{"_id":"@brett.buskirk/agent-gate","_rev":"6-60822a48efb3960a91562af633176883","name":"@brett.buskirk/agent-gate","dist-tags":{"latest":"1.2.1"},"versions":{"0.1.0":{"name":"@brett.buskirk/agent-gate","version":"0.1.0","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","_id":"@brett.buskirk/agent-gate@0.1.0","maintainers":[{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"}],"homepage":"https://github.com/brett-buskirk/agent-gate#readme","bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"bin":{"agentgate":"bin/agent-gate.js","agent-gate":"bin/agent-gate.js"},"dist":{"shasum":"5aa809f0f04e057b127a1af33d115a916d8fce42","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-0.1.0.tgz","fileCount":71,"integrity":"sha512-I+CCiOmJ4S076jUmvhsNbefZlWyoPP1G6cluFBDDfqQFYHii2goR+N2CdICuosjrJus/Qd7TlgODxmGyUUMNdA==","signatures":[{"sig":"MEUCIBGn7Nz5ehw9g56QwT7Cm5Zm9r3PP3trBpImZpOeXLuAAiEAyxzsh7tUpDy/UdrKKR8Lwj/zEi1wFnnDuAP/MUaOExQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61825},"main":"./lib/engine.js","type":"commonjs","types":"./lib/engine.d.ts","engines":{"node":">=20.0.0"},"gitHead":"4db5b5636309fec6a3cb0bf514674df740ce5515","scripts":{"lint":"eslint src test","test":"vitest run","build":"tsc -p tsconfig.build.json","format":"prettier --write .","lint:fix":"eslint src test --fix","typecheck":"tsc --noEmit","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","format:check":"prettier --check .","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"},"repository":{"url":"git+https://github.com/brett-buskirk/agent-gate.git","type":"git"},"_npmVersion":"11.6.2","description":"Guardrail checks for AI-agent-generated pull requests","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.24.2","js-yaml":"^4.1.0","commander":"^13.1.0","@actions/core":"^1.11.1","@actions/github":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^2.0.0","prettier":"^3.3.0","typescript":"^5.4.0","@types/node":"^20.0.0","@vercel/ncc":"^0.38.3","@types/js-yaml":"^4.0.9","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-gate_0.1.0_1782628241221_0.34880752499167755","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@brett.buskirk/agent-gate","version":"0.2.0","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","_id":"@brett.buskirk/agent-gate@0.2.0","maintainers":[{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"}],"homepage":"https://github.com/brett-buskirk/agent-gate#readme","bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"bin":{"agentgate":"bin/agent-gate.js","agent-gate":"bin/agent-gate.js"},"dist":{"shasum":"d91acf91519c30de6d3c6ba93ed4fa700f39d8f3","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-0.2.0.tgz","fileCount":80,"integrity":"sha512-LJbxTW/b40WFmWYqjDC/mYolM9uPtLvg3sugXQVoMCkIyS37+UgSR6wVUobI6BqkbPRtgjY4j07OBnpoJStLEg==","signatures":[{"sig":"MEYCIQDP7Tl43362NovOeBTDIwWVcQdsj2hGEwt6dh0OKmai9QIhAM+YcGMIagUnu2M5sitoM1I2/7TqayIcu+6nIkwRG2u6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68686},"main":"./lib/engine.js","type":"commonjs","types":"./lib/engine.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5282f89ab3228019924d9fb55ffc38d1cc36ae62","scripts":{"lint":"eslint src test","test":"vitest run","build":"tsc -p tsconfig.build.json","format":"prettier --write .","lint:fix":"eslint src test --fix","typecheck":"tsc --noEmit","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","format:check":"prettier --check .","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"},"repository":{"url":"git+https://github.com/brett-buskirk/agent-gate.git","type":"git"},"_npmVersion":"11.6.2","description":"Guardrail checks for AI-agent-generated pull