# Agentic coding verification kit

> Made by CoEdify ([coedify.com](https://coedify.com)). Free to use and share.
> The method behind it: [How to verify agent-written code before production](https://coedify.com/insights/control-system-for-agent-written-code/).
> To have it set up in your own repository: [CoEdify agentic development](https://coedify.com/services/agentic-development/).

Use this kit when a coding agent writes production code, tests, or a completion
summary. The kit gives a reviewer evidence that is independent of the agent's
claim that the work is complete.

## Files

1. `repository-agent-rules.md` - paste this block into the repository's existing
   `AGENTS.md`, `CLAUDE.md`, or equivalent instruction file.
2. `pull-request-template.md` - copy this file to
   `.github/PULL_REQUEST_TEMPLATE.md`, or merge its evidence section into the
   repository's existing pull-request template.
3. `independent-review-prompt.md` - give this prompt to a new Codex or Claude
   Code session that did not implement the change.
4. `github-worktree-verification.md` - create a disposable worktree for the
   independent review. The Docker Compose steps are optional.

## Minimum adoption path

Start with one release-critical behavior such as authorization, billing, tenant
isolation, consent, or an irreversible state change.

1. Add the repository rules.
2. Add the pull-request evidence section.
3. Run the review prompt in `READ_ONLY` mode in an independent agent session.
4. Review the proposed negative control.
5. If the proposed break is safe, run the prompt in `NEGATIVE_CONTROL` mode in a
   disposable worktree. Require the test to fail for the expected reason and pass
   after restoration.

Do not use this procedure as a substitute for threat modeling, security review,
load testing, or human approval. It tests whether a named safeguard detects one
specific failure.
