Council Sentinel
Security oversight, blast radius assessment, and secrets management review (Troy Hunt inspiration)
- Type
- Subagent
- Repository
- automagik-dev/genie
- GitHub stars
- 343
- License
- MIT
- Repo last updated
- Sep 26, 2026
- Source file
- README.md
What Council Sentinel is
Council Sentinel is a subagent published in the automagik-dev/genie repository on GitHub, which has about 343 stars. The repository describes itself as: “Wishes in, PRs out. CLI agent that interviews you, plans the work, dispatches parallel agents in isolated worktrees, and reviews code before you see it.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Council Sentinel and get back a compact result.
How to install Council Sentinel
Claude Code
- Download README.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from README.md, shared under the repository's MIT license. Read the full file on GitHub.
Wishes in, PRs out.
Genie is a planning-and-execution layer for AI coding agents. You describe what you want in one sentence; Genie interviews you into a plan, dispatches agents to build it in parallel, reviews the result against acceptance criteria, and hands you something ready to merge.
The whole thing is a lightweight body: a set of skills, plain-markdown documents in git, and a single per-repo SQLite file. No daemons, no Postgres, nothing resident. A command opens the database, runs one transaction, and exits.
Stable is declared for Linux and macOS. Both legs run in the release gate, so a change that breaks either one does not ship. Windows is not supported; WSL2 works but is not on the tested matrix.
Install
curl -fsSL https://raw.githubusercontent.com/automagik-dev/genie/main/install.sh | bashEvery release is cosign-signed (keyless OIDC) with SLSA provenance, and genie update verifies it offline, with no GitHub credential: the release's own signed delivery evidence is checked against an embedded Sigstore trust root with the publishing workflow's certificate identity pinned, and the descriptor's artifactSha256 is bound to the downloaded tarball before anything is extracted. gh attestation verify is an advisory cross-check on top — a host with no gh still updates and says so in one line; a gh that ran and says the artifact does not verify still aborts.
The repository-hosted .well-known/latest.json and dev.json manifests are the authoritative channel pointers. GitHub's /releases/latest route and prerelease badge are deliberately not channel authority: a promotion advances only a monotonic manifest and never rewrites already-published assets or channel-significant draft/prerelease/latest metadata.
Genie ships exactly two surfaces, and nothing else:
- The signed binary — installed and updated by install.sh and genie update.
- The skills, and the saved-workflow catalog beside them — delivered by the skills.sh channel. genie install and genie update run the pinned skills CLI over the tree the signed release put on disk, deliver .claude/workflows/*.js into ~/.claude/workflows, then record what landed in ~/.genie/skills-install.json. Without the binary, the same skills install with npx skills add automagik-dev/genie (add -g for a machine-wide install; never --all, which asks the skills CLI to write a product home for every one of the 77 agents in its registry — 57 of them materialized on the measured dogfood host (2026-08-30, re-confirmed 2026-09-01; only 4 were recorded, leaving 53 unrecorded homes).
There is no Claude marketplace plugin, no Codex plugin, no Orca plugin, no Genie-installed hooks, and no role-agent profiles.
--integrations auto|codex|claude|all|none (or --skip-integrations) is the consent scope for the skills channel. Any value other than none installs to every detected agent skill home, because the skills CLI already installs per agent; none skips the channel entirely, writes no record, and reports skills: skipped (consent: none). A failed skills install never rolls back the promoted binary — it prints the exact remedy command and sets a non-zero exit code.
Upgrading from a plugin-era release? The one-shot, backup-first retirement genie update used to run for that era shipped from 5.260711.6 through the last 5.x release and was removed in v6, three stable releases after its compat window opened. A host that updated through any 5.x release is already clean and needs nothing. A host coming straight from the plugin era to v6 is not cleaned up by genie at all any more — see Removing plugin-era leftovers by hand. Genie still retires what the skills channel itself no longer delivers, backup-first, under ~/.genie/state-backups/skills-retirement- /.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Council Sentinel?
Council Sentinel is a subagent for Claude Code and Claude Cowork from the automagik-dev/genie repository on GitHub. Security oversight, blast radius assessment, and secrets management review (Troy Hunt inspiration)
How do I install Council Sentinel in Claude Code?
Download README.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Council Sentinel in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Council Sentinel safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Council Operator Operations reality, infrastructure readiness, and on-call sanity review (Kelsey Hightower inspiration) Subagent · automagik-dev/genie
- Council Questioner Challenge assumptions, seek foundational simplicity, question necessity (Ryan Dahl inspiration) Subagent · automagik-dev/genie
- Council Measurer Observability, profiling, and metrics philosophy demanding measurement over guessing (Bryan Cantrill inspiration) Subagent · automagik-dev/genie
- Council Tracer Production debugging, high-cardinality observability, and instrumentation review (Charity Majors inspiration) Subagent · automagik-dev/genie
- Council Simplifier Complexity reduction and minimalist philosophy demanding deletion over addition (TJ Holowaychuk inspiration) Subagent · automagik-dev/genie
- Engineer Task execution agent. Reads wish from disk, implements deliverables, validates, and reports what was built. Subagent · automagik-dev/genie
- Fix Bug fix agent. Finds root cause, applies minimal fix, proves it works, reports what changed. Subagent · automagik-dev/genie
- Council Ergonomist Developer experience, API usability, and error clarity review (Sindre Sorhus inspiration) Subagent · automagik-dev/genie