requests","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.24.2","js-yaml":"^4.1.0","commander":"^13.1.0","@actions/core":"^1.11.1","@actions/github":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^2.0.0","prettier":"^3.3.0","typescript":"^5.4.0","@types/node":"^20.0.0","@vercel/ncc":"^0.38.3","@types/js-yaml":"^4.0.9","@vitest/coverage-v8":"^2.1.9","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-gate_0.2.0_1782655190794_0.41733163772173865","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@brett.buskirk/agent-gate","version":"1.0.0","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","_id":"@brett.buskirk/agent-gate@1.0.0","maintainers":[{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"}],"homepage":"https://github.com/brett-buskirk/agent-gate#readme","bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"bin":{"agentgate":"bin/agent-gate.js","agent-gate":"bin/agent-gate.js"},"dist":{"shasum":"49065dc0ea8c70a4116b1947e78292438b98429f","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-1.0.0.tgz","fileCount":80,"integrity":"sha512-p7jUAVwF/Sttm4wDSj8LLK2Z0J9qhVLu0o0+5dH3A3An/2pKZEkn0jTB8sm8yRECyJ6EkqGV9dQVu1ia94D+pg==","signatures":[{"sig":"MEQCIFc4wd5E6sOOr+qor3b7BfAMRuo/DN4jkyXHQE7xQieQAiAZSWZLdSA/IVCY1MqI6x/3RhOztGqSTNCAakhJYpgU+w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70766},"main":"./lib/engine.js","type":"commonjs","types":"./lib/engine.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a79a7bd872a46cb600a9f312e5f6841b853e4b3d","scripts":{"demo":"node scripts/gen-demo.js","lint":"eslint src test","test":"vitest run","build":"tsc -p tsconfig.build.json","format":"prettier --write .","lint:fix":"eslint src test --fix","typecheck":"tsc --noEmit","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","format:check":"prettier --check .","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"},"repository":{"url":"git+https://github.com/brett-buskirk/agent-gate.git","type":"git"},"_npmVersion":"11.6.2","description":"Guardrail checks for AI-agent-generated pull requests","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.24.2","js-yaml":"^4.1.0","commander":"^13.1.0","@actions/core":"^1.11.1","@actions/github":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^2.0.0","prettier":"^3.3.0","typescript":"^5.4.0","@types/node":"^20.0.0","@vercel/ncc":"^0.38.3","@types/js-yaml":"^4.0.9","@vitest/coverage-v8":"^2.1.9","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-gate_1.0.0_1782661090245_0.01231766504305365","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@brett.buskirk/agent-gate","version":"1.1.0","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","_id":"@brett.buskirk/agent-gate@1.1.0","maintainers":[{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"}],"homepage":"https://github.com/brett-buskirk/agent-gate#readme","bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"bin":{"agentgate":"bin/agent-gate.js","agent-gate":"bin/agent-gate.js"},"dist":{"shasum":"c2d2eddfab7bc611d188fb499f0f56687b51859c","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-1.1.0.tgz","fileCount":92,"integrity":"sha512-y0Fzu1S+1Wq76afgvXbiUMbZtqpdTG3xosOycmjtxZXbxkjmko/MpSRH/Y14Jl568krXUNZjAkwzroqmwgPQsA==","signatures":[{"sig":"MEUCIQDJ3+N42HrRoTpYPt1bRZ4x1NVzpXJb4ucKN/1EMtwPGQIgLqi0ncxdPTV/LMh7lmwYDhPgO7cHlB65+UsI3vI5WV0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":90816},"main":"./lib/engine.js","type":"commonjs","types":"./lib/engine.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8ae37e8f000c08583160f2b1be2e6e88ae5c1ad7","scripts":{"demo":"node scripts/gen-demo.js","lint":"eslint src test","test":"vitest run","build":"tsc -p tsconfig.build.json","format":"prettier --write .","lint:fix":"eslint src test --fix","typecheck":"tsc --noEmit","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","format:check":"prettier --check .","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"},"repository":{"url":"git+https://github.com/brett-buskirk/agent-gate.git","type":"git"},"_npmVersion":"11.6.2","description":"Guardrail checks for AI-agent-generated pull requests","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.24.2","js-yaml":"^4.1.0","commander":"^13.1.0","@actions/core":"^1.11.1","@actions/github":"^6.0.0","@anthropic-ai/sdk":"^0.106.