no-slop

module
v1.54.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 8, 2026 License: MIT

README

NoSlop

NoSlop is the reviewer that knows the author is an AI.

Most review tools evaluate a diff as if a person wrote it. AI-authored changes have additional failure modes: checks that prove nothing, tests weakened to fit an implementation, expected values copied from production logic, permissive defaults after an unknown result, and fixes applied to one path but not its siblings.

NoSlop makes those patterns a first-class review contract. It classifies the change before spending reviewer time, applies named AI-authorship lenses, and uses artifact-specific checks for code and outbound prose.

When generating-agent provenance is supplied, NoSlop also conditions the policy on the last 10 changes from that lane and model. Repeated accepted findings can raise the tier, move affected lenses first, and enable mapped deterministic probes. Every decision prints the history rationale. Missing history keeps the v1 route and says so; unreadable history selects full-adversarial.

This repository is derived from kunchenguid/no-mistakes under the MIT License. The pipeline command is now canonically no-slop; no-mistakes remains a compatibility alias. The separate noslop gate policy engine can run before that pipeline or on its own.

Three pillars

Risk-proportional depth

Every gate starts by scoring:

  • Blast radius: what the changed files can reach at runtime.
  • Novelty: new logic, changed logic, mechanical work, or documentation.
  • Reversibility: whether a revert is enough to contain the result.

The selected tier and all three reasons print before validation continues. Use --tier to override the result. When the override changes the tier, the output records both the original and overridden tier.

Tier Work
leak-scan-only Mandatory leak and identity checks, the configured test-count floor, plus any applicable artifact oracle
single-review Mandatory checks and one reviewer pass through every slop lens
full-adversarial Mandatory checks, a lens review, an adversarial challenge round, the test-count floor, and the configured test command

A Markdown-only diff routes to leak-scan-only unless it matches a configured high-risk path or the operator overrides it. Substantial new source additions also reach the full tier even on a feature branch.

AI-slop lenses

The reviewer receives nine named lenses:

  • vacuous-check
  • test-capitulation
  • self-consistent-oracle
  • comment-defended-workaround
  • scope-expansion
  • asserted-followup-without-artifact
  • fail-open-default
  • rule-applied-in-one-place-not-sibling
  • redundant-comment

Every finding carries its lens name. The taxonomy defines the failure, reviewer guidance, and available mechanical pre-check for each lens.

Artifact-class oracles

Secrets and private identity markers are scanned at every tier. The scanner recognizes common credential shapes, personal home paths, and private names from a local blocklist. A missing built-in default blocklist means no private-name list; an explicitly configured missing file and any unreadable file stop evaluation. Findings identify the file and line without copying the matched value. Every honored noslop:allow-leak marker prints its file and line and counts in the verdict. Set slop.leak_scan.allow_exemptions: false when CI must reject all inline exemptions.

Outbound text can be selected by a configured path or outbound: true front matter. The prose oracle checks AI-tell vocabulary, em dashes, cited JSON or CSV numbers, and optional live GitHub issue or pull request state. With --thread, it uses gh to verify the thread is open and checks whether an existing comment already makes substantially the same claim. An explicit thread with no outbound artifact is an evaluation error.

Build

NoSlop requires Go 1.25 or newer.

git clone https://github.com/Blakeolson21/no-slop.git
cd no-slop
go build -o ./bin/noslop ./cmd/noslop

Build the pipeline CLI separately:

go build -o ./bin/no-slop ./cmd/no-slop

Run

Review committed changes against the merge base of the default branch:

./bin/noslop gate

Name the comparison explicitly:

./bin/noslop gate --base origin/main --head HEAD

Supply the requested scope when the gate should mechanically compare new files and reviewer findings with intent:

./bin/noslop gate --base origin/main --intent "Add the no-store response header only."

Override validation depth:

./bin/noslop gate --base origin/main --tier full-adversarial

If provenance raises the tier, a lower --tier is refused unless --force-tier is also present. The output prints both the provenance signal and the forced override.

Check outbound text against a live GitHub thread:

./bin/noslop gate --base origin/main --thread https://github.com/owner/repo/issues/123

Capture generating-agent provenance for conditioning and later evaluation:

./bin/noslop gate --base origin/main \
  --provider example-provider \
  --model example-model \
  --reasoning-effort high \
  --lane-id review-lane-1 \
  --change-class source

Because the caller supplies --lane-id and --model, provenance conditioning is advisory until a trusted external system supplies and enforces those values.

