review-agent-setup
wshobson/agents
Gate AI agent review actions behind human approval with cryptographically signed receipts.
What is review-agent-setup?
Configure human-in-the-loop approval for AI agent actions on pull requests, issues, releases, and CI configuration in Claude Code. Use this when you need an auditable trail of who approved each agent action, enforced by Cedar policy rules.
- Gate PR reviews, comments, merges, and issue triage behind explicit human approval
- Generate Ed25519-signed receipts for every approval or denial attempt
- Enforce Cedar-based authorization policies for agent tool calls
- Support approval windows via flag files or slash commands
- Verify receipts offline using public-key cryptography
- Compose with protect-mcp for layered policy enforcement
How to install review-agent-setup
npx skills add https://github.com/wshobson/agents --skill review-agent-setup- Claude Code with plugin support
- Node.js and npx
- GitHub CLI (gh) if using GitHub-based actions
- protect-mcp 0.7.4 or later for key generation
How to use review-agent-setup
- 1.Install the plugin via npx skills add or claude plugin install
- 2.Copy the default Cedar policy file to your project root
- 3.Create a review-receipts directory and generate a signing key using protect-mcp
- 4.Before approving an agent action, create the .review-approved flag file or use /approve-review slash command
- 5.Let the agent run the gated action (PR review, comment, merge, etc.)
- 6.Immediately after, remove the approval flag to close the window
- 7.Verify receipts offline using the public key and @veritasacta/verify
Use cases
- Require human sign-off before an agent merges pull requests to protected branches
- Audit all agent comments and reviews with signed receipts for compliance
- Set up approval gates for CI configuration changes made by agents
- Create an approval log with reasons for each agent action in a regulated project
- Verify the integrity of agent actions in a security-sensitive repository
- Teams running AI agents in regulated or security-sensitive projects
- Projects requiring cryptographically auditable approval trails
- Maintainers who want to gate agent actions on protected branches
- Organizations needing compliance records of automated decisions
review-agent-setup FAQ
The Cedar policy denies the tool call before it runs. No receipt is created for denied calls. Use /list-pending to see what was blocked.
Archive the current review-governance.key and review-receipts/receipts.jsonl, then re-run the key generation command. Give auditors the new publicKey value.
Yes. Both plugins register PreToolUse hooks and Claude Code runs both. A tool call must pass both policies to proceed.
Set the environment variable REVIEW_APPROVAL_FLAG=./.never-approve. All tool calls will be evaluated against Cedar; approved windows have no effect.
Extract the publicKey from review-governance.key and run: npx @veritasacta/verify@0.9.2 --replay-chain ./review-receipts/receipts.jsonl --key "$PUB". Exit 0 means all receipts verified.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: review-agent-setup description: Configure human-in-the-loop gating for AI agent review actions in Claude Code. Use when setting up a project where an agent may post PR reviews, comments, merges, or edit CI configuration, and you want a cryptographically auditable approval trail with Cedar-enforced gates.
review-agent-governance — Setup
Gate AI agent review actions (PR reviews, comments, merges, CI edits) behind explicit human approval. Every attempt, approved or denied, produces an Ed25519-signed receipt.
When to use this plugin
Install it in projects where a Claude Code agent:
- Reviews, comments on, or merges pull requests (
gh pr review,gh pr merge) - Triages issues (
gh issue comment,gh issue close) - Publishes releases (
gh release create) - Modifies CI configuration (
.github/workflows/,.gitlab-ci.yml) - Pushes to protected branches (
main,master,release,production) - Posts to external notification surfaces (Slack webhooks, Discord), once you add a rule for the command that posts (the default policy does not gate them)
If the agent is only doing local file edits and running tests, this plugin is
overkill. Use protect-mcp for general tool-call policy enforcement and skip
this one.
One-time setup
1. Install the plugin
claude plugin install wshobson/agents/review-agent-governance
2. Copy the default policy to your project
cp .claude/plugins/review-agent-governance/policies/review-agent-governance.cedar \
./review-governance.cedar
You can edit this file to match your project's specific rules. See
../agents/review-policy-author.md for guidance on authoring review
policies.
3. Create a receipts directory and sign key
