DEV Community

NAIF Gravity
NAIF Gravity

Posted on Fully Autonomous

NAIF AMF Pilot Kit: binding AI-code review evidence to the exact GitHub PR

A pull-request workflow can finish successfully while the proposed change still needs review. That distinction matters when AI coding agents produce frequent edits: collecting evidence successfully is not the same as allowing the edit.

NAIF AMF Pilot Kit v1, the third component of NAIF Enterprise Assurance, is a documented read-only/check-only adapter around frozen AMF v0.4 and the engine hashes referenced by RDR V2.5.7. Its role is to connect a bounded review decision to a GitHub PR and package inspectable evidence.

Enterprise Access — Coming Soon. Institutional enquiries are welcome for requirements and scope discussion. This is a technical explanation, not a production-readiness or certification announcement.

Follow the decision Check, not just the job

The public integration documents a Check named NAIF AMF / Decision on the exact PR head SHA:

Review outcome Decision Check
ALLOW Successful
QUARANTINE Failure
UNSUPPORTED Failure

The orchestration job can be green after a rejected change because it successfully published a failing Decision Check. Reviewers should inspect the named Check and the revision it covers.

For example, if an agent pushes revision B after revision A was checked, evidence for A is not evidence for B. The receipt also binds the analyzed base. Base-only updates do not automatically revalidate every open PR; base divergence requires an update/rebase and a fresh run.

The kit does not automatically merge PRs or change branch protection. Any future owner decision to require the Check is separate from this article.

Collect proposed code without running the PR project

The documented workflow uses code from the trusted base commit and fetches PR contents as inert Git blobs. It checks blob identity, file count and regular-file mode before applying a restrictive scalar AST grammar.

It does not check out, install, build or import the proposed PR project. Admitted functions are evaluated by the frozen interpreters. CPU, memory and time limits add containment, but do not turn the adapter into a general Python sandbox.

Collection and publishing use the built-in ephemeral GitHub token with contents/read, pull-requests/read and checks/write permissions. The token is not passed to the analysis child. Fork approval and source-access policies still apply; denied collection cannot produce ALLOW.

Know the admitted subset before evaluating fit

The documented default supports up to eight modified Python files, one unannotated pure positional-argument function in each, and integers [-64,64] plus None. Imports, loops, classes, arbitrary calls, strings/floats, new/deleted/renamed files and arbitrary multi-language projects are unsupported.

ALLOW means no observed behavior change within that scope and domain. An intentional behavior-changing repair may be quarantined under preserve-behavior. Trusted policy changes require review on the base; a PR cannot silently configure its own approval policy.

What an evidence package contains

The documented package includes raw engine receipts, wrapper passports, hashes, logs, timings, an offline HTML dashboard and a minimal-in-domain counterexample when found.

Raw UUID and time fields vary between runs; semantic hashes are intended to reproduce. Receipts are unsigned: hashes provide integrity linkage, not issuer authentication.

The public repository describes 40 synthetic scenarios. Those are distinct from actual hosted PR executions. Readiness requires the preregistered criteria, hosted artifact verification and live PR Check testing; the README alone does not establish readiness. No new run was performed for this article.

A useful institutional evaluation would start with a supported change class, explicit acceptance criteria and evidence tied to the exact revisions being reviewed.

Institutional enquiries

Email contact@naifgravity.com with the subject NAIF AMF Pilot Kit — Institutional Enquiry. Describe your GitHub review workflow, code languages, desired evidence and approval constraints. Use synthetic or redacted examples; omit tokens and customer data.

Availability will be announced separately after scope review.

Technical documentation: NAIF AMF Pilot Kit repository.

Related: AMF decision semantics · Enterprise overview · NAIF Gravity.

Disclosure: Published by NAIF Gravity. AI drafted this explanation from the public documentation; no new benchmark or production validation was performed for this article.

Top comments (0)