AI engineer building deterministic harnesses around agents.
| Role | Repo | Idea |
|---|---|---|
| Thesis / auth | agent-action-gate | Deterministic allow / deny / human-approval for tool calls. Zero LLM in the auth path. |
| Trailer | lazycoder | Rubric code review (APPROVE / REQUEST_CHANGES / BLOCK). Offline prove & replay without a key; live review optional. |
Related: skill-guard — static pre-install audit for Agent Skills.
Thesis → trailer: agent-action-gate is the auth thesis: local-first, deterministic allow / deny / human approval, with zero LLM keys in decide(). lazycoder is the optional trailer: rubric review with deterministic replay and optional live review; neither repo is a hard dependency of the other.
Proof → security: The gate's offline proof is scripts/prove.sh. aag decide --format sarif exports SARIF, and the SARIF example shows upload to GitHub Security → Code scanning. Stage 3a path/glob covers string-only glob / startswith matching with fixtures; residual: no path normalization, symlink resolution, or .. collapsing.
Honesty boundary: Agent Action Gate is source-install for now; no live PyPI release is claimed. lazycoder's Stage 2 corpus LIVE scoring remains pending credits; the claim here is offline proof / replay. Optional adjacent one-liner: skill-guard — static pre-install audit for Agent Skills.
Short loop from each repo's LEARNINGS.md: SPEC → PLAN → OK → smallest unit → prove with a command → merge → clean tree. No invented precision.
Pinned on the profile (set in GitHub UI — public API has no updateProfilePins for this token):
- agent-action-gate
- lazycoder
- skill-guard (optional)
UI: Profile → Customize your pins → select the repos above.


