@veritack/pi-veritack
Minimal evidence and risk control for coding agents. Verify the run. Hold the course.
Package details
Install @veritack/pi-veritack from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@veritack/pi-veritack- Package
@veritack/pi-veritack- Version
1.3.1- Published
- Jul 23, 2026
- Downloads
- 144/mo · 11/wk
- Author
- gchigoo
- License
- MIT
- Types
- extension, prompt
- Size
- 364.8 KB
- Dependencies
- 0 dependencies · 1 peer
Pi manifest JSON
{
"extensions": [
"./extensions/core.ts"
],
"prompts": [
"./prompts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
Veritack
Verify the run. Hold the course.
Veritack is a minimal evidence and risk control layer for coding agents.
It does not tell the agent how to work. It ensures that "done" is backed by current evidence.
The default workflow is:
Orient → Change → Prove → Close
Everything else is an extension.
Install (Pi)
pi install @veritack/pi-veritack
# or, from a checkout:
pi install /absolute/path/to/veritack
pi install -l ./path/to/veritack
Package: @veritack/pi-veritack (Pi peer: @earendil-works/pi-coding-agent >=0.80.0 <0.90.0).
In a repo:
/veritack init
/veritack start fix redirect query loss after login
/veritack status
/veritack record incident Avatar cache | clear current-user query on logout
/veritack finish
Prompt template:
/veritack-fix user still sees old avatar after logout
Status
v1.3.1 — Brand rename to Veritack + Provider Truth (semantic cases, non-executing check rejection).
Stability surface
- Command surface:
/veritack …only - Provider API:
@veritack/pi-veritack/provider-api+apiVersion: 1/defineProvider - Independent packages:
@veritack/postgres,@veritack/monorepo,@veritack/rust - Config:
policies/ structured or/regex/CheckMatcher; bare substring matchers rejected - Closure: current-revision evidence;
--waive/--abandonexplicit exits - JSON / Why:
/veritack status --json/--why - Long sessions: threshold compact of RunState;
veritack/contextsummary by default (VERITACK_CONTEXT_AUDIT=fullfor full text) - Package exports: only
./provider-apiand./package.json
npm run verify
npm run verify:dist
npm run smoke
npm run smoke -- --dist
npm run dogfood:adversarial
npm run dogfood:runtime
npm run dogfood:host -- --cwd . --profile veritack
Config highlights
{
"guidance": "standard",
"policies": {
"dangerousCommand": { "risk": "guarded", "action": "confirm" },
"dependencyChange": { "risk": "guarded", "action": "confirm" }
},
"checks": {
"default": ["targeted-test", "diff"],
"guarded": ["test", "typecheck", "lint", "diff"],
"commands": {
"test": { "kind": "package-script", "script": "test" },
"unit-smoke": { "kind": "regex", "pattern": "/^make\\s+smoke(?:\\s|$)/i" }
}
},
"providers": [
{
"id": "postgres",
"spec": "@veritack/postgres",
"required": true,
"priority": 100
}
]
}
Writing a provider
Depend only on @veritack/pi-veritack/provider-api. Do not import src/*.
import { defineProvider } from '@veritack/pi-veritack/provider-api';
export default defineProvider({
apiVersion: 1,
id: 'postgres',
capabilities: ['policy', 'check'],
policies: {
inspect(action) {
return [];
},
},
});
Ship a provider-cases.json with accept/reject (checks) or expectTriggers (policies).
npx veritack-provider-test ./index.mjs --cases ./provider-cases.json
npm run check:providers
Release an independent provider with tag provider-<name>-v<version> (must match that package's package.json version).
Matcher migration
Bare substring matchers are rejected. Use /regex/ or structured CheckMatcher:
{
"commands": {
"unit-smoke": "/^make\\s+smoke(?:\\s|$)/i",
"test": { "kind": "package-script", "script": "test" },
"cargo-test": { "kind": "argv", "executable": "cargo", "args": ["test"] }
}
}
- Workspace mutation →
revision+1;/veritack finishaccepts only current-revision evidence /veritack finish --waive "reason"is an explicit risk acceptance- Providers must live under
.veritack/providers/**or be a bare package name; load only after/veritack trust <spec> requiredPolicyProvider failure blocks mutation; optional failure is warning + session disable/veritack doctoris a read-only diagnosis of config / trust / providers / run / env
Develop
npm install
npm run verify
npm run smoke
See NON_GOALS.md, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md.