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^2.0.0","prettier":"^3.3.0","typescript":"^5.4.0","@types/node":"^20.0.0","@vercel/ncc":"^0.38.3","@types/js-yaml":"^4.0.9","@vitest/coverage-v8":"^2.1.9","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-gate_1.1.0_1782663788949_0.37981523479710133","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@brett.buskirk/agent-gate","version":"1.2.0","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","_id":"@brett.buskirk/agent-gate@1.2.0","maintainers":[{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"}],"homepage":"https://github.com/brett-buskirk/agent-gate#readme","bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"bin":{"agentgate":"bin/agent-gate.js","agent-gate":"bin/agent-gate.js"},"dist":{"shasum":"a2947f31b888df59fbdb160c75d8e9a52ca3c659","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-1.2.0.tgz","fileCount":92,"integrity":"sha512-kLuDjj4fcv+XLlP4AroNakRk5nR2DhJhITam13ZhCSjTJwtSV5pzviSxQQ/C36q3FnRigU6dcyjGV1bnefrneQ==","signatures":[{"sig":"MEUCIQCCwgvEnGKL31vFI7bVBJX7bBhQt3zflXVuzTKry746WwIgQmsyKLeCbUBdfA6DYTTfQUtqJEmrUH+v3qvef8/xc3w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":91626},"main":"./lib/engine.js","type":"commonjs","types":"./lib/engine.d.ts","engines":{"node":">=20.0.0"},"gitHead":"fc807de217ccf49b3bcb15e23d526df2befecb4f","scripts":{"demo":"node scripts/gen-demo.js","lint":"eslint src test","test":"vitest run","build":"tsc -p tsconfig.build.json","format":"prettier --write .","lint:fix":"eslint src test --fix","typecheck":"tsc --noEmit","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","format:check":"prettier --check .","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"brett.buskirk","email":"buskirkbrett8@gmail.com"},"repository":{"url":"git+https://github.com/brett-buskirk/agent-gate.git","type":"git"},"_npmVersion":"11.6.2","description":"Guardrail checks for AI-agent-generated pull requests","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.24.2","js-yaml":"^4.1.0","commander":"^13.1.0","@actions/core":"^1.11.1","@actions/github":"^6.0.0","@anthropic-ai/sdk":"^0.106.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^2.0.0","prettier":"^3.3.0","typescript":"^5.4.0","@types/node":"^20.0.0","@vercel/ncc":"^0.44.0","@types/js-yaml":"^4.0.9","@vitest/coverage-v8":"^2.1.9","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-gate_1.2.0_1783371707939_0.20179303408117244","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@brett.buskirk/agent-gate","version":"1.2.1","description":"Guardrail checks for AI-agent-generated pull requests","type":"commonjs","bin":{"agent-gate":"bin/agent-gate.js","agentgate":"bin/agent-gate.js"},"main":"./lib/engine.js","scripts":{"build":"tsc -p tsconfig.build.json","build:action":"ncc build src/action.ts -o dist --source-map --license licenses.txt","demo":"node scripts/gen-demo.js","typecheck":"tsc --noEmit","test":"vitest run","test:coverage":"vitest run --coverage","lint":"eslint src test","lint:fix":"eslint src test --fix","format":"prettier --write .","format:check":"prettier --check ."},"dependencies":{"@actions/core":"^1.11.1","@actions/github":"^6.0.0","@anthropic-ai/sdk":"^0.109.1","commander":"^13.1.0","js-yaml":"^4.1.0","zod":"^3.24.2"},"devDependencies":{"@types/js-yaml":"^4.0.9","@types/node":"^20.0.0","@typescript-eslint/eslint-plugin":"^8.0.0","@typescript-eslint/parser":"^8.0.0","@vercel/ncc":"^0.44.0","@vitest/coverage-v8":"^2.1.9","eslint":"^9.0.0","prettier":"^3.3.0","typescript":"^5.4.0","vitest":"^2.0.0"},"engines":{"node":">=20.0.0"},"keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"author":{"name":"Brett