Show HN: Truth Firewall – Don't trust your coding agent when it says DONE Developer aldi949 released Truth Firewall, an open-source verification tool that blocks a coding agent's "DONE" claim until mandatory acceptance checks pass on the final repository state. Truth Firewall runs on Windows PowerShell with Python 3.11 or newer, Node.js, Git, and an authenticated Codex CLI, and supports three check types — file_exists, python_function, and black_box — returning VERIFIED_DONE, REJECT_DONE, HUMAN_REQUIRED, or ERROR within a three-attempt limit. The tool writes a local run summary to .truth-firewall\runs\\summary.json without task text or source code, and its author states it is not a hostile-worker security boundary. Truth Firewall won’t accept DONE until the work is independently verified. Your coding agent says: “Done. Tests pass.” Maybe it is. Maybe it skipped a requirement. Maybe an edge case is broken. Maybe it changed something it shouldn’t have. And then you have to check everything anyway. That defeats the whole point of having an agent. The agent does the work. Truth Firewall decides whether DONE is actually earned. Give Codex the task. Walk away. Codex works ↓ Codex says DONE ↓ Truth Firewall verifies the required work ↓ ┌──────────────────┬──────────────────┬──────────────────┐ ↓ ↓ ↓ VERIFIED DONE REJECT DONE HUMAN REQUIRED ↓ Codex keeps working Use Windows PowerShell with Python 3.11 or newer, Node.js, Git, and an installed, authenticated Codex CLI. Codex installation and sign-in are separate from this setup. git clone https://github.com/aldi949/truth-firewall.git cd truth-firewall python -m venv .venv .\.venv\Scripts\python.exe -m pip install . $tfRoot = Get-Location .Path Set-Location C:\path\to\your-python-repo New-Item -ItemType Directory -Force .truth-firewall | Out-Null Copy-Item "$tfRoot\examples\pilot-task.json" .\.truth-firewall\task.json notepad .\.truth-firewall\task.json & "$tfRoot\.venv\Scripts\truth-firewall.exe" run --spec .truth-firewall\task.json Before the last command, edit .truth-firewall\task.json to describe your bounded Python task and every mandatory acceptance check. The copied file is a working slugify example, not a universal task spec. Keep the same PowerShell session so $tfRoot remains set. See QUICKSTART.md https://github.com/aldi949/truth-firewall/blob/main/QUICKSTART.md for more detail. The supported checks are file exists a repository-relative path exists or does not exist , python function a top-level function has the exact parameter list , and black box JSON argument lists produce expected return values . Give each condition a unique id . Every listed condition is mandatory, and requirements missing from task.json cannot be verified. - VERIFIED DONE : all listed mandatory checks passed for the observed final repository state. The terminal shows the original task, check summary, and attempts used. - REJECT DONE : a worker completion claim failed at least one mandatory check. This is an intermediate decision; Truth Firewall sends actionable failures back to Codex and continues within the three-attempt limit. - HUMAN REQUIRED : completion could not be proven, including when attempts are exhausted or a mandatory condition cannot be checked. Review the named requirements and decide what to do next. - ERROR : the worker, verifier, or runtime could not complete the run. This is an execution problem, not a verdict that the task failed. A worker saying “done,” code existing, or worker-owned tests passing does not establish that your original requirements were met. Truth Firewall checks the acceptance conditions you supplied after each attempt and blocks an unsupported completion claim. It can continue Codex automatically when a check fails, so you do not have to watch each turn. It means the listed mandatory checks passed on the final observed workspace state. It does not prove that an omitted requirement was met, that the checks themselves are complete, or that all possible behavior is correct. Author the checks to cover the task before you start; if the supported checks cannot establish completion, treat the outcome as requiring human judgment. This first release supports local repositories, bounded Python coding tasks, a Codex CLI worker, deterministic file/API/input-output checks, and at most three worker attempts. A small local run summary is written under .truth-firewall\runs\