Skip to main content

Model-agnostic quality-gate kit for AI-assisted developers

Project description

HyoDo

Honest quality gates for AI-assisted Python work.

CI PyPI Python License

Scan AI-assisted changes for secrets, dangerous commands, and production risks. Then absorb your project's own tests and linters as quality gates. Scores are review signals only — never automatic approval.

Start here (any repository)

pipx install hyodo
cd your-project
hyodo safe                 # early-warning scan, no setup
hyodo safe --strict        # exit 1 on high-severity findings
hyodo safe --json          # machine-readable findings for CI

CI snippet (GitHub Actions)

- run: pipx install hyodo
- run: hyodo safe --strict --json

hyodo safe is an early-warning scanner, not a full security audit.

Bring your own gates (optional)

hyodo init                 # detect tools → write .hyodo/gates.toml
hyodo check                # run absorbed gates
hyodo dashboard --open     # local evidence panel

hyodo init reads existing tooling (pyproject.toml pytest/ruff/mypy/ pyright, npm test/lint, tsconfig.json, go.mod, Cargo.toml, Makefile test:/lint:) and writes .hyodo/gates.toml. It does not reinvent those tools.

Measured CLI contracts (v4.2.0):

  • Existing .hyodo/gates.tomlhyodo init exits 1 unless --force.
  • Empty detection → starter template with commented examples (no guessing).
  • Starter with no gates defined → hyodo check exits 2 (This is not a validation pass).
  • When present, .hyodo/gates.toml beats the HyoDo checkout preset.

Six pillars — branding kept, engineering mapped

Pillar Technical meaning Measured by
Truth (眞 / 진) Type / static correctness Command gate (typechecker)
Goodness (善 / 선) Tests + safety stability Command gate (tests) + safe
Beauty (美 / 미) Lint / format Command gate (linter)
Benevolence (仁 / 인) Public-surface integrity Native AST scan
Hyo (孝 / 효) Consent + data protection Native AST scan
Yeong (永 / 영) Continuity of measurement .hyodo/history.jsonl

Truth / Goodness / Beauty come from commands you absorb (or HyoDo's preset). Benevolence / Hyo / Yeong are never command gates — they cannot be gamed by a fake-green shell script. Missing sources show Not measured.

Detail and fail-closed score math: PHILOSOPHY.md.

Local instrument panel

hyodo dashboard --open
# → http://127.0.0.1:8768
Truth / Goodness / Beauty   PASS | FAIL | Not measured
In / Hyo / Yeong            native collectors
[Measure again now]         raw JSON → /api/evidence

(Replace with a real screenshot under docs/ when available.)

The panel never invents a composite score. With .hyodo/gates.toml, gate rows use your absorbed names; otherwise the checkout preset applies.

How it works / security

  • Loopback only (127.0.0.1) — analysis stays off the LAN.
  • 15s poll of /api/evidence (no websocket dependency).
  • --interval N re-measures in the background.
  • Measure again now is token-protected; no path injection.
  • Change-safety card uses the current Git diff only; no diff → Not measured.

Install

Python 3.10 or newer.

pip install -U hyodo
# or: pipx install hyodo
hyodo --version

See Quick Start.

Commands

Command Purpose
hyodo safe [PATH] Safety findings (non-blocking)
hyodo safe --strict Exit 1 on high-severity findings
hyodo safe --json JSON findings for CI
hyodo init [PATH] Write .hyodo/gates.toml (BYOG)
hyodo check [PATH] Absorbed gates, else checkout preset
hyodo check --general Bounded multi-language syntax sample
hyodo score ... Optional review signal
hyodo dashboard Local evidence panel
hyodo start Onboarding guidance
hyodo trinity "…" Structured review checklist

Exit contracts

safe: 0 print findings · 1 high + --strict · 2 bad path.

check: 0 ≥1 executed gate and all executed passed · 1 executed failed · 2 missing path, malformed gates.toml, or zero executed gates.

Resolution: --general.hyodo/gates.toml → HyoDo checkout preset → guidance toward hyodo init.

Optional review score

hyodo score --truth 0.9 --goodness 0.9 --beauty 0.9 \
  --benevolence 0.9 --hyo 0.9

Optional HYOGOOK V5 F-score (philosophy V6 labels) uses a geometric mean: any pillar at 0 collapses the whole signal (fail-closed). Scores never replace tests, safe, or human approval. See PHILOSOPHY.md.

Scope

Surface Status
hyodo/ package and CLI Public release surface
tests/ and CI workflows Release verification

Model-agnostic ≠ language-agnostic. --general is a bounded sample, not universal multi-stack coverage.

For contributors (dogfood)

git clone https://github.com/lofibrainwav/HyoDo.git && cd HyoDo
python -m venv .venv && source .venv/bin/activate
python -m pip install -e ".[dev]" && ./.venv/bin/hyodo check

See CONTRIBUTING.md.

Documentation

License

HyoDo is available under the MIT License.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hyodo-4.2.0.tar.gz (84.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hyodo-4.2.0-py3-none-any.whl (44.1 kB view details)

Uploaded Python 3

File details

Details for the file hyodo-4.2.0.tar.gz.

File metadata

  • Download URL: hyodo-4.2.0.tar.gz
  • Upload date:
  • Size: 84.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for hyodo-4.2.0.tar.gz
Algorithm Hash digest
SHA256 55245542bd2d1c3a6d0bcb4fa53624ce777262e390383933e260229875f3c377
MD5 d0b453f6ca35e78bfc6d9d19090915f3
BLAKE2b-256 2aba32e8aa2e265a246f08d2143a38a422ccf85d26347c4ce72758c525d525d7

See more details on using hashes here.

Provenance

The following attestation bundles were made for hyodo-4.2.0.tar.gz:

Publisher: publish.yml on lofibrainwav/HyoDo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file hyodo-4.2.0-py3-none-any.whl.

File metadata

  • Download URL: hyodo-4.2.0-py3-none-any.whl
  • Upload date:
  • Size: 44.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for hyodo-4.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f3089f3cf1a197c7d2dd729fdd7e3a1739906f4f692cdcc15fc2acdbc0e516a3
MD5 9ab5addbc65ac1465c273403d420b27d
BLAKE2b-256 000b65d0b9eea7ede69b4c6c1913823aed5b47e1ec4a8da5b74e52f57770b8ac

See more details on using hashes here.

Provenance

The following attestation bundles were made for hyodo-4.2.0-py3-none-any.whl:

Publisher: publish.yml on lofibrainwav/HyoDo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page