Stop risky AI-generated Git changes before push.
CI OpenSSF Scorecard npm version License: MIT
- README: English | 한국어 | 日本語 | 中文
- Operations guide: English | 한국어 | 日本語 | 中文
- HTML overview: https://leehueeng.github.io/aigate-ai-git-workflow-guard-cli/
AIGate is a zero-config pre-push safety CLI for AI-assisted coding. It checks changed files, possible secrets, repository readiness, PR risk, and branch strategy before changes reach your remote branch or pull request review.
- Your AI coding assistant changed files faster than you can review them.
- You want one command that explains readiness before
git push. - You maintain an open source package and need PR, release, and repository health signals.
- You want Markdown, HTML, JSON, and SARIF outputs that work locally and in CI.
- You want Codex, Gemini, and Claude Code to follow the same branch and validation workflow as humans.
Run it without installing:
npx -y aigate-cli check
npx -y aigate-cli start --route default --dry-run
npx -y aigate-cli start --route quickstart --dry-run
npx -y aigate-cli doctor
npx -y aigate-cli test
npx -y aigate-cli ai report
npx -y aigate-cli demo
npx -y aigate-cli pr-check
npx -y aigate-cli evaluate-projectOr install it globally:
npm install -g aigate-cli
aigate start
aigate start --route default --ask-steps
aigate start --route default --steps init,repo-files
aigate start --route oss --dry-run
aigate reset --dry-run
aigate clean
aigate uninstall
aigate check
aigate test
aigate ai report
aigate aitest
aigate git-ready
aigate install-hook --pre-push
aigate pr-checkTry it from source:
git clone https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli.git cd aigate-ai-git-workflow-guard-cli npm install npm test node src/cli.mjs check
AIGate git-ready: READY
Branch: feature/my-work
Changed files: 4
Secret findings: 0
Project score: 92/100
Blockers: none
Warnings: none
Recommendation: Run AIGate test, commit focused changes, push the branch, and open a pull request.
AIGate is useful when AI coding assistants move quickly and you need one
repeatable local gate before git push or PR creation.
AIGate is strongest when it is wired into a workflow, not only run as advice. It reports three practical levels:
- advisory: a person can ignore AIGate and run plain
git push. - partial: a hook is active in this clone, but it can still be bypassed with
--no-verifyand may not be active in a fresh clone. - server enforced: CI runs
aigate git-readyand verified branch protection or merge rules require that CI to pass.
aigate doctor reports the current level as AIGate enforcement.
aigate evaluate-project checks both AIGate CI gate exists and
AIGate server enforcement exists, so a CI job that only runs in advisory mode
does not look fully protected. doctor also separates an active local hook from
a committed hook file and hook activation automation, because core.hooksPath
is clone-local. For GitLab, AIGate treats allow_failure: true or
when: manual jobs as non-enforcing. Declared settings such as
--gitlab-pipeline-must-succeed true are reported as declared evidence; server
enforcement only passes when evidence is marked verified. When a CI gate exists
but verified server enforcement is missing, evaluate-project keeps the raw
score in JSON and caps the final score below A-grade so the warning remains
visible.
| Situation | Process | Commands |
|---|---|---|
| New repository adoption | Create the default AIGate files step by step, then install the pre-push guard. | aigate start --route default --ask-steps -> aigate doctor -> aigate install-hook --pre-push |
| AI changed a lot of files | Inspect changed paths, run tests, and turn failures into a focused AI repair prompt. | aigate check -> aigate test -> aigate aitest --provider codex |
| PR is almost ready | Pass the gate, push through AIGate, and produce reviewer context. | aigate git-ready -> aigate push -u origin feature/my-work -> aigate pr-check |
| Private GitLab monorepo | Pin the profile, run workspace tests with turbo-aware fallback, and keep GitHub/npm package gates out of app scores. | aigate setup --hosting gitlab --ci-provider gitlab --project-type app --package-manager pnpm -> aigate test -> aigate evaluate-project |
| Open source launch | Generate public contribution files and check repository foundations. | aigate start --route oss --owner @team -> aigate evaluate-project --deep --report -> aigate github setup --dry-run |
| Release week | Verify npm and tag readiness, run CI, and record the trend. | aigate release-check --npm -> npm run ci -> aigate trends record |
| Capability | Command |
|---|---|
| Local Git readiness check | aigate check |
| Guided setup router | aigate start |
| Default setup with yes/no step choices | aigate start --route default --ask-steps |
| Deterministic setup step selection | aigate start --route default --steps init,repo-files |
| Reset AIGate config and settings | aigate reset |
| Delete generated local reports and state | aigate clean --force |
| Remove AIGate config, local state, and owned hook | aigate uninstall --force |
| Open source starter README, issue templates, and contribution files | aigate start --route oss |
| Project test runner | aigate test |
| Turbo-aware fallback plus pnpm, yarn, bun, and workspace test detection | aigate test |
| AI remediation prompt and optional agent run | aigate aitest |
| AI project health report with problems, strengths, direction, and handoff prompt | aigate ai report |
| First-run diagnostics | aigate doctor |
| Guided CLI demo | aigate demo |
| Pre-push safety gate | aigate git-ready |
| Pre-push hook installer | aigate install-hook --pre-push |
| Guarded push wrapper | aigate push -u origin <branch> |
| Pull request readiness report | aigate pr-check |
| GitHub PR summary comment | aigate github comment --pr <number> |
| GitHub Checks summary payload | aigate github check --format json |
| GitHub PR template and CODEOWNERS setup | aigate github setup |
| Markdown, HTML, JSON, SARIF reports | aigate report --format <format> |
| Changed-file secret scan | aigate report --format sarif |
| Repository health score | aigate evaluate-project |
| Deep project report | aigate evaluate-project --deep --report |
| Live server enforcement verification | aigate verify-enforcement --apply |
| Compliance control report | aigate compliance-report |
| Local HTML health dashboard | aigate dashboard |
| Project health trend history | aigate trends record |
| Auto and pinned profiles for private apps, GitLab, and pnpm | aigate setup --hosting gitlab |
| Branch strategy policy packs | aigate branch-strategy --apply |
| Branch strategy proposal comparison | aigate branch-strategy --compare |
| Release readiness check | aigate release-check --npm |
| Slack BLOCK notifications | aigate git-ready --notify-channel slack |
| Discord and Teams webhook payloads | aigate notify test --channel discord |
| Codex, Gemini, and Claude Code instructions | aigate integrate all |
| Tool | Main job | How AIGate is different |
|---|---|---|
| Husky | Git hook setup for JavaScript projects | AIGate is a runnable readiness gate, not only hook wiring. |
| Lefthook | Fast multi-language hook runner | AIGate focuses on PR readiness, repo health, and branch strategy. |
| pre-commit | Hook framework and hook ecosystem | AIGate is zero-config and Git/PR workflow focused. |
| Gitleaks | Deep secret scanning | AIGate includes lightweight changed-file checks and SARIF output, and can complement Gitleaks. |
Read the full tool comparison for recommended combinations with Husky, Lefthook, pre-commit, and Gitleaks.
