval window before it and close it after. ### Flag file (simplest) ```bash # Before the action you want to approve touch ./.review-approved # Let Claude Code run the review / comment / merge # Immediately after rm ./.review-approved ``` ### Slash command (from within Claude Code) ``` /approve-review "Reviewing PR #123 authored by contributor X" ``` This creates `./.review-approved` with the given reason embedded as a note, and records the reason in an unsigned approval log under `./review-receipts/approvals/`. A follow-up `rm` is still needed to close the window. ### Dry-run everything (force full policy evaluation) If you want every tool call to go through Cedar with no approval bypass: ```bash export REVIEW_APPROVAL_FLAG=./.never-approve ``` Any tool call matching a forbid rule will be denied; approved windows have no effect. Useful for CI or for a locked-down audit run. ## Verifying the receipts List all receipts: ```bash ls -la ./review-receipts/ ``` Verify every receipt offline with the public key: ```bash PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./review-governance.key")).publicKey') npx @veritasacta/verify@0.9.2 --replay-chain ./review-receipts/receipts.jsonl --key "$PUB" ``` Exit 0 means every receipt verified. Exit 1 means a receipt failed verification, because it was tampered with, the key is wrong, or a line is malformed. Exit 2 means the receipts file could not be read. A denied call never runs, so it has no receipt. To see what the policy blocked, run this inside Claude Code: ``` /list-pending ``` It lists the tool calls that the PreToolUse hook blocked in the current session, with the tool name and the command or path. ## Example: approving a PR review ```bash # 1. Human reviews the agent's proposed comment $ /list-pending Blocked in this session: - Bash "gh pr review 42 --approve --body 'LGTM'" - Bash "gh pr comment 42 --body 'Looking good'" # 2. Human decides the first one is appropriate, approves it $ /approve-review "Approving LGTM on PR 42 after visual inspection" ./.review-approved created # 3. Agent retries the action; this time it succeeds $ agent: gh pr review 42 --approve --body "LGTM" [receipt appended to ./review-receipts/receipts.jsonl, decision=allow] # 4. Human closes the window $ rm ./.review-approved ``` The allowed call has a signed receipt that anyone with the public key can verify offline. The denied attempt has no receipt, and the approval log is not signed, so keep both in mind when you show the trail to an auditor. ## Composing with protect-mcp If both plugins are installed, each plugin's `hooks/hooks.json` registers its own PreToolUse hook, and Claude Code runs both on every tool call: ```json { "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" } ``` Each `evaluate.sh` reads `tool_name` and `tool_input` from the hook payload on stdin (Claude Code sets no `TOOL_NAME` variable) and evaluates its own policy: `./protect.cedar` for protect-mcp and `./review-governance.cedar` here. Both hooks must pass for the tool call to proceed. Cedar deny in either policy blocks it. ## Standards - **Ed25519** — RFC 8032 (digital signatures) - **JCS** — RFC 8785 (deterministic JSON canonicalization) - **Cedar** — AWS's open authorization policy language - **IETF draft** — [draft-farley-acta-signed-receipts](https://datatracker.ietf.org/doc/draft-farley-acta-signed-receipts/) ## Dónde encaja - Categoría: [Seguridad](https://skillsagentes.com/categorias/seguridad.md) — Auditorías, revisión de dependencias, manejo de secretos y modelado de amenazas. - Creador: [wshobson](https://skillsagentes.com/creators/wshobson.md) — 183 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Hermes Tweet](https://skillsagentes.com/skills/wshobson/agents/hermes-tweet.md): Instala y opera Hermes Tweet, un plugin de Hermes Agent para investigar X/Twitter, leer timelines, analizar tweets y ejecutar operaciones privadas o de cambio de estado con aprobación previa. - [Superself](https://skillsagentes.com/skills/wshobson/agents/superself.md): Úsalo cuando un proyecto guarda su estado en Superself: lee `self context` al iniciar sesión, vincula el trabajo a una work unit, reporta con evidencia y registra decisiones confirmadas. - [Grounded Vault](https://skillsagentes.com/skills/wshobson/agents/grounded-vault.md): Úsalo para mantener un almacén Markdown de conocimiento donde cada afirmación compilada se rastrea hasta una fuente inmutable y el drift se detecta con git diff sin gastar tokens. - [Postgresql Table Design](https://skillsagentes.com/skills/wshobson/agents/postgresql-table-design.md): Úsalo al diseñar o revisar un esquema específico de PostgreSQL: buenas prácticas, tipos de datos, indexación, restricciones, patrones de rendimiento y funciones avanzadas. - [Prompt Engineering Patterns](https://skillsagentes.com/skills/wshobson/agents/prompt-engineering-patterns.md): Úsalo cuando pidan optimizar un prompt, mejorar su rendimiento, diseñar una plantilla, aplicar chain-of-thought, few-shot prompting o técnicas avanzadas de prompt engineering para producción. ## Skills relacionadas - [Binary Analysis Patterns](https://skillsagentes.com/skills/wshobson/agents/binary-analysis-patterns.md): Domina patrones de análisis binario: desensamblado, decompilación, análisis de flujo de control y reconocimiento de patrones de código en ejecutables. - [Sast Configuration](https://skillsagentes.com/skills/wshobson/agents/sast-configuration.md): Configura herramientas SAST (Semgrep, SonarQube, CodeQL) para detección automática de vulnerabilidades en el código, útil al montar escaneo de seguridad o adoptar DevSecOps. - [Pci Compliance](https://skillsagentes.com/skills/wshobson/agents/pci-compliance.md): Implementa los requisitos de PCI DSS para el manejo seguro de datos de tarjetas y sistemas de pago. Úsalo al asegurar procesamiento de pagos o lograr el cumplimiento PCI. - [Mtls Configuration](https://skillsagentes.com/skills/wshobson/agents/mtls-configuration.md): Configura mutual TLS (mTLS) para comunicación zero-trust entre servicios, incluyendo gestión de certificados y seguridad de comunicación interna. - [K8s Security Policies](https://skillsagentes.com/skills/wshobson/agents/k8s-security-policies.md): Implementa políticas de seguridad de Kubernetes, incluyendo NetworkPolicy, PodSecurityPolicy y RBAC, para seguridad de nivel productivo. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)