{"_id":"@customgpt/claude-quadruple-verification","_rev":"2-030a81b3737ddaec5954e65120e34c76","name":"@customgpt/claude-quadruple-verification","dist-tags":{"latest":"2.2.0"},"versions":{"2.0.0":{"name":"@customgpt/claude-quadruple-verification","version":"2.0.0","keywords":["claude-code","verification","code-quality","security","audit","customgpt"],"author":{"name":"CustomGPT.ai"},"license":"MIT","_id":"@customgpt/claude-quadruple-verification@2.0.0","maintainers":[{"name":"kirollos-atef","email":"kirolskiroatef.com@gmail.com"}],"homepage":"https://github.com/kirollosatef/customgpt-claude-quadruple-verification#readme","bugs":{"url":"https://github.com/kirollosatef/customgpt-claude-quadruple-verification/issues"},"bin":{"customgpt-quadruple-verify":"bin/cli.mjs"},"dist":{"shasum":"c2f2134728c0c7426ba8d7f87da13dfd32305387","tarball":"https://registry.npmjs.org/@customgpt/claude-quadruple-verification/-/claude-quadruple-verification-2.0.0.tgz","fileCount":20,"integrity":"sha512-jGdlM4107nk+4IF0+KEgSzRI7qNb7rSuKXpKNl4l1h18Nn0+chp8QEbqGSIhxkc5wx+2/Z4iDlzJy60YSkCRXw==","signatures":[{"sig":"MEQCIGPxbeV0Ijli2WgWQFb0NGJuoIGDuzWFc7YNtyDSPzrDAiBhjTwwl97GaSssUC1M1mSo+b7le+PvD5jNjg+y+6d7vA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76548},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"fda5f16afcf0373cbfface8d8a83bdb5337e25d8","scripts":{"test":"node --test tests/test-*.mjs","verify":"node install/verify.mjs","test:audit":"node --test tests/test-audit.mjs","test:config":"node --test tests/test-config.mjs","test:cycle1":"node --test tests/test-cycle1.mjs","test:cycle2":"node --test tests/test-cycle2.mjs","test:cycle4":"node --test tests/test-cycle4.mjs"},"_npmUser":{"name":"kirollos-atef","email":"kirolskiroatef.com@gmail.com"},"repository":{"url":"git+https://github.com/kirollosatef/customgpt-claude-quadruple-verification.git","type":"git"},"_npmVersion":"10.9.3","description":"Quadruple verification plugin for Claude Code — blocks placeholder code, security vulnerabilities, and ensures output quality before every operation.","directories":{},"_nodeVersion":"22.20.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/claude-quadruple-verification_2.0.0_1772567155915_0.5098388557453888","host":"s3://npm-registry-packages-npm-production"}},"2.2.0":{"name":"@customgpt/claude-quadruple-verification","version":"2.2.0","description":"Quadruple verification plugin for Claude Code — blocks placeholder code, security vulnerabilities, and ensures output quality before every operation.","type":"module","bin":{"customgpt-quadruple-verify":"bin/cli.mjs"},"engines":{"node":">=18.0.0"},"scripts":{"test":"node --test tests/test-cycle1.mjs tests/test-cycle2.mjs tests/test-cycle4.mjs tests/test-audit.mjs tests/test-config.mjs tests/test-e2e.mjs tests/test-edge-cases.mjs tests/test-enhanced-prompt.mjs tests/test-llm-advisor.mjs","test:cycle1":"node --test tests/test-cycle1.mjs","test:cycle2":"node --test tests/test-cycle2.mjs","test:audit":"node --test tests/test-audit.mjs","test:cycle4":"node --test tests/test-cycle4.mjs","test:config":"node --test tests/test-config.mjs","lint":"eslint scripts/ bin/ tests/","verify":"node install/verify.mjs","prepublishOnly":"npm test"},"keywords":["claude-code","verification","code-quality","security","audit","customgpt","ai","llm","anthropic","claude","hooks","code-review","static-analysis"],"devDependencies":{"eslint":"^9.39.4","globals":"^17.4.0"},"author":{"name":"CustomGPT.ai"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/kirollosatef/customgpt-claude-quadruple-verification.git"},"homepage":"https://kirollosatef.github.io/customgpt-claude-quadruple-verification/","bugs":{"url":"https://github.com/kirollosatef/customgpt-claude-quadruple-verification/issues"},"funding":{"type":"github","url":"https://github.com/sponsors/kirollosatef"},"exports":{".":"./bin/cli.mjs"},"_id":"@customgpt/claude-quadruple-verification@2.2.0","gitHead":"380ccbfef9d1032e5c041782128a644c5c83335e","_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-iNJdXI8dwQlq4owOttUeD3IhIfKng8eXqR3w0XzjILghJo8u5SyfwH/nbcaMclaVqOanuiCC9OWgXSB8JPWOuw==","shasum":"e4711f28020b5c992fa52cb836c4ab9fec9d78de","tarball":"https://registry.npmjs.org/@customgpt/claude-quadruple-verification/-/claude-quadruple-verification-2.2.0.tgz","fileCount":20,"unpackedSize":83404,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@customgpt%2fclaude-quadruple-verification@2.