Open source / MIT6Independent verification for AI-coded software

Test whatyour AI didn’t.

THE TRUST GAP

AI can change the implementation and the tests that judge it.

MaruCheck keeps an independent record of approved behavior, then challenges every change against it.

npm i -D marucheck@0.5.0
See the decision unfold ↓
AI SAID “DONE” / MARU STARTED CHECKING RELEASE BLOCKED
MARU / VERIFYfeat/subscription-limits ANALYZING
AGENT PATCH2 files changed
src/subscriptions/limits.ts+1 −1
 export const limits = {- FREE_LIMIT: 5,+ FREE_LIMIT: 10, PRO_LIMIT: Infinity }
CODING AGENT

Implementation updated. Existing tests pass.

VERIFICATION SEQUENCERUN-1048
  1. 01
    Diff classifiedbusiness-logic · billing
    DONE
  2. 02
    Risk assessedcontract + historical signals
    HIGH · 72
  3. 03
    Contract checkedsubscription-management#SUB-001
    CONFLICT
  4. 04
    Evidence normalizedexpected 5 · observed 10
    1 FINDING
$maru verify --diffAnalyzing changed behaviorVERIFICATION GATE: BLOCKED
Fits the tools already doing the work

Codex

Claude Code

Cursor

GitHub Actions

Vitest

Jest

Playwright

DEFINITION

What is MaruCheck?

MaruCheck is an open-source verification tool that independently checks whether AI-generated code still satisfies approved product behavior. It records the behavior a release must preserve in reviewed Quality Contracts, then challenges every Git diff against that record — instead of trusting the test suite the coding agent just rewrote.

Category
Independent verification for AI-generated code
License
MIT, free and open source
Install
npm i -D marucheck@0.5.0
Requires
Node.js 24+, npm 11+, Git
Runs
Locally or in your own CI runner — no source upload
Works with
Codex, Claude Code, Cursor, GitHub Actions, Vitest, Jest, Playwright

01 — THE BLIND SPOT

AI writes software fast.

A green suite can still prove the wrong product.

02 — UNDER PRESSURE

One change enters.
Every assumption gets challenged.

Scroll through a real MaruCheck decision. The proof changes because the state changes.

MARU / LIVE VERIFICATION RUNNING
00.00 / Patch capturedThe agent changes the limit.

2 files · billing logic

STEP 01 / 05
00.00 / Patch captured

The agent changes the limit.

The implementation moves from five to ten. The existing tests still pass.

2 files · billing logic
00.17 / Intent loaded

The contract remembers five.

Approved behavior remains independent of whatever the implementation currently returns.

subscription-management#SUB-001
00.31 / Risk compounded

The change is not treated equally.

Path sensitivity, contract criticality, and changed-test coverage produce an explainable score.

contract + billing + blast radius
01.08 / Memory recalled

An old failure returns to the plan.

A confirmed historical bug forces its regression test back into verification.

MEM-0143 · related regression
03.42 / Decision reached

The release stops with a reason.

MaruCheck reports the semantic conflict instead of silently changing approved intent.

expected 5 · observed 10

03 — SEMANTIC DRIFT

The tests adapted.
The promise did not.

src/billing/limits.ts1 semantic change
− FREE_LIMIT = 5+ FREE_LIMIT = 10
SEMANTIC CHANGE DETECTED
Expected
Free users may create 5 projects.
Observed
Free users may create 10 projects.
OWNER APPROVAL REQUIRED

04 — QA MEMORY

A bug should only surprise you once.

When related code changes again, MaruCheck recalls the failure and forces its regression back into the plan.

How memory is matched
MEM-0143

Invoice ownership bypass

Missing server-side account check.

RELATED PATH CHANGED
REGRESSION RECALLED

cross-account.test.ts

Forced into this verification plan.

05 — AGENT BOUNDARY

Let the agent call the verifier.
Don’t let it approve itself.

Codex, Claude Code, Cursor, and compatible MCP clients can run MaruCheck and read structured evidence. Approval remains human-owned.

Connect an MCP client
CODEX → MARU MCP CONNECTED

CODING AGENTI changed invoice authorization. Existing tests pass.

TOOL CALLmaru_run_verification
{ "diff": "working-tree", "evidence": true }
RESULT / 1.42sBLOCKED

Cross-account regression reproduced.

invoice-access#INV-001 · critical

06 — LOCAL EXECUTION

The check runs where
the change lives.

Source and secrets stay in the repository or CI runner. MaruCheck produces reviewable evidence under .maru/.

maru — local verificationstdio / trusted

~/project main*

$maru verify --diff

01Verification gate: BLOCKED

02[CRITICAL] BLOCKING · invoice-access#INV-001

03Expected: Users can only read invoices owned by their account.

04Actual: Cross-account invoice payload returned.

05Reproduce: npx vitest run tests/regressions/cross-account.test.ts

06Report: .maru/artifacts/runs/RUN-1048/report.json

07 — RELEASE PROOF

Not another confidence score.
A decision with receipts.

YOUR REPOSITORYCode · tests · secretsLOCAL
MARUCHECKContracts · findings · evidenceINSPECTABLE

08 — COMMON QUESTIONS

Common questions

What is MaruCheck?
MaruCheck is an open-source verification tool that independently checks whether AI-generated code still satisfies approved product behavior. It records the behavior a release must preserve in reviewed Quality Contracts, then challenges every Git diff against that record — instead of trusting the test suite the coding agent just rewrote.
Why isn't a passing test suite enough for AI-generated code?
A coding agent can change the implementation and the tests that judge it in the same commit, so a green suite only proves the code agrees with itself. MaruCheck keeps approved behavior in a separate, human-owned Quality Contract, so a passing test run cannot quietly redefine what the product promised.
How does MaruCheck verify a change?
MaruCheck reads the real Git diff, scores risk on a deterministic 0-100 scale, builds a requirement-linked verification plan, recalls confirmed regressions from QA Memory, runs the targeted checks, and writes reproducible evidence under .maru/. The result is a ship-or-block decision with receipts, not a confidence score.
What is a Quality Contract?
A Quality Contract is a reviewed YAML file recording durable product behavior: the feature, its criticality, accountable owners, requirement statements with stable IDs, and an evidence policy naming which requirements block a release. Owners approve it, and it is versioned whenever product intent genuinely changes.
What is semantic drift detection?
Semantic drift is when code changes meaning while its tests are updated to keep passing. MaruCheck compares the observed behavior of a diff against the approved contract statement — for example a free-plan limit moving from 5 to 10 projects — and requires owner approval before that changed promise can ship.
Does MaruCheck send my source code to a server?
No. MaruCheck runs locally in your repository or inside your own CI runner, so source code, tests, and secrets never leave that boundary. Verification output is written to the .maru/ directory in the repository, where you can read, diff, and review it like any other file.
Can AI coding agents run MaruCheck themselves?
Yes. MaruCheck ships an MCP server, so Codex, Claude Code, Cursor, and other compatible clients can inspect contracts, assess risk, and run verification as tool calls. The agent may request the check and read structured evidence, but approving a contract change stays human-owned.
Is MaruCheck free and open source?
MaruCheck is free and MIT licensed. The CLI is published on npm as the marucheck package, and both the verifier and this web application are public repositories you can read, run, fork, and contribute to before trusting either one in a release path.