Skip to main content

HyoDo

Honest local guardrails for AI-assisted development.

HyoDo is a model-agnostic Python CLI that helps teams prove which checks ran, record agent actions, enforce local tool and path policy, and reuse existing tests and linters without turning missing evidence into a green result. Review signals never grant automatic approval. Unobserved is never green.

CI PyPI Python License OpenSSF Scorecard

Why HyoDo exists

AI coding tools can move quickly, but a normal green check does not always answer:

  • Did the check actually run?
  • Did the agent touch only approved tools and paths?
  • Was missing or unreadable evidence treated as a pass?

HyoDo makes those boundaries explicit with local evidence, policy decisions, and fail-closed exit contracts.

30-second start

pipx install hyodo
cd your-project
hyodo safe --strict
hyodo init
hyodo check

safe works immediately in any repository. init is optional: it detects tools you already use and writes .hyodo/gates.toml; check then runs those gates. No detected tooling means no invented green check. See docs/GATES_SYNTAX.md for every gates.toml field.

Commit .hyodo/gates.toml and .hyodo/policy.toml (team-shared policy); keep the rest of .hyodo/ out of version control — see what to commit for the .gitignore split.

What it does

Need HyoDo surface
Early-warning safety scan hyodo safe
Reuse existing project checks hyodo init → hyodo check
Agent action audit trail hyodo event record
Tool / path / step policy hyodo policy check
Schema / eval / evidence report hyodo schema, eval, report
Local evidence panel hyodo dashboard --open
Optional MCP adapter hyodo mcp stdio / serve
MCP diagnostics and audit hyodo mcp doctor, access-log, rules
Onboarding, harness and host wiring hyodo start, connect, mcp config
Lens, absorption, graph, eye hyodo skills, inspect, graph, eye
Reader vocabulary, host continuity --audience, hyodo mcp continuity

Current public claim lock

This table is the latest published-package boundary. It does not describe unreleased main work. For current source and measured-state readback, see docs/CURRENT_STATE.md.

Capability Status Evidence boundary
gates / ledger / friction preview SHIPPED Local preview/export; ledger.
Graph v1 SHIPPED (site DEMO FIXTURE) Local dashboard; fixed demo site.
Graph v2 join NOT BUILT No join runtime/viewer; SCC oracle only.
Codex hooks UNOBSERVED Adapter built; no receipt; no installer.
Cursor hooks UNOBSERVED Adapter built; no live host observed.
remote MCP / ChatGPT CONTRACT ONLY Hosted contract; runtime unobserved.
ACL runtime / Wisdom Reflex RESEARCH Hypothesis; no automatic router.
friction collector NOT BUILT No collector/uploader; transport disabled.

Honest boundaries

HyoDo is deliberately narrow:

  • It is not a runtime sandbox or process interceptor.
  • hyodo safe is an early-warning scanner, not a full security audit.
  • A DENY result must still be enforced by the caller.
  • HyoDo Integrity Score: advisory only, never approval; HYOGOOK V5 lineage.
  • The public MCP server supports loopback or authenticated Tailscale binding; public 0.0.0.0 listeners are not supported.
  • Missing, unreadable, or unmeasured evidence is never reported as healthy.
  • Embeddings, model calls, capture tools, and remote inventories stay outside the package: HyoDo keeps digests, hashes, and receipts, never the payload.

Use your existing CI

- uses: actions/setup-python@v5
  with:
    python-version: "3.12"
- run: pip install hyodo
- run: hyodo safe --strict --json
- uses: lofibrainwav/HyoDo/.github/actions/hyodo@vX.Y.Z
hyodo init && hyodo check

init can absorb pytest, Ruff, mypy, Pyright, npm scripts, Go, Cargo, and Makefile targets. Empty or malformed gate configuration exits 2, not 0.

