Fewer scores, clearer launches
Review now covers security risk alongside correctness, quality, and regressions, so the separate Security pass action has been retired. Launching Review checks authentication and authorization boundaries, input validation, secret and credential handling, sensitive data exposure, unsafe command or file access, dependency risk, and misuse of trust or permission boundaries, in addition to everything it already looked at. Findings still land as a task comment with the same severity and evidence you're used to, and stay proportional to the change rather than forcing security commentary onto every task. A saved reference to the old Security pass action fails gracefully instead of breaking.
The Agent readiness fraction is gone from task cards and task detail. A task missing an optional time or token estimate no longer looks less ready than one that has them, and there's no replacement score to read into. When you actually launch an agent, Pekan still tells you exactly what would stop the run, such as a task blocked by an unresolved dependency, and explains what to do about it instead of showing a checklist.
The Agent Action confirmation dialog no longer jumps back to the top or collapses the prompt, execution rules, or command you were reading while it refreshes in the background. Expand Technical details, scroll through a long prompt, and leave the dialog open without losing your place or your selection.
You can now set how much a background Claude Code Agent Action is allowed to spend before Pekan stops it, from Settings, instead of a fixed two-dollar limit.
Highlights
- Review now includes security checks; the separate Security pass action is gone.
- No more readiness fraction on task cards or in task detail.
- A blocked task explains why it can't launch instead of scoring it.
- The Agent Action dialog keeps its scroll position and expanded Technical details while it refreshes.
- New Settings option to set the spend limit for background Agent Action runs.