Add a security review or a gate reviewer
Kraft ships two review skills that no shipped chain runs. This guide adds each
to a copy of the default chain. You need a running Kraft server. The keys used
are in Chain nodes and
Library and chains.
kraft:security-reviewreviews a change that touches authentication, sessions, tokens, secrets or permission checks. It reports findings the waykraft:code-reviewdoes, so they enter the same fix loop.kraft:gate-reviewreads the document a gate is about and reports a verdict, so a gate that needs no person stops reaching one. It never clears the gate itself.
Both are opt-in on purpose. A security pass costs an extra agent session per review round on every item, and a gate reviewer decides whether a human sees a gate at all, so neither belongs in a chain you did not choose them for.
Add a security review to verification
- Add the task to
$KRAFT_HOME/templates/library.yaml, undertasks::security_review: kind: agent harness: claude prompt: Review this work item's change for security defects. skill: kraft:security-review inputs: [review_package, carried_findings, previous_review] - Copy
chains/default.yamltochains/reviewed.yaml, change itsid, and replace theverificationnode with one that runs the security review beside the code review. Lists replace when a node extends, so write both steps out:- id: verification extends: verification steps: - id: tests tasks: - id: test_changed_scopes extends: verify_changed_scopes - id: review tasks: - id: code_review extends: code_review - id: security_review extends: security_review
Tasks in one step run in parallel, so both reviews read the same tests-green change. Their findings share the node's fix loop.
Add a gate reviewer to a gate
Add auto_review to any gate node in your chain. It takes a whole agent task,
not an extends:
- id: spec_approval
kind: gate
message: Review and approve the specification.
artifact: spec
reject_to: spec
auto_review:
id: reviewer
kind: agent
harness: claude
prompt: Decide whether this gate needs a person.
skill: kraft:gate-review
A gate is reviewed when it declares auto_review and the work item has not
opted out with --no-auto-gate. Auto-gate is on by default for an item you
file from the CLI, MCP or the API; an item filed by a cron trigger,
POST /api/triggers or auto-intake has it off. Adding auto_review to a gate
therefore starts a paid reviewer agent on every item that reaches it, unless
the item opted out.
The reviewer runs as a worker, so Kraft refuses it if it tries to approve or
reject. It reports one of approve, reject, fixed or undecided, and Kraft
applies the verdict. The default is undecided, which leaves the gate for a
person with the reviewer's concerns to read first. auto_review_attempts in
policy.yaml (default 1) bounds how many attempts one pending gate gets.
Check it and use it
kraft admin templates lint
kraft admin reload
kraft item create "title" --chain reviewed
Pass --no-auto-gate to leave that item's gates to a person. lint must report no errors before you reload, and
kraft admin templates show reviewed --resolved prints the chain with the
library expanded so you can see both additions. A failing security finding
appears in findings_measured events like any review finding.