Buskirk"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/brett-buskirk/agent-gate.git"},"bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"homepage":"https://github.com/brett-buskirk/agent-gate#readme","overrides":{"undici":"^6.27.0"},"gitHead":"c8b789e11475c5e5506b0ed8ec9a1a47aa318918","types":"./lib/engine.d.ts","_id":"@brett.buskirk/agent-gate@1.2.1","_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-bBnVZKr5NyFAlAN5KMIssjqhQxEGqQkHTPluoKt1ju0Wez3MuZzcr1yRW7WECrPvlbZN2a2PrfGeHz6IHzP+qw==","shasum":"15cd29958d57ca0466781e42d578438446babeae","tarball":"https://registry.npmjs.org/@brett.buskirk/agent-gate/-/agent-gate-1.2.1.tgz","fileCount":92,"unpackedSize":91672,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDjLaEt/jlE3esDiblvfNVA69oyMxTV5mruJ1Daxgud7QIhAIljxPscD0e4iF2Vc4/EHWhYrNESrSOZ3lup4qc+2CoT"}]},"_npmUser":{"name":"brett.buskirk","email":"brett@brett-buskirk.dev"},"directories":{},"maintainers":[{"name":"brett.buskirk","email":"brett@brett-buskirk.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-gate_1.2.1_1783552969741_0.49884688021590184"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-28T06:30:41.071Z","modified":"2026-07-08T23:22:50.012Z","0.1.0":"2026-06-28T06:30:41.347Z","0.2.0":"2026-06-28T13:59:50.930Z","1.0.0":"2026-06-28T15:38:10.368Z","1.1.0":"2026-06-28T16:23:09.078Z","1.2.0":"2026-07-06T21:01:48.090Z","1.2.1":"2026-07-08T23:22:49.890Z"},"bugs":{"url":"https://github.com/brett-buskirk/agent-gate/issues"},"author":{"name":"Brett Buskirk"},"license":"MIT","homepage":"https://github.com/brett-buskirk/agent-gate#readme","keywords":["ai-agents","github-action","code-review","security","ci","guardrails"],"repository":{"type":"git","url":"git+https://github.com/brett-buskirk/agent-gate.git"},"description":"Guardrail checks for AI-agent-generated pull requests","maintainers":[{"name":"brett.buskirk","email":"brett@brett-buskirk.dev"}],"readme":"# AgentGate\n\n[![CI](https://github.com/brett-buskirk/agent-gate/actions/workflows/ci.yml/badge.svg)](https://github.com/brett-buskirk/agent-gate/actions/workflows/ci.yml)\n[![npm](https://img.shields.io/npm/v/@brett.buskirk/agent-gate)](https://www.npmjs.com/package/@brett.buskirk/agent-gate)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![GitHub Marketplace](https://img.shields.io/badge/Marketplace-AgentGate-2ea44f?logo=githubactions&logoColor=white)](https://github.com/marketplace/actions/agentgate-ai-pr-guardrails)\n\n**Guardrail checks for AI-agent-generated pull requests.**\n\nAgentGate runs in CI on every PR, inspects the diff for the risk signals that AI agents commonly introduce — leaked secrets, out-of-scope changes, missing tests, surprise dependencies — posts a structured review comment, and sets a pass/fail check. Your team gets eyes on agent work without rubber-stamping it.\n\n> Built by [Brett Buskirk LLC](https://brett-buskirk.dev) as part of the **Agentic Development Workflow Setup** service — a productized safety net for teams shipping with AI coding agents.\n\n> 💡 **Not an engineer?** Read the [plain-language overview](docs/ABOUT.md) — what AgentGate does and why it matters, no jargon.\n\n> 📝 **The story behind it:** [_A Seatbelt for AI-Generated Pull Requests_](https://medium.com/@brett-buskirk/a-seatbelt-for-ai-generated-pull-requests-5f70d42f8a75) — why agent PRs need a guardrail, how it was built, and where it's headed.\n\n---\n\n## Status\n\n**v1.2.1 — stable.** Six deterministic rules — including default protection for its own `.agentgate.yml` config — plus an opt-in LLM intent check, tested (99%+ coverage, enforced in CI). Action bundled (`dist/index.js`) and listed on the [GitHub Marketplace](https://github.com/marketplace/actions/agentgate-ai-pr-guardrails). Dogfood CI runs AgentGate on its own PRs. CLI auto-detects your default branch and ships an `init` scaffolder. Published to npm as [`@brett.buskirk/agent-gate`](https://www.npmjs.com/package/@brett.buskirk/agent-gate).