Skip to main content

weftgate

A local second brain for coding agents. Understand the code. Remember decisions. Verify changes.

CI PyPI GitHub Marketplace Python 3.10+ Apache 2.0

Give your agent compact source context, decisions that notice changed files, and verification gates for broken code connections. One Python package works through your terminal, MCP, native completion hooks, and GitHub Actions.

Weftgate brain: understand, remember, verify

Understand Remember Verify
Resolve names and explore source-backed contract cards. Save decisions with file anchors; hide stale notes on recall. Check env names, imports and FastAPI routes; collect test evidence before handoff.
weftgate card "POST /orders" weftgate recall "orders" weftgate checkpoint --run

No API key. No runtime dependencies. Local storage. No automatic transcript capture. Context, recall and default verification make no network calls. Explicitly enabled test commands run your repository's code and can have their own side effects.

Watch the 78-second motion demo

Watch the full demo · Transcript and reproducible evidence · How to write an oracle

Try it

pip install weftgate
cd /path/to/your/repo
weftgate setup --agents codex,claude,cursor,antigravity --hooks --instructions
weftgate doctor                   # inspect coverage and configured integrations
weftgate audit                    # find existing broken connections
weftgate resolve "your_function"  # compact source pointers
weftgate checkpoint               # changed code + evidence still needed

From source: pip install git+https://github.com/Avinash-Amudala/weftgate.git. For development, bash scripts/bootstrap.sh installs the extras and runs the offline self-test.

The demo uses an intentionally broken fixture, not a field benchmark:

REJECT  import 'requestz'       → did you mean requests?
REJECT  env var 'DATABSE_URL'   → did you mean DATABASE_URL?
REJECT  handler 'helth'         → did you mean health?

Fix the three names and the fixture passes. A computed key such as os.environ[key] returns review, because static analysis cannot establish its value. To reproduce: weftgate eval mutate --fixture --seed 13.

What the result means

Result Meaning Blocks by default?
accept The extracted reference resolves, or nothing checkable was found. No
review Evidence is incomplete or the reference is dynamic. No
reject A hard claim contradicts the indexed contract. Yes
unverifiable The relevant index or capability is unavailable. No

The rule is block only on a positive, machine-checkable falsehood. Suggestions accompany findings when a nearby candidate exists. An accept verdict is not a test suite result or proof that the application works; inspect coverage with weftgate doctor.

Supported verification contracts

Oracle Checks Conservative limits
Environment variables Reads against dotenv examples, settings schemas, Docker/Compose declarations, code defaults, and configured files. Dynamic keys and absent declaration sources soften. Declare externally supplied variables in your contract.
Python and Node imports Imports against dependency metadata, local packages, known package aliases, and supported path aliases. A manifest alone cannot prove a complete dependency tree. Unknown mappings and optional imports review.
FastAPI / Starlette routes Handler references, router includes, and route claims using a static AST index. Computed registration, external modules, and unresolved prefixes cannot be fully verified.

This is an early static analyzer with bounded parsers. It does not execute your app, replace tests or a security scanner, or cover every framework. Python, Node, and monorepo import resolution can depend on runtime configuration. Missing or ambiguous evidence must soften; please report a false block with a minimal reproduction. Historical field runs document methods and limitations, rather than a claim of zero false positives.

Use it with your agent

weftgate setup --agents all --hooks --instructions --dry-run
weftgate setup --agents codex,claude,cursor,antigravity --hooks --instructions

The standard-library MCP server requires no extra package. Example MCP configuration:

{"mcpServers": {"weftgate": {"command": "weftgate", "args": ["mcp"]}}}

Run the server with the repository as its working directory. weftgate setup --agents all writes supported project configs and prints snippets for clients with global settings. CLI and MCP use the same functions. The new tools are resolve, neighbors, card, remember, recall, forget, and checkpoint, alongside the existing gate tools.

Client Context and recall Native gate installed by setup
Codex Project MCP + AGENTS.md guidance Stop hook requests one repair continuation. Trust via /hooks.
Claude Code Project MCP + rules Pre-edit gate for Edit/Write/MultiEdit; Stop check catches other writes.
Cursor Project MCP + always-applied rule Stop hook with up to two repair follow-ups.
Antigravity Project MCP + workspace rule Stop hook for an idle, normally completed run, with a bounded continuation.
VS Code / Copilot, Windsurf, Claude Desktop MCP setup or printed configuration Use the CLI, Git hook and CI for gating.

Client versions, project trust and organization policy affect hook activation. MCP tools and rules alone do not force an agent to use the gate. Local hooks are guardrails; require the GitHub Action in branch protection to enforce merge checks. Integration paths, activation checks and official references.

