Skip to main content
review-pantheon — Spec Driven AI Coding toolkit

CI License: MIT fail-closed by design

review-pantheon — Spec Driven AI Coding toolkit

  • AI-assisted development produces work faster than a human can independently verify it — the bottleneck moves from writing the change to trusting the report of it.
  • A pass with no fail-closed rule turns a missing or malformed verdict into a quiet green — the one failure mode worse than an honest red.

A portable review gate — a GitHub Action plus a provider-agnostic CLI — that splits "does the diff look right" from "did the PR actually do what it claims" into two independent agents (Artemis, Apollo), backed by three advisory philosopher agents for the planning stage before anything is built. Built for teams where a written spec is the contract, not a suggestion read once and forgotten: DESIGN.md in this repo is itself that contract.

Who it's for: teams or solo builders shipping AI-assisted changes fast enough that human review has become the bottleneck, who want a second opinion that can't be talked out of a red verdict by a confident-sounding PR description.

Quick start

Zero footprint — drop this into a workflow file (plus a PR trigger and pull-requests: write):

- uses: G-Schumacher44/review-pantheon@v1
  with: { claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} }

(@v1 tracks the latest release — it moves when a new one is cut (see RELEASING.md). Prefer updates on your own schedule? Pin a full commit SHA instead — that's exactly what install.sh's generated workflow does.)

Nothing else lands in your repo. The CLI installs from PyPI or Homebrew:

pipx install review-pantheon            # or: pip install review-pantheon
brew install g-schumacher44/tap/review-pantheon

Want to try it first with zero tokens spent? From any install (or a local checkout in a venv, pip install -e .):

pantheon gate --pr <number> --dry-run

runs the real thing — real diff, real prompts — right up to calling a provider, then prints exactly what it would post. pantheon is the CLI (docs/CLI.md). Prefer a vendored install, or the CLI only? Full walkthrough for every path: docs/SETUP.md.

The panel

Gate agents (Artemis, Apollo) enforce — they run on every PR and can block a merge. Counsel agents (Socrates, Diogenes, Plato) inform — a human weighs their verdict; they never gate, whatever they're pointed at (spec, design doc, proposal, code, or a diff).

Agent Tier Role
Artemis Gate Hunts bugs in the diff — assumes nothing works until shown.
Apollo Gate Verifies the claim against git reality, and against the spec when one's configured.
Socrates Counsel Maps distinct approaches, go/no-go — usually runs earliest.
Diogenes Counsel Simplicity — is this more than it needs to be?
Plato Counsel Coherence — one consistent shape, or drifting sprawl?

Full persona definitions, verdict vocabulary, and the gate-flow diagram: DESIGN.md.

Where to go

I want to... Go to
Decide whether to adopt this This page, plus the security TL;DR below
Install it docs/SETUP.md — three ways, zero-token demo
Use the CLI docs/CLI.md — every flag, gate.conf, worked examples
Use it inside Claude Code skills//gate and /counsel commands plus the gate/counsel/spec-driven/design-contract skills, installed via install.sh --claude
Understand the design contract DESIGN.md — the binding spec
Review security SECURITY.md — scope, reporting, honest limits
Contribute CONTRIBUTING.md — ground rules, dev setup
Cut a release (operator) RELEASING.md
See the full doc index docs/README.md

How the gate stays honest

  • Reviewing untrusted PR content runs read-only by default (execution=readonly).
  • That tool-scoping covers both surfaces — the CLI and the published action — which invoke Claude; non-Claude provider lanes aren't covered.
  • Nothing here eliminates a fully-compromised agent handing back a deceptive-but-schema-valid verdict — cross-review by a second agent is the real backstop, not a guarantee.

Full technical detail, honestly scoped: SECURITY.md and DESIGN.md's "Security posture".

Works with Conductor

aug-conductor-wrkflw pairs with this repo — it plans the work (slices, handoffs), review-pantheon verifies the delivery and pressure-tests the plan before it's built.


On generative AI use. review-pantheon is a public rebuild of a private review system the author already runs — ported and re-implemented from scratch for open distribution (no code copied over), with DESIGN.md as the rebuild's binding contract. Claude-based agents did the rebuild work, with the author directing as coordinator — where a commit message says "the coordinator", that's the human in the loop. The gate could not review this repo until it existed: of the first 44 commits, 23 went straight to dev with no pull request, and 14 of those touch code — including the original CLI, the Action, the installer, and bootstrap.sh. Since branch protection landed (2026-07-31), every change has gone through the gate: Artemis and Apollo on a pull request, fail-closed, no direct pushes. The history shows which is which.

88e0b01, one of those 14, is the commit that introduced a shell-injection defect in the vendored workflow — found and fixed later by this repo's own twin gate, once there was a gate to find it. Human-directed, spec-driven, self-gated, and late to gate itself.

License

MIT — © 2026 Garrett Schumacher. See LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

review_pantheon-0.2.1.tar.gz (212.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

review_pantheon-0.2.1-py3-none-any.whl (154.4 kB view details)

Uploaded Python 3

File details

Details for the file review_pantheon-0.2.1.tar.gz.

File metadata

  • Download URL: review_pantheon-0.2.1.tar.gz
  • Upload date:
  • Size: 212.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for review_pantheon-0.2.1.tar.gz
Algorithm Hash digest
SHA256 34f7b0177963a1f9e3904e7e4da6f8c069e38f6ea52679e6d2c9dbe3c452b776
MD5 455f38f7ad08d3fd4819f0710a90c1e5
BLAKE2b-256 bd26db206bbd32d5ed1cd3af9459cf906eeb24ce3f09485372fb23e920eef8ed

See more details on using hashes here.

Provenance

The following attestation bundles were made for review_pantheon-0.2.1.tar.gz:

Publisher: release.yml on G-Schumacher44/review-pantheon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file review_pantheon-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: review_pantheon-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 154.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for review_pantheon-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 eb92f931544bb9058f16690bd5d4c901f0c7a2c097bfea4cd9cd4fa979ec9c24
MD5 ff2c867e51471da14a77719dc0b8b134
BLAKE2b-256 8bcb9d88928398601e1eab2c6e21ca69f44ec0836338bdbd551ed46953597030

See more details on using hashes here.

Provenance

The following attestation bundles were made for review_pantheon-0.2.1-py3-none-any.whl:

Publisher: release.yml on G-Schumacher44/review-pantheon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.3

2 files

0.2.2

2 files

This release

0.2.1 This release

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page