\n\n---\n\n## See it in action\n\nWhen an agent opens a PR that leaks a key, edits a workflow it shouldn't touch, slips in a dependency, and skips tests, AgentGate blocks the merge and explains exactly why:\n\n![AgentGate CLI output](docs/assets/cli-demo.svg)\n\nIn CI it posts the same verdict as a single PR comment — here's a [sample comment](docs/assets/sample-pr-comment.md).\n\n---\n\n## Quickstart\n\n### GitHub Action\n\n```yaml\n# .github/workflows/agentgate.yml\nname: AgentGate\non: [pull_request]\n\njobs:\n  agentgate:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: brett-buskirk/agent-gate@v1\n        with:\n          github-token: ${{ secrets.GITHUB_TOKEN }}\n```\n\n> Pin to an exact release (`@v1.0.0`) for reproducible builds, or track the moving `@v1` tag for the latest v1.x.\n\nAdd a `.agentgate.yml` to your repo to configure it (or skip it — the defaults are sane).\n\n### CLI\n\n```bash\n# Auto-detects your default branch (main, master, or origin/HEAD)\nnpx @brett.buskirk/agent-gate check\n```\n\nOr install globally:\n\n```bash\nnpm install -g @brett.buskirk/agent-gate\nagent-gate check                  # diff against the auto-detected default branch\nagent-gate check --base develop   # or pick a base explicitly\nagent-gate check --json           # machine-readable output\nagent-gate init                   # scaffold a .agentgate.yml\n```\n\n---\n\n## Configuration\n\nPlace a `.agentgate.yml` in your repo root. Everything has a default — the file is optional.\n\n```yaml\nversion: 1\nfail_on: error          # error | warning | never\ncomment: true           # post/update a PR comment\n\nrules:\n  secrets:\n    enabled: true\n    severity: error\n\n  scope:\n    enabled: true\n    severity: error\n    allow:               # if set, only these paths are permitted\n      - \"src/**\"\n      - \"test/**\"\n      - \"docs/**\"\n    deny:                # always blocked regardless of allow\n      - \".github/workflows/**\"\n      - \"infra/**\"\n      - \"**/*.lock\"\n      - \"package-lock.json\"\n\n  diff_size:\n    enabled: true\n    severity: warning\n    max_files: 30\n    max_lines: 800\n\n  tests_required:\n    enabled: true\n    severity: warning\n    src_globs: [\"src/**\"]\n    test_globs: [\"**/*.test.*\", \"**/*.spec.*\", \"tests/**\"]\n\n  dependencies:\n    enabled: true\n    severity: warning\n    manifests: [\"package.json\", \"requirements.txt\", \"go.mod\", \"Gemfile\", \"Cargo.toml\"]\n\n  dangerous_patterns:\n    enabled: true\n    severity: error\n    patterns:\n      - \"eval\\\\(\"\n      - \"--no-verify\"\n      - \"child_process\\\\.exec\\\\(\"\n\n  intent:                 # opt-in — needs ANTHROPIC_API_KEY\n    enabled: false\n    severity: warning\n    model: claude-haiku-4-5-20251001\n    max_diff_bytes: 60000\n```\n\n### `fail_on`\n\n| Value | Behavior |\n|-------|----------|\n| `error` | Only error-severity findings fail the check (default) |\n| `warning` | Warnings also fail the check |\n| `never` | Check always passes; findings are still reported |\n\n---\n\n## Rules\n\n| Rule | Default severity | What it catches |\n|------|-----------------|-----------------|\n| `secrets` | error | AWS keys, GitHub tokens, private key blocks, high-entropy assignments |\n| `scope` | error | Files outside the allow list or inside the deny list |\n| `diff_size` | warning | PRs exceeding `max_files` (30) or `max_lines` (800) |\n| `tests_required` | warning | Source changes with no corresponding test file changes |\n| `dependencies` | warning | Modified dependency manifests (supply-chain risk) |\n| `dangerous_patterns` | error | User-defined regex denylist applied to added lines |\n| `intent` *(opt-in)* | warning | Uses an LLM to flag changes that go beyond the PR's stated description |\n\n---\n\n## LLM intent check (optional)\n\nThe `intent` rule is the one check that isn't deterministic: it asks Claude whether your diff actually does what the PR says it does — catching an agent that quietly did *more*, or *other*, than the description claims. *AI checking AI.