skip to content
// registry

Every workflow, source included_

Limited beta · read-only GitHub access

// live today

Two live workflows.

security-review · default

One repository pass. Findings with evidence.

Read the source

goal-security-review

Threat model → parallel goals → two independent judges.

Read the source

Public and MIT-licensed at github.com/midkernel/playbooks. The app runs exactly these files.

// what a workflow is

A manifest and instructions.

The manifest selects the pipeline. The instructions define the review and report. The app runs these public files.

// how the catalogue grows

Curated, not crowdsourced.

New workflows will enter the registry when they declare what they do, produce evidence-backed reports on real code, and have a maintainer who answers issues. Contributions will be reviewed in public once the registry opens; contributed workflows will be evaluated before they appear here.

Talk to us about contributing
// profiles

Choose how hard it looks.

profilemodelsdefault time per stagecreditsuse it for
lowa fast modelup to 30 min10pull requests, triage
balanceda stronger modelup to 1 h25repository reviews
maxthe strongest modelup to 2 h50releases, audits

Fixed credits per run. Default time limits apply to each stage; adjustable before starting.

// planned
// planned
A wider catalogue — authentication and authorisation reviews, API abuse, smart-contract classes, infrastructure code — is planned as the registry opens. Categories on this page will only ever list workflows you can actually run.
// faq
What is a workflow?

A file in a public repository: metadata that names the workflow plus instructions that tell the agents how to review. The two you can run today — security-review and goal-security-review — are open source at github.com/midkernel/playbooks. Read one before you run it.

Can I run workflows without Midkernel?

The workflows are public — github.com/midkernel/playbooks — and designed to be readable and forkable. The hosted runner is how Midkernel executes them; a self-serve open runner is planned but that repository is not public yet.

Can I use a private workflow?

Not yet. Private forks of registry workflows are planned; today every customer runs the public workflows as published.

Who maintains them?

Midkernel maintains the two current workflows in the open, at github.com/midkernel/playbooks. Third-party workflows will name their maintainers when the registry opens to contributions.

Can I submit one?

Write to hello@midkernel.com. Contributions will be reviewed in public once the registry is open; contributed workflows will be evaluated before they appear in the catalogue.

Read one, then run it.

Limited beta · read-only GitHub access