git switch -c feature/my-work aigate ai report aigate start --route default --ask-steps aigate start --route oss --dry-run aigate start --route ai --provider all aigate reset --dry-run aigate clean aigate doctor aigate install-hook --pre-push aigate test aigate aitest aigate git-ready git add <files> git commit -m "feat: my focused change" aigate push -u origin feature/my-work aigate pr-check --output .aigate/reports/pr.md aigate pr --title "feat: my focused change" aigate github comment --pr <number> aigate github check --output .aigate/reports/github-check.md aigate trends record aigate github setup --owner @your-org/team --dry-run
Send a Slack notification when a blocker appears:
AIGATE_SLACK_WEBHOOK_URL="https://hooks.slack.com/services/..." \
aigate git-ready --notify-channel slackUse AIGate as a reusable public GitHub Action:
name: AIGate on: pull_request: jobs: aigate: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - uses: LeeHueeng/aigate-ai-git-workflow-guard-cli@v0.1.7 with: command: git-ready language: en
Use the current release tag for stable runs, or @main only when you
intentionally want unreleased behavior. Full inputs are documented in
GitHub Action. The same action metadata is mirrored at
.github/actions/aigate for local workflow testing.
Action release status:
- Current stable tag:
v0.1.7 - Action usage: ready through
LeeHueeng/aigate-ai-git-workflow-guard-cli@v0.1.7 - Marketplace publishing: manual GitHub Release screen step
- Action name:
AIGate Git Workflow Guard - Primary category:
Code quality - Secondary category:
Security - Release title:
AIGate Git Workflow Guard v0.1.7
Generate repository instructions for Codex, Gemini, and Claude Code:
aigate integrate all aigate ai report aigate ai report --apply --provider codex aigate aitest --provider codex aigate aitest --apply --provider codex
This creates AGENTS.md, GEMINI.md, CLAUDE.md, and
.aigate/integrations/* so AI assistants follow the same branch, validation,
and guarded push workflow as human contributors. aigate aitest writes
.aigate/reports/ai-test.md; --apply is the explicit switch that lets AIGate
invoke Codex, Claude, Gemini, or a custom --agent-command.
aigate ai report combines the current Git state, repository foundation score,
release readiness, branch strategy, and AI handoff guidance. It does not edit
files by default. Add --apply --provider codex|claude|gemini only when you
want AIGate to run the selected AI CLI with the generated project brief.
When --apply runs, AIGate shows the prompt path, provider, agent command, and
live agent output in the terminal, then captures stdout/stderr in the report.
AIGate supports English, Korean, Japanese, and Chinese CLI output:
aigate setup --language en aigate setup --language ko aigate setup --language ja aigate setup --language zh
These public install paths are available now:
npm install -g aigate-cli
brew install LeeHueeng/tap/aigate-cli
docker run --rm -v "$PWD:/repo" -w /repo ghcr.io/leehueeng/aigate-cli:0.1.7 checkThese remain on the roadmap:
- Standalone binaries
- Hosted dashboard
- Deeper Linear and Jira workflow automation
- Usage guide
- Distribution guide
- Tool comparison
- Notifications guide
- AI integrations
- Basic Node project example
- JSON output examples
- Windows smoke test notes
- Branch strategy
- Release process
- Hotfix process
- Git upload workflow
- Roadmap
- Multilingual documentation index
- Changelog
- English operations guide
- 한국어 운영 문서
- 日本語運用ドキュメント
- 中文运维说明
- Local visual HTML guides: ko, en, ja, zh
- Star or watch the repository if AIGate catches a risky push in your workflow.
- Open a real-world example issue showing how AIGate behaves in your repository.
- Share the demo GIF, terminal screenshot, or
assets/social-preview.pngwhen introducing the project. - Pick a good first issue if you want to improve docs, examples, integrations, or packaging.
Small issues are welcome. Good first contributions include docs examples, GitHub Actions examples, Homebrew/Docker validation notes, and real-world repository case studies.
npm install
npm test
npm run ciRead CONTRIBUTING.md, SECURITY.md, and CODE_OF_CONDUCT.md before opening a pull request.
MIT