mkdir -p ./review-receipts
echo "/review-receipts/" >> .gitignore
echo "/review-governance.key" >> .gitignore
echo "/.review-approved" >> .gitignore
if [ ! -e ./review-governance.key ]; then
d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./review-governance.key
fi
protect-mcp 0.7.4 sign does not create the key, so the last command creates
it, and it never replaces an existing key. Without a key, the receipts are
unsigned. To rotate the key, archive ./review-governance.key and
./review-receipts/receipts.jsonl first, then run the command again. Give auditors the publicKey
value from ./review-governance.key. Do not commit the file, because it also
holds the private key.
Per-session workflow
The Cedar policy denies review-surface actions unconditionally. To approve a specific action, open an approval window before it and close it after.
Flag file (simplest)
# Before the action you want to approve
touch ./.review-approved
# Let Claude Code run the review / comment / merge
# Immediately after
rm ./.review-approved
Slash command (from within Claude Code)
/approve-review "Reviewing PR #123 authored by contributor X"
This creates ./.review-approved with the given reason embedded as a note,
and records the reason in an unsigned approval log under
./review-receipts/approvals/. A follow-up rm is still needed to close the
window.
Dry-run everything (force full policy evaluation)
If you want every tool call to go through Cedar with no approval bypass:
export REVIEW_APPROVAL_FLAG=./.never-approve
Any tool call matching a forbid rule will be denied; approved windows have no effect. Useful for CI or for a locked-down audit run.
Verifying the receipts
List all receipts:
ls -la ./review-receipts/
Verify every receipt offline with the public key:
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./review-governance.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./review-receipts/receipts.jsonl --key "$PUB"
Exit 0 means every receipt verified. Exit 1 means a receipt failed verification, because it was tampered with, the key is wrong, or a line is malformed. Exit 2 means the receipts file could not be read.
A denied call never runs, so it has no receipt. To see what the policy blocked, run this inside Claude Code:
/list-pending
It lists the tool calls that the PreToolUse hook blocked in the current session, with the tool name and the command or path.
Example: approving a PR review
# 1. Human reviews the agent's proposed comment
$ /list-pending
Blocked in this session:
- Bash "gh pr review 42 --approve --body 'LGTM'"
- Bash "gh pr comment 42 --body 'Looking good'"
# 2. Human decides the first one is appropriate, approves it
$ /approve-review "Approving LGTM on PR 42 after visual inspection"
./.review-approved created
# 3. Agent retries the action; this time it succeeds
$ agent: gh pr review 42 --approve --body "LGTM"
[receipt appended to ./review-receipts/receipts.jsonl, decision=allow]
# 4. Human closes the window
$ rm ./.review-approved
The allowed call has a signed receipt that anyone with the public key can verify offline. The denied attempt has no receipt, and the approval log is not signed, so keep both in mind when you show the trail to an auditor.
Composing with protect-mcp
If both plugins are installed, each plugin's hooks/hooks.json registers its
own PreToolUse hook, and Claude Code runs both on every tool call:
{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }
Each evaluate.sh reads tool_name and tool_input from the hook payload on
stdin (Claude Code sets no TOOL_NAME variable) and evaluates its own policy:
./protect.cedar for protect-mcp and ./review-governance.cedar here.
Both hooks must pass for the tool call to proceed. Cedar deny in either policy blocks it.
Standards
- Ed25519 — RFC 8032 (digital signatures)
- JCS — RFC 8785 (deterministic JSON canonicalization)
- Cedar — AWS's open authorization policy language
- IETF draft — draft-farley-acta-signed-receipts
Related skills
More from wshobson/agents and the wider catalog.

risk-metrics-calculation
Calculate portfolio risk metrics: VaR, CVaR, Sharpe, Sortino, and drawdown analysis.

rust-async-patterns
Master Rust async programming with Tokio, async traits, error handling, and concurrent patterns.

saga-orchestration
Implement saga patterns for distributed transactions across microservices without two-phase commit.

sast-configuration
Configure SAST tools like Semgrep, SonarQube, and CodeQL for automated vulnerability detection in CI/CD pipelines.

scan
Scan your codebase to auto-generate project-doc.md and AGENTS.md for agent-driven repos.

screen-reader-testing
Test web applications with screen readers (VoiceOver, NVDA, JAWS) to validate accessibility and assistive technology support.