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICsRg8zo2IyLHO1Vwn0NUdu4qZpsnbj6wc/nH0glT5YUAiA7wnD+e6Co/Xr6183Tp02wtlj48bg6VZElpgs7CE0ERA=="}]},"_npmUser":{"name":"kirollos-atef","email":"kirollosateffawze@gmail.com"},"directories":{},"maintainers":[{"name":"kirollos-atef","email":"kirollosateffawze@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/claude-quadruple-verification_2.2.0_1773349927785_0.8517799666014061"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-03T19:45:55.811Z","modified":"2026-03-12T21:12:08.571Z","2.0.0":"2026-03-03T19:45:56.089Z","2.2.0":"2026-03-12T21:12:08.276Z"},"bugs":{"url":"https://github.com/kirollosatef/customgpt-claude-quadruple-verification/issues"},"author":{"name":"CustomGPT.ai"},"license":"MIT","homepage":"https://kirollosatef.github.io/customgpt-claude-quadruple-verification/","keywords":["claude-code","verification","code-quality","security","audit","customgpt","ai","llm","anthropic","claude","hooks","code-review","static-analysis"],"repository":{"type":"git","url":"git+https://github.com/kirollosatef/customgpt-claude-quadruple-verification.git"},"description":"Quadruple verification plugin for Claude Code — blocks placeholder code, security vulnerabilities, and ensures output quality before every operation.","maintainers":[{"name":"kirollos-atef","email":"kirollosateffawze@gmail.com"}],"readme":"# CustomGPT Quadruple Verification for Claude Code\n\n[![CI](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/actions/workflows/ci.yml/badge.svg)](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/actions/workflows/ci.yml)\n[![npm version](https://img.shields.io/npm/v/@customgpt/claude-quadruple-verification)](https://www.npmjs.com/package/@customgpt/claude-quadruple-verification)\n[![npm downloads](https://img.shields.io/npm/dm/@customgpt/claude-quadruple-verification)](https://www.npmjs.com/package/@customgpt/claude-quadruple-verification)\n[![GitHub stars](https://img.shields.io/github/stars/kirollosatef/customgpt-claude-quadruple-verification)](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/stargazers)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Zero Dependencies](https://img.shields.io/badge/dependencies-0-brightgreen)](https://github.com/kirollosatef/customgpt-claude-quadruple-verification)\n[![npm provenance](https://img.shields.io/badge/provenance-verified-brightgreen?logo=npm)](https://www.npmjs.com/package/@customgpt/claude-quadruple-verification)\n\nCatch security bugs, placeholder code, and hallucinated claims in AI-generated code — before it ships.\n\nBuilt by [CustomGPT.ai](https://customgpt.ai) for production teams running Claude Code at scale.\n\n![Demo — eval() blocked, research claims blocked, clean code passes](demo/demo.gif)\n\n## The Problem\n\n41% of all new code committed in 2026 is AI-generated — and [58% of it contains security vulnerabilities](https://www.veracode.com/blog/research/ai-code-security-2025). Every existing tool (SonarQube, Snyk, Semgrep, CodeRabbit) works **after** the code is written — at CI, PR review, or repo scan. Nothing catches issues at the moment of generation.\n\nQuadruple Verification intercepts Claude Code operations **in real time**, before code hits the filesystem. Regex fast-gates block obvious violations in <50ms. An AI self-review layer catches subtle issues across quality, security, research accuracy, and completeness.