deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Vericore checks AI coding agents against a change contract before you trust the diff

A developer has released Vericore, an open-source verification layer that records a change contract before an AI coding agent runs, then flags edits that fall outside it.

Vericore checks AI coding agents against a change contract before you trust the diff

A verification layer built around a pre-set contract

A developer writing on dev.to has introduced Vericore, an open-source tool designed to answer a deceptively narrow question about AI-assisted coding: did the agent modify only what it was asked to modify? As the author notes, coding agents can rework large stretches of a repository within seconds, and that speed tells you nothing about whether the edits stayed inside the intended scope.

Vericore's answer is what it calls a Change Contract. Before an agent touches anything, the tool digests the repository's context and writes down what an acceptable change for the task should look like. Once the agent has finished, Vericore audits the resulting diff against that earlier record. Because the expectation was fixed before any code was generated, the verdict is anchored to a plan rather than to after-the-fact reasoning about whatever the agent happened to produce.

Understand, prepare, change, verify

According to the dev.to post, the workflow runs in four stages: understand, prepare, agent changes and verify. The first two stages happen before a single edit is made, with Vericore building its model of the repository and formalising the contract. The third stage belongs entirely to the coding agent. In the final stage the tool steps back in and checks the actual changes against the plan.

The verification pass covers several dimensions, which the post lists as:

  • repository scope
  • unexpected files
  • architecture
  • dependencies
  • contracts
  • tests
  • change impact

The post illustrates the idea with a payments example. Suppose an agent is meant to work on PaymentService.kt, PaymentValidator.kt and PaymentServiceTest.kt, but also quietly edits PaymentDatabase.kt along the way. That collateral edit is easy to miss if a human reviewer only looks at the files they expected to change, and it is precisely the kind of deviation Vericore is built to surface.

Exposed to agents over MCP

Vericore also ships as an MCP server, meaning AI agents can call its repository intelligence and verification features directly instead of the tool acting purely as an external gate. In principle this would let an agent check its own work during a task. The post does not go into detail on how tightly that feedback loop is wired up at this stage.

Early days, built in public

Some context is worth keeping in mind. The announcement is first-party: it comes from the project's own developer on dev.to, with no independent benchmarks, adoption figures or third-party evaluations cited. The author describes the effort as an open, work-in-progress project and is explicitly asking developers who work with coding agents what else a verification layer should check before a change can be trusted.

Why it matters

Trust is arguably the main bottleneck holding back autonomous coding agents. Even when agents produce correct code, reviewing their output means wading through diffs that are too large to read line by line, and an agent that drifts beyond its instructions can introduce risk without anyone noticing. A contract-based approach reframes that review: instead of scrutinising every change, a human checks whether the changes deviate from a declared scope. It also complements existing safety nets. Tests catch incorrect behaviour in the changes you wanted; scope verification catches unwanted changes that may still pass every test. If the pattern catches on, it is easy to imagine verification hooks of this kind becoming standard in CI pipelines and agent harnesses. Open questions remain, though — notably who authors the change contract, how granular it can be, and how the system handles legitimate work that genuinely requires touching files outside the initial plan.

  • #ai-agents
  • #developer-tools
  • #open-source
  • #code-review
  • #mcp

Related posts