Use a different private-name blocklist:

./bin/noslop gate --base origin/main --blocklist .private-names

Exit code 0 means pass, 1 means findings blocked the gate, and 2 means the gate could not evaluate the change.

Configure

NoSlop uses the existing .no-slop.yaml repository config shape:

slop:
  data_dir: ".noslop-data"
  leak_scan:
    allow_exemptions: false
  test_command: "go test -race ./..."

Keep the real blocklist private and uncommitted. The repository config reference owns all fields, defaults, outbound selection, and blocklist details.

Replay captured policy findings against the seed corpus:

./bin/noslop evaluate \
  --corpus corpus/seeds \
  --unconditioned-results results/unconditioned.json \
  --conditioned-results results/conditioned.json

The corpus format records diffs and independent expected findings. The runner labels the seed corpus and result files as replayed inputs, then reports found, missed, and false-positive counts without inventing reviewer output.

The first measured 32-case campaign found 10 expectations, missed 22, and emitted no unmatched findings under both policies. All model-backed reviewer invocations timed out, so the result does not support a superiority claim. Raw captures and latency records are checked in for replay and inspection.

Development

make build
go test ./internal/slop/...
go test -race ./...
make lint
go build -o ./bin/noslop ./cmd/noslop

License and credit

MIT licensed. The gate foundation is derived from no-mistakes by Kun Chen.

