Security routines
Security review that happens every week, not every audit.
Security routines re-review what changed — new code, new dependencies, new advisories — on a schedule, and separate what is exploitable in your context from what is noise. Runs are read-only by default and cite their evidence, so the weekly brief is something a reviewer can verify rather than trust.
Put a routine to workWorks with
Linear
Turn recurring findings into triaged issues, project updates, and accountable follow-up work.
Sentry
Review incidents and error trends on a schedule, then surface the changes that need attention.
GitHub
Read repositories and issues, then open reviewable pull requests through GitHub's remote MCP server.
Common questions
- What access does a security routine need?
- Read access to the repository and security findings you connect. Write-like actions, such as opening tracking issues, need an explicitly enabled tool with its own approval.
- Does it replace a security audit?
- No — it covers the gap between audits. The weekly cadence catches newly introduced risks and advisory churn that an annual review only sees months later.
- How does it avoid alarm fatigue?
- Templates instruct the routine to prioritize newly introduced or materially changed risks and to file the rest as noise with a reason, so the brief stays short enough to read.
Give security work a schedule.
Adapt a routine, approve its exact permissions, prove one run, then let the schedule own it.