cyberneticlibrary

Security gate before merge

mishmar-security-gateworkflowsetup L33
Y4NN777/mishkan-cc-harness
What it does

Security-gate a diff with 3 orthogonal lenses + adversarial refute

Best for

Gate a sensitive merge when orthogonal security expertise and adversarial refutation are required.

Inputs
  • · diff ref (PR URL/branch/path)
  • · surface area (auth/payment/pii/rbac)
  • · project root
Outputs
  • · pass/block decision + structured finding list (title/severity/file/line/rationale)
Requires
  • · git (diff parsing)
Preconditions
  • · diff accessible (URL or local file)
  • · three agents available (Ira/Joab/Hushai)
  • · OWASP threat model context
Failure modes
  • · finding refuted by 2 of 3 (dropped)
  • · severity downgraded after refute
  • · false positive high/critical finding blocks merge
Trust signals
  • · 3-vote consensus pattern (2-of-3 refutation)
  • · structured finding schema
  • · severity calibrated by refute phase