{"slug": "show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done", "title": "Show HN: Truth Firewall – Don't trust your coding agent when it says DONE", "summary": "Developer aldi949 released Truth Firewall, an open-source verification tool that blocks a coding agent's \"DONE\" claim until mandatory acceptance checks pass on the final repository state. Truth Firewall runs on Windows PowerShell with Python 3.11 or newer, Node.js, Git, and an authenticated Codex CLI, and supports three check types — file_exists, python_function, and black_box — returning VERIFIED_DONE, REJECT_DONE, HUMAN_REQUIRED, or ERROR within a three-attempt limit. The tool writes a local run summary to .truth-firewall\\runs\\<run-id>\\summary.json without task text or source code, and its author states it is not a hostile-worker security boundary.", "body_md": "**Truth Firewall won’t accept `DONE` until the work is independently verified.**\n\nYour coding agent says:\n\n“Done. Tests pass.”\n\nMaybe it is.\n\nMaybe it skipped a requirement.\n\nMaybe an edge case is broken.\n\nMaybe it changed something it shouldn’t have.\n\nAnd then **you** have to check everything anyway.\n\nThat defeats the whole point of having an agent.\n\n**The agent does the work.**\n\n**Truth Firewall decides whether `DONE` is actually earned.**\n\nGive Codex the task.\n\nWalk away.\n\n```\nCodex works\n    ↓\nCodex says DONE\n    ↓\nTruth Firewall verifies the required work\n    ↓\n┌──────────────────┬──────────────────┬──────────────────┐\n↓                  ↓                  ↓\nVERIFIED_DONE    REJECT_DONE       HUMAN_REQUIRED\n                     ↓\n              Codex keeps working\n```\n\nUse Windows PowerShell with Python 3.11 or newer, Node.js, Git, and an installed, authenticated Codex CLI. Codex installation and sign-in are separate from this setup.\n\n```\ngit clone https://github.com/aldi949/truth-firewall.git\ncd truth-firewall\npython -m venv .venv\n.\\.venv\\Scripts\\python.exe -m pip install .\n$tfRoot = (Get-Location).Path\nSet-Location C:\\path\\to\\your-python-repo\nNew-Item -ItemType Directory -Force .truth-firewall | Out-Null\nCopy-Item \"$tfRoot\\examples\\pilot-task.json\" .\\.truth-firewall\\task.json\nnotepad .\\.truth-firewall\\task.json\n& \"$tfRoot\\.venv\\Scripts\\truth-firewall.exe\" run --spec .truth-firewall\\task.json\n```\n\nBefore the last command, edit `.truth-firewall\\task.json` to describe **your** bounded Python task and every mandatory acceptance check. The copied file is a working `slugify` example, not a universal task spec. Keep the same PowerShell session so `$tfRoot` remains set. See [QUICKSTART.md](https://github.com/aldi949/truth-firewall/blob/main/QUICKSTART.md) for more detail.\n\nThe supported checks are `file_exists` (a repository-relative path exists or does not exist), `python_function` (a top-level function has the exact parameter list), and `black_box` (JSON argument lists produce expected return values). Give each condition a unique `id`. Every listed condition is mandatory, and requirements missing from `task.json` cannot be verified.\n\n- `VERIFIED_DONE` : all listed mandatory checks passed for the observed final repository state. The terminal shows the original task, check summary, and attempts used.\n- `REJECT_DONE` : a worker completion claim failed at least one mandatory check. This is an intermediate decision; Truth Firewall sends actionable failures back to Codex and continues within the three-attempt limit.\n- `HUMAN_REQUIRED` : completion could not be proven, including when attempts are exhausted or a mandatory condition cannot be checked. Review the named requirements and decide what to do next.\n- `ERROR` : the worker, verifier, or runtime could not complete the run. This is an execution problem, not a verdict that the task failed.\n\nA worker saying “done,” code existing, or worker-owned tests passing does not establish that your original requirements were met. Truth Firewall checks the acceptance conditions you supplied after each attempt and blocks an unsupported completion claim. It can continue Codex automatically when a check fails, so you do not have to watch each turn.\n\nIt means the listed mandatory checks passed on the final observed workspace state. It does **not** prove that an omitted requirement was met, that the checks themselves are complete, or that all possible behavior is correct. Author the checks to cover the task before you start; if the supported checks cannot establish completion, treat the outcome as requiring human judgment.\n\nThis first release supports local repositories, bounded Python coding tasks, a Codex CLI worker, deterministic file/API/input-output checks, and at most three worker attempts. A small local run summary is written under `.truth-firewall\\runs\\<run-id>\\summary.json`; it records the decision and attempt counts without task text or source code.\n\nThis is not a hostile-worker security boundary or a claim of universal correctness. Codex runs as your normal user and can access files available to that account, including the task specification. Use disposable or nonsensitive repositories for the pilot. Subjective quality, UI behavior, deployment, external services, broad repository work, and requirements that cannot be observed with the supported checks are outside this pilot.\n\nTruth Firewall does not automatically upload telemetry, source code, or task text. Codex sends task instructions and the context it reads to its configured service under your account settings. Detailed local invocation logs are stored in the operating system's temporary directory and may contain the task prompt and worker output. Review those settings before using private code.\n\nTrying Truth Firewall on a real task? Please use [PILOT_FEEDBACK.md](https://github.com/aldi949/truth-firewall/blob/main/PILOT_FEEDBACK.md). Contribution guidance and local test commands are in [CONTRIBUTING.md](https://github.com/aldi949/truth-firewall/blob/main/CONTRIBUTING.md). Truth Firewall is [MIT licensed](https://github.com/aldi949/truth-firewall/blob/main/LICENSE).", "url": "https://wpnews.pro/news/show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done", "canonical_source": "https://github.com/aldi949/truth-firewall", "published_at": "2026-10-07 06:52:27+00:00", "updated_at": "2026-10-07 07:19:31.932664+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["Truth Firewall", "Codex", "aldi949", "GitHub", "Python", "Node.js", "Git"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done", "markdown": "https://wpnews.pro/news/show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done.md", "text": "https://wpnews.pro/news/show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done.txt", "jsonld": "https://wpnews.pro/news/show-hn-truth-firewall-don-t-trust-your-coding-agent-when-it-says-done.jsonld"}}