\n\n## What It Does\n\nFour verification cycles run automatically on every Claude Code operation:\n\n| Cycle | When | What |\n|-------|------|------|\n| **Cycle 1 — Code Quality** | Before file write/edit | Regex gate blocks TODO, placeholder, stub, and incomplete code |\n| **Cycle 2 — Security** | Before write/edit/bash/MCP | Regex gate blocks eval(), hardcoded secrets, SQL injection, XSS, destructive commands |\n| **Cycle 3 — Output Quality** | Before Claude finishes | AI multi-section review: code quality, security, research claims, completeness |\n| **Cycle 4 — Research Claims** | Before write/edit of research .md | Blocks vague language, unverified stats, missing source URLs |\n| **Audit Trail** | After every operation | Full JSONL audit log + optional LLM advisory analysis |\n\n## Quick Start\n\n### Requirements\n- Node.js >= 18\n- Claude Code CLI\n\n### Option 1: Marketplace (Recommended)\n\nTwo commands inside Claude Code — includes auto-updates:\n\n```\n/plugin marketplace add kirollosatef/customgpt-claude-quadruple-verification\n/plugin install customgpt-claude-quadruple-verification@kirollosatef-customgpt-claude-quadruple-verification\n```\n\nThat's it. The plugin auto-updates every session.\n\n### Option 2: npx\n\nRun from any terminal:\n\n```bash\nnpx @customgpt/claude-quadruple-verification\n```\n\n### Option 3: Manual Install\n\n**Windows (PowerShell):**\n```powershell\ngit clone https://github.com/kirollosatef/customgpt-claude-quadruple-verification.git\ncd customgpt-claude-quadruple-verification\n.\\install\\install.ps1\n```\n\n**macOS / Linux:**\n```bash\ngit clone https://github.com/kirollosatef/customgpt-claude-quadruple-verification.git\ncd customgpt-claude-quadruple-verification\nbash install/install.sh\n```\n\n### Verify Installation\n```bash\nnode install/verify.mjs\n```\n\n### Test It\n1. Start Claude Code in any project\n2. Ask: *\"Create a Python file with a TODO comment\"*\n3. The operation should be **BLOCKED** with an explanation\n4. Check audit logs in `.claude/quadruple-verify-audit/`\n\n## Team Setup\n\nTo auto-prompt all team members to install the plugin, commit this file to each repo:\n\n**`.claude/settings.json`**\n```json\n{\n  \"plugins\": [\n    \"kirollosatef/customgpt-claude-quadruple-verification\"\n  ]\n}\n```\n\nWhen anyone opens the project in Claude Code, they'll be prompted to install the plugin. See [`docs/team-setup/settings.json`](docs/team-setup/settings.json) for the template.\n\n## Auto-Updates\n\n- **Marketplace installs** auto-update every session — push to the repo and everyone gets it.\n- **npx installs** get the latest version each time `npx` runs.\n- **Manual installs** require `git pull` to update.\n\n## How It Works\n\nThe plugin uses Claude Code's hook system to intercept operations at three points:\n\n```\nUser Request → Claude generates code\n                    ↓\n              ┌─────────────┐\n              │  Cycle 1    │  PreToolUse (Write|Edit)\n              │  Quality    │  Blocks placeholder/TODO code\n              └──────┬──────┘\n                     ↓\n              ┌─────────────┐\n              │  Cycle 2    │  PreToolUse (Write|Edit|Bash|MCP)\n              │  Security   │  Blocks eval, secrets, injection\n              └──────┬──────┘\n                     ↓\n              ┌─────────────┐\n              │  Cycle 3    │  Stop (prompt hook)\n              │  Output QA  │  Second AI reviews final output\n              └──────┬──────┘\n                     ↓\n              ┌─────────────┐\n              │  Cycle 4    │  PreToolUse (Write|Edit) + Stop\n              │  Research   │  Blocks vague claims, missing sources\n              └──────┬──────┘\n                     ↓\n              ┌─────────────┐\n              │  Audit      │  PostToolUse (all tools)\n              │  Logger     │  JSONL trail of every operation\n              └─────────────┘\n```\n\n## Benchmarks\n\nTested with a 45-scenario A/B benchmark across 6 categories (Feb 2026):\n\n| Category | Quality Change | Notes |\n|----------|---------------|-------|\n| **Agent SDK tasks** | **+31.8%** | Stop-gate prevents plan-only output |\n| Code Quality | +0.1% (neutral) | Regex gates add near-zero overhead |\n| Security tasks | +2.3% | Catches eval(), hardcoded secrets |\n| Research writing | +8.7% | Source verification enforced |\n| **Overall** | **+4.4%** | 1.5x latency, 1.3x tokens |\n\nThe AI self-review stop-gate (Cycle 3) is where the measurable quality improvement comes from. Regex gates (Cycles 1, 2, 4) add <50ms and catch real but relatively rare violations.