{"slug": "naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr", "title": "NAIF AMF Pilot Kit: binding AI-code review evidence to the exact GitHub PR", "summary": "The NAIF AMF Pilot Kit v1, the third component of NAIF Enterprise Assurance, has been documented as a read-only, check-only adapter that binds a bounded AI-code review decision to the exact GitHub pull-request head SHA, publishing a \"NAIF AMF / Decision\" Check that passes only on ALLOW and fails on QUARANTINE or UNSUPPORTED. The kit evaluates PR contents as inert Git blobs under a restrictive scalar AST grammar without checking out, building or importing the proposed project, and its receipts are unsigned, with hashes providing integrity linkage rather than issuer authentication. The project states that readiness still requires preregistered criteria, hosted artifact verification and live PR Check testing, and that no new run was performed for the writeup.", "body_md": "A pull-request workflow can finish successfully while the proposed change still needs review. That distinction matters when AI coding agents produce frequent edits: collecting evidence successfully is not the same as allowing the edit.\n\n**NAIF AMF Pilot Kit v1**, the third component of NAIF Enterprise Assurance, is a documented read-only/check-only adapter around frozen AMF v0.4 and the engine hashes referenced by RDR V2.5.7. Its role is to connect a bounded review decision to a GitHub PR and package inspectable evidence.\n\n**Enterprise Access — Coming Soon.** Institutional enquiries are welcome for requirements and scope discussion. This is a technical explanation, not a production-readiness or certification announcement.\n\nThe public integration documents a Check named **NAIF AMF / Decision** on the exact PR head SHA:\n\n| Review outcome | Decision Check | \n|---|---|\n| ALLOW | Successful | \n| QUARANTINE | Failure | \n| UNSUPPORTED | Failure | \n\nThe orchestration job can be green after a rejected change because it successfully published a failing Decision Check. Reviewers should inspect the named Check and the revision it covers.\n\nFor example, if an agent pushes revision B after revision A was checked, evidence for A is not evidence for B. The receipt also binds the analyzed base. Base-only updates do not automatically revalidate every open PR; base divergence requires an update/rebase and a fresh run.\n\nThe kit does not automatically merge PRs or change branch protection. Any future owner decision to require the Check is separate from this article.\n\nThe documented workflow uses code from the trusted base commit and fetches PR contents as inert Git blobs. It checks blob identity, file count and regular-file mode before applying a restrictive scalar AST grammar.\n\nIt does not check out, install, build or import the proposed PR project. Admitted functions are evaluated by the frozen interpreters. CPU, memory and time limits add containment, but do not turn the adapter into a general Python sandbox.\n\nCollection and publishing use the built-in ephemeral GitHub token with contents/read, pull-requests/read and checks/write permissions. The token is not passed to the analysis child. Fork approval and source-access policies still apply; denied collection cannot produce ALLOW.\n\nThe documented default supports up to eight modified Python files, one unannotated pure positional-argument function in each, and integers [-64,64] plus None. Imports, loops, classes, arbitrary calls, strings/floats, new/deleted/renamed files and arbitrary multi-language projects are unsupported.\n\nALLOW means no observed behavior change within that scope and domain. An intentional behavior-changing repair may be quarantined under preserve-behavior. Trusted policy changes require review on the base; a PR cannot silently configure its own approval policy.\n\nThe documented package includes raw engine receipts, wrapper passports, hashes, logs, timings, an offline HTML dashboard and a minimal-in-domain counterexample when found.\n\nRaw UUID and time fields vary between runs; semantic hashes are intended to reproduce. Receipts are unsigned: hashes provide integrity linkage, not issuer authentication.\n\nThe public repository describes 40 synthetic scenarios. Those are distinct from actual hosted PR executions. Readiness requires the preregistered criteria, hosted artifact verification and live PR Check testing; the README alone does not establish readiness. No new run was performed for this article.\n\nA useful institutional evaluation would start with a supported change class, explicit acceptance criteria and evidence tied to the exact revisions being reviewed.\n\nEmail **[contact@naifgravity.com](mailto:contact@naifgravity.com)** with the subject **NAIF AMF Pilot Kit — Institutional Enquiry**. Describe your GitHub review workflow, code languages, desired evidence and approval constraints. Use synthetic or redacted examples; omit tokens and customer data.\n\nAvailability will be announced separately after scope review.\n\nTechnical documentation: [NAIF AMF Pilot Kit repository](https://github.com/naief9961-tech/naif-amf-pilot-sandbox).\n\nRelated: [AMF decision semantics](https://dev.to/naifgravity/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained-39en) · [Enterprise overview](https://dev.to/naifgravity/reviewing-ai-generated-code-changes-with-bounded-evidence-naif-enterprise-assurance-3k3c) · [NAIF Gravity](https://naifgravity.com).\n\nDisclosure: Published by NAIF Gravity. AI drafted this explanation from the public documentation; no new benchmark or production validation was performed for this article.", "url": "https://wpnews.pro/news/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr", "canonical_source": "https://dev.to/naifgravity/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr-2kge", "published_at": "2026-10-07 05:43:48+00:00", "updated_at": "2026-10-07 05:47:41.667608+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "developer-tools", "ai-tools"], "entities": ["NAIF AMF Pilot Kit", "NAIF Enterprise Assurance", "AMF v0.4", "RDR V2.5.7", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr", "markdown": "https://wpnews.pro/news/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr.md", "text": "https://wpnews.pro/news/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr.txt", "jsonld": "https://wpnews.pro/news/naif-amf-pilot-kit-binding-ai-code-review-evidence-to-the-exact-github-pr.jsonld"}}