What's in a workflow
Midkernel's live review workflows are Markdown files in midkernel/playbooks. Each contains a metadata header and the instructions used by the selected pipeline.
This note describes security-review.md at revision cb7345e, checked on September 16, 2026. It replaces the earlier fictional authentication-review manifest.
The metadata
The current file identifies its name and slug as security-review, its surface as scan, and its kind as agentflow-graph. The pipeline field points to pipelines/security-review.py; harness and provider identify the execution tools.
This header does not declare a tools allowlist, repository scope, per-profile prices or a report schema. Those controls must be verified in the platform and pipeline that run the workflow.
The instructions
Below the metadata, the file specifies the review task and names report.md as its output. Read the published source for the exact text.
A workflow's instructions describe intended output. They are not evidence of a completed review, and no sample report is published on this site yet.
Profiles and source
The app sets fixed Scan prices: low 10, balanced 25 and max 50 credits. See Pricing for the current profile limits and packs.
The source is public, so you can inspect changes between revisions. The hosted service currently runs the published workflows; private forks are planned. The Workflows page links to both live files.