\n\nFull methodology: [docs/BENCHMARK-RESULTS.md](docs/BENCHMARK-RESULTS.md)\n\n## How It Compares\n\n| Feature | This Plugin | SonarQube | Snyk | CodeRabbit | Semgrep |\n|---------|:-----------:|:---------:|:----:|:----------:|:-------:|\n| **When it runs** | At generation | CI | Repo scan | PR review | CI |\n| **Blocks before file write** | Yes | No | No | No | No |\n| **AI-specific rules** (stubs, TODOs, hallucinations) | Yes | No | No | Partial | No |\n| **AI self-review** | Yes | No | No | Yes (PR) | No |\n| **Research claim verification** | Yes | No | No | No | No |\n| **Zero dependencies** | Yes | No | No | No | No |\n| **Free & open source** | Yes | Community | Free tier | $12-24/dev/mo | Free tier |\n| **Works at generation time** | Yes | No | No | No | No |\n\n## Configuration\n\nConfiguration merges from three sources (later overrides earlier):\n\n1. **Plugin defaults** — `config/default-rules.json`\n2. **User config** — `~/.claude/quadruple-verify-config.json`\n3. **Project config** — `$PROJECT/.claude/quadruple-verify-config.json`\n\n### Example: Disable a Rule\n```json\n{\n  \"disabledRules\": [\"no-todo\"]\n}\n```\n\n### Example: Project-Level Config\nCreate `.claude/quadruple-verify-config.json` in your project:\n```json\n{\n  \"disabledRules\": [\"no-empty-pass\"],\n  \"audit\": {\n    \"enabled\": true\n  }\n}\n```\n\n## Rules Reference\n\nSee [docs/RULES.md](docs/RULES.md) for the complete list of verification rules with examples.\n\n### Cycle 1 — Code Quality\n- `no-todo` — Block TODO/FIXME/HACK/XXX comments\n- `no-empty-pass` — Block placeholder `pass` in Python\n- `no-not-implemented` — Block `raise NotImplementedError`\n- `no-ellipsis` — Block `...` placeholder in Python\n- `no-placeholder-text` — Block \"placeholder\", \"stub\", \"implement this\"\n- `no-throw-not-impl` — Block `throw new Error(\"not implemented\")`\n\n### Cycle 2 — Security\n- `no-eval` — Block `eval()`\n- `no-exec` — Block `exec()` in Python\n- `no-os-system` — Block `os.system()` in Python\n- `no-shell-true` — Block `shell=True` in subprocess\n- `no-hardcoded-secrets` — Block hardcoded API keys, passwords, tokens\n- `no-raw-sql` — Block SQL injection via string concatenation\n- `no-innerhtml` — Block `.innerHTML =` (XSS)\n- `no-rm-rf` — Block destructive `rm -rf` on critical paths\n- `no-chmod-777` — Block world-writable permissions\n- `no-curl-pipe-sh` — Block `curl | sh` patterns\n- `no-insecure-url` — Block non-HTTPS URLs (except localhost)\n\n### Cycle 4 — Research Claims\n- `no-vague-claims` — Block \"studies show\", \"experts say\", and similar vague language\n- `no-unverified-claims` — Block claims without a verification tag (`<!-- VERIFIED -->`, `<!-- PERPLEXITY_VERIFIED -->`, etc.)\n- `no-unsourced-claims` — Block claims lacking a source URL within 300 characters\n\n## Development\n\n### Run Tests\n```bash\nnpm test\n```\n\n### Run Individual Test Suites\n```bash\nnpm run test:cycle1\nnpm run test:cycle2\nnpm run test:cycle4\nnpm run test:audit\nnpm run test:config\n```\n\n### Run Smoke Test\n```bash\nnpm run verify\n```\n\n## Architecture\n\nSee [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) for detailed technical documentation.\n\n## Troubleshooting\n\nSee [docs/TROUBLESHOOTING.md](docs/TROUBLESHOOTING.md) for common issues and solutions.\n\n## Contributing\n\nWe welcome contributions! See [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\nLook for issues labeled [`good first issue`](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/labels/good%20first%20issue) to get started.\n\n## Used By\n\n- [CustomGPT.ai](https://customgpt.ai) — Production AI agent platform, internal Claude Code workflows\n\n*Using this plugin? [Open a PR](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/pulls) to add your team here.*\n\n## Support\n\nIf this plugin helps your team ship safer AI-generated code, please [star this repository](https://github.com/kirollosatef/customgpt-claude-quadruple-verification) — it helps others find it.\n\nFound a bug or want a new rule? [Open an issue](https://github.com/kirollosatef/customgpt-claude-quadruple-verification/issues).\n\n## License\n\nMIT — see [LICENSE](LICENSE)\n","readmeFilename":"README.md"}