Epistemic Engine – verify AI-generated code and forecast what will break Epistemic Engine, a new open-source tool that reads codebases as systems of justified beliefs, has been released to verify AI-generated code and forecast which parts of a codebase will break. The tool, which runs offline with no LLM or network dependency, includes a pre-commit/CI verifier that blocks unsafe code and a prediction tool that forecasts belief collapse with causal chains, probability, and ROI. Field-tested on 1,500+ production files, it achieved precision/recall/false-positive rates of 1.0/1.0/0.0 with a 95% CI lower bound of 0.92 on a 114-sample corpus. Computational epistemology for software. It reads a codebase as a system of justified beliefs — claims the code makes about itself "this function authenticates the caller", "this value is never null", "this uses approved crypto" — reconstructs how well-justified each one is from git history, and tracks how that confidence changes over time. On top of that foundation it ships two tools you can use today: — a pre-commit / CI verifier that ee guard blocks unsafe or unjustified code before it lands great for reviewing AI-generated changes .— forecasts ee predict-chain which beliefs are about to collapse , why, roughly when, and what it would cost to fix now vs. later — and it tells you when it can't trust its own forecast. Everything is deterministic no LLM, no network, no wall-clock in any computed value , runs offline , and is backed by 167 tests . pip install epistemic-engine Requires Python 3.10+. Apache-2.0 licensed. ee ingest ./my-repo read git history into a local graph ee analyze ./my-repo extract beliefs, justifications, trajectories ee guard ./my-repo --all find unsafe / unjustified code ee predict-chain ./my-repo forecast which beliefs will collapse ee dashboard ./my-repo explore all of it in your browser ee guard extracts the beliefs a change makes about itself and blocks on risky ones, then layers on direct OWASP-class scanners and known-CVE matches. Each finding carries a severity, the reason, a concrete fix, and a stable fingerprint. It catches, among others: | Class | Examples | |---|---| | Weak crypto | md5 / sha1 / mt rand used as a security primitive | | Injection | SQL built by string concatenation, os.system / popen on user input | | Unsafe sinks | eval , innerHTML , unserialize , pickle.loads on untrusted data | | Secrets | hardcoded API keys / tokens the value is never printed or stored | | Misconfig | TLS verification off, Access-Control-Allow-Origin: , debug enabled | ee guard ./repo --staged verify staged changes exit 1 = would block the commit ee guard ./repo --all verify the whole tree ee guard ./repo --format sarif SARIF 2.1.0 for GitHub code scanning ee guard ./repo --emit-workflow print a ready .github/workflows/ee-guard.yml ee hook install ./repo run it automatically on every git commit Adoption features so it fits a real team: inline ee-ignore rule suppression, a disabled rules config, and a baseline mode --update-baseline / --baseline FILE that fails only on new findings so you can adopt on an existing repo without fixing everything first. Field-tested on 1,500+ real production files: precision / recall / false-positive rate of 1.0 / 1.0 / 0.0 95% CI lower bound 0.92 on a 114-sample corpus . The engine already knows how each belief's confidence is eroding. predict-chain projects that forward and, for each at-risk belief, gives you: - a causal chain — the ranked factors driving the predicted collapse, each tagged measured from your repo's history or assumption your cost model ; - a collapse probability within a horizon, from a seeded Monte Carlo; - a calendar ETA from your repo's own commit cadence; - a fix + ROI , computed under your cost assumptions and labelled as such. ee predict-chain ./repo --horizon 30 forecasts with causes, ETA, ROI ee calibrate ./repo is the forecast trustworthy on THIS repo? It refuses to lie. ee calibrate runs a leakage-free back-test against your repo's own history and reports a Brier skill score vs. a base-rate baseline. If the model doesn't beat guessing on your repo, the report says so — and predict-chain prints that verdict above every forecast. It never fabricates probabilities for undisclosed future CVEs, and never presents a dollar figure as fact. ee dashboard ./repo loopback-only web UI; Ctrl-C to stop A local, offline, self-contained dashboard with three tabs: Beliefs — every claim the code makes, by domain, coloured by confidence. 🔮 Predictions — the collapse forecasts, with the calibration verdict on top. 🛡 Guard — the ee guard findings, grouped by severity, with a BLOCK/PASS banner. Scans the whole repo by default and caches the result. Deterministic. Identical inputs produce byte-identical output. No LLM, no sampling, no wall-clock in any computed value — so results are reproducible and diffable in CI. Honest about uncertainty. Gates are evaluated on the lower bound of a Wilson confidence interval, not a point estimate. Predictions ship with a calibration verdict. Cost/ROI figures are labelled assumptions. Offline-first. No network access except an explicit ee sync . Bounded formalism. Beliefs outside the closed PO-1 predicate ontology are recorded as unformalised and excluded from reasoning — never silently coerced. pip install epistemic-engine core zero heavy dependencies pip install "epistemic-engine parsing " + tree-sitter for entity-level beliefs Without the parsing extra the engine degrades gracefully to file-granularity analysis. Python 3.10+. | Command | What it does | |---|---| ee ingest