KDD: deterministic contracts + mechanical verification for agent-built code #4799
MauricioPerera
started this conversation in
General
Replies: 1 comment
|
Cross-reference: the |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
KDD — Knowledge-Driven Development
Repo: https://github.com/MauricioPerera/KDD
A methodology (with a working, MIT-licensed template repo) for governing code built by ephemeral AI agents with deterministic contracts and mechanical verification — no LLM in the required path. The thesis, in one line from the repo's own docs: the agent that implements is never the same one that decides "this is correct." Only real command output counts, never the agent's own word.
The three pillars
.mdunderknowledge/with required YAML frontmatter (type,title,description,tags), one of 4 valid types (Task Contract, Data Model, Architecture, Concept), linked fromindex.md(an unindexed node is orphaned), content is linked not duplicated.intent/target/signature/test_command, a frozen oracle (tests_sha256— the implementer can't quietly rewrite the tests to make broken code pass), and atouch_onlyperimeter checked against the realgit diff, not a prompt instruction the model could ignore.Two-level validation
Level 1: 18 mandatory gates, pure-stdlib Python, no network/LLM/subprocess except two documented exceptions (one of them is literally "run the test_command and check the exit code"). Level 2 (optional): a real cyclomatic-complexity gate via an MCP server with tree-sitter backends for 13 languages.
Why it exists
Compared to
AGENTS.md-only setups (no verification mechanism of their own) or QA-by-another-LLM approaches (still model judgment, not a deterministic check), KDD's bet is that "the agent quietly drifted out of scope and nobody noticed" is a real risk worth the extra weight — while admitting it's overkill for a trivial one-person prototype.Practical entry point for this community specifically
If you're running agents through
dsh, there's a companion plugin —kdd-gates(announced separately in #4797) — that exposes the gates as native Tools (kdd_validate,kdd_seal,kdd_perimeter,kdd_preflight) instead of shelling out by hand.To try KDD standalone: clone the repo, run
python scripts/init_project.py --applyto strip the example artifacts and turn it into your own project (keeps the gates/tooling), thenpython scripts/preflight.pyto see all 19 gates run.All reactions