AI coding agents can make large changes to a repository very quickly.
But an important question remains:
Did the agent actually change only what it was supposed to change?
I built Vericore to explore this problem.
Vericore is an open-source verification layer for AI-assisted development.
The workflow is:
Understand → Prepare → Agent Changes → Verify
Before the agent changes code, Vericore builds repository context and creates a Change Contract.
After the agent finishes, Vericore verifies the resulting changes against that original contract.
It can check things like:
- Repository scope
- Unexpected files
- Architecture
- Dependencies
- Contracts
- Tests
- Change impact
For example, if an agent was supposed to modify:
PaymentService.kt
PaymentValidator.kt
PaymentServiceTest.kt
but also changes:
PaymentDatabase.kt
Vericore can flag that unexpected change.
Vericore also provides an MCP server, allowing AI agents to use its repository intelligence and verification capabilities.
GitHub: Vericore
I'm building this in the open and would love feedback from developers working with AI coding agents.
What else should an AI-agent verification layer check before a code change can be trusted?
Top comments (0)