@schava09/slopgate
v0.1.0
Published
The verification gate for AI-generated code. Catches the failure modes coding agents introduce — hallucinated APIs, silent logic drift, weakened tests, security regressions — and blocks the merge until they're addressed.
Maintainers
Readme
slopgate
The verification gate for AI-generated code.
Coding agents ship code faster than humans can review it. The bottleneck in 2026 isn't writing code — it's verifying it. slopgate is the gate that runs on a diff and catches the specific failure modes agents introduce, so bad changes stop at the door instead of in production.
npx @schava09/slopgateIt reviews your current diff and exits non-zero if it finds a blocking problem — drop it in CI and it gates every PR.
What it catches
Not style. Not nits. The things that actually pass human review under volume and break the build (or the business):
| | | |---|---| | 🧩 Hallucinated APIs | Calls to functions, imports, config keys, or flags that look real but don't exist. | | 🔀 Silent logic drift | An inverted condition, a changed default, a dropped edge case in a "no-behavior-change" refactor. | | 🧪 Weakened / missing tests | New logic with no test; an assertion loosened or changed to match wrong behavior. | | 🚧 Stubs masquerading as done | TODOs, mock return values, empty catch blocks, functions that return early without doing the work. | | 🔓 Security regressions | Injected SQL/command/path, committed secrets, removed auth checks, unsafe deserialization. | | 🐛 Agent-blind correctness bugs | Missing awaits, null derefs, resource leaks, races, broken error handling. |
Every finding cites a real line, quotes the offending code, carries a confidence level, and gives a concrete fix — no "consider reviewing this."
What it looks like
Run against a 4-line diff that inverts a + into a -, adds a raw-SQL checkout, and leaves a TODO:
## slopgate — verification gate
Verdict: This diff is not mergeable: it inverts the summation in `total`
(now returns a negative total), adds a `checkout` function that concatenates
user input into raw SQL against an undefined `db` reference, and leaves a
TODO in place with no tests.
6 finding(s): 2 critical, 2 high, 2 medium
🟥 Summation operator flipped from + to -, total is now negative
cart.js:3 · critical · logic-drift · confidence: high
`return items.reduce((a,b)=>a-b.price,0)` — starting from 0 and subtracting
each price yields the negation of the cart total. Nothing in the diff
justifies this.
Fix: Restore `a+b.price`.
🟥 SQL injection via string-concatenated user id in checkout
cart.js:5 · critical · security · confidence: high
Fix: Use a parameterized query, `db.execute('... id = ?', [u.id])`.
🟧 `db` is undefined — no import or parameter provides it
cart.js:5 · high · hallucinated-api · confidence: high
Throws ReferenceError at call time.…plus the missing-tests, un-awaited-promise, and TODO-stub findings. Exit code 1 → CI fails.
Install & run
Requires Node 18+ and an Anthropic API key.
export ANTHROPIC_API_KEY=sk-ant-...
# Review your branch against origin/main
npx @schava09/slopgate
# Review only what's staged (great as a pre-commit hook)
npx @schava09/slopgate --staged
# Diff against a specific ref, block only on high+ severity
npx @schava09/slopgate --base origin/develop --fail-on highOptions
--staged Review staged changes instead of a branch diff
--base <ref> Diff against this ref (default: merge-base with origin/main)
--fail-on <severity> Block at/above: critical|high|medium|low|never (default: high)
--format <fmt> markdown | json (default: markdown)
--context <text> Extra repo context to hand the reviewer
--context-file <path> Read that context from a file
--model <id> Model override (default: claude-opus-5)Exit code is 1 when something at or above --fail-on is found, 0 otherwise — so CI fails loudly and pre-commit hooks block the commit.
Gate your PRs (GitHub Action)
Add .github/workflows/slopgate.yml:
name: slopgate
on: pull_request
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: sharanya09/slopgate@v0
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
base: ${{ github.event.pull_request.base.sha }}
fail_on: highThe findings render into the job summary, and the check fails when a blocking issue is found.
Pre-commit hook
echo 'npx --yes @schava09/slopgate --staged --fail-on high' > .git/hooks/pre-commit
chmod +x .git/hooks/pre-commitCost
slopgate makes one model call per run over your diff. Defaults to claude-opus-5 for the sharpest review. For high-volume repos, --model claude-sonnet-5 is meaningfully cheaper and still strong on this task.
Tune what it catches
The entire rubric lives in src/prompt.js. Fork it, add the failure patterns your team keeps hitting, and it becomes your team's institutional review knowledge in one file.
License
MIT
