a project-aware verification gate for AI coding agents
What if a coding agent had to pass the project’s own checks before it could say “done”?
An open-source extension for the π coding agent. It detects any repository’s stack, commands, conventions and instruction files, injects them as a stable system-prompt section, then runs the project’s own typecheck, lint, tests and build after every agent turn — with a bounded self-repair loop and a review of the agent’s diff. It never writes into the repository.
Read-only detection across Node/TypeScript (npm, pnpm, yarn, bun, workspaces, Turborepo, Nx), Rust, Go, Python, JVM, .NET, Swift, PHP, Elixir, Dart/Flutter, C/C++, Zig and more — plus Makefile/justfile targets, CI configs and docker-compose services.
Verification tiers (syntax → typecheck → lint → test → build) with narrowed runs — vitest related, jest --findRelatedTests, cargo test -p, go test ./pkg — parallel read-only checks, and a pre-existing-failure baseline so the agent is never blamed for a repo that was already red.
A diff review that flags added suppressions, skipped or focused tests, stubs, loosened configs, leaked secrets, unignored .env files and stale lockfiles.
Instruction-file support for AGENTS.md, CLAUDE.md, .cursorrules, Copilot, Windsurf, Cline, Gemini and Codex — nested and glob-scoped rules are delivered when the agent first touches a matching file.
A byte-identical profile for every turn of a session so prompt caching keeps working; cache and settings live outside the repository.
Zero runtime dependencies; tests on Linux, macOS and Windows across Node 22, 24 and 26; a weekly detection corpus on ~20 real repositories; releases with npm provenance and signed build attestations; OpenSSF Scorecard.
Built with
TypeScript
Node.js
π extension API
node:test
GitHub Actions
npm provenance
Why
A coding agent dropped into an unfamiliar repository guesses: which package manager, which test runner, whether tsc or biome is the source of truth, where tests live, which files are generated. Then it reports “done” without having run anything, or runs the wrong thing. pi-project-profile answers those questions once per repository, keeps the answer stable so prompt caching works, and turns “done” into “the project’s own checks pass” — without ever running installs, migrations or deploys on its own.
How it works
Session start — the repository is scanned (manifests, lockfiles, CI files, Makefiles, instruction files; nothing is executed), cached under ~/.pi/agent/project-profile/, and rendered as <project_profile> in the system prompt.
Each turn — files the agent touches are tracked; nested AGENTS.md / CLAUDE.md and glob-scoped rules that apply to them are delivered with the first matching tool result; generated files get a warning.
Before the turn settles — if files changed, the syntax, typecheck and lint tiers run (tests and builds once you have allowed them for the repo). New failures go back to the agent for at most three repair rounds; pre-existing failures are reported to you once and never blamed on the agent. The diff review runs alongside.
Design rules
Nothing is hardcoded per project; every capability degrades detected → generic → no-op, never to a wrong action.
Only read-only checks run unprompted. Installs, migrations, deploys and anything network-bound are never run.
Tools are bound late (node_modules/.bin, uv run, poetry run), so the profile stays valid before and after installs.
Repository instructions are framed as repository content, inlined only when small, and skipped when they read like a bot directive.