Skip to main content
review-pantheon — Spec Driven AI Coding toolkit

CI License: MIT fail-closed by design

review-pantheon — Spec Driven AI Coding toolkit

  • AI-assisted development produces work faster than a human can independently verify it — the bottleneck moves from writing the change to trusting the report of it.
  • A pass with no fail-closed rule turns a missing or malformed verdict into a quiet green — the one failure mode worse than an honest red.

A portable review gate — a GitHub Action plus a provider-agnostic CLI — that splits "does the diff look right" from "did the PR actually do what it claims" into two independent agents (Artemis, Apollo), backed by three advisory philosopher agents for the planning stage before anything is built. Built for teams where a written spec is the contract, not a suggestion read once and forgotten: DESIGN.md in this repo is itself that contract.

Who it's for: teams or solo builders shipping AI-assisted changes fast enough that human review has become the bottleneck, who want a second opinion that can't be talked out of a red verdict by a confident-sounding PR description.

Quick start

Zero footprint — drop this into a workflow file (plus a PR trigger and pull-requests: write):

- uses: G-Schumacher44/review-pantheon@v1
  with: { claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} }

(The @v1 tag lands with this repo's first release — see RELEASING.md. Until then, pin a commit SHA or point uses: at a local checkout instead; a bare @v1 404s on a brand-new checkout, not a typo.)

Nothing else lands in your repo. Want to try it first with zero tokens spent? From a local checkout, in a venv (pip install -e .):

pantheon gate --pr <number> --dry-run

runs the real thing — real diff, real prompts — right up to calling a provider, then prints exactly what it would post. pantheon is the CLI (docs/CLI.md). Prefer a vendored install, or the CLI only? Full walkthrough for every path: docs/SETUP.md.

The panel

Gate agents (Artemis, Apollo) enforce — they run on every PR and can block a merge. Counsel agents (Socrates, Diogenes, Plato) inform — a human weighs their verdict; they never gate, whatever they're pointed at (spec, design doc, proposal, code, or a diff).

Agent Tier Role
Artemis Gate Hunts bugs in the diff — assumes nothing works until shown.
Apollo Gate Verifies the claim against git reality, and against the spec when one's configured.
Socrates Counsel Maps distinct approaches, go/no-go — usually runs earliest.
Diogenes Counsel Simplicity — is this more than it needs to be?
Plato Counsel Coherence — one consistent shape, or drifting sprawl?

Full persona definitions, verdict vocabulary, and the gate-flow diagram: DESIGN.md.

Where to go

I want to... Go to
Decide whether to adopt this This page, plus the security TL;DR below
Install it docs/SETUP.md — three ways, zero-token demo
Use the CLI docs/CLI.md — every flag, gate.conf, worked examples
Use it inside Claude Code skills//gate and /counsel commands plus the gate/counsel/spec-driven/design-contract skills, installed via install.sh --claude
Understand the design contract DESIGN.md — the binding spec
Review security SECURITY.md — scope, reporting, honest limits
Contribute CONTRIBUTING.md — ground rules, dev setup
Cut a release (operator) RELEASING.md
See the full doc index docs/README.md

How the gate stays honest

  • Reviewing untrusted PR content runs read-only by default (execution=readonly).
  • That tool-scoping covers three surfaces — the CLI, the published action, and the vendored workflow — all of which invoke Claude; non-Claude provider lanes aren't covered.
  • Nothing here eliminates a fully-compromised agent handing back a deceptive-but-schema-valid verdict — cross-review by a second agent is the real backstop, not a guarantee.

Full technical detail, honestly scoped: SECURITY.md and DESIGN.md's "Security posture".

Works with Conductor

aug-conductor-wrkflw pairs with this repo — it plans the work (slices, handoffs), review-pantheon verifies the delivery and pressure-tests the plan before it's built.


On generative AI use. review-pantheon is a public rebuild of a private review system the author already runs — ported and re-implemented from scratch for open distribution (no code copied over), with DESIGN.md as the rebuild's binding contract. Claude-based agents did the rebuild work, with the author directing as coordinator — where a commit message says "the coordinator", that's the human in the loop. The gate could not review this repo until it existed: of the first 44 commits, 23 went straight to dev with no pull request, and 14 of those touch code — including the original CLI, the Action, the installer, and bootstrap.sh. Since branch protection landed (2026-07-31), every change has gone through the gate: Artemis and Apollo on a pull request, fail-closed, no direct pushes. The history shows which is which.

88e0b01, one of those 14, is the commit that introduced a shell-injection defect in the vendored workflow — found and fixed later by this repo's own twin gate, once there was a gate to find it. Human-directed, spec-driven, self-gated, and late to gate itself.

License

MIT — © 2026 Garrett Schumacher. See LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

review_pantheon-0.1.0.tar.gz (207.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

review_pantheon-0.1.0-py3-none-any.whl (153.3 kB view details)

Uploaded Python 3

File details

Details for the file review_pantheon-0.1.0.tar.gz.

File metadata

  • Download URL: review_pantheon-0.1.0.tar.gz
  • Upload date:
  • Size: 207.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for review_pantheon-0.1.0.tar.gz
Algorithm Hash digest
SHA256 d4644f98bd51321a33c236bf5985b0946f46e3c611de466f3092a96566d7d721
MD5 001b4d29b9ba3be837acdc99b525e113
BLAKE2b-256 bb54f51f735e85aee72c453f6650ce6828102f1f0831fa5fd7b4b61ab4193ddb

See more details on using hashes here.

Provenance

The following attestation bundles were made for review_pantheon-0.1.0.tar.gz:

Publisher: release.yml on G-Schumacher44/review-pantheon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file review_pantheon-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: review_pantheon-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 153.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for review_pantheon-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8e32e657831910bbc6c6048904192831e5ec7f166db8118ecc6172ee20818ed1
MD5 529c02a2366a57949eae39a4a3807f66
BLAKE2b-256 9b6bd62a9a0589ea1d882e6e213c3ba442c83f3f09ff1adb6d6f491fb9631305

See more details on using hashes here.

Provenance

The following attestation bundles were made for review_pantheon-0.1.0-py3-none-any.whl:

Publisher: release.yml on G-Schumacher44/review-pantheon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page