A small agent workflow

weftgate card "POST /orders" --budget 1200
weftgate remember "Order idempotency" "Keep duplicate requests idempotent." --file app/orders.py
weftgate recall "orders"
weftgate check app/orders.py
weftgate checkpoint --run --require-ready

Use paths and routes that exist in your project. Configure the commands the last step should observe in weftgate.toml:

[weftgate.workflow]
commands = ["python -m pytest -q"]

--run explicitly permits execution of configured, allowlisted commands. A checkpoint distinguishes proven failures, review findings, missing test evidence and changes during verification. --require-ready exits 3 when evidence is incomplete. A ready checkpoint covers those contracts and commands only. Workflow details.

Context responses contain source pointers, not file bodies. The default budget is 1,500 estimated tokens with a hard cap of 6,000 UTF-8 JSON bytes. Actual model token counts vary. weftgate ledger reports payload bytes and gate events; it does not invent a savings percentage or equate every rejection with an avoided retry. Context coverage and budgets.

CLI and CI

git diff | weftgate check -
weftgate check --staged
weftgate check --path app/main.py --content proposed.py
weftgate claim '[{"kind":"route","method":"POST","path":"/users"}]'
weftgate audit --format=json
weftgate index --show routes

Exit codes: 0 allows the change, 1 blocks according to policy, 2 means a usage or configuration error. Use --format=github for workflow annotations.

name: Verify connections
on: [pull_request]
permissions:
  contents: read
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
        with:
          fetch-depth: 0
      - uses: Avinash-Amudala/weftgate@v0.2.0
        with:
          mode: check             # or audit to inspect the repository

The Action supports base, paths (shell-quoted paths, no shell expansion), block-on, and python-version. Use a full checkout for diff ancestry. The pre-commit hooks use the same gate; pin rev: v0.2.0.

Configure the contract

# weftgate.toml
[weftgate]
oracles = ["env_vars", "imports_lockfile", "routes_fastapi"]
block_on = "reject"                 # reject | review | never
env_declared_in = [".env.example"]

Precedence: WEFTGATE_* environment variables, repository configuration, user configuration, then defaults. The index lives in the user cache, outside the repo. weftgate doctor explains the selected configuration and missing contracts.

Outcome claims such as “tests passed” need machine-checkable evidence. Re-running a named test command or probing a URL requires explicit --run and the configured allowlist. See security and execution boundaries.

Memory that notices changed code

The public package integrates a compact, repository-scoped subset of mnemo's lexical memory design. remember, recall and forget need no companion install. File hashes are checked before recall. Notes with changed or deleted sources stay hidden unless you explicitly request --include-stale. Review a note and replace it with remember --id ID to update its grounding.

An anchored note has unchanged source files; its prose is not proven true. Notes without sources are clearly unverified. Nothing captures your conversations automatically. Storage, privacy and legacy mnemo integration.

Contribute

bash scripts/bootstrap.sh
.venv/bin/ruff check .
.venv/bin/ruff format --check .
.venv/bin/mypy weftgate
.venv/bin/python -m weftgate.selftest
.venv/bin/python -m pytest -q --cov=weftgate --cov-fail-under=85

Start with CONTRIBUTING.md, the oracle guide, and AGENTS.md. New oracles need a real broken example, a correct example, and a dynamic case that reviews. Reproducible false blocks and missing-contract reports are especially useful.

Apache-2.0 · Changelog · Launch plan

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

weftgate-0.2.0.tar.gz (890.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

weftgate-0.2.0-py3-none-any.whl (131.7 kB view details)

Uploaded Python 3

File details

Details for the file weftgate-0.2.0.tar.gz.

File metadata

  • Download URL: weftgate-0.2.0.tar.gz
  • Upload date:
  • Size: 890.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for weftgate-0.2.0.tar.gz
Algorithm Hash digest
SHA256 374ae7e7cac96b70e62b1cc7269daaabd63b7af84f9984221e097840fae87f3f
MD5 e9cdd005d0c399e3b05f2ec5a98da943
BLAKE2b-256 c282ae03e07aeb4f730a5422e99600bba7d1d8e990ef4bd047485b5baafb3710

See more details on using hashes here.

Provenance

The following attestation bundles were made for weftgate-0.2.0.tar.gz:

Publisher: release.yml on Avinash-Amudala/weftgate

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file weftgate-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: weftgate-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 131.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for weftgate-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 99d1a66799faafa8a2706b9bef2f62bde3454f59af47e4448751957934711ccb
MD5 10523decbb32428e19c8eafd70d3ee8e
BLAKE2b-256 74343109738b15907b006e0898f91de6c7eb61f544e9214613dd6fd7169cf998

See more details on using hashes here.

Provenance

The following attestation bundles were made for weftgate-0.2.0-py3-none-any.whl:

Publisher: release.yml on Avinash-Amudala/weftgate

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

This release

0.2.0 This release

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page