*\n\nHere it is catching a PR titled *\"fix a typo in the README\"* that actually added a whole new module:\n\n![AgentGate's intent check flagging an out-of-scope PR](docs/assets/pr-comment-intent.png)\n\nIt's **off by default**. Turn it on in `.agentgate.yml`:\n\n```yaml\nrules:\n  intent:\n    enabled: true\n```\n\nand give it an Anthropic API key — the `ANTHROPIC_API_KEY` env var, or the `anthropic-api-key` Action input:\n\n```yaml\n- uses: brett-buskirk/agent-gate@v1\n  with:\n    github-token: ${{ secrets.GITHUB_TOKEN }}\n    anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}\n```\n\nLocally, supply the intent yourself:\n\n```bash\nagent-gate check --intent \"Add a refund flow to the payment processor\"\nagent-gate check --intent-file PR_DESCRIPTION.md\n```\n\nNotes:\n- **Never blocks on infrastructure** — a missing key or a failed API call is reported as info, not a failure; your deterministic gate still runs.\n- **Bounded cost** — the diff is summarized and truncated to `max_diff_bytes`; the default model (`claude-haiku-4-5-20251001`) is fast and cheap.\n- **Default severity is `warning`** — LLM judgment is advisory; bump it to `error` if you want it to block.\n\n---\n\n## PR Comment\n\nAgentGate posts a single comment on the PR and updates it in place on re-runs — never spams. It shows the overall verdict, a rule-by-rule summary table, and expandable findings with a file, line, and fix for each.\n\nWhen a PR trips multiple rules, every finding is grouped with its suggestion:\n\n![AgentGate blocking a PR with multiple findings](docs/assets/pr-comment-blocked.png)\n\nA clean PR passes quietly:\n\n![AgentGate passing a clean PR](docs/assets/pr-comment-passed.png)\n\n---\n\n## How it works\n\n1. On a `pull_request` event, the Action fetches the PR diff from the GitHub API\n2. The diff is parsed into a structured model (files, chunks, added/removed lines)\n3. Each enabled rule runs over the model and returns findings\n4. The engine aggregates findings and computes a verdict based on `fail_on`\n5. Reporters post the PR comment, set the check status, and write the Step Summary\n6. The check fails if the verdict is `fail` — blocking merge until the agent's work is reviewed\n\nThe CLI (`agent-gate check`) uses `git diff` instead of the GitHub API, making it usable locally and in pre-commit hooks.\n\n---\n\n## Project structure\n\n```\nagent-gate/\n  action.yml              # GitHub Action metadata\n  src/\n    cli.ts                # CLI entry (commander)\n    action.ts             # Action entry\n    engine.ts             # Aggregates rules → verdict\n    diff/                 # Diff providers + parser\n    rules/                # Rule implementations\n    report/               # Reporters (comment, check, summary, CLI)\n    config/               # Schema (zod) + loader\n    utils/                # Glob matching\n  test/\n    fixtures/             # Sample diffs (clean + dirty per rule)\n    rules/                # Rule unit tests\n    engine.test.ts\n  docs/\n    ABOUT.md              # plain-language overview (non-technical)\n    DESIGN.md             # architecture & internals\n    RELEASING.md          # release + Marketplace runbook\n    SPRINTS.md            # sprint plan\n```\n\n---\n\n## Stack\n\n| Layer | Technology |\n|-------|-----------|\n| Language | TypeScript 5, strict mode |\n| Runtime | Node 20+ |\n| Action bundler | @vercel/ncc |\n| Config validation | zod |\n| Config format | js-yaml |\n| CLI | commander |\n| GitHub API | @actions/github (Octokit) |\n| Tests | Vitest |\n\n---\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md). New rules are the most welcome contribution — there's a dedicated issue template and a clear pattern to follow.\n\n---\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}