ralabarta

Agentproof — Testing skill for Claude Code

Testing community

Local-first Go CLI that turns coding-agent sessions into integrity-checked merge evidence: Git association, test ingestion, blast radius, and deterministic risk findings.

How to install Agentproof

This entry records only its repository, not the path inside it, so there is no exact command to give. Open ralabarta/agentproof and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agentproof does

Local-first Go CLI that turns coding-agent sessions into integrity-checked merge evidence: Git association, test ingestion, blast radius, and deterministic risk findings. No account, no telemetry, stdlib only.

Alternatives in Testing

  • Pua — Use when the user invokes /pua or asks for PUA mode, try-harder/retry help, change-approach coaching, completi 19.5k ★
  • Testing Strategy — This project is small, runs in a terminal, and is mostly deterministic 10.9k ★
  • Baro — A CLI that turns a goal into a pull request - and a sandbox for testing concurrent AI coding agents on the Moz 120 ★

README

AgentProof

**Know exactly what your coding agent changed — and collect the evidence needed to decide whether it is safe to merge.**

[![CI](https://github.com/ralabarta/agentproof/actions/workflows/ci.yml/badge.svg)](https://github.com/ralabarta/agentproof/actions/workflows/ci.yml) [![MIT License](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![Go 1.22+](https://img.shields.io/badge/go-1.22%2B-00ADD8.svg)](https://go.dev) [![Zero dependencies](https://img.shields.io/badge/dependencies-stdlib%20only-6f42c1.svg)](#contributing) [![Local by default](https://img.shields.io/badge/data-local%20by%20default-1f9d55.svg)](#privacy-and-trust-model)

[Quickstart](#quickstart) · [Why](#why-agentproof) · [GitHub Action](#github-action) · [Real report](docs/example-report.md) · [Architecture](docs/architecture.md) · [Threat model](docs/threat-model.md)


AgentProof is a **local-first Go CLI** that associates Codex and Claude Code sessions with Git changes, ingests test-result artifacts, detects deterministic risks, estimates code impact, and emits reproducible **Markdown, HTML, and JSON evidence**.

No account. No service. No telemetry. No network request.

Quickstart

go install github.com/ralabarta/agentproof/cmd/agentproof@latest

agentproof init
agentproof record --objective "Protect refresh tokens from replay" --agent codex -- codex
agentproof verify --test-result test-results.jsonl
AgentProof verification: WARNING
✓ Required evidence complete: 3/3
✓ Canonical manifest integrity passed
✓ 28 test results passed
✓ No secret patterns detected in captured added lines
⚠ Authentication or authorization code modified
Affected components: internal/auth, internal/api
Bundle ID: 7f0c…d91a

[!IMPORTANT] AgentProof does **not** certify code as safe. It separates observed evidence, deterministic derivations, associations, unsupported checks, and unknowns so reviewers can make a better merge decision.