# Review Engineering Governance

> Engineering governance review for ownership, standards, repository hygiene, documentation, dependency policy, exceptions, release discipline, change controls, maintainership, and policy consistency. Use for stewardship, governance, or engineering-control questions.

- Skill: `kenlck/review-engineering-governance` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add kenlck/review-engineering-governance`
- Raw SKILL.md: https://api.skillmd.com/api/skills/kenlck/review-engineering-governance/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: kenlck (https://skillmd.com/u/kenlck)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/kenlck/review-engineering-governance

---


# Review engineering governance

Assess one repository, a repository group, or an existing fleet evidence bundle. Judge whether ownership and controls are explicit, current, consistently applied, and capable of handling exceptions.

## Run the lens

1. Read the [standalone lens protocol](../audit-software-fleet/references/standalone-lens.md) completely and prepare the supplied scope with lens ID `engineering-governance`.
2. Read [the engineering governance checks](references/checks.md) completely. Apply every check family relevant to repository criticality, ownership, policy, and supplied platform metadata.
3. Compare declared standards with observable enforcement and active exceptions. Classify supported outcomes as strengths or findings; record unavailable organization or platform controls as unknowns rather than repository failures.
4. Follow the protocol to account for every contract-registered check family, validate the result, ingest it, and hand back the canonical artifact path.

For raw collection or platform metadata retrieval, read and follow the [safety model](../audit-software-fleet/references/safety-model.md). Use only explicitly supplied or authorized external data.

Read the [review basis](../audit-software-fleet/references/research-basis.md) when mapping evidence to SSDF or OpenSSF guidance.

## Boundary

Own stewardship, standards, exception processes, and control consistency. Route technical defects to their technical lens while retaining governance findings about absent ownership or enforcement.

## Completion

**Complete when:** every in-scope repository has an exact commit or explicit unavailable state, every applicable check family is accounted for, every claim has bounded sanitized evidence at an appropriate confidence, gaps remain visible in unknowns and coverage, and the shared result validator succeeds.

