The Security PM
“Should that user really be able to do that?”
- Roles and permissions
- Cross-tenant boundaries
- Auth and session edge cases
OPEN SOURCE. SLIGHTLY FERAL.
Give each PM a mandate. They explore in a real browser, find the gaps, and help turn approved tickets into tested fixes. You keep building. They keep improving.
Self-hosted · Real browsers · Your final say
$ git clone
https://github.com/AgentBurgundy/shipgremlins.git
$
cd shipgremlins && npm ci
$ npm run setup
-- --check
A LITTLE CHAOS.
A LOT OF SCREENSHOTS.
01 / MEET THE CREW
One PM owns one area. Give each a mandate, a schedule, and boundaries. Let curiosity do the rest.
“Should that user really be able to do that?”
“Okay, but what if I upload this?”
“It works. But does it make sense?”
Not fixed job titles. Start with a template, then write the mandate your product needs.
02 / SHOW YOUR WORK
Every useful finding needs a reproduction. Every verified fix needs evidence. Follow the trail from a browser observation to a production merge.
Illustrative workflow. No live agents are running on this page.
Reproduce with two isolated test accounts. Record the request and the actual browser state.
Evidence goes into Linear. Approved scope becomes a developer task.
Check the deployed revision, capture screenshots, and rerun the regression.
03 / GUARDRAILS INCLUDED
Your crew can be relentless without having the keys to everything.
Control the scope, approved tickets, test environment, and amount of work in flight.
Bounded retries and a dedicated recovery lane keep ordinary work paused while a broken integration is repaired.
Require current deployment evidence before a promotion opens. Stale checks and a confident comment don't count.
04 / BRING YOUR STACK
Keep your code, tickets, and infrastructure.
Add a crew around
them.
THEY'RE SMALL. THEIR STANDARDS AREN'T.
Start with the source. Inspect your setup.
Give your first PM
a job.
# Bring the crew home
git clone
https://github.com/AgentBurgundy/shipgremlins.git
cd shipgremlinsnpm ci# Check your tools and connections
npm run setup -- --check
Early alpha, built in the open. Bring your own provider credentials. A full management dashboard and additional provider stacks are on the roadmap.
A FEW FAIR QUESTIONS
No. Agents work on approved scope in a test environment. Promotion has verification gates, and the owner retains staging and production merge decisions. Reconciliation marks work Done only after production inclusion is proven.
Yes. The alpha runs through GitHub Actions with your self-hosted runners. The setup command checks prerequisites and initializes configuration. Containers are included for the CLI and local site; they are not an agent control plane.
The current workflows use Claude Code. Additional runtimes are planned. You control the credentials and model configuration in your own environment.
The browser can explore many kinds of apps, but reliable testing needs configured accounts, isolated data, and acceptance criteria. The first integration is GitHub with Vercel; GitLab and Railway are next.
Yes. The fixture CLI generates CSVs from JSON and reproducible PNG test images, ready to upload through Playwright MCP. Semantic AI image generation and automatic test-data cleanup are on the roadmap.