Hooks and SARIF

Pin a signed release containing the hooks (v4.11.0 predates them):

- repo: https://github.com/lofibrainwav/HyoDo
  rev: vX.Y.Z
  hooks: [{id: hyodo-check}, {id: hyodo-safe-strict}]

hyodo report --format sarif writes a SARIF 2.1.0 visibility report. Measured DENY and unreadable-ledger conditions become alerts; hyodo check remains the fail-closed gate for missing or unmeasured quality evidence.

Optional agent evidence

hyodo event validate --file step.json
hyodo event record --file step.json --root . --policy .hyodo/policy.toml
hyodo policy check --file step.json --config .hyodo/policy.toml
hyodo schema check --schema agent.schema.json --payload step.json --json

Default event storage is digest-only. See examples/fde-evidence-spine/ for a demo event and examples/host-policies/ for a dual-host allowed_tools list (not a Cursor hook). Policy trust: docs/POLICY_TRUST.md.

Optional MCP

pip install 'hyodo[mcp]'
hyodo mcp stdio --root .                       # local stdio
hyodo mcp serve --bind tailscale --bind-ip 100.99.88.77 \
  --token "$HYODO_MCP_TOKEN" --root .          # private-network connector

The MCP adapter uses the same CLI contracts rather than a second engine. SDK v1/v2 are in CI. mcp.hyodo.app is contract-only, not this path.

Exit contracts

Command Contract
safe 0 report · 1 strict high finding · 2 bad path
check 0 executed gates passed · 1 gate failed · 2 none/malformed
event, policy 0 valid/ALLOW; 1 invalid/DENY; 2 unobserved; 3 ASK
schema check 0 valid · 1 validation error · 2 unobserved input

Install and support

Python 3.10+: pipx install hyodo or pip install -U hyodo.

License

MIT. See LICENSE.

Release files for hyodo 4.19.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hyodo 4.19.3
File Size Uploaded
hyodo-4.19.3.tar.gz 506.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hyodo 4.19.3
File Interpreter ABI Platform
hyodo-4.19.3-py3-none-any.whl Python 3 none any Details

Total release size: 792.9 kB

Release files / hyodo-4.19.3.tar.gz

Download URL hyodo-4.19.3.tar.gz
Size 506.7 kB
Tags Source
SHA-256 checksum
How to use checksums
08c3ea97ce2dab84f3da447f979fe7e74eb06508cc93b7474e5b6f33200ad72f
BLAKE2b-256 checksum
How to use checksums
1d713ea7a2478068c8cc010f36904fb34586f867d625b0597914ef6ac4f28405
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release files / hyodo-4.19.3-py3-none-any.whl

Download URL hyodo-4.19.3-py3-none-any.whl
Size 286.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e467eb18c27f8e54df188f04dd4c1cc8a5d18fced0cc6bd85a04c4dce4e22adb
BLAKE2b-256 checksum
How to use checksums
54d53ff360f58ad17db021b5b8752c0b10e119a1a2f40a275da4f25d7e81e0e9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release history Release notifications | RSS feed

4.21.8

2 release files

4.21.7

2 release files

4.21.5

2 release files

4.21.4

2 release files

4.21.3

2 release files

4.21.1

2 release files

4.21.0

2 release files

4.20.2

2 release files

4.20.1

2 release files

4.20.0

2 release files

4.19.9

2 release files

4.19.8

2 release files

4.19.7

2 release files

4.19.6

2 release files

4.19.5

2 release files

4.19.4

2 release files

This release

4.19.3 This release

2 release files

4.19.2

2 release files

4.19.1

2 release files

4.19.0

2 release files

4.18.0

2 release files

4.9.0

2 release files

4.8.2

2 release files

4.8.1

2 release files

4.8.0

2 release files

4.4.0

2 release files

4.3.0

2 release files

4.2.0

2 release files

4.0.1

2 release files

4.0.0

2 release files

3.3.0

2 release files

3.2.1

2 release files

3.2.0

2 release files

3.1.8

2 release files

3.1.7

2 release files

3.1.6

2 release files

3.1.5

2 release files

3.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page