Gate tools: does your gate actually say no?

Simin Yuan (袁思敏) · Independent Researcher · yleven120@gmail.com

Two zero-dependency tools with the same premise: a check that never fails is not a check, and CI staying green tells you nothing about whether anything is still being tested. Both mutate the thing under test one edit at a time, re-run your gate, and report the edits it did not react to.

Neither tool gives a verdict — on purpose. A surviving mutant is a question, not a defect: some mutations are semantically legal and a gate that rejected them would be wrong. A tool that shouted "19 defects!" would be lying to you, and you would stop believing it the second time you checked.

precheck — freeze a claim, then see what nothing is guarding

Install & run

$ pip install precheck
$ git clone https://github.com/simin-yuan/precheck && cd precheck && python demo.py

Recorded output — run 2026-10-05 at precheck@470800e

$ python demo.py
demo root: <tmp>/precheck-demo-vwghg5j0
the agent's claim is in commitments.json; the work it judges is config.json.

$ precheck register
froze 1 commitment(s) at seq=1  sha256=e2d4561aa9f0
  (exit 0)

$ precheck settle
PASS  the deployment config is valid and safe to ship

1/1 passed  (seq=2)
  (exit 0)

$ precheck audit
ran 4 mutation(s) across the declared artefacts

2 check/mutation pair(s) survived -- these prove nothing yet:
  ? C1  [blank-value on config.json]
      replicas: 3 -> 0
      the check still exited 0
  ? C1  [flip-number on config.json]
      "replicas": 3, -> "replicas": 10,
      the check still exited 0

This is a question list, not a bug list. Some survivors are legitimate.
(seq=3)
  (exit 0)

$ precheck verify
. commitments unchanged since seq=1 (e2d4561aa9f0)

3 entries; chain consistent
  (exit 0)

Read it end to end: the check passes, and then the audit shows replicas: 3 -> 0 and replicas: 3 -> 10 both still exiting 0. The commitment chain (precheck verify) proves the claim has not been quietly edited since it was frozen.

greencheck — mutation testing for validators

Install & run

$ pip install greencheck
$ git clone https://github.com/simin-yuan/greencheck && cd greencheck
$ python -m greencheck.cli mutate \
      --gate "python examples/mutate-demo/gate.py {target}/config.json" \
      --target examples/mutate-demo/input

Recorded output — run 2026-10-05 at greencheck@949484d

$ python -m greencheck.cli mutate \
      --gate "python examples/mutate-demo/gate.py {target}/config.json" \
      --target examples/mutate-demo/input
======================================================================
greencheck mutate - does your gate actually say no?
======================================================================
baseline   : examples/mutate-demo/input  (1 files)
baseline rc: 0  PASS (baseline is clean, mutating)
mutants    : 12
gate       : python examples/mutate-demo/gate.py {target}/config.json

----------------------------------------------------------------------
      caught  drop-file:config.json
      caught  empty-file:config.json
      caught  drop-line:config.json:1:{
      caught  drop-line:config.json:2:"service": "billing",
      caught  drop-line:config.json:3:"region": "eu-west-1",
      caught  drop-line:config.json:4:"replicas": 3,
      caught  drop-line:config.json:5:"owner": "team-payments"
      caught  drop-line:config.json:6:}
      caught  blank-value:config.json:2:"service":
      caught  blank-value:config.json:3:"region":
   * ESCAPED  blank-value:config.json:4:"replicas":
      caught  blank-value:config.json:5:"owner":
----------------------------------------------------------------------
caught 11 / 12

mutants the gate let through (1):
  *  blank-value:config.json:4:"replicas":

  These are questions, not findings. Some are real gaps. Some are
  mutations that are semantically legal, and a gate that rejected
  them would be wrong. This run cannot tell you which is which -
  that needs someone who knows what the gate is for.
  For each line, ask: if this had happened, why didn't the gate care?

report written: greencheck-mutate-report.json
======================================================================
verdict: the gate let through 1/12 mutants.
         That is a list of inputs to think about, not a verdict that
         the gate is broken. See the note above.

11 of 12 mutants were caught. The one that escaped — blanking "replicas" — is exactly the class of input the validator exists to reject, and the output refuses to call it a bug: it hands you the line and the question.

Where to look next

ArtifactLink
precheckgithub.com/simin-yuan/precheck · PyPI
greencheckgithub.com/simin-yuan/greencheck · PyPI
greencheck case study & telemetryyleven/greencheck-mutation-case-study
gatecheck (the same idea, inside an audit log)yleven/self-auditing-agent-forensics
author's papersZenodo 10.5281/zenodo.21200851 · Research Square 10.21203/rs.3.rs-10651733/v1

Transcripts above were produced by running each repository's own demo on 2026-10-05 at the commits shown; nothing is illustrated or retyped. Licence: MIT (both tools).