Skip to content

Renma

Renma is a Git-native Context Repository and deterministic governance CLI for agent-facing knowledge and its static repository declarations. It keeps Skills, Context Assets, Context Lenses, ownership, lifecycle, provenance, security policy, declared relationships, and review evidence maintainable in Git. Renma analyzes and reports repository state; it is not the runtime that consumes these assets.

Why A Context Repository?

Agent-facing guidance is often copied across Skills, prompts, and repository instructions until its authority, owner, and lifecycle are unclear. A Context Repository gives reusable knowledge stable identity and explicit, Git-reviewed governance. A Context Asset is the governance entry point for independently maintained knowledge and its authoritative sources. The content may live in the Context Repository or in an external governed system; Renma does not require copying the complete external source into contexts/.

A reviewed reference does not prove that the source was consulted or its contents validated, and it does not grant permission to access the source.

What Renma Checks

Renma reviews discovered agent-facing repository assets and produces deterministic evidence for humans, CI, and coding agents. renma scan is the normal starting point; focused commands expose the related inventory, graph, ownership, readiness, and change evidence.

AreaExamples of what Renma checks or reports
Agent Skills and layoutCanonical entrypoints and metadata shapes, historical paths, reserved-directory boundaries, and repository classification.
GovernanceStable identity, declared and inherited ownership, lifecycle and freshness, required metadata, and security-profile resolution.
Relationships and supportMissing, inactive, conflicting, or cyclic dependencies; broken references; unreachable Skill support; and inspection blockers such as symlinks, unreadable files, size limits, or depth limits.
Authoring qualitySelection boundaries, required inputs, preflight and verification guidance, scaffold residue, machine-local paths, token budgets, and possible mixed responsibilities.
Security policy and instructionsPolicy alignment for data, network and upload destinations, secrets, forbidden inputs, and human approval; sensitive-data exposure; destructive or privileged commands; risky error suppression; floating dependency or remote-script execution; hidden or untrusted instructions; hierarchy or safeguard bypass; and suspicious Unicode or frontmatter integrity.
Review coverageWhich expected files were inspected, which supported security-analysis layers ran, and which formats or surfaces remained unsupported, blocked, or not analyzable.

Security checks apply to documented, supported forms in agent-facing instructions and metadata. They do not perform general code SAST, CVE lookup, dependency-content validation, complete secret scanning of executable code, or runtime permission enforcement. See the Security Policy Guide for the effective-policy and instruction-analysis boundary, and the Diagnostics Reference for current finding identifiers and remediation guidance.

Product Boundary

Renma discovers, validates, compares, and reports repository assets. It does not call an LLM for core analysis; select, retrieve, or load live context; assemble prompts or inject Context; execute agents or Skills; collect runtime telemetry; or replace runtime security and language-specific analysis tools.

The review boundary is:

text
LLM proposes. Renma verifies. Human approves.

Quick Start

bash
npx renma scan . --fail-on high
npx renma catalog . --format markdown
npx renma graph . --format markdown
npx renma readiness . --format markdown