HostLatch
The trust-handoff firewall for AI-written repositories. HostLatch finds changes that can gain authority later when Git, an IDE, a package manager, CI, a container tool, or another coding agent consumes them.
Audit the handoff, not only the agent run
Coding-agent sandboxes constrain what an agent executes during a task. Repository files can still be loaded later by more trusted host tools. HostLatch maps those paths as artifact → consumer → trigger → effect, then separates ordinary changes from quarantined activation surfaces.
Try the public beta
# Run the immutable release directly from GitHub
npx --yes github:iammurtaza53/hostlatch#v0.2.0 scan /path/to/repository --snapshot
# Or clone it for the demo and repeated local use
git clone https://github.com/iammurtaza53/hostlatch.git
cd hostlatch
npm ci
npm run demo
# Scan a task delta
node ./bin/hostlatch.js scan /path/to/repository --base main
# Audit a complete snapshot
node ./bin/hostlatch.js scan /path/to/repository --snapshot
What it covers
Evidence without inflated claims
The initial corpus produced 77 rule-fit findings, including two high-severity activation patterns. These are review signals, not 77 confirmed vulnerabilities. The report publishes pinned public commits, anonymized private aggregates, performance data, privacy treatment, and limitations.
Read the complete validation report or inspect the machine-readable aggregate.