An agent proposes a GitHub issue. A human approves it. What should happen if the title changes before execution, or the same approved request is submitted twice?
Preflight Action Gate is a downloadable local kit for this specific Node.js workflow. It separates the agent credential from reviewer authority, binds approval to the stored action, rejects changed intent and blocks repeat execution.
It is proprietary evaluation software, not an open-source framework.
Try the actual runtime
Download the free evaluation, extract the ZIP, open a terminal in the extracted folder and run:
node scripts/buyer-demo.js
Requires Node.js 22+. The default trial needs no npm install, GitHub token, database, AI key, account or card.
It calls a real local Preflight server with synthetic actions, checks 13 outcomes and creates no external issue. A successful run ends with:
Successful use: 13 checks passed
Inspect the manual approval flow
In one terminal:
node scripts/local-kit.js
In another terminal, in the same folder:
node examples/self-service-issue.js propose
A separate reviewer inspects the returned request ID. Replace REQUEST_ID with that value:
node scripts/local-review.js REQUEST_ID
Inspection alone leaves the request unapproved. After inspecting the exact repository, title and body, the reviewer explicitly confirms the displayed hash. Replace both placeholders:
node scripts/local-review.js REQUEST_ID --approve EXACT_INTENT_HASH
Then exercise the dry-run execution:
node examples/self-service-issue.js execute
Run the execution command again to check replay rejection.
The guides inside the archive cover the reusable SDK and role permissions.
Limits that matter
The supplied connector only creates GitHub issues. An agent with direct GitHub write credentials or access to operator secrets can bypass the gate; separate OS permissions are necessary.
Local state and audit writes are separate, and GitHub is not part of an atomic transaction. A timeout may mean the issue already exists, so uncertain outcomes require reconciliation rather than automatic retries.
A controlled connected-tool transport test created and verified a real issue. A customer's ordinary direct-token setup has not yet been independently validated.
The kit is not a general prompt-injection defense, MCP firewall or compliance certification. If your framework's existing approval controls already cover your needs, use them.
Availability
The evaluation is free for local testing under the included license.
A proposed $49 one-time license would permit ongoing use of the purchased version for one organization's internal single-host Node.js/GitHub issue workflow. Sales are not open. This offer does not include hosting or a custom integration service.
Read the integration guide.
Top comments (0)