review-agent-governance

PackSecurity

review-agent-governance is a plugin that adds a required human approval step before an AI agent can post PR reviews, comments, merges, or writes to CI configuration. It joins protect-mcp and signed-audit-trails in the governance category and composes with protect-mcp for runtime enforcement.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have an AI agent setup that can use plugins.

What your AI can do with it

  • Requires a human approval signal before an agent posts PR reviews
  • Requires human approval before an agent posts PR comments
  • Requires human approval before an agent performs merges
  • Requires human approval before an agent writes to CI configuration
  • Composes with protect-mcp for runtime enforcement

Getting started

  1. Have an AI agent setup that can use plugins.
  2. Add the review-agent-governance plugin to it.
  3. Configure the human approval signal so it is required before PR reviews, comments, merges, or CI configuration writes.
  4. Optionally pair it with protect-mcp if you want runtime enforcement of the approval step.

Signals

GitHub stars
40k
Forks
4k
Last commit
Sep 2026

Questions

What does review-agent-governance do?
It requires a human approval signal before an AI agent can post PR reviews, comments, merges, or writes to CI configuration.
Does it work with protect-mcp?
Yes. It composes with protect-mcp for runtime enforcement, and both belong to the governance category alongside signed-audit-trails.
Which actions require approval?
Posting PR reviews, posting PR comments, performing merges, and writing to CI configuration.
Advanced
Item type
plugin
Key
wshobson-agents-review-agent-governance
Source
github.com/wshobson/agents