Gap
The autonomy pipeline runs automated code review on every PR (claude[bot] review + work-lane post-green review pass), but there is no dedicated security review anywhere in the flow. Boris's full-autonomy guidance stresses both: code reviews AND separate dedicated security reviews. We have the first, not the second.
Current state
Questions for triage
Filed from control-tower checkpoint on operator direction (2026-07-19 late-afternoon).
Reference: Boris Cherny, "Steps of AI Adoption" (Google Doc)
Gap
The autonomy pipeline runs automated code review on every PR (claude[bot] review + work-lane post-green review pass), but there is no dedicated security review anywhere in the flow. Boris's full-autonomy guidance stresses both: code reviews AND separate dedicated security reviews. We have the first, not the second.
Current state
review:security-revieweragent and asecurity-reviewskill exist in the toolbox, but nothing wires them into lane flow, the work-lane review pass, or babysit merge criteria.Questions for triage
Filed from control-tower checkpoint on operator direction (2026-07-19 late-afternoon).
Reference: Boris Cherny, "Steps of AI Adoption" (Google Doc)