Garnet records what your CI jobs ran at the kernel and every outbound connection they made, then posts the Execution Profile to the pull request.
The diff shows what changed. It doesn’t show what ran.Agents and dependencies run code you didn’t write in your CI, with your secrets. Garnet records each job’s execution chains — what ran, and the outbound connection each chain opened — at the kernel, on the runners you already use, and posts the record to the pull request before anyone approves.
The diff added a postinstall hook. The run reached a host the diff never names.
The GitHub App connects your repos · the Garnet Action records your workflows · the PR comment carries one Execution Profile per job.
Human reviewers
Add Garnet to your CI — first Execution Profile in about five minutes.
Agentic reviewers & harnesses
Review agents and gates that consume the record as an input.
Garnet records the run. The policy stays yours.
⌘I
Assistant
Responses are generated using AI and may contain mistakes.