Skip to main content

weftgate

Catch broken connections in agent-written code before it ships.

CI PyPI Python 3.10+ Apache 2.0

A mistyped environment variable. An import missing from the lockfile. A FastAPI route pointing at a handler that does not exist. Weftgate checks these connections against your repository through one local CLI, MCP server, hook, or GitHub Action.

No API key. No runtime dependencies. No network calls on the default verification path.

Watch the 52-second demo

Watch the full demo · Transcript and reproducible evidence · How to write an oracle

Try it

pip install weftgate
cd /path/to/your/repo
weftgate doctor                  # see which contracts can be checked
weftgate audit                   # inspect the current repository
weftgate check app/main.py        # check a file or directory

From source: pip install git+https://github.com/Avinash-Amudala/weftgate.git. For development, bash scripts/bootstrap.sh installs the extras and runs the offline self-test.

The demo uses an intentionally broken fixture, not a field benchmark:

REJECT  import 'requestz'       → did you mean requests?
REJECT  env var 'DATABSE_URL'   → did you mean DATABASE_URL?
REJECT  handler 'helth'         → did you mean health?

Fix the three names and the fixture passes. A computed key such as os.environ[key] returns review, because static analysis cannot establish its value. To reproduce: weftgate eval mutate --fixture --seed 13.

What the result means

Result Meaning Blocks by default?
accept The extracted reference resolves, or nothing checkable was found. No
review Evidence is incomplete or the reference is dynamic. No
reject A hard claim contradicts the indexed contract. Yes
unverifiable The relevant index or capability is unavailable. No

The rule is block only on a positive, machine-checkable falsehood. Suggestions accompany findings when a nearby candidate exists. An accept verdict is not a test suite result or proof that the application works; inspect coverage with weftgate doctor.

Supported contracts in v0.1

Oracle Checks Conservative limits
Environment variables Reads against dotenv examples, settings schemas, Docker/Compose declarations, code defaults, and configured files. Dynamic keys and absent declaration sources soften. Declare externally supplied variables in your contract.
Python and Node imports Imports against dependency metadata, local packages, known package aliases, and supported path aliases. A manifest alone cannot prove a complete dependency tree. Unknown mappings and optional imports review.
FastAPI / Starlette routes Handler references, router includes, and route claims using a static AST index. Computed registration, external modules, and unresolved prefixes cannot be fully verified.

This is an early static analyzer with bounded parsers. It does not execute your app, replace tests or a security scanner, or cover every framework. Python, Node, and monorepo import resolution can depend on runtime configuration. Missing or ambiguous evidence must soften; please report a false block with a minimal reproduction. Historical field runs document methods and limitations, rather than a claim of zero false positives.

Use it with your agent

weftgate setup --agents claude,cursor,vscode
weftgate setup --hooks             # review the generated local configuration

The standard-library MCP server requires no extra package. Example MCP configuration:

{"mcpServers": {"weftgate": {"command": "weftgate", "args": ["mcp"]}}}

Run the server with the repository as its working directory. weftgate setup --agents all writes supported project configs and prints snippets for clients with global settings. CLI and MCP use the same gate functions. Tools include check_change, check_claim, audit, suggest, index_status, and index.

CLI and CI

git diff | weftgate check -
weftgate check --staged
weftgate check --path app/main.py --content proposed.py
weftgate claim '[{"kind":"route","method":"POST","path":"/users"}]'
weftgate audit --format=json
weftgate index --show routes

Exit codes: 0 allows the change, 1 blocks according to policy, 2 means a usage or configuration error. Use --format=github for workflow annotations.

name: Verify connections
on: [pull_request]
permissions:
  contents: read
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
        with:
          fetch-depth: 0
      - uses: Avinash-Amudala/weftgate@v0.1.0
        with:
          mode: check             # or audit to inspect the repository

The Action supports base, paths (shell-quoted paths, no shell expansion), block-on, and python-version. Use a full checkout for diff ancestry. The pre-commit hooks use the same gate; pin rev: v0.1.0.

Configure the contract

# weftgate.toml
[weftgate]
oracles = ["env_vars", "imports_lockfile", "routes_fastapi"]
block_on = "reject"                 # reject | review | never
env_declared_in = [".env.example"]

Precedence: WEFTGATE_* environment variables, repository configuration, user configuration, then defaults. The index lives in the user cache, outside the repo. weftgate doctor explains the selected configuration and missing contracts.

Outcome claims such as “tests passed” need machine-checkable evidence. Re-running a named test command or probing a URL requires explicit --run and the configured allowlist. See security and execution boundaries.

Optional memory integration

Weftgate exposes memory anchor, memory check, and memory changes through the CLI and MCP. With mnemo installed in the same interpreter, add "oracles": ["weftgate.memory"] to .mnemo.json to check structured memory claims.

Changed evidence keeps memories stale; checking does not silently replace the original hashes or prove remembered prose. See the integration contract. Mnemo is a separate companion repository and is not required to use Weftgate.

Contribute

bash scripts/bootstrap.sh
.venv/bin/ruff check .
.venv/bin/ruff format --check .
.venv/bin/mypy weftgate
.venv/bin/python -m weftgate.selftest
.venv/bin/python -m pytest -q --cov=weftgate --cov-fail-under=85

Start with CONTRIBUTING.md, the oracle guide, and AGENTS.md. New oracles need a real broken example, a correct example, and a dynamic case that reviews. Reproducible false blocks and missing-contract reports are especially useful.

Apache-2.0 · Changelog · Launch plan

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

weftgate-0.1.1.tar.gz (309.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

weftgate-0.1.1-py3-none-any.whl (113.5 kB view details)

Uploaded Python 3

File details

Details for the file weftgate-0.1.1.tar.gz.

File metadata

  • Download URL: weftgate-0.1.1.tar.gz
  • Upload date:
  • Size: 309.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for weftgate-0.1.1.tar.gz
Algorithm Hash digest
SHA256 67f176e89880c53ef348bb94cba4808fcb4f1fad1c02b28e16ae319c2da18c45
MD5 add4c43d2fb6e137a99d579adbb06e4f
BLAKE2b-256 5add5eeb3b6edfc65c4be03c17ea8fd5100ed527d6e0d8334eea27a48b66ba95

See more details on using hashes here.

Provenance

The following attestation bundles were made for weftgate-0.1.1.tar.gz:

Publisher: release.yml on Avinash-Amudala/weftgate

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file weftgate-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: weftgate-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 113.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for weftgate-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 fddd08b6f8ee1ae5cbf6ec1361909bc7573570ee695573b5886f09981214a6ab
MD5 6bdd2376a3dc9ad277e15edae29b5cb3
BLAKE2b-256 c3fdf5a3f42275dc74aa65501804626a4a5404e5a6acba6640bfcbe33756b69b

See more details on using hashes here.

Provenance

The following attestation bundles were made for weftgate-0.1.1-py3-none-any.whl:

Publisher: release.yml on Avinash-Amudala/weftgate

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.0

2 files

This release

0.1.1 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page