CUSTOS
Python · open source

Proof-based guardrails for AI coding agents: no green check, no “done”.

An AI coding agent likes to claim that something is finished, correct or secure. CUSTOS makes it prove that with an executed command, not with a sentence in its reply.

View on GitHubRead the README

What it does

Proof gate

A Stop hook forces a test run or linter before a session is allowed to end.

Mechanical gates

Hooks run linters and static tools, an AI-slop detector, an accessibility check and a scope guard, and block on exit code 2.

Plan approval

A plan reviewer must clear a plan before implementation starts.

Regression guard

Blocks a subagent from turning a green check red.

Evidence record

Every finding lands time-stamped in custos_findings.json; zero-tolerance mode is fail-closed.

Honest limits

Read this first. Active security scans (nmap/ZAP) and fleet auto-fix push are deliberately left as ready-to-arm placeholders. Findings are heuristics, not proof of absence of bugs. Needs Python 3 on the PATH and Claude Code.