Directories

Path Synopsis
cmd
fakeagent command
fakeagent is a deterministic stand-in for the real Claude, Codex, and OpenCode CLIs used by no-slop' e2e tests.
fakeagent is a deterministic stand-in for the real Claude, Codex, and OpenCode CLIs used by no-slop' e2e tests.
genskill command
Command genskill renders the canonical no-slop SKILL.md from the internal/skill package into skills/no-slop/SKILL.md.
Command genskill renders the canonical no-slop SKILL.md from the internal/skill package into skills/no-slop/SKILL.md.
no-mistakes command
no-slop command
noslop command
recordfixture command
recordfixture captures real agent CLI output as fixture files for the e2e test suite.
recordfixture captures real agent CLI output as fixture files for the e2e test suite.
internal
cimonitor
Package cimonitor is the single source of truth for the CI monitor's human-facing log vocabulary and agent-facing monitoring state.
Package cimonitor is the single source of truth for the CI monitor's human-facing log vocabulary and agent-facing monitoring state.
cli
convergence
Package convergence derives review-loop convergence telemetry from a step's persisted execution rounds, and decides when the loop is measurably not converging (the "ladder" failure mode: fix rounds that relocate or grow the finding set instead of shrinking it).
Package convergence derives review-loop convergence telemetry from a step's persisted execution rounds, and decides when the loop is measurably not converging (the "ladder" failure mode: fix rounds that relocate or grow the finding set instead of shrinking it).
db
e2e
Package e2e holds end-to-end tests that drive the real no-slop binary against a temporary git repo and a fake agent.
Package e2e holds end-to-end tests that drive the real no-slop binary against a temporary git repo and a fake agent.
e2edaemon
Package e2edaemon owns isolated temporary no-mistakes process lifecycle: exact inventory, a reaper with bounded ownership checks, and a concurrency slot cap.
Package e2edaemon owns isolated temporary no-mistakes process lifecycle: exact inventory, a reaper with bounded ownership checks, and a concurrency slot cap.
eval
Package eval implements the local-only review evaluation toolkit.
Package eval implements the local-only review evaluation toolkit.
evidence
Package evidence publishes pipeline test-evidence artifacts to a dedicated orphan branch in the same repository.
Package evidence publishes pipeline test-evidence artifacts to a dedicated orphan branch in the same repository.
filelock
Package filelock provides a small advisory whole-file lock used to serialize read-modify-write cycles on shared JSON state under NS_HOME across processes.
Package filelock provides a small advisory whole-file lock used to serialize read-modify-write cycles on shared JSON state under NS_HOME across processes.
gatecontext
Package gatecontext owns the authoritative classification of callers that are executing inside an active no-slop validation step.
Package gatecontext owns the authoritative classification of callers that are executing inside an active no-slop validation step.
gateguidance
Package gateguidance owns the shared phase-ownership contract rendered into every validation-step prompt and the installed no-slop skill.
Package gateguidance owns the shared phase-ownership contract rendered into every validation-step prompt and the installed no-slop skill.
git
identity
Package identity owns the canonical no-slop names and their compatibility aliases.
Package identity owns the canonical no-slop names and their compatibility aliases.
intent
Package intent extracts a short summary of the user's original intent for a code change by reading recent transcripts from local coding agents (Claude Code, Codex CLI, OpenCode, Rovo Dev, Pi, and GitHub Copilot CLI) on the developer's machine.
Package intent extracts a short summary of the user's original intent for a code change by reading recent transcripts from local coding agents (Claude Code, Codex CLI, OpenCode, Rovo Dev, Pi, and GitHub Copilot CLI) on the developer's machine.
ipc
lanehealth
Package lanehealth records which configured agent lanes are currently unusable because the provider's quota is exhausted, so the pipeline's mid-run fallback can skip a dead lane instead of paying a full agent spawn to rediscover it.
Package lanehealth records which configured agent lanes are currently unusable because the provider's quota is exhausted, so the pipeline's mid-run fallback can skip a dead lane instead of paying a full agent spawn to rediscover it.
logstore
Package logstore owns byte bounds and deterministic retention for process logs.
Package logstore owns byte bounds and deterministic retention for process logs.
procreap
Package procreap finds and terminates processes that outlived the pipeline run whose worktree they were launched in.
Package procreap finds and terminates processes that outlived the pipeline run whose worktree they were launched in.
proctree
Package proctree enumerates and kills process trees.
Package proctree enumerates and kills process trees.
scm
scm/azuredevops
Package azuredevops implements scm.Host backed by the az CLI with the azure-devops extension.
Package azuredevops implements scm.Host backed by the az CLI with the azure-devops extension.
scm/github
Package github implements scm.Host backed by the gh CLI.
Package github implements scm.Host backed by the gh CLI.
scm/gitlab
Package gitlab implements scm.Host backed by the glab CLI.
Package gitlab implements scm.Host backed by the glab CLI.
skill
Package skill holds the canonical content of the no-slop agent skill.
Package skill holds the canonical content of the no-slop agent skill.
slop/cli
Package cli owns the standalone noslop command surface.
Package cli owns the standalone noslop command surface.
slop/corpus
Package corpus loads recorded review cases and scores captured policy findings against independent expectations.
Package corpus loads recorded review cases and scores captured policy findings against independent expectations.
slop/engine
Package engine runs NoSlop's risk-proportional front-stage pipeline.
Package engine runs NoSlop's risk-proportional front-stage pipeline.
slop/leakscan
Package leakscan detects credentials and private identity markers without copying matched values into its findings.
Package leakscan detects credentials and private identity markers without copying matched values into its findings.
slop/lenses
Package lenses owns the named AI-authorship review taxonomy.
Package lenses owns the named AI-authorship review taxonomy.
slop/pathmatch
Package pathmatch owns repository-relative path pattern matching for NoSlop.
Package pathmatch owns repository-relative path pattern matching for NoSlop.
slop/precheck
Package precheck runs conservative diff-pattern checks for the named AI-authorship lenses.
Package precheck runs conservative diff-pattern checks for the named AI-authorship lenses.
slop/prose
Package prose validates text artifacts intended for outbound publication.
Package prose validates text artifacts intended for outbound publication.
slop/provenance
Package provenance stores the generating-agent history used to condition later NoSlop policy decisions.
Package provenance stores the generating-agent history used to condition later NoSlop policy decisions.
slop/risk
Package risk classifies a change before expensive validation begins.
Package risk classifies a change before expensive validation begins.
slop/testfloor
Package testfloor compares discoverable test counts across two revisions.
Package testfloor compares discoverable test counts across two revisions.
testguidance
Package testguidance owns the default test-quality rule rendered into no-slop agents that can write, repair, or review tests.
Package testguidance owns the default test-quality rule rendered into no-slop agents that can write, repair, or review tests.
tui
winproc
Package winproc hardens child processes so Windows does not allocate a visible console window for them.
Package winproc hardens child processes so Windows does not allocate a visible console window for them.
wizard
Package wizard provides the pre-pipeline onboarding flow: it detects repo state, optionally creates a branch, commits uncommitted changes, and pushes to the no-slop gate, then hands off to the main TUI.
Package wizard provides the pre-pipeline onboarding flow: it detects repo state, optionally creates a branch, commits uncommitted changes, and pushes to the no-slop gate, then hands off to the main TUI.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL