security-review · default
One repository pass. Findings with evidence.
Read the sourceLimited beta · read-only GitHub access
security-review · defaultOne repository pass. Findings with evidence.
Read the sourcegoal-security-reviewThreat model → parallel goals → two independent judges.
Read the sourcePublic and MIT-licensed at github.com/midkernel/playbooks. The app runs exactly these files.
The manifest selects the pipeline. The instructions define the review and report. The app runs these public files.
New workflows will enter the registry when they declare what they do, produce evidence-backed reports on real code, and have a maintainer who answers issues. Contributions will be reviewed in public once the registry opens; contributed workflows will be evaluated before they appear here.
Talk to us about contributing| profile | models | default time per stage | credits | use it for |
|---|---|---|---|---|
low | a fast model | up to 30 min | 10 | pull requests, triage |
balanced | a stronger model | up to 1 h | 25 | repository reviews |
max | the strongest model | up to 2 h | 50 | releases, audits |
Fixed credits per run. Default time limits apply to each stage; adjustable before starting.
A file in a public repository: metadata that names the workflow plus instructions that tell the agents how to review. The two you can run today — security-review and goal-security-review — are open source at github.com/midkernel/playbooks. Read one before you run it.
The workflows are public — github.com/midkernel/playbooks — and designed to be readable and forkable. The hosted runner is how Midkernel executes them; a self-serve open runner is planned but that repository is not public yet.
Not yet. Private forks of registry workflows are planned; today every customer runs the public workflows as published.
Midkernel maintains the two current workflows in the open, at github.com/midkernel/playbooks. Third-party workflows will name their maintainers when the registry opens to contributions.
Write to hello@midkernel.com. Contributions will be reviewed in public once the registry is open; contributed workflows will be evaluated before they appear in the catalogue.