Python · open source
Proof-based guardrails for AI coding agents: no green check, no “done”.
An AI coding agent likes to claim that something is finished, correct or secure. CUSTOS makes it prove that with an executed command, not with a sentence in its reply.
View on GitHubRead the READMEWhat it does
Proof gate
A Stop hook forces a test run or linter before a session is allowed to end.
Mechanical gates
Hooks run linters and static tools, an AI-slop detector, an accessibility check and a scope guard, and block on exit code 2.
Plan approval
A plan reviewer must clear a plan before implementation starts.
Regression guard
Blocks a subagent from turning a green check red.
Evidence record
Every finding lands time-stamped in custos_findings.json; zero-tolerance mode is fail-closed.
Honest limits
Read this first. Active security scans (nmap/ZAP) and fleet auto-fix push are deliberately left as ready-to-arm placeholders. Findings are heuristics, not proof of absence of bugs. Needs Python 3 on the PATH and Claude Code.