gateprobe

Can an approval be reused or bypassed after the target changes? A deterministic, versioned evaluator for agent approval tokens.

zero-dependencydeterministicfree & offline

What it checks

The verdict is three-valued: pass, fail, and unknown. unknown is distinct from fail - missing evidence is surfaced, never silently treated as a pass.

Try it locally

git clone https://github.com/LibertyDigitalSystems/gateprobe.dev
cd gateprobe.dev
node src/cli.mjs fixtures/adversarial/nonce-replay.json   # exit code = verdict
node src/cli.mjs --report fixtures/negative/recipient-changed.json

Or run it as a stateless HTTP service and check the health probe:

node src/server.mjs
curl -s localhost:3000/healthz
curl -s -XPOST localhost:3000/v1/evaluate -d @fixtures/positive/exact-match.json

How it works

A pure function compares a prior approval to a later request over a canonical, order-independent representation of the bound fields, and emits a reproducible receipt (inputHash) so a verdict can be re-derived byte-for-byte. No datastore, no secrets, no network calls - the core is offline.

Verdicts are explainable: every check reports pass / fail / unknown with the finding that drove it, machine-readable as JSON or human-readable as a text evidence report.

Read the evaluation methodology.